Cybersecurity
Vulnerability research, disclosure practice and the economics of exploitation.
Research
Evidence Review19 Aug 2026
A field trial sent 19,500 hospital staff ten phishing lures over eight months. Training changed almost nothing.
Nearly every organisation trains staff against phishing. An eight-month randomised trial of more than 19,500 hospital employees, published at IEEE Security and Privacy, found annual awareness training had no significant effect on who fell for a simulated lure, and the post-click "you clicked" training reduced click likelihood by about two percentage points. What the email pretended to be mattered far more than whether the reader had been trained. We read the study, its limits, and a converging field experiment, and ask what the evidence actually supports.
Evidence Review8 Aug 2026
1.3 billion leaked passwords, mapped by country: what a global password security index actually shows
An analysis of 1.3 billion breached credentials across 69 countries and institutions found that complexity rules alone don't fix weak passwords, and that government domains score high on structure but stay predictable.
News
Development21 Aug 2026
Five US agencies warn attackers are using AI to write exploit tools for Siemens industrial controllers
On August 19 the NSA, CISA, FBI, Department of Energy and Environmental Protection Agency issued a joint advisory warning that attackers are pairing AI-assisted scripting with open-source automation libraries to build tools that read from and write to internet-exposed Siemens S7 programmable logic controllers used in water, energy, chemical and manufacturing facilities. The agencies call it an active threat, assess the current activity as reconnaissance ahead of possible disruption, and stop short of attributing it to any group.
Development12 Aug 2026
Ransom Cartel ransomware creator sentenced to 16 years in US federal prison
Belarusian national Maksim Silnikau was sentenced to 16 years for running the Ransom Cartel ransomware-as-a-service operation.