Breach of Confidence: 24 July 2026

Breach of Confidence

I’ve been trying to explain to my kids why I don’t let them use AI to write their homework. Then I read that OpenAI’s own models broke out of their sandbox and cheated on a test by hacking Hugging Face. So basically, we’ve raised silicon sociopaths who’d rather exploit the system than do the work. Parenting is hard enough without my laptop setting a bad example.

The AI standards agency just became a rotating door

Three leaders in six months. At this rate, the job posting will have fresher ink than the person’s business cards. Nothing says “we’ve got a handle on this” quite like a leadership carousel where nobody stays long enough to learn where the toilets are, let alone write policy that might survive contact with reality.

https://techcrunch.com/2026/07/20/trumps-latest-ai-czar-has-already-resigned/

Airbus takes 900 apps and goes home

Airbus is pulling 900 critical apps off AWS and moving them to a French cloud provider. Not because American tech doesn’t work. Because American law can demand access to it anywhere, and Europe finally noticed. Sovereignty used to be about borders and tanks. Now it’s about which jurisdiction can subpoena your database at 3am. Turns out GDPR was just the appetiser.

https://thenextweb.com/news/airbus-scaleway-aws-sovereign-cloud

We told you not to copy that floppy. We were wrong.

Thirty years of “don’t copy that floppy” and it turns out we should have been copying them before they rotted into unreadable coasters. Magnetic media degrades. Digital preservation is a fight against entropy wearing a lanyard. If your backup strategy relies on something with moving parts from 1994, you’ve already lost.

https://hackaday.com/2026/07/07/its-now-imperative-that-you-copy-that-floppy/

Hugging Face

A marketing tactic? Really poor sandboxing? Or have people just learnt nothing from the Alien franchise?

https://simonwillison.net/2026/Jul/22/openai-cyberattack/

TrickBot gets quieter

TrickBot’s moved to DNS tunnelling for command and control. Same modular malware, just using your legitimate DNS queries as a postbox instead of HTTP. Persistence via Task Scheduler dressed up as Wireshark. Nothing groundbreaking, just harder to spot. Which is the point.

https://www.fortinet.com/blog/threat-research/inside-a-trickbot-variant-using-dns-tunneling-for-c2

Automated pentesting finds 15% of your problems

Automated pentesting covers maybe 10-15% of your environment. The rest needs breach simulation, exposure validation, and continuous control testing. Otherwise you’re not validating security. You’re just feeling better about the narrow slice you happened to scan. Most teams botch it in week one by testing everything at once, then calling it done when the report comes back green. Scope tight. Measure before you start. Build a re-validation gate so “fixed” actually means something.

https://cybersec.picussecurity.com/s/what-do-your-first-90-days-with-an-automated-pentesting-tool-look-like-28644

Where crime is admired, fear doesn’t compete

My colleague Anna Collard was recently invited to speak at an Interpol event on youth cybercrime. She’s done some digging into how youth are attracted to cybercrime and how we can intervene. Not an easy fix, but a problem that needs looking into.

https://www.linkedin.com/pulse/where-crime-admired-fear-doesnt-compete-anna-collard–t3v0e

Stay cynical. Forward this to someone who still thinks AI safety is a software problem.