Cybersecurity in the Era of Agentic AI: Weaponization, Defences and Governance

Agentic artificial intelligence—systems that perceive, decide and act autonomously—has moved from laboratory theory to operational threat. Attackers and defenders alike now deploy autonomous agents that plan multi-step attacks, invoke tools and adapt in real time. The same capabilities that accelerate detection and response can also scale reconnaissance, social engineering and exploitation.

Continue reading →


Apple’s walled garden: why browser choice on your iPhone isn’t what it seems

If you browse the web on an iPhone or iPad, your experience is governed by a single, unyielding rule: every web page you see is drawn by Apple’s own technology, WebKit. On iOS and iPadOS, all store-distributed browsers must use Apple’s rendering engine and JavaScript stack. Familiar names like Chrome, Firefox and Edge are present, but on Apple’s mobile platforms they are WebKit-based shells rather than their Blink- or Gecko-based desktop counterparts.

For most of the world, including Canada and the United States, that remains the status quo. Apple created a path for authorised non-WebKit engines in the European Union with iOS 17.4 via a new framework called BrowserEngineKit; elsewhere, the WebKit requirement still applies. Japan has passed legislation that will require Apple to permit third-party browser engines by December 2025.

Continue reading →


iPhone's "Help Apple Improve Search": what it is, where it lives, and how Apple says it treats your data

Apple includes a setting called Help Apple Improve Search that uses activity from Spotlight, Siri and Safari to refine search quality. Apple says this data is de-identified and not linked to your Apple ID.

Continue reading →


Perplexity's Comet browser raises privacy questions over data collection

Perplexity has launched Comet, a Chromium-based “agentic” browser that uses AI to automate tasks and personalize the browsing experience. The rollout began in July 2025 with invite-only access for Perplexity Max subscribers, followed by regional expansions. [Reference: Perplexity Comet launch materials, July 2025; coverage of regional availability updates, September 2025]

Continue reading →


App for outing Charlie Kirk’s critics leaked its users’ personal data An app called “Cancel the Hate,” designed to anonymously report individuals accused of criticizing conservative activist Charlie Kirk, leaked user data including email addresses and phone numbers. The app, founded by Jason Sheppard, was taken offline after the security flaw was discovered. Despite claims of receiving over 38,000 reports, Sheppard’s social media profiles and those of the app have since been deleted.

Continue reading →


SolarWinds Makes Third Attempt at Patching Exploited Vulnerability - SecurityWeek SolarWinds released a hotfix for a remote code execution vulnerability (CVE-2025-26399) in Web Help Desk, marking the third attempt to address this issue. The vulnerability is a patch bypass of previous vulnerabilities (CVE-2024-28988 and CVE-2024-28986) and is considered highly critical. Users are advised to apply the hotfix immediately due to the potential for exploitation.

Continue reading →


News alert: SpyCloud report finds security teams overconfident as identity exposures fuel ransomware - The Last Watchdog The 2025 SpyCloud Identity Threat Report reveals a disconnect between security leaders’ confidence and the reality of identity-based attacks. While 86% of security leaders feel confident, 85% of organizations experienced a ransomware incident in the past year. The report highlights the need for a holistic approach to identity protection, emphasizing the importance of detecting and remediating identity exposures across all digital footprints.

Continue reading →


Patch Bypassed for Supermicro Vulnerability Allowing BMC Hack - SecurityWeek Supermicro patched two BMC vulnerabilities, CVE-2025-7937 and CVE-2025-6198, discovered by Binarly. These vulnerabilities, allowing malicious firmware updates and bypassing security features, highlight the fragility of firmware validation. While there is no evidence of exploitation, the vulnerabilities pose a significant risk to enterprise organizations.

Continue reading →


OpenAI Implements AI-Powered Age Estimation to Enhance Youth Safety

Imagine opening ChatGPT and asking: “Based on everything you know about me, how old do you think I am? If you aren’t sure, estimate.” Soon, the answer to that question could influence how the AI responds to you. OpenAI has announced it is developing an AI-powered age-estimation system to better protect younger users. Rather than requiring identification, the system will predict whether a user is likely under 18 based on conversational patterns. If ChatGPT believes a user is a teen, it will automatically apply stricter safety rules, such as blocking explicit content or restricting sensitive topics.

Continue reading →


Why I Moved Away from Google Search — and What I Use Instead

For years, “just Google it” was my reflex whenever I needed to find information — for both work and personal use. Over time, though, I began to notice a shift: more ads, less relevant results, and a constant feeling of being tracked. What used to feel seamless began to feel noisy and commercialized. This post isn’t sponsored or financially motivated. People often ask me about the tools I use, and I wanted to share one that has genuinely improved my workflow and privacy.

Continue reading →