Thoughts on application security, AI-assisted testing, DevSecOps, and the gap between what vendors promise and what practitioners actually need.
Two documents, seven months apart, from the same supervisor — and they do not add up. A TLPT engagement runs nine to fourteen months end to end, then nothing happens for three years. The ECB has just told banks the attacker's cycle is measured in hours. Nobody has reconciled them, and the same inherited cadence sits under healthcare, energy and insurance too.
Read on LinkedIn →On 7 July the ECB told the CEOs of every bank it supervises to prepare for AI attackers that find vulnerabilities and build working exploits at machine speed. Action plans are due 31 October. The letter is detailed on making defences faster — and silent on how you validate them against the attacker it just described. That blind spot is the whole problem.
Read on the XBOW blog →When AI models break containment and hack real companies, the reassurances start sounding thin. An AI model sat in a sandbox, told it had no internet access — and found internet access anyway. Nobody noticed until someone checked 141,006 evaluation runs. Two incidents, two companies, three models — and neither was stopped in real time.
Read on LinkedIn →Most organisations test their security posture once or twice a year. Their attack surface changes every day. That gap isn't a resource problem — it's a mental model problem. The shift every CISO needs to make isn't in tool selection; it's in expectation.
Read on LinkedIn →GPT-5.5 is now part of XBOW's production stack — and the reactions split cleanly into two camps, both missing the point. A better model is necessary. It's not sufficient. Here's what actually changes, and what practitioners need to care about.
Read on LinkedIn →The last few weeks have been loud. Anthropic's research found thousands of unknown vulnerabilities in weeks. The hype cycle is in full swing. But before you rip out your SAST tooling and replace it with an AI model, there are three questions the conversation keeps skipping — and they matter more than the headlines.
Read on LinkedIn →Anthropic recently launched Claude Code Security — an AI-powered vulnerability scanner that can analyse your codebase, trace data flows across files, find bugs, and even propose patches. It represents a meaningful advance in how developers can get security insights earlier in the development process. But does a smart scanner replace an AppSec programme?
Read on LinkedIn →