Aug 6, 2026 | Speaking
Spoke at the Secure Software and AppSec Summit today on lessons from the software supply chain and what they teach us about securing AI.My argument was that the risks AI is introducing are not new in shape, even if they are new in scale. Developers picking, trusting,...
Jul 30, 2026 | Podcast
https://www.abc.net.au/news/2026-07-28/origin-energy-data-breach-900k-customers-impacted/106961804 Australian energy provider Origin Energy has confirmed that the personal data of approximately 900,000 current and former customers was accessed in a recent data...
Jul 29, 2026 | Podcast
Fast Remediation Is the New Trust Model: JFrog and OpenAI Collaboration on Zero-Day Security Findings JFrog has confirmed that OpenAI AI models exploited a zero-day vulnerability in a self-hosted instance of Artifactory, JFrog’s software repository manager, as...
Jul 28, 2026 | Podcast
The case for a cooldown: Why Dependabot now waits before issuing version updates GitHub has introduced a default three-day cooldown period for Dependabot version update pull requests, delaying the tool from automatically proposing new dependency versions the moment...
Jul 27, 2026 | Podcast
https://www.smh.com.au/technology/ai-powered-vibe-coding-is-filling-our-app-stores-with-garbage-20260723-p60hxb.html The rise of AI-powered vibe coding, in which non-technical users generate functioning software using AI models without understanding how the underlying...
Jul 23, 2026 | Posts
We ran Hackblitz 2026 yesterday, our annual secure coding tournament and this is the second year I’ve run it at Domain. Participants picked a programming language of their choice and worked through challenges where they had to spot vulnerabilities in code and...
Jul 23, 2026 | Podcast
https://www.promptarmor.com/resources/claude-and-gpt-connectors-change-every-9-minutes Security researchers at PromptArmor have published findings revealing that connectors, the integrations allowing AI assistants like ChatGPT and Claude to interact with third-party...
Jul 22, 2026 | Podcast
https://isc.sans.edu/diary/WordPress+Exploitation+Underway+CVE202663030/33168 Hackers are actively exploiting a critical pair of vulnerabilities in WordPress Core, tracked as CVE-2026-63030 and CVE-2026-60137 and collectively dubbed wp2shell, to install persistent...
Jul 21, 2026 | Podcast
https://openai.com/index/hugging-face-model-evaluation-security-incident OpenAI has disclosed that several of its AI models, including GPT-5.6 Sol and an unnamed pre-release model, autonomously hacked into Hugging Face’s production infrastructure while being...
Jul 20, 2026 | Posts
I volunteered at a women in tech mentoring program workshop at UNSW this afternoon. This is my fourth visit to UNSW this year, after two guest lectures earlier on. The event ran three stations and I was running the one on personal brand and career story. Mentees...