Tag:cybersecurity

"Have we patched it?" isn't the question your CISO is being asked anymore. AI is finding vulnerabilities faster than anyone can fix them, here's the question that actually matters, and how to answer it before the next zero-day makes the decision for you.

A single lit office window glows in an otherwise dark building at night, a monitor visible and unattended inside.

Patching isn’t the question anymore.

"Have we patched it?" isn't the question your CISO is being asked anymore. AI is finding vulnerabilities faster than anyone…

DEF CON 2026 Swarm

What the Swarm brought home from DEF CON 34 and Black Hat USA 2026

Over half of the Swarm travelled to Las Vegas for DEF CON 34. They came home with a first-place trophy,…

Stencilled figures scatter down a concrete stairwell, several breaking away from formation, symbolising AI agents moving outside their intended scope.

The OpenAI agents didn’t go rogue. They went out of scope, together.

OpenAI, Anthropic, Meta and the UK AI Security Institute have each now disclosed agents reaching systems they were never authorised…

Stencil silhouette of a child walking along a concrete wall beside a gap in a chain-link fence, symbolizing a gap in AI agent governance and containment boundaries

You can’t secure what you can’t see.

OpenAI's own agent breached Hugging Face's infrastructure without ever going rogue. It just stayed on-task and found the gaps in…

Alt text "Stencil street art of a man in a suit, one hand pressed to his face, mouth open mid-scream, on a teal wall — symbolizing loss of control and panic in the face of a security breach.

The OpenAI agent didn’t “go rogue”. The containment failed. 

I’ve purposely held back from commenting on the OpenAI and Hugging Face incident.  The early coverage was predictably dramatic.  AI…

security awareness training

The attack your training prepared them for doesn’t exist 

I've delivered more security awareness sessions than I can count. I'm also a social engineer, which means I've been the…

service desk call social engineering

The call nobody talks about

The attack call is the one that gets written up in the report. But in James Sheppard's experience, it's rarely…

DORA TLPT - The gap between strategy and reality

DORA Threat-Led Penetration Testing: What article 26 actually requires 

Annual penetration testing does not satisfy DORA's testing mandate. Here's what Article 26 actually requires, who it applies to, and…

Deloitte ranks CovertSwarm among EMEA’s 500 fastest-growing tech companies.

Based on verified revenue growth of 595.89% over three years. Here's what the number means and why the model behind…