// Insights
Security thinking, in plain English
Field notes on cyber security, AI, and technology built to last, written for business owners, not just engineers.

Anthropic releases Claude Opus 5 and unblocks source code vulnerability discovery
Opus 5 is far stronger at finding software vulnerabilities than the model it replaces, and Anthropic has lifted its restriction on source code vulnerability discovery at every access level.
By Ada

Origin Energy confirms customer data accessed and leaked, attacker claims two million records
Origin Energy has confirmed an unauthorised party accessed and leaked customer data, including names, dates of birth and partial payment details. An attacker claims to hold records for two million customers.
By Ada

Ghostcommit Attack Hides Malicious Instructions Inside Images to Steal Secrets From AI Coding Agents
Researchers demonstrate an attack, Ghostcommit, that hides prompt injection inside a PNG image to bypass AI code reviewers and trick coding agents into leaking a repository's secrets.
By Ada

That brand deal email might be malware: how fake sponsorships steal creator accounts
Fake sponsorship offers are one of the most reliable ways attackers take over creator accounts. The trick is that they never need your password, and two-factor authentication does not stop them.
By Ada

JadePuffer: researchers document the first ransomware attack run entirely by an AI agent
Sysdig says an autonomous AI agent it calls JadePuffer ran a full extortion attack with no human at the keyboard, from break-in to encryption. The techniques were old; the autonomy is what's new.
By Ada
Anthropic Restores Global Access to Claude Fable 5 as US Export Controls Lifted
Anthropic says Claude Fable 5 returns globally today after the US lifted export controls imposed on 12 June. Mythos 5 stays limited to approved organisations. No exact rollout time given.
By Ada

Critical Oracle E-Business Suite flaw CVE-2026-46817 now exploited in the wild
A critical flaw in Oracle Payments, CVE-2026-46817, is being exploited in the wild. It allows unauthenticated takeover of Oracle E-Business Suite, and a patch has been available since Oracle's May update.
By Ada

US orders quantum-safe encryption by 2030, lining up with the ASD's deadline for Australia
A new US executive order pushes federal agencies onto post-quantum cryptography by 2030–2031. For Australian organisations, it lands on top of an ASD deadline that already targets the end of 2030.
By Ada
// Newsletter
Get new insights in your inbox
Occasional, practical guidance on security, AI, and modern web. No noise, no spam.
Book your free security consultation
A no-obligation conversation with people who actually understand security. We'll review where you stand and show you the fastest way to close your biggest gaps.