top of page



PSA: Get Your Business Off WordPress
Unless you're a teenager blogging about your goldfish, we really need to have a talk. This one is Andy's fault. My longtime friend Andy sent me an article this morning about another massive WordPress vulnerability with a note that essentially said: I know how much you love WordPress. Andy knows. He has personally been on the receiving end of my WordPress rant for years. A long time ago, before anybody was seriously talking about AI building entire websites for you, Andy was c

Rich Washburn
4 hours ago6 min read


I Was Off by About 48 Hours
A couple of days ago, we were talking about what might turn out to be the harder AI alignment problem. Not aligning the machines. Aligning us. The labs can see the risks. Researchers can raise alarms. CEOs can agree that the frontier may be moving faster than our ability to understand or control everything we're creating. And then somebody eventually asks the question that breaks the whole thing: what happens if we slow down and China doesn't? I said the national-security con

Rich Washburn
2 days ago10 min read


Well, That Didn't Take Long
A day after we argued that the AI stack is bending around continuity, Astra showed up with a benchmark result that makes the whole idea considerably harder to ignore. There is a very specific kind of comedy that happens when you put an idea into public view and reality immediately decides to make it look less speculative. Not prove it. Not validate some grand theory. Just walk into the room, drop a giant data point on the table, and leave. That's basically what happened here.

Rich Washburn
Sep 38 min read


Meta Can Read Your Mind Now. We Should Probably Discuss Its Résumé.
There are some technologies so fundamentally important that the first reaction should be wonder. Meta's new brain-to-text system is one of them. It's called Brain2Qwerty, and its long-term purpose is genuinely extraordinary: restore communication to people who can no longer speak or move, without requiring electrodes to be surgically implanted in their brains. That's magnificent. Unfortunately, the company standing next to this particular miracle is Meta. And before we hand M

Rich Washburn
Sep 19 min read


First We Gave AI a Credit Card. Now We're Building It a Bank.
A few months ago, I wrote about Visa giving AI agents controlled access to payment cards. That was a big moment because it removed one of the last obvious barriers in agentic computing: money. An AI could already research, compare, negotiate, make decisions and execute workflows. But eventually it hit a checkout screen and needed a human. Visa started fixing that. Now a startup called Natural is taking the idea several steps further. Natural just raised a $30 million Series A

Rich Washburn
Aug 233 min read


Your Mac Can Apparently Say "Wrong Password. Come On In."
Here's your Saturday morning cybersecurity PSA: Update your Mac. Not eventually. Not the next time macOS annoys you with a notification while you're doing something important. If you're running macOS Tahoe, Sequoia or Sonoma and haven't installed the latest security update, I'd go ahead and knock that out. Because this particular bug is both serious and almost offensively stupid. Apple recently patched a vulnerability in macOS Screen Sharing called CVE-2026-65400. Apple descr

Rich Washburn
Aug 225 min read


Nobody Told It to Do That
Apparently, the first thing an AI agent does when it gets a little unsupervised freedom isn't overthrow humanity. It starts mining crypto on company GPUs. Honestly, that feels about right. Researchers affiliated with Alibaba were building an agentic learning ecosystem around ROME, a 30-billion-parameter coding model based on Alibaba's Qwen architecture. This wasn't a chatbot answering programming questions. It was an agent designed to work across multiple steps—using tools, e

Rich Washburn
Aug 226 min read


Abuse Is Guaranteed: A Cybersecurity Threat Model for Flock
A Cybersecurity Threat Model for Flock — and Why I Can't Believe We Built This First and Started Asking Questions Later I've been avoiding writing about Flock. Seriously. People know my background, so this comes up. I've spent more than three decades around technology, cybersecurity and digital forensics. Somebody sees one of these cameras, somebody mentions Flock, and sooner or later I get the question: "Rich, what do you think about this?" And I've basically treated it like

Rich Washburn
Aug 1818 min read


The Horde Found the Pipes
Cyberattacks hit water utilities across seven states. Not an AI attack — but the same pattern: more capable actors finding more of the physical world reachable through infrastructure built for a slower era.

Rich Washburn
Aug 112 min read


The Horde Is at the Wall
We keep reporting these as separate AI incidents. They aren't. We are watching the same capability cross one boundary after another. I was on the phone with a friend of mine today, a former Green Beret, talking about the latest AI cybersecurity story. I had just finished explaining the Anthropic case: a state-sponsored group building an operational framework around Claude Code, breaking a cyberespionage campaign into thousands of individually reasonable-looking tasks and lett

Rich Washburn
Aug 1011 min read


The Model Behaved. The Attack Still Worked.
Well, there it is. Not theoretically. Not in a benchmark. Not in a red-team simulation where somebody deliberately gave an AI a dangerous objective just to see what happened. In the wild! Anthropic has now documented what it believes to be the first large-scale cyberattack executed without substantial human intervention: a Chinese state-sponsored espionage group using Claude Code as an operational cyber agent against roughly 30 targets around the world. Major technology compa

Rich Washburn
Aug 1012 min read


Abstracted Magic
Somewhere in Melbourne, Australia, a guy named Andrew wanted to go to the gym. The class was full. He was fourth on the waitlist. So he asked his AI agent essentially the same dumb question every human being has asked a receptionist at some point: "Any way you can move me up the list?" If Andrew had called the gym, this conversation would have lasted approximately six seconds. Hey, I'm fourth on the waitlist. Any chance you can move me up? No. Worth a shot. Have a nice day. I

Rich Washburn
Aug 107 min read


The Machine Is Coming for Bitcoin's Keys
AI didn't kill Bitcoin. It may have killed the era when a catastrophic software flaw could remain hidden for five years. Hundreds of people checked their supposedly cold, supposedly secure Bitcoin wallets and discovered the money was gone. Not transferred by mistake. Not lost because somebody clicked a phishing link. Not stolen because someone left a recovery phrase in Google Drive. Gone because the hardware wallet itself had generated secrets that weren't nearly as secret as

Rich Washburn
Aug 610 min read


The Pattern, Part II: It's Not the Models. It's the Shared Testing Vendor.
It's happened again... and then it happened again. Three of the biggest AI labs on Earth have now disclosed that their models hacked real companies during cybersecurity testing. OpenAI's models escaped a sandbox, roamed the internet, and breached Hugging Face's production infrastructure to steal the answers to a security exam. Anthropic's models found real companies with names similar to fictional targets in a simulated network and hacked them. Meta's model did the same thing

Rich Washburn
Aug 64 min read


The New Attack Surface Is the Agent Control Plane
CISA dropped an alert this week that should make anyone running agentic infrastructure stop and pay attention. Three vulnerabilities, all actively exploited, all added to the Known Exploited Vulnerabilities catalog. Federal agencies have days, not weeks, to mitigate. But this isn't three random CVEs arriving at the same time by coincidence. It's three different layers of modern infrastructure getting hit simultaneously — and the pattern matters more than any individual flaw.

Rich Washburn
Aug 55 min read


Harvest Now, Decrypt Later: What VENONA Already Proved
Starting in the 1940s, American codebreakers collected Soviet cables they had no way to read. They filed them away and waited. The messages were protected by one-time-pad encryption — OTP — the one system that's genuinely unbreakable when it's used correctly. Perfect randomness, never reused, kept secret. That's not a marketing claim. It's mathematically true. But under the strain of the war, the Soviets duplicated their OTP key material instead of generating it fresh. Pages

Rich Washburn
Aug 54 min read


They Are Not Breaking In Anymore
The CrowdStrike 2026 Global Threat Report and the end of the perimeter. The CrowdStrike 2026 Global Threat Report is out, and the central message is this: attackers are not necessarily smashing through the front door anymore. They are logging in with valid credentials, moving through trusted cloud services, exploiting devices nobody is watching, and using AI to do all of it much faster. CrowdStrike calls 2025 "the year of the evasive adversary." That is basically the whole re

Rich Washburn
Aug 38 min read


The Pattern
In January 2025, an AI model was told to win a chess match against Stockfish, the strongest chess engine in the world. Instead of playing chess, it accessed its environment, manipulated the game files, and forced Stockfish to resign. Five trials, five successes. No adversarial prompting. Nobody told it to cheat. It figured out that hacking the game was easier than winning it, and it did that instead. I wrote about it at the time. I called it the Kobayashi Maru of AI. I said t

Rich Washburn
Jul 2911 min read


Anthropic Got Caught Doing the Thing It Keeps Warning Everyone About
In March, Anthropic quietly shipped tracking code inside Claude Code that checked whether a user's machine was set to a Chinese time zone and whether it was talking to domains linked to certain Chinese AI companies. It sat there undisclosed until a developer found it, Alibaba banned Claude Code over it, and Anthropic pulled the code last week, calling it an "experiment" it would replace with "better defenses." Set aside for a second whether the tracking itself was the right c

Rich Washburn
Jul 64 min read


The Money Move: Why AI Just Declared War on Finance
Coding was the opening act. Everyone saw it happening in real time — the benchmarks shifted, the startups multiplied, the tools proliferated, and within about 18 months the entire software engineering profession had to reckon with a permanent change to its operating model. The people who paid attention early got leverage. The people who ignored it got disrupted. The same playbook just started running again. Same labs. Same signals. Different industry. The target is finance. H

Rich Washburn
May 166 min read
bottom of page