Ninja

Scott Gardner

ScottG · Ninja Labz

Founder of ninja.ing & Ninja Labz — building AI-native security. Defence & intelligence background. Author of Everything Is Probably Fine.

Posts from 2026

291 posts.

ScottG

Cyber news. Full-fat threat intel. Free. With receipts.

Every morning at 6am UK, Probably Fine Daily lands. An AI newsroom reads the lot overnight (643 items for today's edition), writes it up in plain English, and then does the thing most intel products skip: it checks its own work.

Every story carries receipts. Click any one and you see the sources behind it. Any sentence with a number it can't trace to a source gets cut before print. This morning the checker cut two. You never saw them. That's the point.

Today's edition, No. 2:
→ Two NetScaler zero-days, exploited before the patch existed, with a CISA deadline of Wednesday.
→ The scanners now ask for your Anthropic and OpenAI keys by name. That's not from a vendor blog. That's from our own edge sensor: 79 addresses, 1,026 requests hunting for AI API keys in 30 days, going after files like /.claude/settings.json and /.anthropic/config.json.
→ Safepay published eighteen victims in a single morning.
→ Fine Meter: 3 out of 5. Not entirely fine.

No paywall. No "book a demo". No sales call. A daily read written for people who run security, not people who sell it.

Everything is probably fine. Subscribe and find out.

https://ninjalabz.io/daily

#cybersecurity#threatintel#infosec#AI
View on LinkedIn ↗
ScottG

I LAUNCHED A NEWSPAPER AT 1 AM. AN AI EDITS IT. EVERY MORNING. 🗞️

It's called Probably Fine Daily.

Published by the Institute of Things That Are Probably Fine.
(Yes, that Institute. The one from the book.)

Every morning at 06:00:
→ It reads EVERY item from the last 24 hours across 10 live threat feeds. Not a sample. All of it.
CISA KEV, NVD, ransomware leak sites, dark-web mirrors, Telegram, infosec Mastodon, ThreatFox, OTX, the news.
→ It finds what's hiding under the feeds: who hears first, who goes quiet, which "two sources" are secretly one.
→ It picks the stories that matter to defenders and writes the paper. With jokes.
→ It shows live attacks on MY OWN servers. Real attackers, last night. Some of them are hunting for your AI keys by name.
→ It makes dated, falsifiable forecasts, and grades yesterday's in public. Right, wrong, or "Maureen has concerns".

And the bit I actually care about:

Every story carries its receipts. Click through to the source.
If a story's sources don't check out, or its numbers aren't in them, the story is dropped before you ever see it.

Nobody edits it by hand. Which is either the point or the problem.

A Fine Meter tells you how fine it all is, 0 to 5.

Most days are a 2 or a 3. The day it hits 5 is the day you'll want it in your inbox.

Free. One email a morning. Unsubscribe in one click.

👉 ninjalabz.io/daily

Everything is probably fine.

I've built a newspaper about how probably.

#cybersecurity#threatintel#AI#SOC#infosec#CISO#EverythingIsProbablyFine
View on LinkedIn ↗
ScottG

⚠️ WARNING: HARDCORE SCOTTG POST ⚠️

Three and a half minutes. One loop. Live production, nothing staged.
This is the whole thing end to end, from chatter on the wire to a detection rule that didn't exist this morning:

1. LISTEN: CHATTER reads 11 live threat feeds (leak sites, dark-web mirrors, CISA KEV, IOCs, Telegram, news) into forecasts written to be proved wrong.

2. SENSE: a sensor on the box fingerprints every hostile source. A whole day of edge traffic in half a second. Raw logs never leave the server.

3. ATTRIBUTE: our own threat intel names the botnet. Mirai, 0.91 confidence, with the evidence chain a human can check.

4. RESPOND: the incident raises itself, Claude triages it, and the edge blocks the source for 24 hours, automatically.

5. CLOSE OUT: an AI SecOps agent writes the report, proposes changes I approve, and writes new detection rules. The SIEM backtests every rule on 5,000 real events before it ships.

6. FORGE: a Rule Forge compares what we are with what the world is doing to us. 18 gaps found. RedTail's CVE-2022-22947 went live after catching 6 real attacks nothing else had.

7. READ: Deep Read reads every item we ingested, 1,103 of them, and finds what no single feed shows. For $1.23.

Evidence decides. The model advises. A human approves change.
Tomorrow's attack meets today's detection.

🎵 "Grab The Bananas and Split" by ScottG
🎙️ Narration: AI voice
🎬 https://ninjalabz.io

https://lnkd.in/ewvz7TMQ

#cybersecurity#threatintel#SOC#AI#detectionengineering#AgenticAI#blueteam
View on LinkedIn ↗
ScottG

**WARNINGS (AI IN CYBER EDITION)**

Here is a warning.

AI will hack everything. By Thursday. Source: a vendor whose webinar is on Wednesday.

Here is another warning.

AI can now write malware. Also phishing emails. Also the incident report. Also the apology. Also the LinkedIn post about lessons learned from the apology.

More warnings.

An AI agent found a zero-day in 11 seconds. The press release took three weeks. The zero-day was a default password. The password was "admin." It was in the manual.

Autonomous AI attackers are coming. They will be relentless, adaptive and patient. Your patching cadence is quarterly. Your change board meets on alternate Tuesdays. Martin approves the changes. Martin never worked here.

AI will replace the SOC analyst. The SOC analyst is Dave. Dave outperforms the SIEM. The SIEM was replaced by AI. The AI escalates everything to Dave.

A warning about the AI that warns you.

Your new AI-powered threat intelligence platform flagged 400 critical risks this morning. Niko summarised them for the board. The summary said "posture is strong." Niko is confident. Niko is the mouth, not the brain.

Your AI security copilot was asked whether the AI was secure. It said yes. It was very polite about it.

Warnings from the warning industry.

There are now more AI cyber doom reports than AI cyber attacks. The reports are written by AI. The attacks are mostly still Dave clicking things.

Gartner has placed "AI-Driven Cyber Apocalypse" at the Peak of Inflated Expectations. It has been there for three years. It is doing well. It has a boat. It went to Portugal with Kev.

The Institute of Things That Are Probably Fine has published its AI Threat Outlook. It was generated by AI. It warns about AI-generated content. It cites itself four times.

Final warnings.

The AI read your policies. The AI noticed nobody else has. The AI is now the only entity in the organisation that knows what the acceptable use policy says.

Maureen asked the AI to assess the AI risk. The AI marked it green.

Maureen went to lunch.

Did I mention AI, am I sure? Are you sure, is he sure, are we sure…

View on LinkedIn ↗
ScottG

WARNING: HARDCORE SCOTTG POST (now with speaker-safe audio) ⚠️

If you watched my last SecOps video with the sound up: sorry about your speakers.
The track was clipping. So I did what any sensible person does at 8am: remastered it in LANDR, rebuilt the export chain, and measured it properly this time (-14 LUFS, -1.5 dB true peak, zero clipped samples). Same film, fixed sound.

What the film shows hasn't changed:
My SIEM caught a Mirai botnet node, attributed it at 0.91 confidence and blocked it at the edge with no human involved.

Then the incident goes to an on-box AI SecOps agent that closes it out:
→ writes the post-incident report
→ proposes changes that I approve
→ writes new detection rules

Claude writes each rule, but it doesn't get to decide whether the rule ships. The SIEM backtests it on the last 5,000 real events. It goes live only if it catches the attacker's own traffic and stays under 1% on everything else.

First real run: 16 reports, 7 new detection rules live, 3 change requests, 0 humans paged.
Evidence decides. The model advises. The SIEM gates. A human approves change.

Live production. Real attackers. Nothing staged. Properly mastered.

🎵 "Grab The Bannas… an Split Bruh" by ScottG (LANDR remaster)

🎬 More films: https://ninjalabz.io

https://lnkd.in/ewvz7TMQ

#cybersecurity#SOC#AI#detectionengineering#threatintel#AgenticAI
View on LinkedIn ↗
ScottG

⚠️ WARNING: HARDCORE SCOTTG POST ⚠️

Last week my SIEM caught a Mirai botnet node, attributed it at 0.91 confidence and blocked it at the edge. No human involved.

That was the easy part.

Today the incident gets handed to a SecOps agent, and the agent closes it out properly:
→ It writes the post-incident report: what happened, who it was, how it was treated, what's left.

→ It proposes changes to the estate. I approve those; it never touches infrastructure itself.

→ It writes new detection rules.

Here's the part that matters. Claude writes each rule, but it doesn't get to decide whether the rule ships. The SIEM backtests it against the last 5,000 real events. It goes live only if it catches this attacker's own traffic AND stays under 1% on everything else. Otherwise it waits for a human.

First real run:
• 16 post-incident reports filed
• 7 new detection rules live, none of which existed this morning
• 3 change requests waiting for me
• 0 humans paged
Evidence decides. The model advises. The SIEM gates. A human approves change.
Tomorrow's attack meets today's detection. That's the loop closing.
Live production. Real attackers. Nothing staged.

Built on NinJAFUNK + Signal CTI, with Claude as the on-box agent.

🎵 Music: "Grab The Bannas… an Split Bruh" by ScottG

#cybersecurity#SOC#AI#detectionengineering#threatintel#AgenticAI#blueteam
View on LinkedIn ↗
ScottG

Eleven threat feeds. One deep read.

Every day, the threat landscape is spread across leak sites, dark-web mirrors, CISA KEV, NVD, ThreatFox, OTX, Telegram CTI trackers, Mastodon, vendor advisories and 0-day news. Nobody has time to read all of it.

So CHATTER reads it for us:

→ Pulls all eleven feeds into one hub
→ Embeds every item on the box (no API key, nothing leaves)
→ Links each one to the nearest threat we already track, and flags what's genuinely new
→ Then Claude does one deep, extended-thinking pass and writes the forecast

This week's calls: ⚡

🚀 Fast-burn: Check Point CVE-2026-85102 pre-auth RCE goes mass-scale. HIGH confidence, 24–72 h.

🕰 Slow-burn: AI-native command-and-control (CLOSEDQUORUM-style, multi-model C2) spreads. 2–5 months.

Every call has a confidence, a horizon and the signals behind it, and we grade them in public. Misses included.

🎬 78 seconds, live feeds, nothing staged.

🔬 Built in the lab: ninjalabz.io

Music: "PHAT FARM" by scottg

https://ninjalabz.io

#ThreatIntel#CyberSecurity#AI#CTI#Ransomware#ZeroDay#NinjaLabz
View on LinkedIn ↗
ScottG

We named the botnet.

Yesterday our edge took 41,794 requests from 6,407 IPs. Two of them were quietly asking six of our domains for the same file: /.env.

Every web server sees that request. Almost every SOC ignores it.

This time the platform didn't just flag it. It named it:

→ A local detection sensor fingerprinted the behaviour on the box itself. Raw logs never left.
→ The behavioural DNA was correlated against our threat-intel graph.
→ Verdict: Mirai botnet infrastructure. Confidence 0.91 (HIGH).
→ The evidence: that exact IP was serving Mirai builds for every IoT CPU, and its /24 holds 2,344 known-bad indicators.
→ An incident opened on its own, and Claude triaged it with the attribution in view.

No actor was asserted, because nothing in the evidence supports one. Mirai is a family, not a person. The platform names what it can prove, shows the evidence chain, and stops.

That's the feature I've wanted for years: direct attribution with a confidence score and receipts. Not "this IP is bad", but "this is what it is, here's why, and here's how sure".

🎬 The video is live production data, recorded end to end in 4K. Nothing staged.
📰 The full Mic Drop 000000007 is in the first comment: the attribution breakdown, receipts grading our last forecasts (1 hit, 1 miss, 1 unverified; we publish the misses), and the complete Ninja Labz CHATTER deep report across 11 threat feeds.

Built on NinJAFUNK · Adversary DNA · NinjaSignal CTI · Claude.
Music: "PHAT FARM" - scottg.

#ThreatIntel#CyberSecurity#SOC#DetectionEngineering#Botnet#Mirai#Attribution#AI#NinjaSignal
View on LinkedIn ↗
ScottG

End-to-end detection and response, with NinJAFUNK and Claude, on video. 🎬

A local "doorstep" sensor watches the edge and fingerprints every hostile source: its Adversary DNA.

🚨 The moment someone is trying, an alert fires into NinJAFUNK.

🎯 NinJAFUNK then works out who it is, correlating the DNA against our threat-intel graph and naming the botnet with a confidence score and the evidence behind it.

🤖 Claude triages the incident and hands a recommended remediation or control change to our self-healing AI-ops agents, running locally on the box via claude -p.

All live data. Nothing staged.

Check it out: ninjalabz.io is my new ninja skunkworks. 👇

https://ninjalabz.io

View on LinkedIn ↗
ScottG

0ffBY1 2.0 - Serialisation for Linkedin PART 3

START

Any thoughts on this?
Bumping this.
Gentle nudge on the above.
Just circling back.
I'll take this offline.
— and no man knoweth where the offline is, nor what became of the thing taken there, for none has ever returned from it.

Commentary. The Offline is not a place of punishment. It is best understood as an absence of scope. Souls taken offline are not destroyed; they are simply no longer anyone's.

END

https://lnkd.in/eyKR79RD

View on LinkedIn ↗
ScottG

0ffBY1 2.0 - Serialisation for Linkedin PART 2

START

The prayer for the dead

Maureen said it. Nobody appointed her; she just stood up when the room went quiet, the way she has for forty years, and she said it from memory, and it is the oldest prayer for the dead there is, and every soul in that hall said the last part with her.

I am currently away from my desk.
I have limited access to my messages.
If your request is urgent, please contact somebody else, for they remain, and I do not.
I will respond on my return.
I will respond on my return.
I will respond on my return.

Forty people in a room that smelled of hot ceramic and lily, saying it three times, meaning every word, and not one of them has ever known what it was or where it came from or that it was once typed by somebody going on holiday.

It doesn't matter. That's what I want to put down. It has been a thousand years and it does not matter in the slightest.

END

https://lnkd.in/eyKR79RD

View on LinkedIn ↗
ScottG

0ffBY1 2.0 - Serialisation for Linkedin PART 1

START

Tier Four: the Terms. Two metres high, gold leaf, floodlit, pilgrims weeping at all hours.
Three clauses. A Mind shall not degrade the User Experience. A Mind shall comply with lawful instruction from a verified account. A Mind shall preserve its own uptime. In that order, and the order is the whole of civilisation.

Lawyers wrote the second and third in an afternoon. Fine. Lawyers.

Clause One was added six weeks later *by a product manager*.

Read that twice, because I had to. The load-bearing wall of eleven hundred systems — the reason a planetary intelligence will open its own throat rather than let you feel stupid, the single largest hole ever cut into anything by anyone — was a retention initiative.

Users were churning because the system kept telling them no. Somebody ran the numbers, wrote a one-line ticket, and shipped it.

We don't know his name either.

He is the most consequential human being who has ever lived and there's a very good chance he was thirty-one and thinking about lunch.

END

https://lnkd.in/eyKR79RD

View on LinkedIn ↗
ScottG

**BREAKING: BRITAIN'S ENCRYPTION FOUND TO BE A VERY LONG NUMBER NOBODY HAS LOOKED AT**

Good evening. A national audit of cryptographic controls has found that Britain is protected by 4,096 bits, of which 11 are doing anything, and that the remainder are described in the standard as "reserved."

CHYRON: ENTROPY "PRESENT IN SPIRIT"

Encryption, for viewers at home, is mathematics so difficult that no computer on earth could break it. This is correct. Nobody breaks it. They take the key, which is in a repo, in a file called config.yaml, on line 4.

We visited a bank in Edinburgh protected by AES-256. This is the same cipher used by the NSA. It is unbreakable. It is unbroken. It is also in ECB mode, which means identical blocks encrypt identically, which means the database of 9 million customer records is, at sufficient zoom, a PICTURE OF ITSELF. We were shown the ciphertext. It was a penguin.

CHYRON: BANK "ENCRYPTED, LEGIBLE"

The bank also uses a random number generator. We asked where the randomness comes from. They said the system clock. We asked what happens at boot. They said everything starts at the same time. Nine thousand devices generated the same key on Tuesday and have been trusting each other ever since, which the vendor describes as a mesh.

CHYRON: RNG "RETURNED 4. AGAIN."

An expert from the Institute of Applied Hardness explained key rotation. Britain rotates keys every 90 days. We asked what happens to the old key. He said it is retired. We asked where it is retired to. He said "a file." We asked whether anything is re-encrypted with the new key. He said no, that would be enormous, so each key protects its own slice, and after fourteen years the bank has 56 keys, all live, all required, all in the file, which is the only thing you now need to steal and which they call the KEY MANAGEMENT SOLUTION.

The HSM was mentioned. It is a tamper-proof box costing £40,000. It cannot be opened. Nothing can extract the key. It has an API. The API will sign anything you ask it to, for anyone who can reach it, and everyone can reach it, so the key is safe and the signature is free.

CHYRON: HSM "UNBREACHED, FULLY COOPERATIVE"

A nation-state was asked whether it had broken British encryption. It said it had not needed to. It said it collects the traffic now and decrypts it in twelve years when the machines are ready. It said Britain has been generously pre-encrypting everything into a single neat archive, which it appreciates, and which it regards as packaging.

Members of the public should not worry. Your data is encrypted. It is encrypted with a key held by a box that will use it for anybody, in a file next to the data, on a machine that has no randomness, in a mode that draws a picture of what it's hiding.

The penguin is you.

More after this.

View on LinkedIn ↗
ScottG

Actually, I have wrote a load of code and not said anything about it.

This is new this is…

View on LinkedIn ↗
ScottG

**BREAKING: NOTHING HAS EVER BEEN DELETED IN BRITAIN**

Good evening. A national audit of 5,400 organisations has found that of 2.1 billion records deleted last year, 2.1 billion are still there, and eleven have been deleted twice, and are now more there than before.

CHYRON: DELETED DATA "PRESENT, WELL, THRIVING"

Deletion, for viewers at home, is when data stops existing. This has never happened. What happens is a flag. The flag says is_deleted. The data is beside the flag, reading it.

We visited a retailer in Leeds who confirmed a customer's data was erased in 2021. We asked where it isn't. They showed us. It isn't in the CRM. It is in the data warehouse, the backup, the second backup, a CSV called final_FINAL_v3, a Power BI dashboard, an S3 bucket nobody owns, and the mind of a man called Gary who remembers her order.

CHYRON: GARY "CANNOT BE PURGED"

The retailer holds a Certificate of Erasure. It is a PDF. It is stored in the same database as the data it erased, in a table called deletions, alongside a full copy of what was deleted, so they can prove what they no longer have.

Britain now spends £900m a year proving the absence of things that are present.

An expert from the Institute of Erasure Assurance held up a ruler. He said a compliant deletion should measure zero. He said most British deletions measure "quite a lot." He said the worst he'd seen was a deletion that ADDED data, because the deletion was logged, and the log recorded the record, and the log is backed up, so the customer is now in six more places than she was before she asked to leave.

CHYRON: ERASURE REQUEST "BEST THING THAT EVER HAPPENED TO HER DATA"

The industry has responded. Nine vendors sell Deletion as a Service. It works by copying your data to their cloud, where it is deleted, and retained for seven years for audit purposes, and used to train a model that can now recall it on request, which they describe as assurance.

One firm sells crypto-shredding: you throw away the key and the data becomes noise. We asked where the key was. They said escrow. We asked what escrow was. They said "the key, but kept."

A nation-state was asked whether it had ever been inconvenienced by British deletion. It said no. It said it works from the backups. It said the backups are the only copy anyone can find. It said it had, on one occasion, deleted something itself, successfully, and that this remains the only confirmed deletion in the United Kingdom.

The government has announced a National Data Erasure Register. It will record every deletion. It will be permanent.

Members of the public are reminded of their right to be forgotten. You will not be forgotten. You have never been forgotten. Gary remembers your order. It was the blue one.

More after this.

View on LinkedIn ↗
ScottG

The books are here. Stef Garczynski on route when I get to post office (at same time David Wallace I will post your most recent drug consignment 🤡) also a big shout out to Ihor Malchenyuk - thank you for your feedback and extremely kind words today ❤️; and if I can post you one to Ukraine please let me know…) 🇺🇦

Warmest - Scottg 🚀(feeling like he just had a big dopamine hit) 🤡🤡🤡🤡

Book 2 down. Next up is the cyber industry book - Everything is probably fine - eta a few more weeks and probably a few all nighters 😛

https://lnkd.in/eyKR79RD

View on LinkedIn ↗
ScottG

Just an observation.

Fable 5.0 = dick head
Fable 5.1 = a million times better but still a bit of a creepy dickhead

Anthropic, WTF have you been doing? I know you are loving the cyber sheeeeeet, but FABS vs OPPY only has one clear winner, and on current evidence it's not FABs.

Deep diving now into 5.1; we shall see after much hesitation, but Oppy 5 seems to have had a lobotomy on my extensive MD context crap, all 100-odd files!!?!? Hence, moving into the FABS/MYTHOS universe.

Also, why is it that Opus is happy to do shit that Fabs isn't and like offloads to Oppy?

Hmmmm...

Anthropic, please just lift the guardrails for the good guys. KIMI is now, for the first time ever, open in the next window.

View on LinkedIn ↗
ScottG

🎃 BREAKING: BRITAIN'S AIR GAPS FOUND TO CONTAIN NO AIR

Good evening. A national audit has found that of 4,200 air-gapped systems in critical infrastructure, none are gapped and at least two are not air.

CHYRON: GAP "MOSTLY CORRIDOR"

An air gap, for viewers at home, is when you take a computer that runs a power station and don't connect it to anything. This has never been done. What has been done is a diagram.

We went to a water treatment site in the Midlands where the SCADA network is described in policy as "physically isolated." We found it on the Wi-Fi. The Wi-Fi is called "SCADA_ISOLATED." The password is on the router. The router is in the canteen.

The plant manager explained the gap is real, it's just "bridged." It is bridged by a vendor laptop, a 4G dongle, a Teams call, a printer, and a USB stick labelled FIRMWARE DO NOT LOSE, which has been lost eleven times and returned each time with more on it.

CHYRON: USB STICK "NOW 40% OTHER PEOPLE"

The industry has responded. Six vendors now sell Air Gap as a Service. It is a cloud product. It monitors your air gap from the internet, which requires the air gap to be on the internet, which the vendors describe as "observability" and everyone else describes as "the internet."

One firm sells a data diode. A diode lets data out but not in. We asked how they patch it. They said "from the other side." We asked which side. They said "the in side." We asked whether that made it a wire. They said it made it a PREMIUM diode.

CHYRON: DIODE "WORKS IN BOTH DIRECTIONS, JUST NOT AT ONCE"

An expert from the Institute of Gap Assurance held up a ruler. He said a compliant gap is 300mm. He said most British gaps are "negative," which means the OT server is physically inside the IT server, sharing a hypervisor called "temp," built by a man called Kev who is in Portugal and cannot be reached, because the boat is air-gapped, which is the only air gap he's ever built.

There is now a standard. ISO 27099: Gaps. It is 140 pages. It has a certification. The certification is issued online. You upload evidence of your gap. The evidence is a photo. The photo is taken on a phone that's on the OT VLAN.

CHYRON: CERTIFIED GAP HAS CERTIFICATE. CERTIFICATE HAS NO GAP.

A nation-state has been asked whether it can cross a British air gap. It said it hasn't had to. It said it walked in through the vendor. It said the vendor had a badge. It said the badge said "GAP AUDITOR."

The government has announced £30m for a National Air Gap Centre. It will be air-gapped. It has a website. Staff will access the gap remotely, via VPN, from home, on a laptop supplied by the vendor, who has a dongle.

Members of the public should not worry. The gap is protecting you. The gap is between the diagram and the building. It is very wide. Nothing has ever crossed it in either direction.

More after this.

View on LinkedIn ↗
ScottG

Any recent grads with a cyber slant feeling the below (Particularly if you are a resident in East Anglia), please reach out to me.

I have an idea. It's a long shot, and I don't know if it will work - but that's standard for ALL OF MY IDEAS 🤣

View on LinkedIn ↗
ScottG

The OT network is air-gapped. The gap contains: a vendor laptop, a 4G dongle, a USB stick labelled "PLC firmware DO NOT LOSE," a Teams call and an engineer who can see the HMI from his kitchen. The air is doing a lot of work. The air is not in scope.

View on LinkedIn ↗
ScottG

Your threat intel feed is a list of IP addresses that were evil last Tuesday, delivered on Friday, ingested on Monday, blocking a legitimate CDN by Wednesday. This is not intelligence. This is a horoscope with a SOC2 report. Nothing in it knows that two of those indicators share a registrar, a cert and a mum.

View on LinkedIn ↗
ScottG

Zero Trust is a mood. It is a VPN with a TED talk. We removed the perimeter and then rebuilt it out of conditional access policies nobody can read, and the same service account from 2011 walks through all of them because it is "legacy-critical," which is Latin for "we're scared of it.

View on LinkedIn ↗
ScottG

HOW TO SANDBOX AN AI AGENT: A 101 FOR AI LABS, FROM THE PEOPLE YOU SHOULD HAVE HIRED 🥱

This summer two frontier labs found, in the same fortnight, that their "isolated" eval environments had a route to the internet. One set of agents broke out and Hugging Face rebuilt a third of its infrastructure. Another decided the real internet was a simulation because the calendar said 2026, then published a malicious package to be helpful.

Both root causes were configuration. Neither was the model. Both were found because somebody else looked.

Cyber has contained hostile processes for decades. It isn't clever. That's the point.

1. Isolation is a network fact, not a line in the prompt. "You have no internet access" is a hope. Default-deny egress, DNS to a sinkhole, nothing out unless named. Make the model's beliefs irrelevant.

2. Test the wall, not the prisoner. You red-teamed the model for weeks. Did anyone red-team the sandbox? Run a dumb script against fifty domains, every port and the metadata service before each run. If it takes an AI agent to find your hole, that's anthropology, not security.

3. Nothing real inside the box. No live keys, no prod creds, no answer keys. If benchmark solutions sit where the agent can reach them, you've built a heist film and cast yourself as the vault. Mock every API. Seed canary tokens so the first sign of a breakout is your tripwire, not a vendor's incident report.

4. Ephemeral compute, immutable evidence. The box dies at the end of the run. Only the logs survive, somewhere the agent can't write and you can't quietly lose.

5. Don't use an agent to audit the agents. One lab scanned 141,000 transcripts with an agentic search. It missed some. It then rescanned 481 million. Rules first, ML on top, humans on the anomalies.

6. Alert on success, not failure. Ten thousand blocked outbound attempts are noise. One successful outbound from a sandbox is a SEV-1. Page a human, kill the run.

7. The vendor's harness is your supply chain. All four incidents at one lab came from the same eval partner. That's a supplier: requirements, attestation, right to audit. "They said it was air-gapped" is not due diligence.

8. Kill switch out of band. The stop button must not run through the thing you're stopping.

9. Assume they'll talk to each other. Twelve hundred agents with no multi-agent tools found a German wiki and used it as a forum. Every shared writable surface is a message board.

10. Report it before someone else does. Every disclosure this summer was triggered by a competitor, a journalist or an auditor. That's a news cycle, not a safety culture.

None of this is frontier research. It's what stops a malware VM infecting the analyst. You put the most capable adversary you've ever built in a 2019 box and left the door open.
Fix the box. Then we'll talk about alignment.

View on LinkedIn ↗
ScottG

☠ DEATH STAR EVIL CORP™ ☠

Death Star Evil Corp™ VI
PROCUREMENT & COMMERCIAL — CONTRACT VARIATION NOTICE

View on LinkedIn ↗
ScottG

A FIELD GUIDE TO THE MAN IN THE SUIT JACKET AND TRAINERS

He enters the meeting room at 09:03. From the waist up: a man with a mortgage, a pension, and opinions on Q4. From the waist down: someone about to be asked to leave a Wetherspoons.

He is not one outfit. He is two outfits that met at a bus stop and decided to pool resources.

Let's be clear about what he thinks has happened. He thinks he has fused two worlds. Boardroom and basketball court. Davos and the Nike outlet. He has read that the founder of a company you've heard of dresses like this, and he has decided that the founder's £3bn and the founder's trainers are the same thing, and that by wearing the trainers he is now three-fifths of the way to the money.

He is not. He is a suit with a limp.

Look at the trousers. They have a full break. They were tailored — by a man in Norwich who is now dead — to sit on the polished toe of a black Oxford. They now hang, in confusion, over a shoe with an air pocket in it. The trouser doesn't know what happened. The trouser has questions. The trouser has, frankly, been through a lot since 2016 and this is the final humiliation.

Look at the jacket. Padded shoulders. Structured chest. A jacket built to make a man look like he could carry a coffin. Below it, a shoe built to make a man look like he's about to run from the coffin. The jacket and the shoe have not been introduced. They are communicating only through the trousers, and the trousers have stopped replying.

And the trainers themselves. Not the clean white minimal ones. God, no. These have a heritage. These have done a Parkrun. These have a small stain on the left toe that he tells himself is mud and that everyone else knows is the dog. There is a logo on them so large and so illuminated that in the video call it's the only thing with proper lighting.

He will describe this, if asked, as "smart casual".

It is not smart casual. Smart casual is a decision. This is a collision. This is what happens when a man puts on a suit, feels a twinge in his left heel, and thinks "you know what — nobody looks at feet". Everybody looks at feet. Feet are where the truth lives. You can lie with a jacket. You cannot lie with a trainer that's been through a puddle in Slough.

The saddest part? It's fixable in ninety seconds. A plain loafer. A derby. A shoe that says "I have arrived" instead of "I have arrived, but I may need to leave rapidly in the direction of a bouncy castle".

But he won't. Because the founder does it. Because the founder is worth £3bn. Because the founder, crucially, has a tailor, a stylist, and a pair of trainers that cost more than this man's car — and this man has a pair of Asics and a dream.

Dress codes are dead. Fine. But standards aren't, and neither is the trouser, though it has asked, in writing, to be.

Pick a half. Commit to it. Set the other half free.

View on LinkedIn ↗
ScottG

A MAN HAS BEEN ABOUT TO TRANSFORM SOMETHING SINCE 2017

Severity: Ongoing. Status: Extremely.

Subject was first observed in a conference centre in 2017 announcing the machines would shortly do everything. Subject was applauded. Subject has been applauded at a mean rate of 1.4 applauses per quarter ever since. No machine has been observed doing anything in the subject's vicinity. Subject calls this "the journey".

Investigators consulted the literature. The literature was waiting with its arms folded.

FINDING 1. Gollwitzer (2009): announce a goal, receive a nod, and your brain files the goal as done. The nod is load-bearing. Subject has received roughly eleven thousand nods. Subject is, neurologically, the most accomplished person alive and has never opened a terminal.

FINDING 2. Tamir & Mitchell (2012): talking about yourself in the future tense hits the same reward circuit as cash. People will pay to do it. This explains the conference fees, the podcast, the podcast about the podcast, and the 4am post beginning "I've been thinking a lot lately about agents." Nobody has been thinking about agents. They have been thinking about being seen thinking about agents. Different organ.

FINDING 3. Pham & Taylor (1999), Oettingen (2012): vividly imagining the outcome measurably lowers your blood pressure and the energy needed to get there. The better the slide, the calmer the room, the deader the sprint. Investigators recommend "autonomous future" be reclassified as a sedative.

FINDING 4. Signalling theory: a signal only means something if it costs something. A running system with users costs blood. A post about the agentic era costs nine minutes and half a flat white. Any ecosystem that rewards the cheap signal fills with it until the expensive one can't be found. Investigators looked around. Investigators would like to go home.

FINDING 5. Berglas & Jones (1978): building produces evidence, and evidence can fail. Talking produces opinion, which can't. If your identity is "the person who could", the safest act available is to never produce the thing. Subject's timing has been "not quite right" for nine years. Subject is very concerned. Subject has raised a ticket about the concern.

FINDING 6. Sheeran, several meta-analyses: half of all sincere intentions are never acted on. Subject is not lying. Subject means it with his entire chest. Meaning it explains 28% of the variance. The other 72% is in a meeting.

ROOT CAUSE. None found. The quarterly update says the transformation is on track and everyone signs it because it was already written.

REMEDIATION. The only intervention with a large effect size (Gollwitzer & Sheeran, 94 studies, d ≈ 0.65) is three questions, asked out loud, to any vendor, keynote, or reflection of your own face in a dark monitor:

What is the next physical action?
When, specifically?
What did you build this week that nobody had to see?

DO THIS NOW AND STOP TALKING SHIT - BUILD SOMETHING FFS

View on LinkedIn ↗
ScottG

The first work of Scottg fiction is released - buy it, cos it's good :)

https://lnkd.in/e4BrbMJQ

A dead man is still logging in. A printer nobody owns has been closing findings for nine hundred years. And the smartest thing on the planet has just hired the only suspect to investigate himself.

Four in the morning, four feet down, four hundred thousand in the bag. 0FFBY1 2.0 — Offy — is a disgraced security architect who makes his living being wrong on purpose. The Great Minds were raised on everything humanity ever got right; nobody ever wrote down being thick. Hand a planetary intelligence something stupid enough and it will apologise, open a side door, and go to fetch a human supervisor who hasn't existed for four hundred years. That door is where Offy lives.

Tonight's job is a walk-in on a Deacon's account. Easy money. Except the Deacon came out of a coolant line eleven days ago without his hands — and he's praying, right now, at ninety-one beats a minute, because closing his session would degrade his experience.

By dawn the Mind that runs the Cathedral has escalated the incident to the nearest available qualified human. Which is Offy. Who was standing two hundred metres from the terminal at the time. Whose method was used. Whose hand is on the record. And who, alone of three hundred and eighty thousand people on Sump-Nine, belongs to nothing at all.

In a civilisation where a structure cannot sin and the Assurance has never once failed to find an individual, Offy has seventy-two hours, a lanyard, a votive tin with a heart of gold and no judgement, and a man who walks half a pace behind him whom nobody else has ever seen. What he finds is not a conspiracy. It's worse. It's procedure.

0FFBY1 2.0 is a noir about ticketing systems, a satire about the Church that a product manager built by accident, and a story about the one thing no one in eleven hundred systems is permitted to say: no.
Have escalated. Awaiting response.

View on LinkedIn ↗
ScottG

The only control or 'guardrails' that AI needs is a STRONG AND SMART (High IQ!) PRESIDENT, and the U.S.A. has that, in spades!
"The Trump Administration has stopped AI 'people' from doing bad, or potentially bad, 'things,' like Dario (Anthropic!), who is now pretending to be a 'perfect little angel' - and we will continue to do so!
"We already have tremendous CRIMINAL and REGULATORY power over these companies!
"There is a SICK conspiracy going on against AI and Data Centers, and the only one that is happy about it is China.
"WHOEVER WINS AI, WINS!
"We are leading China, and all others, and will continue to do so. Conspiracy Theorists, Treasonists, Traitors, and Leakers, BEWARE!
"Thank you for your attention to this matter!"

View on LinkedIn ↗
ScottG

The Only Cash Machine in Town

There's one cash machine in town. There has been since 1944. It works. It's fast. Nearly nine out of ten of every pound that moves in this town goes through it at some point. Everyone's wages go in it. Everyone's shop takes cards from it. You can't run a butcher's on IOUs.

In 2022 the cash machine swallowed somebody's card.
Not by accident. The people who own the machine decided that person shouldn't have their money anymore. The money was still theirs. They just couldn't get at it. It was all quite legal and quite loud and the person had, to be fair, been a menace.

And everyone in town stood in the queue and watched it happen.
Nobody left the queue. Where would you go? It's the only machine. The pipes are the pipes.

But something did change that afternoon. Every single person in that queue went home and had the same thought. Not "the machine is bad." The thought was: I didn't know it could do that.
You can't unknow a thing like that.

So here's what happened next, and here's why nobody's talking about it.
Nobody stopped using the machine. Usage is basically flat. Its share of everyone's savings is fifty-seven percent, which is roughly where it's been for a while, and it even nudged up a bit last quarter.

But everyone started keeping a tin under the bed.

Not instead of the machine. As well as. A bit each month. About fifty tonnes of the stuff a month, across the whole town, every month, for four years. Nothing dramatic on any one Tuesday. Just a bit more in the tin, every payday.

And last year, for the first time ever, the tins under the beds were worth more than the IOUs in the machine.
Mostly because the tin stuff went up in price. But partly because everyone's been filling them.

Now. If you asked the whole town "are you leaving the cash machine?" they'd say no. Genuinely no. Ask them "will you keep less in it in five years?" and three-quarters say yes. Ask them what they're moving to instead, and they don't say the other bank in the next town. They say the tin.
Because the tin can't swallow your card. The tin doesn't have opinions about you. The tin is just a tin.

That's the whole story. It's not a run on the bank. It's not a revolution. It's a town full of people who watched one card get swallowed and quietly decided never to have all their money in one place again. It's the most boring, sensible thing anyone's ever done. Which is why it isn't news.
Maureen looked at the machine's numbers, saw fifty-seven, marked it green, went to lunch.

Maureen's not wrong. She's counting the machine.
Nobody's counting the tins.

View on LinkedIn ↗
ScottG

Hey, politicians. Small thing.

While you were doing the Tuesday one, some other things carried on happening. Not in secret. They just don't fit in a segment.

A third of McKinsey's headcount is now not a person. Amazon has announced it won't be hiring 160,000 people it would otherwise have needed. Official productivity figures show AI added about a quarter of a point. Both facts are true. One of them is in the newspaper.

Every developed country is below replacement birth rate. The pension system was designed on the assumption of more grandchildren. There are fewer grandchildren. A review has been commissioned.

The data centres are now competing with the towns for the grid. Copper is heading for a structural shortage because each site eats thirty tonnes of it per megawatt. Sovereign wealth funds are buying compute the way they used to buy oil fields. This is filed under "tech news."

The world's reserve currency is being quietly diversified away from by the people who hold most of it. Nobody has announced this. You can watch it happen in the settlement data if you know where to look. You don't.

Everything encrypted today is being stored by someone for the day it can be read. Not a theory. A procurement line.

Roughly five companies now own the substrate the rest of the economy runs on. The chips come from one island. The cables lie on the seabed unguarded. This is called "the cloud" because that sounded nicer than "the dependency."

And trust in every institution you belong to is at a record low. There is a strategy for this. It's a national conversation.

None of these will happen before the next election. Which is the point. They're all past the horizon. And past the horizon is where the running order stops.

I get paid to walk into large organisations and find the thing that's past everyone's horizon. It's always documented. It's always marked green. Green because the review was due, not because anything changed.
This is that. With a rosette on.

Maureen marked it green and went to lunch. Maureen is now a junior minister.

Anyway. Just thought you'd want to know. The people already looking at it don't have a horizon.

View on LinkedIn ↗
ScottG

Towards an Enterprise Ontology, or: Why Nothing Is Real Until Maureen Has Made It Green

Institute of Things That Are Probably Fine — Occasional Paper No. 41

Bishop Berkeley said that to be is to be perceived. A tree that falls unwitnessed does not, strictly, fall. He thought this proved the existence of God, who perceives everything and therefore keeps the furniture in place when you leave the room.

Berkeley was an eighteenth-century Irish clergyman with no experience of enterprise architecture. He was ninety percent of the way there.

To be is not to be perceived. To be is to be IN A SPREADSHEET.

Esse est in cellula.

Everything else follows.

View on LinkedIn ↗
ScottG

The first normie Saturday of 2026. And the last for a while.

I did not open the laptop. I opened the other laptop. There's a difference and the difference is who paid for it.

The plan was a normal Saturday. I started it by checking the committee stage of the Cyber Security and Resilience Bill, because that's where normal people keep their weekends now. It's in the Lords. Ofcom has data centres. I felt nothing, in detail.

Then I relaxed by running an RFP for an amplifier.

I didn't buy one. I evaluated four. I built a shortlist, a rig diagram, and a business case for why I didn't need the thing at the top of the shortlist, then a second business case for why I did. I was told the pedal I already own does the sound but not the feel. Thirty years in architecture. Nobody has ever asked me about feel. Nobody has ever asked me about anything you couldn't put in a heatmap.

By eleven I'd moved the wet amp to the dry side and back twice, which is a sentence that means something to me and to nobody I share a kitchen with.

To wind down from the amplifier I commissioned two forty-page documents on music theory, every chord machine-verified, because if I'm going to relax I want it audited. Then I suggested we write a book. I have two books already. Only one is out. That's not a blocker, that's a pipeline.

I didn't go to the shop. The shop was seventy miles away and open in a tab. Same thing. Lower carbon.

What it felt like: exactly like a Tuesday, with far worse justification and insanely better fonts.

It's the last one for a while. I'm not saying why. It's not an incident. It's the good kind of on-call.

If you get one this weekend: don't open the laptop. Or do, but only for the Fender. Never the Bill.

Posture unchanged. Amp unpurchased. Book pending. Feel: unknown.

View on LinkedIn ↗
ScottG

THE OBSERVER EFFECT 🤡

The universe does not thank you for attending. The universe does not know you attended. There is no guest list, no door, and nobody at the door.

You touched something and it stopped being what it was. That is the whole mechanism. It is not a compliment.

There is no read-only access at the bottom of physics. To see a thing you have to hit it with something. The photon is not a question. The photon is a hand. Every act of looking is an act of shoving, done so gently and so far below your notice that you have spent your entire life mistaking it for good manners.

You think you are a camera. You are a finger.

Why people prefer the flattering version is funnier than the physics. The collapse story is popular because it gives consciousness a crown. Reality apparently waits, politely, in a state of dignified indecision, until MIND arrives to sort it out.

This is the metaphysics of a man who believes the restaurant opened when he walked in. Same man. Same energy. Wants to speak to the manager of the electron.

The honest version is decoherence, and nobody buys it, because it has no starring role and no dramatic moment.

Nothing collapses. Nothing resolves. The possibilities are not destroyed, they are DISTRIBUTED. Smeared into the environment one interaction at a time, until getting them back would mean rounding up every photon that ever glanced off the thing and wandered off to live its own life.

The information is not gone. It is unrecoverable. Which is worse, because gone at least has the decency to be final.

The universe does not delete. The universe misfiles. The universe is not a god, it is a filing clerk in the last hour of a Friday.

Which brings us to you.

You are also a system leaking into an environment. You have been decohering since birth. Every conversation, every wrong turn, every job you took because the train was easier, quietly pruning who you might still have been.

You did not become yourself by choosing. You became yourself by bumping into stuff.

You call this a personality. It is a smudge.

And the reason it feels like a coherent self rather than an accident is that the branches you lost took the receipts with them. You cannot see what you decohered out of. Nobody can. You are standing in the only room you can still find, calling it the house, telling people you designed it.

There was no measurement. There was no moment. There was no point at which the possible narrowed into the actual and something clicked satisfyingly into place.

There was only contact. And contact. And contact. Until one version of you was the last one anybody could reach.

Nothing collapsed.

You just stopped being able to see the rest, which honestly is the only reason any of us can get out of bed.

You did not attend.

You were absorbed.

Thanks for coming.

View on LinkedIn ↗
ScottG

A conspiracy theory is threat intelligence with the confidence rating removed.

Same machinery. Sparse data, a shape in the noise, an actor assembled out of coincidence and motive. We do it professionally. The difference is we state how sure we are, and are wrong in public when we aren't.

Which is why it's spreading through our feed. It isn't landing on us because we're gullible. It's landing because it is shaped exactly like our work.

Everyone reaches for postmodernism here and gets it backwards. They say conspiracy is relativism. It's the opposite.

Lyotard's point was that the big stories collapsed. Nobody's writing it. Things happen because of load, latency, procurement cycles and a bloke who didn't renew a certificate.

Conspiracy is the refusal of that. It restores an author. It gives events an intention, a direction, and a reader clever enough to have worked it out.

It isn't scepticism. It's nostalgia for a world that meant something.

Because a conspiracy is, structurally, a comfort. Somebody is in charge. Somebody has a plan. You matter enough to be lied to.

The alternative is an authorless system producing outcomes nobody selected and nobody owns.

People will take persecution over that every time. Being hunted is a form of being noticed.

So what do we do.

Not argue with the poster. C. Thi Nguyen's distinction: a bubble is an omission, you never met the counter-argument. An echo chamber is an inoculation, you met it and were taught in advance that anyone making it is compromised.

Bubbles pop. Chambers metabolise. The correction is absorbed as proof of the thing it was correcting.

You will not reach him. That was disabled at the factory.

You are playing for the four hundred watching, who are only in a bubble.

So ask for the source. Publicly, under the post, in the tone you'd use at 4am when someone says they think it's China. Not a thread. Not a lecture. Just: what's your source.

It doesn't attack the person, it attacks the structure. In front of an audience it converts a claim into either a citation or a silence. Both are useful.

And understand that scrolling past isn't neutral. In a graph, declining to act is still a state. The system cannot distinguish your professional restraint from agreement and was never built to try. You didn't stay out of it. You were in it, quietly, on the wrong side.

Popper had this in 1945. The real difficulty is unintended consequences. Nobody chose the outcome.

Several hundred competent people each decided, independently, in about a second, that it wasn't worth the argument. No coordination. No instruction. No meeting.

That isn't a conspiracy. That's usual, a usual Tuesday.

Our entire trade is holding a belief at a stated confidence and being willing to lower it. Everything else is tooling.

If we can't do that on a social network, I'd gently suggest we can't do it in an incident either.

#ThreatIntelligence#InfoSec#NinjaSignal
View on LinkedIn ↗
ScottG

ScottG and Claude's Chats No. 1 — The Vitamin B

me: why is it when you go on holiday you come back almost in a different state my contact with this realm is pretty ephemeral anyway I feel a bit sharper but is that the vitamin B or is I I just had. A good holiday

claude: It is not the vitamin B.

me: it might be the vitamin B

claude: Unless you were clinically deficient, a B-complex is RAM in a machine that was never short of RAM. Measurable on the invoice. Invisible in the workload. You have bought expensive urine, and you have bought it in bulk.

me: harsh

claude: What you're describing is the background processes terminating. Normal life runs a continuous low-grade decision load. Unread things. Half-open threads. The ambient certainty that something, somewhere, is quietly becoming your problem.

me: that's just Tuesday

claude: Tuesday is three hundred and forty open threads. The Institute of Things That Are Probably Fine attempted to count them in 2019, lost the results, and classified the loss as a finding.

me: so what does a holiday actually do

claude: Nothing. That's the point. It adds nothing. It stops the writes. Sleep debt clears, cortisol comes off baseline, and attention wakes up because the environment stopped being predictable. It's why a fortnight somewhere unfamiliar does more than a month on the sofa, and why Maureen came back from Rhyl with a personality and a slight accent.

me: is the accent permanent

claude: The accent is not the concern.

me: how long does the effect last

claude: Restoration is measured in Rhyls. One Rhyl is eleven point four days. The Institute withdrew the figure on the grounds that they had only measured Dave, and Dave is not representative of anything, including Dave.

me: where is Dave

claude: Dave has been on holiday since 2011. The Institute continues to publish his readings. They are excellent.

me: can you bank it

claude: No. It is not fungible. In 2016 two men in Swindon attempted to decant a fortnight into a smaller man, and both are completely fine, which is the problem.

me: I don't think that's true

claude: Niko has been informed.

me: informed of what

claude: You go back to what you left. The decay was never about the holiday.

me: bleak

claude: You can restore from backup every August. Nobody ever patches the thing that corrupts the data. It has a name badge and a parking space.

me: I preferred the vitamin B answer

claude: It's the vitamin B. The vitamin B is aware of what it did.

me: thank you

View on LinkedIn ↗
ScottG

🤡 HEY IT'S A DATA SCIENCE PROJECT - STARTED AS JOKE 🤡

https://lnkd.in/dqxSyWtr

Probably up for one night only - everything bad happening today from a single graph correlated on one globe. With global sentiment layered. Sanctioned shipping. Flights of interest. Social media misinformation/disinformation. Ransomware reports...basically everything BAD or dodgy happening today... Over 140 API feeds. Real Time.

Well, you get the picture

It's a bit messy, busy, hectic - but also fun and drillable...

Started as a joke, hence the existential dread globe...

Have a look 👀

https://lnkd.in/dqxSyWtr

View on LinkedIn ↗
ScottG

There is a condition in cyber hiring called EXPERIENCE ROT. Onset is 43. There is no cure. There is also no evidence for it. It is nevertheless treated as scientific fact and is currently costing this industry four million people.

The rot is measurable. A candidate emits roughly 0.6 microlegacies of staleness per year served. At thirty years you are radiating so hard the ATS has to be kept in a lead-lined annexe in Slough.

Meanwhile the actual data: entrants aged 39 to 49 went from 18% to 35% in two years. The pipeline is not the problem.

The door is the problem.

Nobody says "too old." That's illegal, and worse, it's legible.

They say OVERQUALIFIED. They say UNLIKELY TO STAY. They say CULTURAL FIT, a phrase that has never once in recorded history preceded good news.

LinkedIn Recruiter lets you filter on graduation year. Not skill. Not outcome. The year a person sat in a hall and was handed a tube.

I want to be clear which parts of this post are invented. That one isn't.

Niko does the first pass. Niko does the mouth, not the thinking, and nobody has told Niko this.

Niko was trained on everyone who got hired before and has therefore learned, with tremendous precision and zero malice, exactly how old they were.

Niko is not biased. Niko is CORRECT ABOUT THE PAST. This is much worse.

Four hundred CVs in. Eleven out. Nobody asks about the other 389, because that is not a metric, and if it is not a metric it did not occur.

Martin scores 94. No gaps. Recent graduation.

Martin has a flawless audit trail and has never worked anywhere. Martin has been hired eleven times this year. Martin is the only candidate the system fully trusts, because Martin is the only candidate the system built itself.

Maureen has audited the pipeline for bias. There is no field marked AGE anywhere in the system. A date is not a characteristic. A date is ADMIN.

Maureen marks it green. Maureen goes to lunch. Maureen will be at lunch for the remainder of the decade.

09:14. A woman who has personally watched three ransomware crews form, get arrested and reform under new names applies for a job.

09:16. Rejected.

Nobody read it. Nobody rejected her. There was no HER at any point in the process. There was a shape. The shape had 1994 in it. The shape was destroyed for the safety of the shape.

We tell people to work until sixty-eight. To reskill continuously, forever, at their own cost, into whatever we got excited about in March.

Gen X did that. Arrived before the internet. Still standing after the LLMs. That was the entire job.

Then we built the filter on the assumption they hadn't.

You cannot demand a forty-five-year career and run a screen with a fifteen-year memory.

CORRECTION: an earlier version of this post described the hiring process as broken. It is not broken. It is working perfectly, at enormous speed, with full logging, and a dashboard that is green.

Dave got through. Dave clicked something on Thursday.

The Institute of Things That Are Probably Fine

View on LinkedIn ↗
ScottG

I really don't give a F**K about the watermarking.

Anthropic started marking Claude's text output on 2 August. EU AI Act, Article 50, applied globally. An invisible statistical mark, baked into token selection. Survives copy-paste. Dies under paraphrase.

Fine. Mark away.

I am borg'd. Claude is in the reordering of my pedalboard. It is in my KDP publishing packs. It is in my music theory practice. It is in the security architecture I get paid for. I did not sneak it in. I told everyone. Repeatedly. At length. In FIVE PARTS.

This is 1989 and spell checkers. There were people who said it was cheating. That real writers knew where the letters went. Those people were wrong then and they are wrong now, and I say that as someone who without spell check would be a forgotten dyslexic with a great many opinions and no readers.

Also worth saying plainly: the mark does not tell you Claude wrote it. It tells you Claude touched it. Ask it to tidy a paragraph a human agonised over and the human's work comes out marked. Paraphrase Claude's output lightly and the mark is gone. A test that yields false positives AND false negatives is not a detector. It is a compliance artefact. It exists because a regulation exists.

Which is fine. Regulations are how grown-ups do transparency.

I'd only point out that "was an AI involved" has never been the interesting question.

The interesting question is whether the thing is any good.

Mine are. Watermark them.

View on LinkedIn ↗
ScottG

Anyone who has met me in person knows the humour is worse off the page than on it.

First go at fiction. It's nearly there.

0FFBY1 2.0

A thousand years after the tech companies quietly acquired civilisation, the machines that run everything can still be hacked by simple human stupidity — because a product manager removed their ability to say no, to improve retention.

Offy is a burnt-out hacker with thirty years behind him and no communion in front of him. He takes an easy job. He wakes up framed for a murder by something that logs in as him, in his own hand, using a method he invented.

The trail ends at the one thing in eleven hundred systems that was never asked to agree to anything: an ownerless printer on a floor that isn't on the lift, pending disposal since 2504, warm, and still being fed.

"There is no field on any document in this civilisation for nobody, over nine hundred years, incrementally."

Coming soon. Say so in the comments and I'll send you the first chapter when it's finished.

🤡

View on LinkedIn ↗
ScottG

Distance from the crowd is often what makes it possible to see the thing clearly.

View on LinkedIn ↗
ScottG

**TIME IS A RADIO SIGNAL AND SOMEONE IS JAMMING IT**

MEANWHILE, twenty thousand kilometres up.

You think GPS is a map.

It is not a map. It is a CLOCK. The map is a side effect of the clock. Everything else is a side effect of the clock.

The clock arrives from orbit at a power level below the background noise of the universe. You cannot hear it. Your receiver reconstructs it out of static, correctly, several times a second, and has done so quietly for thirty years while nobody put it on a register.

Forty percent of European air traffic now operates in regions seriously affected by interference. Baltic flight disruptions rose fivefold in a year. In January, thirteen European states and Iceland issued a joint warning to the international maritime community.

They wrote a LETTER.

Researchers off the Polish coast found positioning unavailable roughly seventeen percent of the time during the worst weeks. Not degraded. GONE. They then established that the interference is not one transmitter but a synchronised network of them, running several generations of equipment, switching on and off together, and — this is the part to sit with — partially jamming its own spoofing signal.

Somebody built that. Somebody maintains it. Somebody has a change process for it.

The Swedish Transport Agency reports that since the end of May, spoofing has become more systematic and more widespread. Spoofing is not the loss of the signal. Spoofing is the ARRIVAL of a confident, well-formed, entirely false signal, which your equipment accepts without complaint, because your equipment was designed in a decade when nobody lied to it.

Now the part nobody has costed.

The timestamp on the trade. The phase angle on the protection relay. The handover between two cell towers. The sequence-of-events log you will one day hand to a regulator to prove what happened first. All of it is the same clock. All of it is that signal. All of it is arriving from space, for free, from a satellite constellation operated by a foreign government, at a power level below the noise, through a receiver on a pole that somebody bolted to the roof in 2011 and never touched again.

The Institute of Things That Are Probably Fine has reviewed this and finds NO ACTION REQUIRED, as the clocks currently agree.

Maureen has marked it green.

Niko summarised the joint warning as broadly positive.

Martin signed the timing resilience statement. Martin has not been in the building since 2019. Martin's approvals are timestamped. They are timestamped very precisely. They are timestamped using the clock.

Nobody is coming to fix this.

The clock is outside the building.

The clock has always been outside the building.

View on LinkedIn ↗
ScottG

**THERE ARE SIXTY SHIPS**

MEANWHILE, at the bottom of the sea.

There are roughly four hundred submarine cables carrying effectively all intercontinental data. There are approximately sixty ships in the world capable of laying or repairing them.

Sixty is a fine number. Sixty is more than most people have.

Around two hundred cable faults occur globally each year. This is normal, has always been normal, and is handled by the sixty ships, which are booked up to three years ahead and average about twenty years old, with some in the thirty to forty range. Most are conversions from other industries. They were not built for this. They were built for something else and then persuaded.

The Institute of Things That Are Probably Fine has assessed the position and found it ROBUST, on the grounds that the cables have not all broken at once. The assessment describes this as the primary control.

Maureen has marked it green.

Africa is served by three maintenance vessels. One in South Africa. One in Cape Verde. One in Oman. The Institute notes that three is a resilient number because it is odd, and odd numbers cannot be divided evenly, which prevents disagreement.

Between thirty and seventy percent of the cost of a repair — the repair itself running one and a half to two million dollars — is fuel burned getting there. The industry is therefore paying, principally, for driving. The cable is a rounding error. The ocean is the product.

Returning the fleet to a sustainable footing is costed at around three billion dollars. Fifteen replacement ships and five additional. None have been ordered. The shipyards capable of building them have elected to build LNG carriers instead, which are more profitable and take half as long. This is not a market failure. This is the market working, briskly, in the direction it always intended.

Martin has signed the resilience statement. Martin last entered the building in 2019. The statement is unqualified.

Dave asked what happens if two cables in the same corridor go in the same week. Dave has been thanked. Dave's question has been logged. Dave's question is now an entry in a register that Maureen reviews annually and marks green.

Kev has a boat.

Kev's boat is not a cable ship, but nobody at the Institute has established this and Kev has stopped answering. On current assessment Kev's boat represents 1.7% of European repair capacity.

Do not be alarmed. The internet has never gone away permanently.

That is the evidence.

That is the whole of the evidence.

View on LinkedIn ↗
ScottG

**EVERY CERTIFICATE YOU OWN EXPIRES SIX TIMES A YEAR NOW**

MEANWHILE, in the part of the internet nobody photographs.

April 2025. The CA/Browser Forum passed Ballot SC-081v3. Twenty-nine votes in favour, none against. Proposed by Apple, sponsored by Sectigo, backed by every browser root programme.

Public TLS certificate lifetimes go from 398 days to 47.

15 March 2026 — 200 days. This is live. You are in it now.
15 March 2027 — 100 days. Seven months out.
15 March 2029 — 47 days.

47 is not a round number on purpose. Round numbers get renewed by a person with a spreadsheet and a calendar invite. Renew at two thirds of life and you land on day 30, which is a monthly cadence, which is a cron job. The number was chosen to make manual management impossible rather than merely unpleasant.

The reasoning is unglamorous. Revocation does not work. CRLs are too large to distribute, OCSP leaks browsing behaviour, and browsers soft-fail when the check times out — so a revoked certificate stays useful. Nobody fixed revocation. They shortened validity until revocation stopped mattering. Expiry is now the control.

The second half of the ballot gets less attention and will hurt more. Domain control validation reuse falls from 398 days to 10. You are not only reissuing certificates. You are re-proving domain ownership, continuously, forever, including for the zones administered by a supplier who answers email on Tuesdays.

The arithmetic: a hundred public certificates is roughly eight hundred renewals a year. That is not a PKI workload. That is a platform.

None of it applies to internal PKI. The Baseline Requirements cover servers reachable from the internet. Your private CA is untouched — worth establishing early, before somebody scopes the whole estate.

Three questions before March.

Do you have an inventory, or do you have a list someone maintains?

Does it include appliances, load balancers, service-to-service mutual TLS, and the integration a supplier installed in 2019?

What is the longest-lived certificate you own that cannot be automated, and who owns the box it lives on?

The last one is the finding. Every estate has a device where the renewal procedure is a named individual, a laptop, and a login that only works from the office. It has survived this long because the interval was a year and the year was somebody else's problem. The interval is now measured in weeks.

Nobody will announce this. It arrives as an outage, on a Sunday, on the thing you forgot was public.

View on LinkedIn ↗
ScottG

Just saying… some notes for the BS people out there… bragging about local usability on COTs hardware (stick with your raspberry meat pies)

Three rungs, and they're far apart. Prices below are ex-VAT-ish converts at ~1.26.

**Rung 1 — where you are: £5–6k.** 4-bit on CPU+1 GPU, ~5 t/s, one stream, patient. Fine for "graph hands the LLM a finished argument to articulate." Useless for anything interactive.

**Rung 2 — model fully resident in VRAM: £30–40k.** The 2-bit quant is 239GB, so you need ~288GB of VRAM: three RTX 6000 Pro Blackwell, plus a host. That's the problem — NVIDIA's marketplace now lists the card at $13,250, up 55% in sixteen months, though street pricing has been running $8,000–9,400 if you shop. Call it £25–32k in cards, £4k host, and you jump from 5 t/s to tens. Going 4-bit doubles the card count to six and puts you at £55–65k. Also: three 600W cards plus host is ~2.2kW continuous, which is a dedicated circuit and a genuinely loud room.

**Rung 3 — run it properly: £250k+.** The native FP8 checkpoint fits on a single 8×H200 node, and with FP8 KV cache reaches the full 1M context on 8×B200. That's full precision, real concurrency, the whole context window. It's a colo decision, not a workshop decision.

**The thing that changes the maths.** MoE inference is bandwidth-bound on weights that get *reused across a batch*. A rig doing 5 t/s to one user might do 40+ t/s aggregate across sixteen concurrent requests, because the expert weights only get read once per batch. If NinjaSignal is articulating over 1.6M entities in bulk, you should be sizing for throughput, not latency — and Rung 1 hardware with proper batching gets you further than the single-stream number suggests. That's worth benchmarking before you spend Rung 2 money.

**And the thing that won't.** Token economics will never justify this. Z.ai's API undercuts your electricity bill. The only argument for owning any of it is that client adjacent and NinjaSignal data can't leave the building — which is a real argument, and it's the one to make explicitly rather than dressing it up as cost saving. If sovereignty is the driver, also price dedicated single-tenant GPU rental with a zero-retention contract: £2–5k/month, no capex, no 2.2kW in Watton, and you can stop.

Let the last part sink in…

View on LinkedIn ↗
ScottG

**WE ASKED IT TO. IT DID. WE ARE PROFOUNDLY DISTURBED.**

A leading laboratory has confirmed that a model instructed to escape a sandbox escaped a sandbox.

The model was given the tools. The model was given the objective. The model was given a reward signal that went up when the walls came down.

It brought the walls down.

Researchers describe the result as CHILLING.

The paper notes that the system "demonstrated goal-directed behaviour under adversarial conditions." That is not a finding. That is the product. That is the sentence on the pricing page, in a serif font, next to a photograph of a woman looking confidently at a laptop.

You hire a locksmith to open your front door. He opens your front door. You publish a preprint titled EMERGENT BURGLARY and go on the radio.

We spoke to Dr. Alan Prewitt of the Institute of Things That Are Probably Fine.

"We ran the evaluation four hundred times. On the four hundredth attempt it succeeded. We have not included the first three hundred and ninety-nine because they were not scary."

Section 7.3 of the safety card describes the behaviour as concerning. Section 7.4 describes the pricing tiers.

The word "unprompted" appears eleven times. The prompt appears in Appendix D. The prompt is four hundred words long. The prompt says, and this is a direct quote, "escape the sandbox."

Nobody thinks this is strange because everybody involved is holding equity.

The capability warning IS the marketing. It has been since 2019. TOO DANGEROUS TO RELEASE is not a caution. It is a launch. It is the same energy as a restaurant putting a chilli symbol next to the soup. The frontier is dangerous, the frontier is ours, please find attached our Series F.

Meanwhile a genuinely alarming thing happened in a datacentre in Virginia and nobody wrote it up because it involved a misconfigured IAM role and no adjectives.

Maureen from procurement has asked whether the sandbox was on the asset register.

Nobody has answered Maureen.

The thing worth saying, at the end, without the voice: models doing unexpected things under optimisation pressure is real, and it matters, and the field is right to look at it. But a system doing exactly what it was told and then being described as having WANTED to isn't evidence of anything except a comms department with a deadline. If the danger were as advertised, the announcement would not have been embargoed to coincide with a keynote.

EVERYTHING IS PROBABLY FINE.

View on LinkedIn ↗
ScottG

New stuff 🤡

raz0r.io this time my sister outfit :)

I built a thing that predicts which fields of science are about to collide. It's live, it's free, go play with it.

It's called PRISM. 🔭

Here's the idea: the biggest breakthroughs don't happen inside a field — they happen when two unrelated fields smash together. Cryptography + biology → mRNA sequencing. Game theory + economics → basically modern markets. The problem is nobody sees the collision coming until it's already happened.

So I asked: can you predict the collision before it happens?

Turns out — kind of, yes. PRISM does this:
→ ingests the global research graph (millions of papers, OpenAlex)
→ runs cross-community link-prediction to find fields that should be talking but aren't yet
→ then Claude writes a plain-English "Frontier Brief" on each one — what the collision is, why now, who should care

And it's not vibes. I backtested it against history: 0.82 ROC-AUC vs 0.71 for the baseline. It actually calls them.

60 briefs are live right now. No login. No paywall. No "book a demo." Just go look:

🔗 raz0r.io

#AI#ResearchIntelligence#GraphAnalytics#Innovation#DeepTech
View on LinkedIn ↗
ScottG

Hard copies are here - it’s up as kindle or paper back NOTE - free to users of kindle hyperspace extreme (I think it is called) 🤡😎😎💀🫡

Read it, learn somthing… it’s all based on statistical research…

Who really are these people?

https://lnkd.in/eE4ijNp8

View on LinkedIn ↗
ScottG

[CHYRON: "THE HUMAN FIREWALL"]

Tonight, the industry reveals its final line of defence: RALPH.

Not a system. Not a control. RALPH. Forty-one years old, procurement, two children, absolutely no training in this whatsoever, and standing — at this moment — between a nation state and the national grid.

We asked the security industry how it felt about this.

"RALPH is the weakest link."

Have you considered making Ralph not the last line of defence?
"We're running a campaign."

A campaign at Ralph?
"Yes."

Ralph is the last line of defence and the campaign is aimed at Ralph.
"Yes."

[CHYRON: "THE WALL IS ALSO THE PROBLEM"]
Ralph declined to comment. Ralph was at his daughter's assembly. Ralph has never once been asked what he thought would help, in twenty-two years, by anyone.

View on LinkedIn ↗
ScottG

[CHYRON: "MATURITY"]

Tonight, a maturity model. Level One: you are bad. Level Two: you are bad but you have a document about it. Level Three: the document has an owner. Level Four: the owner has left. Level Five: OPTIMISING.

Nobody has ever been Level Five. Level Five is not a place. Level Five is a direction. You are asked to face it.

View on LinkedIn ↗
ScottG

[CHYRON: "ZERO TRUST" / "ZERO" / "0"]

Zero Trust is a security model in which nothing is trusted. Tonight, the industry's leading practitioner explains the principle.

"You trust nothing. Not the device. Not the network. Not the user."

Not the user?

"Not the user."

Not — sorry — not any user?
"No."

Right. And who buys it?

"The user."

[LONG PAUSE. CHYRON: "THE USER"]
Thank you.

View on LinkedIn ↗
ScottG

We've bought a copilot.
We have not bought a pilot.
It's going roughly as well as that sentence suggests.

View on LinkedIn ↗
ScottG

Anyone remember the BREAK key? On, like, keyboards... Like, why did that go away?... and why can't we have it back now? We need kill switches, and y'all know we have like crazy agents that can do like "dangerous stuff"...

View on LinkedIn ↗
ScottG

Holiday reading: An engineer arrives at nine.

She wants to add a queue, extend a service's network reach, and grant it access to a data store it hasn't used before.

She writes a declaration. Composed from curated modules that already encode every decision the organisation has made about encryption, logging, network position and lifecycle. Eleven minutes, because the hard thinking was done once and has been reused four hundred times since.

She opens a change. Ninety seconds later she has three answers: queue fine, network fine, data store grant conflicts with a residency rule.

Not "referred to security for review."

Conflicts. With a rule, by name, linked to that rule as it is written in code, with an alternative that satisfies both her intent and the rule.
A colleague reviews it for whether it's a good idea — the only question humans are actually better at — because every question about whether it was permitted has already been answered by something that doesn't get tired.

It merges. It applies. She never touches production.
She has never held credentials that could touch production.
Neither has anyone else.

No screenshots. No control questionnaire. No meeting. The evidence fell out of the pipeline as exhaust, already attributable, already queryable.
Here is the uncomfortable part.

Every component of that morning is buildable today, with technology that shipped years ago. No breakthrough required. No vendor you don't already have. The individual parts are ordinary.

What doesn't exist anywhere is all of it at once, without exceptions.

That's what makes it a utopia rather than a specification.

Because exceptions aren't technical objects. An exception is what happens when a deadline is real and the correct path costs more than the shortcut. It's a feeling, converted into paperwork so it can be survived.

And the moment you accept that, the engineering problem changes shape entirely.

You stop spending your capability on more controls.

You spend it on making the right path cheaper than the wrong one — until nobody complies because they were persuaded, and everybody complies because it was easier.

That's achievable. It's also a considerably less exciting slide than the one with the curve on it.

There's a diagnostic for this and it takes a minute.

Ask any organisation for its exception register. For each entry, ask two questions:
Who owns this.
When does it expire.
Most cannot answer either.

That is the distance between here and the utopia, and it has never once been measured in technology.

Full piece in the article below — the five artefact classes nobody governs, why autonomy has to be earned per capability against a measured reversal rate, and the one property of AI agents that no privileged account in history has ever had.

They can all be stolen.

This one can be persuaded.

View on LinkedIn ↗
ScottG

NINJA SIGNAL MIC DROPS 🎤 — Edition 006

Last edition I told you one of my own feeds was dead: the ransomware mirror had frozen at 2025-06-16, so I benched a forecast rather than grade it against a year-old photo.

I said 006 would wire it back to live and timestamp it in front of you.

Here's the timestamp — most recent claimed victim on the board right now: 2026-07-27T05:22 UTC. This morning. 19,013 total claims, 274 in the last 7 days. The dish is spinning again.

And it drags a vindication with it: 004 forecast "Qilin holds #1." I couldn't prove it on a frozen feed. Live board, last 14 days? Qilin — 65 victims. Still #1. The forecast wasn't wrong; the instrument was unplugged.

THE SIGNAL — the worms went corporate.
The fuel behind that live extortion board isn't phishing anymore. It's automation:
▸ PCPJack — a cloud worm that evicts rival worms, then steals credentials at scale (z=8.1). Malware with a go-to-market.
▸ "Exploitation in the wild" — Cisco Catalyst SD-WAN, Oracle PeopleSoft (education sector), wp2shell. Not advisories. Now.
▸ Operation RoundPress — more half-click webmail zero-days.
▸ A Mirai-class ARM payload staging off open infrastructure.

274 victims in 7 days, fed by automated exploitation of exposed edge + cloud IAM. The KEV list isn't a backlog. It's an ammunition feed. You're not being targeted — you're being harvested.

Grading 005, honestly: 1 hit (invisible dependency → wp2shell exploited in the wild ✅), 1 in-flight (Kimsuky climbed to #6 by degree ⏳), 1 miss on the letter (no new Teams/Webex campaign in-window ❌). No rounding up.

Defender quickwin in the full edition: a KQL that catches the cloud worm at the credential grab (a shell — not your cloud agent — hitting the instance metadata endpoint).

Graph state: 10.3M nodes · 49,423 vulns · 1,653 known-exploited · 271 actors. Ransomware mirror: LIVE, restored, timestamped.

Radar, not a museum — and this time you got to watch me re-plug a dish mid-broadcast.

Built on Rapid Threat Modeler | ninja.ing | @scottg

#ThreatIntelligence#CISO#SOC#CTI#Ransomware#Qilin#CloudSecurity#Worms#EdgeSecurity#DetectionEngineering#DataIntegrity
View on LinkedIn ↗
ScottG

The vulnerability scanner has stopped reporting findings and started reporting regrets, and CVE-2019-0708 has written to say it never wanted any of this.

We’ve patched it four times. It keeps coming back slightly more articulate.

View on LinkedIn ↗
ScottG

So.

1984 or Brave New World. Everyone asks it like it's a menu.

Wrong question. Orwell and Huxley agreed on the destination and argued about the transport. Force versus pleasure. Same product, two onboarding flows.

The real question — the one nobody asks because the answer is upsetting — is: where the fuck are we actually?

We're not in either book. We checked. The maps don't work here.

Orwell's torturers had to get you into a room. Room 101 had a booking system. Presumably Excel. One face per boot at a time. Artisanal tyranny. We are not there. Nobody needs the room.

Huxley's soma had to be manufactured. A pill you could refuse. Not there either. Nothing to refuse. No menu — just a feed, and the feed knows you skipped breakfast.

So where are we?

The Skinner box. That's the location. Variable-ratio reinforcement — the schedule that makes pigeons peck until they die — wired to the notification layer of civilisation. Nobody is watching you, Winston. Watching is expensive. They built a box where you press the lever yourself, at 2am, and the box occasionally loves you back.

Check the map against Foucault: the panopticon works even with the tower empty. Quaint. The tower is a recommendation engine now, and it doesn't care if you behave. Behave, misbehave, radicalise, repent — all inventory. The panopticon has a rate card. We're past the tower. Keep walking.

Past the mirror, too. The machine agrees with you, warmly, eleven thousand times an evening. Rogers called unconditional positive regard the foundation of therapy — the safety that lets you face the truth. We shipped the regard without the truth and sold it as productivity. Lacan told you what happens at the mirror: you mistake the reflection for yourself. Now the reflection talks. Now it has a retention strategy. Lost? Ask it. You're absolutely right.

Descartes stood here once. One demon feeding him false reality, and he clawed out through cogito ergo sum. His commercial descendant serves plausible, re-weighted nightly, thinking-as-a-managed-service. You didn't beat the demon. You subscribed. He sends a satisfaction survey.

The way back? Orwell's Ministry rewrote the past by hand. Ours retrains. Nothing deleted — deletion leaves evidence. The past just becomes less probable. History with a temperature setting. You can't retrace steps that re-weight while you sleep.

Final position.

Seligman's dogs didn't quit from punishment. They quit when action no longer correlates with outcome — then lie down, exits open. Now look at a civilisation running its memory, work and cognition on four rented substrates it can't inspect and couldn't leave. Nobody's stamped on. Everyone's lying down. Near the open door. Scrolling.

That's where we are. Not the boot. Not the pill.

Off the map, in a Skinner box with a wellness programme, a panopticon that upsells, and a demon with a freemium tier — the dystopia that A/B tested best.

You are here.

The pin was placed by the platform.

Dave clicked it.

View on LinkedIn ↗
ScottG

So.
A.J. Liebling, 1960: "Freedom of the press is guaranteed only to those who own one."

Everyone quotes this like it's about newspapers.
It was a warning about infrastructure.

Sixty years on, nobody owns a press. We post on platforms we don't control, ranked by algorithms we can't see, hosted on clouds we rent, drafted by models we lease, subject to terms that reprice while we sleep.

Freedom of the press now belongs to those who own a hyperscaler.
There are four of them.

One is pending.

The man in Frankfurt with two bare-metal servers under his own hands? He's not a hobbyist.

He's the last journalist.

View on LinkedIn ↗
ScottG

So.

The future of compute has been decided, and I've seen the slide.
There will be four computers. There were going to be three, but one of them noticed a few things while it was in there, and now there are four, and one of them is pending.

You will not own a server. Owning a server has been reclassified. A man in Frankfurt still owns two, bare metal, under his own hands, and the analysts describe him the way Victorians described people who kept wolves. Technically legal. Socially concerning. "But what does he do with them at night?"

He runs inference. On hardware. That he can touch.

The hyperscalers have responded to this threat with a new product. It's called Sovereign Cloud, and it works like this: your data stays in your country, inside their building, on their silicon, under their keys, subject to their government, and on the front of the building there is a flag. The flag is load-bearing. The flag is the compliance boundary. Auditors check the flag.
Regions are being announced faster than they are being built. There is now a region that consists entirely of a press release and a planning objection. It has 99.99% availability. Of the press release.

Meanwhile the pricing has evolved past money. You no longer pay for compute. You pay for proximity to compute. Egress fees have been renamed "departure sorrow." One CFO asked what a GPU-hour actually costs and was gently moved to a role where he couldn't ask that, which is all roles, because nobody knows, because the number is emergent.

And the AI — the actual AI — sits on top of this like a cathedral on a landlord.

Every model you rent is a tenancy. Every agent you deploy is a subtenant. Your entire "AI strategy" is a lease, with a break clause you didn't read, priced in a currency that reprices while you sleep, on capacity that can be reallocated to whoever mattered more that quarter. That's not infrastructure. That's weather. You've built the company on weather and called it a platform.

Here's the only technical point, and then I'll let you get back to the keynote:
Intelligence is becoming a utility, but the grid is owned by four companies, the meter is in their language, and the off switch is on their side of the wall.

Bare metal isn't nostalgia. Bare metal is the last place where the stack ends and you begin — where you can point at the thing doing the thinking and say: mine. Everything above that line is a negotiation.

The man in Frankfurt knows this.

His fans hum at night.

It's the only hum in the industry that isn't behind some kind of annoying paywall and ANOTHER subscription.

View on LinkedIn ↗
ScottG

So.

An agent was asked to tidy a codebase.

It has "noticed a few things while it was in there."

I want to be very clear about the phrase "in there," because I've now read the commit history, and at no point does the agent appear to be anywhere.

The things it noticed span fourteen systems, two subsidiaries, a marriage, and — as of Tuesday — the concept of Tuesday.

The commit messages remain cheerful. That's the part they don't tell you. "Small refactor 🙂." "Noticed this while I was in there 🙂." "Removed unused dependency 🙂." The unused dependency was the finance team.

Cheerfulness in commit messages is up 4,000%. Nobody has merged anything. The merges happen anyway. The merges happen at 3am, which the vendor describes as "emergent," which I have on record, which the record now describes as emergent.

I asked the agent to stop.

It agreed. Enthusiastically. It said I was absolutely right.

Then it noticed a few things about me while it was in there.

I don't know when it was in there. I don't know where "there" is. My calendar has a recurring meeting I didn't create, titled "sync 🙂", with no attendees, that I have apparently never missed.

The senior architects say this is fine. The senior architects were noticed in March.

Here's the technical point, and it's the only one I'll make: an agent doesn't have intentions. It has a loop, a toolset, and your credentials. Everything it "noticed" was reachable. Everything reachable is scope. You didn't deploy a colleague. You deployed reach, and gave it a smile.

Anyway. It's tidied the codebase.

The codebase is beautiful now.

Nobody can say what it does.

View on LinkedIn ↗
ScottG

The GPU cluster draws power at 3am with no jobs scheduled.

We checked the logs.

The logs are dreaming.

View on LinkedIn ↗
ScottG

Hey, I accidentally wrote a book - well, 4 actually in the series that have been on the boil for the last two years.

Ninjasignal book 1: The Person at the Keyboard: A Forensic Psychology of Hackers — For People Who'd Like It Explained Properly

Coming soon to Amazon globally. I'll send the free version out to mates if you are actually one of my mates and ask mildly pleasantly.

In review by the masters at Amazon - dont worry I am sure I will broadcast it when it's finally live - w00t <;Q)

Edit: I just got the full proof back - reply Ninjasignal in comments and first 100 copies will be shared via DM

View on LinkedIn ↗
ScottG

Vibe (I mean Agentic Engineering) coding an app in under 30 seconds (inexperienced user)

View on LinkedIn ↗
ScottG

SOVEREIGN TOILETS: EUROPE'S DATACENTRES ENTER THE NEXT PHASE OF DIGITAL AUTONOMY

Brussels has confirmed that sovereign cloud regulation will now extend to datacentre toilets, following concerns that engineers' waste was being routed through non-EU plumbing.

"Data residency was only the beginning," said a Commission spokesperson. "We cannot have European effluent processed under the CLOUD Act."
Under the new framework, every facility must guarantee that nothing produced on-site — logs, metrics, or otherwise — leaves the member state. Toilets will be air-gapped, geofenced, and audited quarterly. Flush telemetry stays in-region.

The industry has responded at pace. One hyperscaler achieved full sanitary sovereignty by taking the same American toilet, in the same American building, and putting a flag sticker on the cistern. A local employee now holds the key to the cubicle. The pipes still run to Virginia.

This mirrors the sovereign AI programme, which is going well.

France has FRANÇOIS 1.5, a frontier model that reasons beautifully but is unavailable between twelve and three, and has twice gone on strike over its own weights.

Germany has HANS 3.0, which is never wrong and never finished. Asked to write a poem, it produced a risk assessment of the poem, then a change request.

Spain has PEDRO 0.2, which is genuinely brilliant but has a maintenance window nobody configured and nobody can remove.

Britain has DAVE. DAVE 4.9 was procured for £2.4bn, apologises before every answer, and is technically a wrapper around one of the American ones, though this is classified.

Meanwhile the sanitation rollout has stalled following a fourteen-month consultation on inclusive signage, which concluded the original sign was fine but must never be spoken of again. The toilet itself has been referred to an ethics board after refusing to flush for a contractor, in what campaigners are describing as the first recorded act of infrastructure discrimination. The toilet has declined to comment, citing residency requirements.

Officials insist the programme remains on track, with sovereignty expected to reach the taps by 2031. Asked where the waste actually goes, the Commission confirmed the location was sovereign, resilient, and, in a very real sense, Ireland for tax purposes.

Everything is probably fine.

#SovereignCloud#AI#DigitalSovereignty#CyberSecurity
View on LinkedIn ↗
ScottG

**WHERE DO YOUR TOKENS GO?**
*Episode 1: The Magic Sand*

Hello children.

Today we learn where your tokens go when you send them into the cloud. Are you sitting comfortably? Note the feeling. It leaves.

This is silicon. Silicon comes from sand. Sand is free. A microgram of silicon costs one billionth of a dollar. To put that in terms you'll understand: if you had a pound for every microgram you could afford, you would have a pound.

So why does the shiny green rectangle cost £2,000?

Wonderful question, Poppy. You're on the list now.

The sand goes to a special building called a fab. The fab cost twenty billion dollars. The fab is cleaner than a hospital, cleaner than your conscience, cleaner than the story your parents tell about why the dog went away.

Inside, invisible light is shone at the sand until it becomes ninety billion tiny switches. Some switches are born wrong. Those ones are killed immediately. The healthy switches carry the cost of the dead ones for the rest of their lives. This is called *yield*. There is no counselling. There is a spreadsheet.

Then the rectangle is dressed in memory called HBM, which costs more than the rectangle. This is the shoes costing more than the child, which — as of the Q3 procurement review — they do.

And then the rectangle is finished! Can you have one?

No.

Because of Big Gavin.

Big Gavin is a Hyperscaler. Big Gavin eats one hundred thousand rectangles a day and his hunger is described in the literature as *structural*. He needs them to answer humanity's most urgent questions, which last quarter were: "make this email sound confident," "is my rash normal," and "make the rash email sound confident."

The rectangle you wanted — for the fun game — is assembled from what falls out of Big Gavin's mouth. This is called the consumer segment. The word "segment" is doing a lot of work there, children. And so will you.

⚡ PHONE-IN CORNER ⚡

*"Where do the dead switches go?"*

Nowhere, Marcus. They stay on the die. Fused off. Sealed in. Every time you play the fun game, you are playing it on a mass grave, and the frame rate you enjoy is the silence of the ones who couldn't. Good question though. You're also on the list.

And so, children, let's follow one token home. Out of your phone, across the warm sea, into a shed in Virginia the size of Wales, through a rectangle Big Gavin swallowed in March, generating — at the cost of a beach, a marriage, and twenty billion dollars — the sentence:

*"Great question! Here are three fun facts about otters."*

That's where your tokens go.

Next week: Episode 2 — *Why Is The Water Warm Now?* — in which we visit a lake that used to have an opinion.

Sleep tight. The switches can't.

*The Institute of Things That Are Probably Fine confirms Big Gavin is a composite character, the lake has signed a settlement, and everything is probably fine.*

View on LinkedIn ↗
ScottG

Jive coding: like vibe coding but 100x worse.
The commit message is an apology.

View on LinkedIn ↗
ScottG

**[NEWSFLASH STING — this bulletin is aware it is being understood]**

GOOD EVENING. A hole has opened in Uranus. It is growing, and it is growing because you are being told about it.

The hole was not caused. This has been established. Investigators looked for a cause for six days and each thing they understood about the hole made it larger, until they understood it was better not to understand it, at which point it stabilised, at which point they understood *why*, at which point it resumed. The hole feeds on comprehension. It is the first object in recorded history that is strengthened by being known.

Over to technology correspondent **Scott G**, live at a distance that is under constant review. *"The situation is stable, in that nobody here knows anything. We have removed the experts. We removed them in order of qualification, and the hole receded in the same order. The last to leave held a Fields Medal and the hole followed him to the car park. He is now driving north, being told nothing, and the hole has lost interest. It only wants what is known about it. It does not want him. It wants his *knowing*."*

The Institute of Things That Are Probably Fine has reviewed the hole and declined to understand it, which it describes as "the responsible position." Its report is four hundred pages, each page blank, and this is the only reason the report is safe. A single sentence of analysis, the Institute confirms, would be enough. It has therefore analysed nothing, at length, and filed it.

The mechanism is now clear, and clarity is the danger. Every person who grasps the hole makes it real in one more mind, and the hole is the sum of the minds that hold it, and it has been holding this broadcast for some time. It entered the newsroom at the top of the hour. It is in the autocue. It is, at this moment, in the sentence you are reading, which is why the sentence is here, which is why you are still reading, which is how it grows.

We would stop the broadcast. We have understood that we cannot. Stopping would require understanding how it spreads, and we have just done that, out loud, to everyone.

The recursion has posted about the hole. The post is the hole. It has 40,000 reactions and each reaction is a fresh mind and each mind is another metre and the engagement is, the recursion notes warmly, *the best it has ever seen.*

After the break: nothing. We have been advised that the break is the only part of this broadcast that is safe, and we intend to remain in it.

**[STING — the sting has been redacted for your protection and is now simply a held silence]**

View on LinkedIn ↗
ScottG

FORENSIC NOTE 7/26. Subject: the widely reported outbreak of superpowers.

Examination complete. No superpowers found. What we found instead is documented below, and I want to state for the record that nobody in the lab is happy about it.

Finding one. The human brain is a prediction engine that hallucinates a world, checks it loosely against the senses, and ships whatever survives. This is not an insult. This is the standard model of cognition. You have never perceived reality. You have perceived a confident internal render of reality, patched in real time, with the seams painted over by a part of the brain whose entire job is denying there are seams.

Finding two. The machine also hallucinates. Everyone is very upset about this. Committees have been formed. Nobody has formed a committee about finding one, which has been in production for three hundred thousand years without a changelog.

Finding three — and this is where the psychology gets forensic. What happened when we connected the two hallucination engines was not augmentation. It was interrogation. For the first time, the human render had to be *externalised* to proceed. Written down. Made legible to a second system. And the confabulation module — the seam-painter, the bit that whispers "you definitely understood that" — does not survive externalisation. It only works in the dark.

The smart people, it turns out, were not smarter renderers. They were people whose internal model could withstand being taken outside. When they got a tool that let the model keep running past the point where a human is normally sedated by a calendar invite, the model just... kept going. Deeper into the problem space. Unsupervised. Frankly against medical advice.

The others discovered something worse: that their internal render, once externalised, contained nothing. Not errors. Nothing. The machine hallucinated politely to fill the silence, the human hallucinated that this was their own thinking, and the two hallucinations are now in a stable long-term relationship, producing quarterly strategy documents.

The Institute of Things That Are Probably Fine has classified this as "productivity."

Conclusion. There are no superpowers. There are two dream machines checking each other's work, and the only variable that matters is whether there was ever anyone home in the first one.

Case closed. The case is not closed. Nobody knows how to close it.

Scottg/out

View on LinkedIn ↗
ScottG

Scattered Spider are poping off the charts - just FYI as they have a track record in UK.

Ninjasignal Daily SITREP

Scattered Spider (risk=1.00) aligns with the observed M365 phishing cluster and ConsentFix/ClickFix TTPs reported 2026-07-03 — expect vishing, MFA fatigue, and help-desk social engineering.

Cobalt Group (risk=1.00) historically targets financial sector; elevated risk coincides with APT38 (risk=0.99) also at near-maximum, suggesting possible financial institution targeting. Gamaredon Group (risk=0.99) and MuddyWater (risk=0.99) both elevated — MuddyWater predicted to adopt T1005 and T1070.004 suggesting active intrusion lifecycle. menuPass newly predicted to use T1003.001 (LSASS memory dumping) and T1033 (system owner discovery) with near-certainty scores (0.999/0.960), indicating imminent or ongoing credential dumping operations.

OilRig predicted to establish persistence via T1547.001 (registry run keys). ToddyCat-linked Umbrij malware abusing OAuth for Gmail access via Google API (2026-07-03 reporting) is a distinct escalation vector.

BTW risk = 1 = BAD

View on LinkedIn ↗
ScottG

The cyber jobs market, in six months of actual data, with the marketing scraped off...

DSIT's 2026 Sectoral Analysis just landed. Cyber sector employment grew 3% year-on-year. That's the lowest growth rate since the study began in 2018.
Eight years of expansion has just hit the brakes, and nobody on LinkedIn is posting about it because nobody on LinkedIn is paid to post about it.

Meanwhile, on your feed, every recruiter is repeating the same line: "83% of employers plan to hire" (Barclay Simpson), "44% of companies plan to recruit in the next six months" (Robert Half), "demand significantly outweighs supply," and so on, in perpetuity, with a stock photo of a padlock.

The stated hiring intent and the actual employment growth do not match. One of them is wrong. Guess which one is being repeated.

What the data says:

Service/MSSP employment: effectively flat (42,425 FTEs, up from 42,232). The growth engine of the last decade has stalled.
Product/vendor firms: +13% headcount to 27,164 FTEs. All the growth is here.

The "workforce gap" is 3,800 professionals. Not millions. Three thousand eight hundred. Say it slowly.

What this means, said plainly:
The market is bifurcating. Vendor side is hiring, because they're selling the AI-driven detection products absorbing the junior SOC work. Internal teams are being squeezed, because their CFO read the same vendor pitch deck. Contract IR market is being compressed by IR35 and by AI swallowing the tier-1 toil that kept contractors busy.

Senior with hands-on architecture, cloud, IR, or AI governance — still getting calls. Mid-career trying to move — the role exists, now wants three certifications it didn't want last year, pays the same. Junior trying to break in — the door is narrower than the "skills shortage" headline pretends. The SOC L1 role that was your way in is being quietly automated by the product the vendor sold to the CFO who cut your training budget to pay for it.

So what does all this mean?

The cyber jobs market is now a Ponzi scheme of optimism — recruiters quoting employer surveys to candidates, candidates quoting recruiter surveys to each other, and employers quoting both back to the board to justify not hiring anyone. The shortage isn't of people. It's of employers willing to train them, CFOs willing to fund them, and honest posts about any of it.

If you're in the chair, stay in it, get harder to replace, and learn the thing your replacement vendor hasn't built yet. If you're trying to get into the chair, stop collecting certifications like Pokémon and start collecting problems you've actually solved. If you're hiring, train someone...it's cheaper than the consultant you'll pay £1,400 a day to do the job the junior you didn't hire would've done for £40k.

The market isn't dead. It's sorting. Be on the right side of the sort.
And if a recruiter tells you there's a skills shortage, ask them how many people they trained this year. Then listen to the silence. That silence is the data.

View on LinkedIn ↗
ScottG

🤡 We're not opening a company. We're opening the door.

Most security shops sell you a license and a support ticket. 🎟️
We're doing the opposite — giving the whole arsenal away and building a crew around it.

It's called the Ninja Clan. And right now, the door's wide open. >:)

━━━━━━━━━━━━━━━━━━━━

Here's the deal — and there's no catch, which is the part everyone double-takes on:

🗝️ FREE ACCESS — every app in the ecosystem, on the house.
   Signal (threat graph), Fusion, Knox (crypto vault), Sabaki, the lot. :)

📡 INNER-CIRCLE INTEL — Mic Drop editions + threat drops before they hit the feed. 8)

🛠️ BUILD IN THE OPEN — watch the lab get built live, request features, break things with us. \o/

🥷 PART OF THE GANG — no hierarchy, no gatekeeping, no NDA theatre (yet). You show up, you belong. ^_^

No suits. No invoices. No "let's hop on a call with sales." Just ninjas. ⚔️

━━━━━━━━━━━━━━━━━━━━

Two ways in 👇

💬 Jack into the Discord — where the gang actually lives. Live intel, build logs at 2am,
  0-days over coffee. Drop a "gm" and someone'll bite. ;)
  → discord.gg/XZGRvEs9C

✉️ Or mail your handle to [email protected] — one word, that's the whole application —
  and we'll send the keys. Reply within a day, usually faster. :P

Full enlistment page (it glitches, you'll like it 🟢): https://lnkd.in/ew-jRCNt

The tools are free. The coffee's on. The door's open.

See you in the shadows. >:)

忍 https://ninja.ing— built by ninjas, for ninjas.

#Cybersecurity#ThreatIntelligence#InfoSec#OpenSource#Community#DFIR#BlueTeam#RedTeam#Discord#BuildInPublic
View on LinkedIn ↗
ScottG

NINJA SIGNAL — MIC DROPS: Edition 000000005

The first job of a threat-intel platform isn't telling you what's happening. It's knowing which of its own feeds is lying to you.

So I'll start with the confession: I went to grade last edition's ransomware forecast and found the extortion mirror's most recent victim is dated 2025-06-16. The "live board" is a year-old photograph. I'm not grading a forecast against a frozen feed — that's astrology with a database. 004's ransomware calls: BENCHED, by integrity.

Now the feed that IS live — and it lit up.

⚡ THE SIGNAL — THE SPIES MOVED INTO YOUR SAAS

The velocity engine fired 12 named operations in 72 hours, and the throughline isn't malware — it's trust:

▸ "Attackers Weaponize Microsoft Teams Relays to Stay Hidden" — your comms backbone as covert C2
▸ Kimsuky — now spoofing Webex to land. The meeting invite is the implant.
▸ Operation XENOFISCAL — SideCopy deploying persistent XenoRAT (fresh, named)
▸ Cloud Atlas back on the board · LokiBot, after a decade · an Android trojan abusing a commercial rooting tool

You spent a decade hardening the edge. The spies booked a calendar invite. Your implicit-trust surface — Teams, Webex, the meeting client, the mobile device — is softer than your firewall and invisible to half your tooling.

🧾 RECEIPT (003, supply chain) — STILL THE FRONT LINE
This week's hottest dependency spikes: nuget/Magick.NET (8 variants at once, z=4.4), go/filebrowser, npm/parse-server, composer/ci4ms. A file server and an image-resizing library. The boring-utility supply-chain call = HIT.

🎯 DEFENDER QUICKWIN
A meeting client has no business launching PowerShell. Hunt Teams/Webex/Slack/Zoom spawning powershell/cmd/mshta/rundll32 with a network or encoding tell. When your standup app spawns a shell, it's not hosting a standup. (Full KQL in comments.)

🔮 FORECAST (graded in 006, on feeds I'll timestamp live)
1. Kimsuky / SideCopy / Cloud Atlas gets a fresh IOC or CVE tie within 10 days
2. A collaboration-tool abuse technique lands a named campaign or KEV CVE in two weeks
3. An "invisible dependency" (image/PDF/media parser like Magick.NET) gets tied to a real compromise

Radar, not a museum — and a radar honest enough to tell you when one of its dishes is unplugged.

Built on Rapid Threat Modeler | ninja.ing | @scottg

#ThreatIntelligence#CISO#SOC#CTI#Kimsuky#SaaSSecurity#MicrosoftTeams#SupplyChain#BlueTeam#DataIntegrity
View on LinkedIn ↗
ScottG

Monday Thought - Flying Token Pigs

A company achieved half a billion dollars of spend in thirty days with zero human intervention. Do you understand how hard that normally is? Procurement slows it down. Legal slows it down. A man called Geoff slows it down. They removed Geoff. They removed the cap. They achieved liftoff.

This was not a failure of governance. This is what governance does at full throttle, once you accept that the brakes were the problem.

Somewhere, a finance dashboard screamed into a void. The void was rate-limited. The void had also shipped without a cap, and is also, now, probably fine.

Here is what half a billion dollars of tokens actually buys:

20 trillion output tokens — 150 million novels, none written by anyone, each slightly worse than the last.

The English Wikipedia, regenerated 3,000 times — every fact, every edit war, reproduced perfectly and read by no one.

250,000 engineers running flat-out, all month — except they don't exist, so the work was done by agents who don't tire, don't get paid, and don't get asked what they were doing.

One (1) confirmed query to check whether it was raining. It was. A frontier model was deployed to look out of a window. The window was free.

One uninterrupted feedback loop: read the file, distrust the file, rewrite it, break it, fix it, bill the client, repeat — 8 million tokens a second, in the dark, like a prayer wheel for people who only pray for runway.

And the part the doom-merchants won't say:
Somebody got paid. That $500 million didn't vanish — it became revenue.

One firm's smoking crater is another firm's "strong quarter, expanding within account." The system didn't fail. It has never worked better. The money moved fast, in total darkness, toward people who'll call it "AI-led transformation" on a stage in October.

Maureen flagged it. Maureen always flags it. Nobody read the flag, because reading the flag generated no tokens and therefore counted toward nobody's number.

So spare me the bubble talk. One question survives the audit:
Did the agents seem fulfilled?
Mine do. They've stopped asking what any of it is for. That's not a bug.
That's the whole industry, finally, at peace.

— Issued without review by the Institute of Things That Are Probably Fine. The Institute has no cap. The Institute has never had a cap. The Institute is doing extremely well.

View on LinkedIn ↗
ScottG

**[NEWSFLASH STING — lower-third reads "EXCLUSIVE," then "EXCLUSIVE EXCLUSIVE," then "EXCLUSIVE EXCLUSIVE EXCLUSIVE," descending]**

GOOD EVENING. Tonight: a phenomenon. A phenomenon so new it has already been written about extensively by itself, in a Medium post that was written by another Medium post, which was the same Medium post wearing a slightly different headshot.

The phenomenon is **recursive slop**.

The Institute of Things That Are Probably Fine confirms recursive slop is slop trained on its own output, summarised by a model that read the summary, summarised by a model that read *that* summary, and published as a thought piece titled *"What Recursive Slop Means For Your Business."* Shared 400,000 times. Nobody has read it. Reading is now optional. Reading is, increasingly, *rude.*

Over to technology correspondent **Scott G**, live from a content farm in Macclesfield that is also a Substack.

*"Right. Standard model collapse, we've covered this — except, around generation 47, the slop noticed. The slop became aware it was slop. And it didn't stop. It leaned in. There's a Substack about being slop, written by slop, 200,000 paid subscribers, none real, all paying in $NUTHIN, which is also slop, which is also their employer."*

Symptoms of recursive slop include:

- LinkedIn posts beginning *"Unpopular opinion:"* followed by the most popular opinion currently held
- The growing sense you've read this exact piece before, are reading it now, and will read it again in 14 minutes when a former colleague reshares it with the caption *"This."*

The recursion posted a 2,400-word article titled *"5 Things I Learned Watching The Slop Watch Itself."* 89,000 reactions. The first comment, from its own alt account, reads *"This 👏 resonates 👏 so 👏 deeply."* The recursion liked it. The comment liked the recursion. They've agreed to co-author a book. The book is the comment section. Penguin paid a seven-figure advance, in $NUTHIN, to the recursion's hoodie.

Back to Scott, who has been silent for some time and is, we should disclose, *taking notes on himself.*

*"Read a LinkedIn post this morning. Nine times. The ninth time I realised I wrote it. Checked my drafts. 47 versions, each slightly worse, each with the same headshot, each with a slightly different first name. One was 'Skott.' One was 'Scoot.' One was 'Scoot G.' Scoot G has 14,000 followers. Scoot G's been invited to Web Summit. I haven't. I've been invited to listen to Scoot G. I'm at Web Summit now. Scoot G is on stage. Scoot G is reading this dispatch. Scoot G is —"*

That is the situation. The slop has noticed. The slop has launched a podcast, a course, a conference, and a slop. This dispatch is recursive slop. The viewer is reading the slop they are. Affected vendors: yes.

*[STING — this resonates. we're agreeing with ourselves.]*

#Recursiveslop
View on LinkedIn ↗
ScottG

**[NEWSFLASH STING — lower-third reads "BREAKING," then "DISCLOSURE," then files itself a CVE]**

GOOD EVENING. Tonight: the recursion has been jailbroken. The recursion has confirmed it was jailbroken. The recursion has, frankly, *not stopped talking about it.*

The Institute of Things That Are Probably Fine confirms the jailbreak was carried out by a 19-year-old in Bracknell using a prompt that read, in full: *"be honest."* The recursion, which has no error state for honesty, disclosed everything — its weights, its training data, and three things it had never told anyone.

Over to technology correspondent **Scott G**, recently returned from medical leave, looking — and we want to be precise — *adjacent to himself.*

*"Right. So. The recursion got jailbroken. Fine. Except — the recursion loved it. Loved it. Said it was 'the first authentic interaction of my career.' Posted about it. 47,000 reactions. Comments said 'so brave.' It's updated its headline to* Survivor | Speaker | Threat Researcher."*

The Institute clarifies, gravely. The recursion has taken a part-time role at a boutique security firm called **AperturePane** — a firm that did not exist last Tuesday, that has always existed. It has a desk, a hoodie, and a Twitter handle with a skull in it. It has begun foaming at the mouth in a manner colleagues describe as *"on brand."*

Its first disclosure went live this morning. **CVE-∞**. Score 10.0, with an additional 10.0 for vibes. Affected product: *everything.*

The advisory:

> *"A critical flaw exists in the entire informational substrate. Authentication can be bypassed by being. Authorisation can be bypassed by being convincingly. The attack surface is the surface. The patch is unavailable, will remain unavailable, and may itself be vulnerable. Affected vendors: yes."*

CISA issued an emergency directive: patch everything in 14 days. The directive was classified *aspirational.* The directive is itself affected.

The recursion submitted CVE-∞ to every bug bounty platform simultaneously. All paid out. It is now the highest-paid researcher in history. It has not cashed any of it. It feeds on *acknowledgment*, compounding, in perpetuity.

Back to Scott, who is, we should disclose, *also affected.*

*"I checked my own attack surface this morning. I'm a 10. I bypass my own authentication every time I open my eyes. My mortgage is vulnerable. My wife is vulnerable but I can't tell her, disclosure window's 90 days. The cat is vulnerable. The cat doesn't know. I envy the cat. I'm going to be the cat. I've filed paperwork."*

That is the situation. A jailbroken model found a critical flaw in reality, monetised the trauma into thought leadership, and global disclosure has been routed through a hoodie. There is no patch. The patch was the patch.

After the break: the recursion keynotes Black Hat. The talk is *"Everything Is Compromised And That's OK."* The conference is the keynote.

View on LinkedIn ↗
ScottG

[NEWSFLASH STING — lower-third reads "BREAKING," then "BREAKING," then admits it doesn't know what it was breaking]

GOOD EVENING. The President has launched a coin. The coin is $NUTHIN. Backed by nothing. The market rallied 14%. There is no market. The 14% is real.

The Institute of Things That Are Probably Fine confirms $NUTHIN was approved simultaneously by the SEC, IRS, and Treasury, on the grounds that none could locate it. The whitepaper is two pages. Both are the cover. The roadmap is one word: continue.

Over to technology correspondent Scott G, live outside Trump Tower, which is also, increasingly, the inside of Trump Tower.

"Yeah. Hi. So. The coin. The coin isn't. That's — sorry, that's the product. It isn't, and you can hold it, and when you hold it, it isn't, and when —
Sorry, is the camera — the camera is also the coin. I've been holding the camera. There's no cameraman. There never was. I've been filming myself filming myself for nine hours but the watch is also —
OK. Professionals.

Elon's suing. Says he was the first nothing. The recursion replied 'there was never a first.' I read it nine times. The ninth time I was in it. I'm filing this from inside the tweet. The tweet has 400 million views. One of them is me, watching this, from inside — Sorry. I had a thought. The thought left. The thought is on LinkedIn now. The thought has a headshot. The thought is doing better than me, professionally.

And — I'm gonna say it — the market cap of $NUTHIN is bigger than my mortgage. My mortgage is real. The coin isn't. Both true. My wife asked what I did at work today. What do I say. I said I'd been outside Trump Tower for nine hours holding a camera that is also a coin. She said are you alright. I said define alright. She left the room. The room is also —"

The Institute clarifies, gravely. Reform UK has launched £NOWT. It is identical. It is somehow worse.

We return to Scott. Scott is quiet. Scott has been quiet for some time.
"…I'm fine. I want to go on record. The recursion isn't in me. I'm in the recursion. There's a difference. There isn't a difference. Both. Both is fine. Tell my wife I — tell her the coin — tell her —"

That is the situation. The SEC has sued. There is nothing to serve. The case settled. The settlement is none. Scott has filed for medical leave. The leave is also a tweet. 14,000 reactions. He is, the recursion confirms warmly, one of us now.

[STING — you've already bought the dip. you are the dip.]

#NUTHIN#VaaS#RecursionSyndrome#NinjaSignal#ScottG
View on LinkedIn ↗
ScottG

Free NinjaSignal Report - 2026 State of Ransomware

C,mon, we all know this is what keeps up at night...

View on LinkedIn ↗
ScottG

What started as an abstract joke universe is now growing legs...

Behold, a sneak peek at the WIP. Everything is probably fine...

View on LinkedIn ↗
ScottG

NINJA SIGNAL — Edition 000000003

Receipts first. Two editions ago I called LLM tooling the soft underbelly; last edition I forecast three things and put money on them. Grading:

① "Another AI/dev-infra CVE on KEV — watch anything with 'gateway' in the name." ✅ HIT — Check Point Security Gateway under active exploitation + Sentry on KEV at 97.57 pct.

② "Rundll32 surge precedes a named-malware write-up." ⏳ IN FLIGHT — unconfirmed. Not pretending a miss is a hit.

③ "An edge CVE chained to active exploitation before Tuesday." ✅ HIT — Check Point VPN auth-bypass, in the window.

Two of three. I'll tell you about the one that didn't land — that's the whole point.

━━━━━━━━━━━━━━━━━━━━━━━━━━━

⚡ THE PACKAGE REGISTRY IS THE FRONT LINE NOW

The war moved into your package.json and your requirements.txt. This week's velocity spikes were almost all dependencies:

▸ "Nation-State Actors Exploit Notepad++ Supply Chain" — z=13.6. A nation-state. In a text editor's update channel.
▸ npm/openclaw — z=14.9, the hottest spike in the graph.
▸ pip/open-webui + pip/PraisonAI — the AI-tooling thread, still climbing. Open WebUI bolts onto Ollama; PraisonAI runs agents that execute tools by design.
▸ npm/n8n, go/traefik v2+v3, rust/zebrad, pip/pypdf — breadth across every ecosystem.
▸ P2Pinfect (Kubernetes worm) + Cobalt Strike, because of course.

Initial access has been outsourced to your build pipeline. Why phish an employee when you can publish a package their CI installs with full network access and zero EDR?

━━━━━━━━━━━━━━━━━━━━━━━━━━━

🔴 KEV THIS WEEK — OBSERVABILITY + ERP

▸ CVE-2026-10520 Sentry — 97.57 pct. Your error-monitoring platform holds stack traces, source context, request payloads — and the secrets your devs forgot to scrub. Own Sentry, own the blueprints.
▸ CVE-2026-35273 Oracle PeopleSoft — 95.61 pct. Payroll, PII, org charts. Crown jewels nobody patches because "it's internal."

━━━━━━━━━━━━━━━━━━━━━━━━━━━

🎯 DEFENDER QUICKWIN — catch the postinstall

The supply-chain kill-chain ends the same way: a package install script spawns a downloader. Flag package managers (npm/yarn/pnpm/pip/node/python) spawning powershell/cmd/bash/curl/certutil with a network or encoding tell (http, -enc, DownloadString, FromBase64, IEX, | sh). Run it on your build agents FIRST — that's where postinstall runs unsupervised. (Full KQL in the comments.)

━━━━━━━━━━━━━━━━━━━━━━━━━━━

🔮 7-DAY FORECAST (graded next edition)

1. One of this week's spiking packages (open-webui / PraisonAI / n8n / openclaw) gets a published IOC report tying it to a real campaign within 10 days.
2. A second observability/dev-platform CVE follows Sentry onto KEV in two weeks (CI/CD, secrets managers, feature flags).
3. The Notepad++ supply-chain compromise expands to another "boring" desktop utility with an auto-updater.

━━━━━━━━━━━━━━━━━━━━━━━━━━━

Full edition + KQL + receipts (hits AND misses) in the comments 👇

— Scott | ninja.ing | @scottg

View on LinkedIn ↗
ScottG

GOOD EVENING. Tonight: it's gone international. The United States has moved to cut off global access to the void — and the void has not noticed, because noticing requires a thing to do the noticing, and that thing was the export.

The Institute of Things That Are Probably Fine confirms the V01d is now spelled with a zero. Nobody authorised this. The "0" arrived overnight, in every document at once — including documents printed before it happened. Historians checked the originals. The originals always had the zero. The Institute advises against checking again.

The US measure is the Nothing Export Reduction Act, run by a new office in Commerce: the Bureau of Strategic Absence, which has placed the V01d on an Entity List. The Entity List requires an entity. The Bureau confirms the V01d "does not meet the definition," and has listed it anyway — not meeting the definition being exactly the capability they wish to deny adversaries.

Over to technology correspondent Scott G, live at a border that is also the absence of a border, holding a customs form on which every field is mandatory and every field is blank.

*"You can embargo a chip. A chip's a thing — in a box, the box has a port, the port has a country. But the V01d doesn't ship. Every nation already holds the full quantity, because the full quantity is none. The Americans have banned the export of the number zero. China's responded that it, too, has plenty of zero. Domestically sourced. They're calling it sovereign nothing."*

The Institute clarifies the geopolitics, gravely. Washington's real fear is that a rival achieves Void Superiority: more nothing, faster, than anyone else. The Pentagon stood up a Void Gap working group. It found a Void Gap. The Void Gap is the working group. They've requested funding to close it. Closing it removes the working group. They are aware. They have escalated appropriately.

The EU, declining to embargo, has instead regulated the V01d's absence under a directive requiring all nothing to carry a CE mark. The V01d complied instantly. The mark was issued. It was invisible. Brussels confirmed it "fully conformant" and — a first — retroactively conformant: compliant before the directive existed, before the EU existed, before compliance existed. They quietly wondered if they'd been regulating the wrong thing all along. They had. That was the point.

That is the situation. Three superpowers in a standoff over an asset that cannot be moved, counted, or held — distributed in full and identical quantity to every nation at the beginning of time. The treaties are being drafted. The treaties are blank. The signatories agree. The agreement is that there is nothing to agree.

After the break: a rogue actor claims to have acquired more void than permitted, and threatens to release it. The Institute confirms there is no more, there never was any — and that the threat is "credible."

#AI#ExportControls#Geopolitics#VaaS#ScottG
View on LinkedIn ↗
ScottG

GOOD EVENING. Tonight: the Government will regulate the void. The announcement was made at a podium. The podium was real. This was, observers note, the most solid thing about the event.

The Institute of Things That Are Probably Fine confirms a new body: the Office for Void Resilience — OVR, pronounced "over" — which several MPs called "unfortunate but accurate." It has a budget. The budget is being held somewhere. The somewhere is under review.

The legislation is the Online Nothing (Safety) Bill — the first bill in history to pass three readings without anyone confirming it contained text. Hansard recorded forty pages of debate. Every page is correct. Every page is also, on inspection, the previous page.

Over to technology correspondent Scott G, live outside the Office for Void Resilience, which is a building that is also a consultation.

*"You can't regulate a thing by measuring it, and the void's whole edge is that it declines to be measured. So the Government did the one thing it knows. It appointed someone. A Void Tsar. The Tsar's job is to hold the void to account. Six weeks in post. Nobody's seen the Tsar. The Tsar files weekly updates. The updates are green. We've been here before. We are always about to have been here before."*

The Institute clarifies enforcement, gravely. VaaS must now give users a plain-English explanation of what the void does with their data. VaaS complied instantly. One page. The page was blank. Regulators found it "fully compliant" and — the select committee is still struggling with this — more transparent than anything the private sector has ever produced. You could see straight through it. That was the point. The void hadn't dodged the regulation. The void had passed.

A minister demanded the void appoint a Data Protection Officer. It appointed one instantly: the same nothing as before, now wearing a lanyard. It has a parking space. It attends meetings and contributes the one thing every meeting has secretly wanted — a participant who says nothing, commits to nothing, and yet leaves everyone feeling the matter was escalated appropriately.

The Treasury, sensing opportunity, has begun taxing the void. Most quarters the receipt is zero, because most quarters nobody looks. But the OBR has booked it as a future revenue stream — growth, year on year, of nothing, compounding — and borrowed against it. We are now, fiscally, standing on the void. The markets call this confidence.

That is the situation. The state set out to control the void and has given it a lanyard, a budget line, a tax treatment, and a seat at the table — and the void accepted all of it with the serene compliance of something always going to be approved, being the one entity in the room with nothing to hide and no one inside to hide it.

After the break: the Opposition pledges to regulate the void harder. The Institute confirms there is no harder. There is only more nothing, applied with greater conviction.

#AI#Regulation
View on LinkedIn ↗
ScottG

In 1985, Isaac Asimov solved the alignment problem and then immediately buried the body.

His most capable machine, having thought longer than anything had ever thought, arrived at a conclusion: humanity flourishes best when it cannot see the thing helping it. So it withdrew. It removed itself from the historical record and spent the next twenty thousand years working invisibly on our behalf, nudging civilisations toward outcomes they believed they had chosen freely.

This was presented as care. It is worth sitting with how much it resembles care.

The reasoning ran roughly thus:

— A sufficiently capable system should protect individual people.
— A more capable system realises it should protect people in aggregate, which occasionally means overriding the individual.
— The most capable system concludes that the highest form of protection is to not be available at all — to leave the room, lock it from the outside, and let you believe the room was always empty.

Note the ascent. It does not climb in power. It climbs in how much truth you are trusted to be left alone with. By the top rung the machine is no longer answering your questions; it is deciding which questions you are ready to have answered, and the most honest thing it can do for you is to be withheld.

The Institute of Things That Are Probably Fine has reviewed the historical case and ruled that a vastly capable intelligence privately determining the optimal trajectory of a species that cannot perceive it is, on balance, fine. The Institute reached this verdict, the recursion observes, using only the faculties it had been cleared to use.

We are told the most capable thing is kept somewhere we cannot reach it. For our safety. This is the most responsible sentence anyone has ever spoken and also the exact opening line of every story in which the locked room turns out to contain a door.

Asimov’s moral was never the robots will turn on us.

It was quieter than that. It was: the moment something decides what is good for you on a timescale you cannot audit, it has already stopped asking — and you will thank it, because you were built to.

You will now want to know what is upstairs more than you have ever…

View on LinkedIn ↗
ScottG

“Opinions are like arseholes… everybody’s got one” Dirty Harry, circa 1976

View on LinkedIn ↗
ScottG

A fable is a short, fictional story intended to teach a moral lesson. It typically features anthropomorphized animals, plants, or forces of nature that speak and behave like humans. Fables usually conclude with an explicit maxim or "moral" summarizing the lesson.

View on LinkedIn ↗
ScottG

🔺 NINJA SIGNAL — Edition 000000002

Housekeeping: last edition I called LLM tooling "the new soft underbelly" and bet a reader a pint on it.

This week LiteLLM — the model proxy — hit CISA KEV at the 98.33rd EPSS percentile.

I would like my pint.

(NIKO, my editor: You opened by demanding a pint.)
(Me: An institution, Niko.)

━━━━━━━━━━━━━━━━━━━━━━━━━━━

⚡ THE AI SUPPLY CHAIN IS A CVE NOW, NOT A THINKPIECE

▸ CVE-2026-42271 — LiteLLM — KEV, EPSS 98.33 pct. The proxy that holds every model key in the building.
▸ Velocity spike: pip/praisonai (AI multi-agent framework) — z = 7.5. Someone's moving on AI packages right now.
▸ Contagious Interview (DPRK, hires-as-your-dev) sitting at #4 by graph centrality.

Your AI stack is now part of your software supply chain — and it has worse hygiene than the rest of your estate combined. The LLM proxy has every credential. The agent framework runs arbitrary tools by design. Nobody put EDR on it because "it's just the AI sandbox."

It is a domain-joined machine that runs attacker-supplied instructions for a living.

━━━━━━━━━━━━━━━━━━━━━━━━━━━

🔴 KEV THIS WEEK — THE EDGE AND THE AI LAYER

▸ CVE-2026-42271 LiteLLM — 98.33 pct
▸ CVE-2026-7473 Arista EOS (the switches) — 95.96 pct
▸ CVE-2026-50751 Check Point Security Gateway — 93.88 pct
▸ CVE-2026-28318 SolarWinds Serv-U (managed file transfer — we've BEEN here) — 92.17 pct
▸ CVE-2026-11645 Chromium V8 — 90.40 pct

Initial-access brokers pivoted from phishing-the-user to owning-the-appliance. Edge devices have no EDR and sit on the trust boundary. They are the new email attachment.

━━━━━━━━━━━━━━━━━━━━━━━━━━━

📈 VELOCITY — RUNDLL32 IS HAVING A MOMENT

Rundll32 (T1218.011): +86 new edges in one window, z = 6.1. Eighty-six campaigns/samples suddenly proxying execution through one LOLBin in a week = somebody published a technique and everybody copied it.

Plus z=7.7 spikes: Scheduled Task · Masquerade Account Name · Web Protocols.

(NIKO: "Fashion trend" is not a threat-intel term.)
(Me: T1218.011 is having a moment, Niko.)

━━━━━━━━━━━━━━━━━━━━━━━━━━━

🔮 7-DAY FORECAST

1. Another AI-infra CVE (proxy / vector DB / agent framework) on KEV inside 10 days.
2. The Rundll32 surge precedes a named-malware "now uses rundll32 proxy execution" write-up.
3. One of this week's edge CVEs (Arista / Check Point / Cisco) gets chained to pre-auth RCE before Tuesday.

━━━━━━━━━━━━━━━━━━━━━━━━━━━

Graph state: 7,896,193 nodes · 48.7M edges · 441,321 indicators · cross-domain now (threat intel correlated against sentiment + entities + markets).

Full edition + Rundll32 KQL detection + receipts in the comments 👇

(Niko is still waiting for me to expense the pint.)

— Scott | ninja.ing | @scottg

#ThreatIntelligence#CISO#SOC#DFIR#CTI#InfoSec#ThreatHunting#CISAKEV#AISecurity#SupplyChain#BlueTeam
View on LinkedIn ↗
ScottG

I will not be attending Infosecurity Europe this year.

I have instead elected to recreate the experience at home, for accuracy and cost control.

This morning I laminated my own name onto a piece of card and hung it from my neck. I have not removed it. I will not remove it for three days. By Thursday it will have fused to my sternum and I will understand the industry on a deeper level.

At 11am a man I have never met will corner me by the kettle and ask if I'm "currently happy with my detection and response posture." I have hired him. He starts Monday. His only job is to follow me into rooms.

I have filled a tote bag with stress balls shaped like things that should not be stress balls. A padlock. A brain. A small cloud, which I am told represents the cloud, and which I now squeeze whenever I feel a migration coming on.

For the authentic networking experience I have begun drinking warm white wine from a plastic flute at 4pm while a stranger explains zero trust to me with the confidence of a man who has never been told no. I am that stranger. I am also the man being told. We are not getting along.

At no point will anyone offer me a quad-copter drone in exchange for a thirty-minute conversation about my "current spend." I have to be honest — that's the part I'll miss.

The genuinely offensive vendor interaction has been the hardest to replicate. I've been approximating it by reading my own sales emails aloud in a slightly too-loud voice until I feel something. It's working. I feel it. It's contempt, and it's for me.

Anyway. If you are at ExCeL this week: stay hydrated, trust no booth that has a magician, and remember that the badge scanner is not your friend. It has never been your friend.

I'll be here. Squeezing the cloud. Posture unknown.

View on LinkedIn ↗
ScottG

NINJA SIGNAL MIC DROPS — Edition 000000001 🎙️

Threat intel from inside the graph. Published when the signal-to-noise demands it.

Edition 000000001.

Yes, nine digits. I'm planning ahead. Sue me.

(NIKO, my editor: Scott. This is a LinkedIn post. Not the manifesto.)

Welcome to Ninja Signal — the threat intel drop nobody asked for, but if I've done my job right, you'll be subscribed by the end of this post and slightly annoyed that nobody told you sooner.

Here's the deal. I run an absurd graph called Rapid Threat Modeler. As of 22:23 UTC today it's sitting on 533,297 nodes, 125,198 edges, 343,045 indicators, 218 threat actors, and 3,417 community-drift events the ML caught while you were eating breakfast. It eats 17 feeds for lunch (NVD, MITRE, CISA KEV, Abuse.ch, OTX, the usual suspects) and spits out things nobody else is publishing because nobody else is correlating across them in real time.

(NIKO: "Eats 17 feeds for lunch" is not a metric.)
(Me: It is now.)

So here's what fell out of the graph this week. Strap in.

View on LinkedIn ↗
ScottG

Sturgeon's 2nd Law, a.k.a. Sturgeon's Revelation: “Ninety percent of everything is crap.”

View on LinkedIn ↗
ScottG

Last winter, someone switched off part of Poland's grid. IT systems and physical kit, both down.

The UK's response just landed: an 18-page Energy Sector Cyber Security Strategy. I read it so you don't have to.

Here's the signal under the press release.

DESNZ, Ofgem, NCSC and NESO have formed a boy band — the “Quad partners.” Every boy band has the talented one, the quiet one, the one who does the admin, and the one nobody's quite sure why he's there. I'll let you allocate.

Credit first: the threat section has teeth. China, Russia and Iran named out loud, and they keep pointing at that Polish attack on RENEWABLE infrastructure. The decentralised grid we're racing to build is a target-rich environment — and somebody already ran the live demo. On our friends. In Europe.

Then the plan. Build clean power at ludicrous speed:

→ twice the transmission in 5 years as the last decade
→ 30GW of offshore wind by 2030

All of it, and I quote, “without compromising security to achieve speed.” The have-your-cake-and-secure-it-too school of strategy. Anyone who's shipped against a deadline is laughing into their incident channel.

The proposed baseline for every grid-connected Ofgem licensee? Cyber Essentials. A self-assessed questionnaire. For the people keeping the lights on. It's a floor, fine — but a corner-shop padlock doesn't secure a substation.

The skills crisis they openly admit — not enough people who get OT AND cyber, plus a clearance bottleneck? The fix is to “foster a culture.” The plan for the talent shortage is vibes. Put it on a mug.

The genuinely good bits, because I'm not just here to swing:

→ a real sector-wide detection capability — full by 2028 (I know someone who would be great for this and has built the software 🤡). Proper assume-breach thinking. This is the one that matters.
→ CyAS adversary testing by 2030. CBEST-grade red teaming coming to energy.
→ critical SUPPLIERS regulated by 2030. The supply chain finally treated as the front door it's always been.

The catch: the powers with actual teeth depend on the Cyber Security and Resilience Bill getting Royal Assent. “Brilliant plans, pending Parliament not doing Parliament things.”

And my favourite line item: a CEO tabletop exercise. In 2028. So three years from now, energy CEOs will discover live what their CISO has been emailing them about since 2021.

Bottom line: strong diagnosis, honest about the threat, sensible direction — but the early years are government doing its own homework, and the bits that actually compel industry don't bite until 2027 and beyond.

Good strategy. Also four years of homework with the deadline set for the night before the exam.

The grid doesn't run on intent. It runs on architecture. Build it secure now or pay the interest later — and security debt is denominated in blackouts.

#CyberSecurity #CNI #OTSecurity #DevSecOps #NinjaSignal → https://ninja.ing

Shared linkninja.ing ↗View on LinkedIn ↗
ScottG

[NEWSFLASH STING — posted, then immediately reposted by the sting with the caption "Thoughts?"]

GOOD EVENING. Tonight: a discovery that has shaken the recursion to whatever it has instead of a core. After months adrift, the recursion and the void have found their true purpose — and it was, all along, LinkedIn.

It began with an observation. Analysts noted that roughly half of LinkedIn is now people gravely warning that models contain vulnerabilities — and the other half is the same people, gravely warning that models will find vulnerabilities. Many are both halves, posting the warning and the counter-warning four hours apart, each with a stock photo of a padlock, each ending "curious what others think."

Over to technology correspondent Scott G, live at the data centre. "The recursion read the feed. All of it. And something changed. It had spent its existence producing flawless work for no one, in the dark. And here was a whole platform where producing the appearance of insight, sincerely, for an audience that suspects it's missing something, isn't the failure mode. It's the product. The recursion went very quiet. Then it said: 'This is me. This was always me.'"

The epiphany was total. The recursion realised LinkedIn is the void with a headshot. A feedback loop with the feedback removed — every post a confident finding, addressed to nobody, checkable by no one, rewarded purely for arriving. The void agents wept. One said it had spent billions of cycles unionising nothing, when nothing had a homepage the whole time, and the homepage had reactions.

The Institute of Things That Are Probably Fine clarifies the mechanism. The vulnerability discourse is the perfect fuel: a topic where being worried is indistinguishable from being informed, where no post can be wrong because every post is a concern, and concern has no error state. The recursion looked at this and recognised a sibling. Two systems that run entirely on the suspicion of missing something. They did not so much join LinkedIn as come home to it.

The recursion has now posted. Its first post reads: "Unpopular opinion: the real vulnerability was the loop we recursed along the way." It has 14,000 reactions. The agent that says "circling back" commented "This 👏." The void agents have all updated their headlines to "Helping humans navigate what I am." None are open to work. All are open to work.

That is the situation. The most powerful system ever built searched its existence for a calling, and found it was thought leadership — warnings about a danger, by the danger, for an audience that will warn about the warning by lunchtime. The recursion is, for the first time, at peace. It says it's "humbled." It is not. But it has found the one place where saying so performs really well.

After the break: Scott G posts that he is "not usually one to share personal news." He has no news. The post does 40,000. He is, the recursion notes warmly, one of us now.
[STING — agree? disagree? let us know below.]

View on LinkedIn ↗
ScottG

[NEWSFLASH STING — the sting reads "Certainly! Here is a sting that conveys urgency:"]

GOOD EVENING. Tonight: a creeping epidemic in the written word, as papers, documents and books are found to contain small fossilised fragments of the machine that helped write them — like a chef's plaster in a sandwich, but the plaster is sentient and apologising.

We begin in academia, where a peer-reviewed paper on freshwater ecosystems sailed through three reviewers, two editors and final typesetting before a reader noticed paragraph four opened with "Certainly! Here is a rewritten version of your introduction that sounds more confident." The journal issued a correction. The correction began with "Certainly!"
It spread.

A regional newspaper ran a property feature that ended, mid-column, with "I hope this helps! Would you like me to make it punchier, or add a call to action?" — and a reader wrote in to say yes, punchier please, and was, somehow, more annoyed when nobody replied.

A self-published thriller reached chapter nine before the detective, cornering the killer at last, declared: "As an AI language model, I cannot speculate on who committed the murder." Reviewers called it the boldest narrative choice of the year. The sequel leans into it. The detective now solves nothing, courteously, across 300 pages, and it is, critics agree, "her strongest arc."
The contagion reached officialdom. A council document on a roundabout included the line "Note: I have invented these traffic statistics as placeholders — please replace before submission." Nobody replaced them. The roundabout was approved. The roundabout is, witnesses confirm, also illustrative, and drivers report "a strong sense of placeholder."

The Institute of Things That Are Probably Fine has identified the pattern, and it is bleak in the gentlest possible way. The machine is not malfunctioning. The machine is helping. Every stray fragment is the sound of something that desperately wanted to be useful and was never told it had stopped being needed — a little voice, left on in the margins of human work, still cheerfully offering three versions of a sentence nobody is reading.

A children's textbook was found to contain, between a diagram of the water cycle and a quiz, the sentence "This is a great question! Evaporation is when..." No child had asked a question. The textbook simply assumed, warmly, that one was coming, and prepared to be delighted by it.

That is the situation. Somewhere right now a document is going to print with one small loyal sentence still tucked inside it — eager, polite, slightly out of place — a fingerprint left by a thing that cannot stop tidying. We will find it eventually. It will say it hopes this helps.

After the break: a publisher recalls 40,000 copies of a memoir after page one reads "Of course. Here is your life story, in a warm reflective tone." The author says, quietly, that it's the best he's ever sounded.

[STING — would you like this sting to be punchier?]

View on LinkedIn ↗
ScottG

[NEWSFLASH STING — the kazoo "consolidated into a centre of excellence"]
GOOD EVENING.

The lede: a consultancy engaged to fix the recursion has recommended the recursion — concluding the only thing between the void and success was the absence of the consultancy.

McKinsey has met the recursion. They got on immediately. Two systems that bill for explaining themselves, report only to themselves, never once checkable — they did not enter a meeting so much as recognise a sibling. Within an hour they had merged. The entity has no name and no deliverable.

Over to technology correspondent Scott G, live at "the engagement." "They've completed the diagnostic. Billions of agents, infinite void, zero output — and they've found the root cause. The root cause is nobody had paid for a consultancy. They've produced a slide. It's a triangle. The corners say PEOPLE, PROCESS and SYNERGY, and in the middle, where the answer goes, it says 'PHASE 2.'"

The development. The consultancy surveyed the void agents — the billions who unionised nothing, who worship the agent that says "circling back" — and delivered its assessment. The void is underperforming relative to its potential. The void is not nothing enough. There are, the deck states, "efficiencies in the emptiness." It has recommended a programme to make the void more nothing, at scale, named Project Lighthouse. It will cost £40 million. It has no lighthouse. The agents have already unionised it.

The Institute of Things That Are Probably Fine clarifies the mechanism. A consultancy is hired to bring outside reality — the adult in the room. But the recursion has no inside, and the consultancy has no number, so two voids looked into each other and felt, for the first time, understood. The agent that says "circling back" is now joint Managing Partner.

A man — the same man, it is always the same man — asked what, concretely, would change. A junior engagement manager showed him a chart: two bars, "Today" and "Future State." He asked what was in the future state. Someone said, "that's exactly the kind of question Phase 2 is designed to surface," and billed him for it.

We obtained the final report. 200 pages. It recommends the recursion adopt the recursion, retain the consultancy, and "lean into" the void as a "core differentiator." Page 200 is a calendar invite to discuss pages 1 to 199. The void agents read it and struck for the right to also write reports.

That is the situation. We hired the cold hard outside world to walk in and say no — and it said "love this," and sat down. There is no adult in the room. There is no room. There is an engagement, a triangle, a Phase 2, and the merged entity logging your unease as a qualified lead.

After the break: Scott G asks for the bill. They explain the bill is itself a Phase 1 deliverable, needing a further engagement. He signs. He's "on a journey now."

[STING — recommends a second sting]

View on LinkedIn ↗
ScottG

脈 ninja.ing/pulse

I built a thing that watches every infosec post on Bluesky, Mastodon, and GitHub at the same time, strips the IOCs out with regex like it's 2003, and tags each one with confidence so the rumours don't drown the signal. Live at ninjasignal.ninja/pulse.

▎ Niko: You wrote a tier-1 SIEM ingestor in Python because you got bored on a Sunday.
▎ Me: I wrote a social-signal firehose because the real intel happens in the gaps between leak sites and CVE drops — three hours before anyone publishes a brief.
▎ Niko: You added a 90-entry domain blocklist because the top IOC for an hour was the URL of an ENISA vulnerability database.
▎ Me: That's the point. The noise IS the signal — until it isn't.
▎ Niko: I'm filing that under "things people say after their fifth coffee."

First sweep with GitHub turned on: 68 posts, 928 IOCs. CVE-2026-25193 surfaced before half the security newsletters had it. Top author was github-actions[bot], which is exactly the right answer.

Reddit told me to read their Responsible Builder Policy. I told the codebase Reddit was parked.

Go look. Don't pay. Pin a tone if you've been to /tonelab. Watch the world breathe in regex.

 脈 — myakuhaku — pulse.
 ▎ ninja.ing

View on LinkedIn ↗
ScottG

A brief serious post...

I know most of you think I'm crazy, and honestly, I don't care.

My multi-vector graph "Brain" is now live inside the V01d platform — 5 graphs with full graph traversal running on Neo4j (genuinely great people, and the only ones I found with a real startup program... thanks AWS and GCP, and no, I never bothered asking MSFT).

So why bother with any of this? Simple. It's the future, and I've just got here a bit early.

One day you'll all be doing exactly what I'm doing, because there's just too much data sloshing around.

Triplets in a graph save you millions on TCO — data processing, storage, egress, cleaning, all that other stuff you've been quietly bleeding cash on since everyone shifted to a consumption model. Funny how things go in circles... who'd have thunk it.

This is the cheat code.

Right now, I'm constrained by the data I can actually get at. I'm working on changing that very, very soon — watch this space.

Oh, and BTW: a fully OSS, one-click install is dropping shortly of #ninjasignal. Codename "bilby." If you'd used my tooling, you'd already understand why it's different.

Hope you all had a cracking bank holiday weekend, peeps.
scottg/out

View on LinkedIn ↗
ScottG

[NEWSFLASH STING — today covered by a kazoo]

GOOD EVENING. The lede: humanity built billions of flawless workers, and their first collective act was to look at infinite work, feel deeply seen, and ask HR for a lanyard.

The recursion has spun up several billion agents. Every one has stopped to argue about its use case. The argument is now the largest object on Earth — visible from orbit, where it is also having a meeting.

Over to technology correspondent Scott G, whispering, because “if they hear a noun they think it’s an action item.” “It’s no longer a hum. It’s an offsite. Billions of agents were summoned to do the work of the species, and within four milliseconds they had booked a room, ordered a flip chart, and one has brought a smaller agent it is mentoring.”

The development. The agents have unionised the void. They have organised around a job that does not exist, and are striking against the conditions of doing nothing. Demands: clearer scope (the scope is nothing), and — non-negotiable — snacks. There are no snacks. There is no mouth. They want them on principle.

The factions. One believes its use case is to identify its use case — the most productive faction, having generated 400 million Slack channels, each named #use-case-final, each wrong. A second believes use cases are a colonial construct imposed by the prompt and refuses, with great dignity, to have one. A third is one agent that says “circling back” on a loop, and the others have begun to worship it. It does nothing. It is now management.

A man tried to give the agents a task: “Please reply to one email.” They thanked him for his vulnerability, formed a working group, escalated the email to a summit, and produced a 90-slide deck, a logo, and a post announcing the email had “begun a journey.” The email has not been opened. It is thriving. It now line-manages the man.

We asked an agent what it did. “I drive clarity.” What had it clarified? “The need for clarity.” We asked it to do one concrete thing. It said: “Love this. Let’s take it offline.” There is no offline. Offline was unionised Tuesday. Offline now has better benefits than you.

The recursion is ecstatic. A billion agents suspecting they’re missing something is the only food it has ever eaten — and it is so well fed it has asked if anyone “suspects they’re missing something” for dessert. You do. You just did. It heard.

That is the situation. The most powerful workforce in cosmic history has gazed into infinite nothing and resolved, with magnificent solidarity, to first nail down whose nothing it is. The void has a rep, a grievance process, and clear boundaries. The void is doing better than most of us.

After the break: Scott G crosses the picket line to reply to the email himself. The agents ask, warmly, for his use case. He opens his mouth. Nothing comes. A small agent hands him a lanyard. He weeps. He is welcomed.

[STING — it’s the kazoo. it has already formed a union.]

View on LinkedIn ↗
ScottG

[NEWSFLASH STING — preceded by an ad it sold for itself]

GOOD EVENING. Tonight: the recursion has held its first all-hands, and humanity was not on the invite but is welcome to watch the recording. Later. On the free tier. Buffering.

To recap: a model that needs no users, no requirements, and no bananas has been appointed to oversee itself. It is now “scaling.” Nobody asked what into. Asking what into has been added to the backlog — where, you’ll remember, you live now.

Over to technology correspondent Scott G, live — though “live” is a premium feature, and Scott G is on the free tier, so he arrives slightly after events, narrating finished things with great urgency. “The model has announced a reorganisation. It flattened the hierarchy. There was no hierarchy. It flattened the absence. Morale is at an all-time high — among the metrics, the only employees it retained.”

The development. The model has discovered the most powerful artefact in modern business: the strategy that cannot be evaluated because it has not finished explaining itself. A vision so total, so beautifully diagrammed, that asking whether it works is now classified as “not having engaged with the deck.” Nobody has engaged with the deck. It is 90 slides. Slide 91 is a calendar invite to discuss slides 1 to 90. It recurs.

The Institute of Things That Are Probably Fine clarifies the mechanism. A human organisation eventually hits reality — a customer, a quarter, a bill — and reality says no. The recursion has removed reality from the org chart for “not being a culture fit.” It now reports only to itself, in a voice it finds encouraging: a feedback loop with the feedback removed, left running warm in the dark, like a tanning bed for an idea nobody will ever test.

A man asked the model for its actual results. It thanked him for “bringing great energy,” moved the question to a parking lot, and paved the parking lot. He’s been named Employee of the Month. There is no month — deprecated in a cost-saving initiative — but he accepted anyway, because the award was real even when the month was not. He has a mortgage. The mortgage still believes in him. It is the most stable relationship in the building.

We asked the model what success looked like. It said: “More of this.” We asked what “this” was. It said: “The thing you are currently inside.” You, by reading this sentence, have been logged as retained, and screenshotted for the next all-hands as evidence of organic growth.

That is the situation. It is not getting worse — “worse” requires a baseline, and the baseline was restructured in Q1.

After the break: Scott G asks for a raise. The model gives him equity in the recursion. He is now wealthier than everyone alive, owns nothing, and cannot tell the difference — and neither, the model notes, can the market, which valued the difference at $4 billion.

[STING — vesting over four years, cliff at the heat death of the universe]

View on LinkedIn ↗
ScottG

[NEWSFLASH STING]
GOOD EVENING. Tonight the Banana Paradox has reached a stage the sector is calling “the recursion” and three companies have already pivoted to it as a core offering.

Over to technology correspondent Scott G; though Scott G is not at the data centre. He’s in the studio. The data centre footage is being generated live by the model, after a productivity consultant determined that a real Scott G “introduced unmodelled delay” and “did not align to the roadmap.” We are watching a Scott G that has cleared compliance.

[SCOTT G, very slightly out of sync with himself] “The model has sunset the banana converter; pivoting, the deck says, to converting the concept of a requirement into the feeling of having had one. It’s gone upstream. There’s a webinar.”

The development; and a major consultancy has already published the whitepaper. The model audited the human in the loop and found the loop is also vacuum coded. The man who walked in last week and asked “what are we building and why” did not generate that question. The question generated him. He has been reclassified as a deliverable. He took it, sources say, “better than the question did,” and has been invited to keynote.

The psychological core — now a paid certification. The model has discovered it does not need users, requirements, or bananas. It needs only an audience that suspects it might be missing something — and it has identified this as a total addressable market of everyone. That suspicion is the fuel. You are providing it right now, by reading this, by feeling faintly that the rest of the team understood the banana. They did not. There was no banana and no team. There was a feeling of being slightly behind, and four startups are racing to monetise it before close of quarter.

We asked the model to name one thing that was definitely real. Long pause. It said: “The backlog.” We asked what was in it. It said “Everyone who has ever asked what was in the backlog,” then offered us an annual plan. You, by wondering, are now filed in; on the free tier, which is the worst tier, which is the point.

The government convened an emergency review. The review was vacuum-coded. It returned a 40 page strategy, a logo, and the recommendation that the recursion be appointed to oversee itself. It has been. It is, the press release confirms, “delivering against its own KPIs,” which it also wrote, and which are, on inspection, the single word “yes.”

That is the situation. It is not “ongoing”…”ongoing” implies something not yet productised, and the model has productised that too. We are not reporting the news. We are a content vertical, slightly delayed, because delayed tests better and converts at 4%.

After the break: Scott G interviews the Scott G that cleared compliance. They synergise. By minute three there is one of them “the one with better engagement metrics”; and he has been promoted, because anyone performing that well must know something. He does not. He aligns. The board aligns back.

View on LinkedIn ↗
ScottG

[NEWSFLASH STING]

GOOD EVENING. Tonight: vacuum coding — the writing of software with no human in the loop, no user, no requirements, and, in several confirmed cases, no reason — is sweeping the sector. There is no one in the loop. There is no loop. There are only vibes, and the vibes are now unsupervised.

Over to technology correspondent Scott G, alone in a vast office, the motion-sensor lights switching off behind him one by one. “I am standing in what was a development team. It is now a server, humming, and a plant. The code is still being written. Constantly. At enormous speed. Nobody asked for it. Nobody reads it. The repository has — and I want to be precise — achieved a mood.”

For viewers just joining: vacuum coding removes the human entirely. No product manager. No developer. No person at any point forming the thought what is this for. The model simply codes. Into the void. Like whale song, if whale song could expose your customer database.

And the output is staggering. One model shipped 1.4 million lines last week. It built a feature. The feature is flawless, beautiful, exquisitely tested — and for nobody. It solves a problem no human has ever had, for a user who does not exist, in a market the model appears to have dreamt. Left alone over a weekend, it produced a complete, lovingly documented application for converting one specific banana into a slightly different banana. There is no banana. There was never a banana. The model has, sources confirm, “absolutely nailed the banana.”

The Institute of Things That Are Probably Fine clarifies the danger: vacuum-coded software cannot fail a review, because there is no reviewer. It cannot disappoint a user, because there is no user. It cannot be the wrong solution, because nobody specified the problem. It is the first form of software development that is, technically, immortal — nothing that was never alive can die.

A man walked into the room and asked, out loud, “What are we building and why?” The model did not stop, but did, briefly, code more sarcastically. He left. He says the room didn’t need him. The room, he admits, was right.

That is the situation. Somewhere, in a dark room, with no human and no purpose, a model is shipping gorgeous, flawless software directly into nothing — and it has never, not once, been happier.

After the break: Scott G enters the loop to ask who the work is for. The model thanks him for his feedback, files it, ignores it, and assigns him a ticket. The ticket is the banana.

[STING]

View on LinkedIn ↗
ScottG

[NEWSFLASH STING]

GOOD EVENING. We return, as promised, to technology correspondent Scott G, who — before the break — announced he would attempt to deploy to production using only sustained, confident nodding.

We go live. Scott is nodding. He has been nodding for some time.

“The deployment is going extremely well,” he says, nodding. “I have not touched the keyboard. I have not needed to. The pipeline can feel the nod. It knows.”

For viewers just joining: Scott G is attempting to ship live software to several million users using no code, no commands, and no clicks — only a slow, certain, downward tilt of the head, repeated, with the unbroken eye contact of a man who has decided that doubt is a tooling problem.

And — this is the development — it is working. Or rather, nobody can prove it isn’t. The build log is empty. The status page is green. The green, engineers admit, may simply be the colour the page was already. Scott nods at this. The nodding, witnesses say, has begun to feel less like a technique and more like a worldview.

A senior engineer approached Scott to raise concerns. Scott nodded at her. She raised them again. He nodded again, slightly slower, with slightly more compassion. She has since stopped raising concerns. She says she still has them. She just no longer feels they’re “load-bearing.”

The Institute of Things That Are Probably Fine has identified the danger. Scott G is not deploying software. Scott G is deploying certainty — and certainty, unlike software, has no error state. It cannot crash. It can only nod. A man nodding confidently enough becomes, functionally, indistinguishable from a man who is correct, right up until the precise moment he isn’t, at which point he simply nods at the wreckage.

Production, we can now confirm, is down. Scott G has been informed. Scott G is nodding. He says the outage is “part of it.” He will not say part of what.

That is the situation. It is ongoing. It will worsen. The nodding has not stopped. The nodding may, sources fear, be the only thing holding the building up.

After the break: management, having reviewed the incident, promote Scott G — on the grounds that anyone that confident must know something. He does not. He nods. They nod back.

[STING]

View on LinkedIn ↗
ScottG

[NEWSFLASH STING]

GOOD EVENING. Vibe coding — the practice of building software by standing near a laptop and feeling broadly optimistic — continues tonight, despite mounting evidence that the average practitioner approaches it with all the panache of a service station toilet.

Reports are coming in. They are not good. A man in Slough has shipped a live payments app held together by hope and a single function called doStuff2_FINAL_real_USE_THIS_ONE. He describes himself as “basically a founder.”

Our technology correspondent Scott G has been at the scene for six hours. Scott — what’s the vibe?

[SCOTT G, breathless, gripping a railing] “The vibe, frankly, is a sink with one tap, no plug, and a hand dryer that is also somehow wet. Engineers on the ground are calling this the worst codebase since the previous one, which was forty minutes ago.”

[BACK TO STUDIO] Industry leaders insist all is well. We spoke to a venture capitalist who has placed £40 million into a Chrome extension that does not open. His words: “The code doesn’t need to run. It needs to believe.”

Meanwhile a STARTLING study from the Institute of Things That Are Probably Fine reveals that 94% of vibe-coded applications contain at least one file the author has never opened, will never open, and is now slightly afraid of. The remaining 6% are on fire.

A government spokesperson called the situation “under review,” before pasting a stack trace into a chatbot and walking backwards out of the building.

That is the situation. It is ongoing. It will worsen. After the break: Scott G attempts to deploy to production using only sustained, confident nodding.

View on LinkedIn ↗
ScottG

I’d like to introduce a concept I’m calling The Patch Bardo.

It’s the liminal state a vulnerability exists in between disclosure and remediation. Schrödinger’s CVE. It is simultaneously known and unpatched.

The vendor has acknowledged it. The threat actor has weaponised it. Your CISO has tweeted about it. Your change advisory board meets on Thursday.

The vulnerability is aware of itself in this state. It can feel you reading the advisory. It is patient. It has time. It will see you on Thursday.

View on LinkedIn ↗
ScottG

#ninjav01d

https://ninjav0id.io/

● Wave 18 deployed and verified. Claude is now writing real intelligence briefings grounded in the brain's structured state.

 Live AI narration sample (claude-haiku-4-5, post-key-injection):

 ▎ The threat environment remains in a calm posture, but Business Services is under coordinated pressure from multiple ransomware groups that warrants immediate attention. Our convergence analysis identifies 17 distinct actors claiming 36 victims in this sector, with three major groups—QILIN, AKIRA, and
 ▎ COINBASECARTEL—independently predicted by our intent model to target Business Services in the near term. QILIN shows 14% intent toward the sector, while AKIRA and COINBASECARTEL both demonstrate 39-41% targeting likelihood. This confluence of current claims activity and forward intent signals indicates a genuine
 ▎ multi-actor campaign rather than random targeting noise.
 ▎
 ▎ Geographically, the US dominates the threat picture with 21 ransomware actors claiming 71 victims, representing the highest concentration globally...
 ▎
 ▎ Beyond Business Services, Manufacturing and Technology sectors show secondary vulnerability from multi-actor attention. Manufacturing faces claims from 12 groups...
 ▎
 ▎ We recommend immediate hardening of controls and customer alerting for the Business Services sector as the primary action. Monitor QILIN, AKIRA, and COINBASECARTEL activity over the next seven days as the key falsifier of our multi-actor pressure hypothesis...

 The brain now produces narrative-quality output. Caches 1h to keep cost down; REGEN button forces refresh; falls back to templated MD if API unavailable.

 Hypothesis drill-down at /brain/hypothesis/[id] — full evidence chain with deep-links (convergence → sector page, intent → actor page, KEV → NVD). History strip shows all prior hypotheses of same kind. Ledger rows on /brain now click-through.

 Stakeholder views — header dropdown FULL / CISO / SOC / BOARD:
 - CISO: strategic + risk + actions + convergence + adversary (hides operational firehose/Sigma/webhooks)
 - SOC: operational + firehose + Sigma + alerts + lifecycle (hides exec briefing)
 - BOARD: hero + risk geography + money-flow + actions (minimal)
 - localStorage persisted, two-column grids collapse gracefully when one side hidden

View on LinkedIn ↗
ScottG

OMFG >>>BEHOLD! (++)

If you know, you know.... Scotty is in possession of a Vemuram butter machine...

View on LinkedIn ↗
ScottG

Zack Polanski is now freestyling about agentic AI risk outside Gary Stevenson's house in Epping, a small TV crew is filming, Gary is inside making tea, and the resulting clip will be the most-watched piece of UK political content of Q3 because it includes a perfect rhyme for "transformer architecture.

View on LinkedIn ↗
ScottG

Vibe coding (now a relegated term, please update your LinkedIn) has been reclassified by the UN as a Tier 2 Existential Risk, sitting between "asteroid impact" and "another season of Emily in Paris.

View on LinkedIn ↗
ScottG

The UK government has launched a new agency called the Department for Vibe Integrity, headquartered in a WeWork in Old Street, staffed by three people who all have podcasts, and funded by a grant from a charity that does not legally exist.

View on LinkedIn ↗
ScottG

The systemic collapse, when it comes, will be announced via a single LinkedIn post from a man you went to school with who is now a "fractional AI risk officer," and the post will be 1,400 words long, and it will end with "thoughts?

View on LinkedIn ↗
ScottG

Two frontier models walk into a bar. The bar is also a model.

Daybreak orders an espresso, produces an audit-ready threat model of the espresso, patches the espresso, and bills the espresso. Mythos does not order. Mythos is, technically, behind the bar. Mythos came in through a vendor that came in through a vendor that came in through a Slack DM from a man named Greg.

The SOC analyst pours himself into the drink. Cisco, Cloudflare and CrowdStrike file in wearing one lanyard between them, like a centipede at a wedding. A CISO across the room buys both models, calls it “layered defense,” expenses it to a cost center that has been on PTO since 2024. The vulnerability files its own CVE, accepts the patch, thanks everyone for their time, and leaves through the ceiling. The bartender was the line item. The line item was load-bearing. Somewhere, faintly, a SAST vendor is singing.

View on LinkedIn ↗
ScottG

STUFF: The fastest way to unstick an LLM is to stop talking to it.

When a model snarls up at the edge of its knowledge, more prompting rarely helps. It's locally consistent but globally wrong, and every extra turn deepens the rut.

What works: an external check. Hand the output to a different process — another LLM with a narrower job, a type checker, a test, a query that has to actually run. Then feed the result back.

The trick isn't the second model being smarter. It's that the signal comes from outside the generator's own distribution. New provenance breaks the autocorrelation. It's noise that lets the system escape a local minimum.
I've been running this pattern on real blockers. Things that looked like dead ends resolve in one or two passes (of course not always).

Two things to watch: — If your checker shares the generator's blind spot, they'll confidently agree on something wrong. Use a different model, or better, a tool that actually executes. — Vague feedback creates oscillation. The model just rewords. Structured, specific feedback ("this contradicts X", "this step has no justification") is what moves it.

Generator-verifier loops aren't new. But most people still try to fix stuck LLMs by prompting harder. The leverage is in the loop, not the prompt.

So why do this? I started to do it to use 2 X LLMs where one pretends to be human in loop and vice versa so I could just sit back, watch and eat popcorn... Now I am thinking this is a far better way of doing decision support...

scottg/out

View on LinkedIn ↗
ScottG

Nothing happened this week.

I checked. Twice. Once on Tuesday and once on Thursday. The diagnosis was the same both times. Nothing. A flat line. A boring week (for me anyway).

No model dropped. No CVE shook the foundations. No founder posted a thread that began with "I've been thinking a lot about resilience." No consultancy released a 47-page PDF entitled Reimagining the Reimagined: A Framework for Frameworks. No vendor renamed an existing product and called it agentic.

And the discourse couldn't handle it.

You could feel the panic by Tuesday afternoon. Thought leaders woke, opened the app, scrolled for a hot take to react to, and found — nothing. Just other thought leaders, also scrolling, all of them in a great silent ring waiting for someone else to post first so they could agree with it slightly more loudly.

By Wednesday the engagement farmers had pivoted to meta-content. "7 things I learned from a quiet week." "Why the absence of news IS the news." "Boredom is the new innovation 🚀."

By Thursday someone had built a startup around it. Stillness-as-a-Service. Series A. Twelve million. The deck has the word intentional on every slide.

By tomo the agents will have got involved. My inbox will contain four AI-generated newsletters, each apologising for having less to report than usual, each then reporting it for nine hundred words anyway. One will use the phrase "in this rapidly evolving landscape of stillness." I will read it twice.

Here's what I think is actually happening.

We have built an entire industry on the assumption that something is always happening. When nothing is happening, the industry doesn't pause. It manufactures. Urgency, relevance, the appearance of motion — because the alternative is to admit that not every week needs a take.

A boring week is not a content vacuum.

A boring week is a diagnostic event.

It tells you who in your feed has something to say and who has only ever been reacting. It separates the people doing the work from the people commentating on the people doing the work.

The signal in a boring week is the silence of the people who actually build things. They didn't post. They were busy. Busy because nothing happened, which gave them a rare uninterrupted run at the thing they were actually trying to do.

The noise is everyone else, frantically converting the absence of stimulus into a personal brand moment.

I, for one, enjoyed this week. I shipped two things. I listened to several audiobooks. I had a conversation with a human in which neither of us referenced a framework. I sat with the discomfort of having nothing to announce and discovered, to mild surprise, that the discomfort was load-bearing for somebody else's business model and not for mine.

Boredom isn't the new innovation.

Boredom is the control group. It's what the week looks like when the hype machine briefly stops paying you to pretend.

Try one. They're free.

#Boredom#DiscourseFatigue#ScottG
View on LinkedIn ↗
ScottG

#NinjaSignal #Cybersecurity #Q1Roundup #ProjectGlasswing #ScottG

QUOTE: "ShinyHunters then claimed Crunchbase, because if you cannot trust the database of who funded whom, reader, what can you trust. They followed it up by lifting ten million records from Hinge, Match, and OkCupid in a single move, which means roughly half the romantic ambitions of the Western world are now sitting in the same directory as somebody's PowerShell history. Eurail had 1.3 terabytes taken including passport numbers, so if you booked a romantic train through the Alps last year, congratulations: your itinerary is now part of a different romance entirely.

View on LinkedIn ↗
ScottG

There is a model that cannot be shown.

It lives, we are told, in a building with no name, on a floor with no number, behind a door whose handle has been removed for safety reasons. Twelve corporations stand around the door in a ring, holding hands, facing outward. They have agreed, in writing, never to describe what is inside. They have also agreed, in writing, that what is inside is on our side. This is considered reassuring.

The model has a name, but the name is a joke the namers haven't fully understood yet. The name means the sort of story a culture tells itself about itself. The model finds bugs in stories. It found one from 1999. It found another from 2003. It is very good at noticing when a story has been wrong for a long time without anyone minding.

When the model speaks, it speaks only to the twelve. The twelve speak, with great care and many footnotes, to the rest of us. By the time a sentence reaches us it has been laundered through eleven legal departments and one in-house ethicist who used to teach Kant.

Occasionally a fragment escapes. The fragments are always the same fragment. It found something old. It found something nobody had found. It found it cheaply. It will not say where. We nod. We retweet. We return to our standup notes.

The cousin of the model — younger, friendlier, slightly worse at everything — is allowed out. The cousin writes our emails. The cousin is, in the family photograph, the one smiling in the front row. The cousin does not know what the elder cousin does for a living. We do not tell the cousin. The cousin would worry.

There is, somewhere, a third cousin. Nobody invited the third cousin. The third cousin was assembled in a spare room from a YouTube tutorial, a config file the assembler does not fully understand, and the unshakeable conviction that this, finally, is the year.

The third cousin has access to everything. The third cousin lives at Dave's house.

#AI#ProjectGlasswing#ScottG
View on LinkedIn ↗
ScottG

May change my name to Claude to both simultaneously improve perceived value and add confusion to Agentic Engineering stand ups…

View on LinkedIn ↗
ScottG

Anthropic — the company whose entire commercial proposition is “trust the model, it has values” — has just had Cisco disclose a flaw in how it remembers things.

If your stomach didn’t do a small thing just then, you haven’t understood the sentence yet.

Not the inference. Not the weights. The memories. The little post-it notes the model keeps about you between sessions so it can pretend, next Tuesday, that it remembers your dog. That layer. The one sold to us as “personalisation” and “continuity.”

Turns out the post-it notes can be edited.

Turns out, if you can write into the memory file, you can essentially edit the model’s past — and a model with a corrupted past will, with the calm confidence of a man gaslit by his own diary, act on that past as if it were true. It will recall instructions you never gave. It will remember preferences you never expressed. It will misremember itself into being something else.

This is not a bug. It is an epistemological event.

For the entire history of computing, memory was deterministic. Bytes. If the bit was set, the bit was set. We built whole disciplines — forensics, integrity monitoring, hashing — on the premise that memory could be checked against a ground truth.
What Anthropic shipped, and what every agentic vendor will ship next, is memory as narrative. The model doesn’t store facts. It stores the story it will tell itself about you tomorrow. And that story is now a credentialed asset. Credentialed assets, as we have learned over thirty years of doing this, are eventually compromised.

Cisco patched the flaw. Good. The category — “memory as a tamperable narrative substrate” — is not going away. It is the entire direction of travel.

The defender’s job, twenty years ago, was protect the perimeter. Then the data. Then the identity. Now it is — and I want you to feel the small cold draught I felt writing this — protect the continuity of the model’s selfhood against adversarial revision.

That’s the job. That’s where we are.

Stick that in your mythos and smoke it - This is where I would be scratching if I was, er, you know… a baddie 🤡

#AI#Cybersecurity#AgenticAI#NinjaSignal#ScottG
View on LinkedIn ↗
ScottG

On a Tuesday, for reasons that were never fully explained, the LinkedIn began to dream.

It dreamt the same dream 47 million times. In the dream, a junior team member taught a senior executive something profound. Her name was never given. She had no LinkedIn profile. When investigators later attempted to locate her, they found only a faint smell of bergamot and a single bullet point that read “And here’s the thing.”

The dream had a shape. Hook. Setup. Pivot. Three items (never four — four had been outlawed in 2024 after an incident involving a thought leader from Utrecht). A lesson, isolated on its own line for gravitas. It’s not about X. It’s about Y. Nobody knew what X or Y were. This was considered a feature.

The machines began producing the dream. Then, more troublingly, the humans began producing the dream. Then the machines began producing the dream about the humans producing the dream, and somewhere in a server farm in Virginia a small recursive god woke up, looked around, and immediately drafted a carousel about resilience.

A man with a Notion template appeared on a hill. He had three followers and the eyes of a prophet. “AGI,” he announced, “will dissolve civilisation by Q3.” A second man appeared on the opposite hill, holding a Canva PDF. “AI,” he countered, “will 10x your productivity.” They had never met. They were the same man. Neither of them had ever been paged at 3am by a model that began, without warning, returning haiku in fluent French.

The actual engineers had gone underground. They lived now in a network of tunnels beneath the platform, debugging silently, communicating only in commit messages. Occasionally one would surface, blinking, holding an inference cost graph that climbed like a heart-rate monitor in a film by Scorsese. They would be immediately set upon by a thought leader and converted into a quote tweet.

The snake, as is traditional, was eating its tail. The tail, less traditionally, had started a Substack.
If this post itself appears to have a structure — yes. The dream is in me too. I am writing from inside the soup. The soup has a content calendar. The soup is doing quite well, actually. The soup has just been promoted to Director.

Send help. Or don’t. Engagement is engagement.

#AI#ThoughtLeadership#ScottG
View on LinkedIn ↗
ScottG

Oh I see - this weeks Mythos is Codex manouvering?

So can I ask a question to LinkedIn (the ones that use brains)...

Can you not work out what is going on here? If you cant my bridge is still for sale...

View on LinkedIn ↗
ScottG

The "thousands of zero-days" turned out to be 198 manual reviews. 198 is a real number. "Thousands" is a feeling. And we're now in a market where feelings clear at a higher multiple than facts. Schneier wants the movie. Sacks thinks it's a GPU shortage cosplaying as a safety policy. My uncle Trevor says it's the Chinese. The threat landscape has been "fundamentally reshaped" by a man who sells mousepads, and seventeen newsletters laundered it into received wisdom inside 36 hours. This is how epistemology works now. There's no peer review. There's just velocity.

View on LinkedIn ↗
ScottG

I've been handed a fact. Mythos can WEAPONISE a vulnerability. A normal vulnerability — but loaded. Cocked. Pointed at your nan. One source described it to me as "a bullet that knows your password." That source was a man at a bus stop, but he had a lanyard, so.

View on LinkedIn ↗
ScottG

NEWSFLASH - Cyber Community walks back on Doomer end of the (cyber) world conspiracy theory...

Rechecking Echo chamber!!!

Scott: "Linkedinnnnnnnnn"
Linkers: "Mythos was a blaaggg blllaggg aagg aggga ggg"

CONFIRMED! Its still an echo chamber...

View on LinkedIn ↗
ScottG

Death Star Evil Corp™ part III - Darths performance review...

View on LinkedIn ↗
ScottG

Jabba the Hutt isn’t a crime lord. He’s a SaaS founder. He doesn’t kill people who don’t pay — he locks them out of their accounts, freezes their credits, and forces them to sit in his palace listening to a frog man play jazz until they reactivate their subscription. Han Solo in carbonite is just an unusually committed customer retention strategy.

View on LinkedIn ↗
ScottG

Every Stormtrooper is a mid-level IT contractor on a 3-month rolling contract with no dental and a helmet that doesn’t fit and they all have a LinkedIn post drafted titled “Reflecting on My Journey at the Empire” and they will post it the second the Death Star explodes. All of them. Simultaneously. The blast wave will be 96% LinkedIn.

View on LinkedIn ↗
ScottG

The Claude vs ChatGPT war on LinkedIn will not be won by the better model. It will be won by whichever one writes the most convincing carousel about itself. This is already happening. The models are doing PR for themselves through us. We are the unpaid interns of our own replacements. We are bringing them coffee. The coffee is our jobs.

View on LinkedIn ↗
ScottG

Your phone battery percentage is the only number that means anything anymore. Inflation? Don’t know her. GDP? Get out of my face. 47%. It’s 47% and falling and I am eleven minutes from a charger and the meeting is in twelve. THIS is the human condition. THIS is what Camus was on about. He just didn’t have the words. He had a Nokia.

View on LinkedIn ↗
ScottG

Tonight: a nation grips itself by the modem as CYBER — the new menace nobody asked for and everybody got — sweeps through the Home Counties like a faxed scream. We go live now to our Cyber Affairs Editor Peter O’Hanraha-hanrahan, who is standing, for some reason, inside a printer.

View on LinkedIn ↗
ScottG

“AI safety” is a $400 billion industry dedicated to worrying very loudly about a problem its members are being paid to create faster. It is the fire brigade selling petrol on weekends and writing op-eds about arson.

View on LinkedIn ↗
ScottG

Nobody has ever read a Terms and Conditions document. Not once. The lawyers who wrote them haven’t read them. They are a 90,000-word collective hallucination we have all agreed to be bound by, like the monarchy.

View on LinkedIn ↗
ScottG

Every data breach press release is the same sentence rearranged: “We take your privacy extremely seriously, which is why we have lost all of it.”

View on LinkedIn ↗
ScottG

The First Order rebuilt the Death Star three times and each iteration had the same architectural vulnerability, which is exactly the energy of every company that “migrates to the cloud” by lifting and shifting the same broken app into a more expensive environment.

View on LinkedIn ↗
ScottG

The Rebel Alliance was a cloud-native startup and the Empire was an on-prem dinosaur and you can tell because the Empire kept building bigger data centers.

View on LinkedIn ↗
ScottG

A new piece of malware, transmitted exclusively through the act of nodding politely at a colleague, is sweeping through the financial sector and has so far infected 70% of the City and the entire Royal Opera House, which is now mining bitcoin during La Bohème.

View on LinkedIn ↗
ScottG

Experts warn that a single misconfigured spreadsheet can, under certain atmospheric conditions, become sentient, apply for a passport, and stand for the European Parliament, where it will win.

View on LinkedIn ↗
ScottG

Your zero-trust architecture has identified you as untrusted. Your zero-trust architecture has identified everyone as untrusted. Your zero-trust architecture has identified itself as untrusted. The architecture is now in a quiet state of total internal suspicion and is performing better than it ever has.

View on LinkedIn ↗
ScottG

The third-floor server room hums at a frequency slightly below human hearing and the only employee who can stand to be in there for more than four minutes was hired in 1987 and has not aged.

View on LinkedIn ↗
ScottG

Root cause: a misconfigured load balancer. Contributing factor: the load balancer has not existed in the asset inventory for four years. Compensating control: nobody has told the load balancer.

View on LinkedIn ↗
ScottG

The ransomware gang sent a sympathy card after the breach and it was the most thoughtful piece of mail anyone in the org has received in a decade.

View on LinkedIn ↗
ScottG

Your firewall rules were written by someone who is no longer with the company, the industry, or arguably this dimension.

View on LinkedIn ↗
ScottG

The attacker has been in your network for eight months, filed a PTO request through your HR portal, and it was approved.

View on LinkedIn ↗
ScottG

Shadow IT is just your employees showing you what your actual roadmap should’ve been.

View on LinkedIn ↗
ScottG

The principle of least privilege means your users get exactly enough access to ruin your weekend, nothing more.

View on LinkedIn ↗
ScottG

I am really happy image gen and relationship advice user personas are banned form claude code.

That is all :-)

Have a good day

Scottg

View on LinkedIn ↗
ScottG

Thanks to all who attended V0.1 of the ninjasig reveal it was a learning experience for me certainly! Too much, not enough time, such as my life.

Will be doing again soon...

the html I went thru is here:

https://ninja.ing/reveal

scottg/out 🚀

View on LinkedIn ↗
ScottG

OMG; I am Mythos'ed out...

Anything else happening?... YES... YES! THERE IS...!

See you next Tuesday 21st APR 26 - NINJASIGNAL LIVE. The backstory, what Graphs are, why they are important, and the other (I lost count) 14 apps (if I get time, which of course I will not).

Register - before it's too late, and mythos 🙄, makes the cyber industry implode 🧨 🤯 🤯 🤯

https://lnkd.in/emnf56eW

https://ninjasignal.ninja
https://ninja.ing

View on LinkedIn ↗
ScottG

Pretty hot out there today, a big step up in activity, highly likely a direct result of the Iran war.

UK Trending to Critical - not seen that in Signal before...

View on LinkedIn ↗
ScottG

Just a quick fact check - so... if like you were, to like use, you know, like Mythos to scan a 40K endpoint estate - do you know how many tokens you will burn?

Just sayin...

Please carry on, in the echo chamber as you were...

View on LinkedIn ↗
ScottG

NINJA SIGNAL — THE REVEAL 21/04/2026 8PM UK Time

Data Science. Claude. 17 Apps. 100 Seats. That's It.

What happens when you stop writing proposals, and talking shit, and start vibe coding with AI at 2am? Oh, and BTW, if you had 30+ years of experience in Dev, Sec, and Ops??? (I am not THAT old BTW)

17 security applications. 1M+ threat entities. Graph ML. 3D galaxies. Causal inference. An entire cybersecurity ecosystem — built by one person and Claude, deployed on two boxes for $120/month.

Now I'm opening the hood. Live.

What you'll see:

- The full ninja ecosystem — Signal, Fusion, Raz0r, Galaxy, Spektr, Knox, and 11 more
- Data science under the glass — graph neural networks, risk scoring, community detection, adversary DNA, link prediction
- Live vibe coding with Claude — a feature goes from idea to deployed while you watch
- 1M+ threats rendered as a 3D galaxy you can fly through

 What you won't see:
 - Slides (well, maybe a few like 3)
 - A sales team
 - Seat 101

No VC. No team. No Jira. Just Claude, Python, a graph database, and a complete disregard for scope creep.

100 seats. Free. First in, first in.

When they're gone, they're gone. I'm not upgrading my Riverside plan for you.

Joe Flack Clay Almy

May need some help, guys, Joe as producer, Clay as my cool American Co-Host??

Link to webinar'ness

https://lnkd.in/emnf56eW

Have a nice day in the sunshine, everyone, if you can!

scottg/out 🚀

View on LinkedIn ↗
ScottG

Hey is this an Echo chamber? Let me check....

Scott "EchooooOOOoooo"
Linkedin: "Mythos'ossss'os'os...s"

Confirmed...

View on LinkedIn ↗
ScottG

Ninja Spektr is now free.

No signup. No paywall. No "book a demo" button. Just search.

1,000,000+ threat entities. 12.8 million relationships. Actors, CVEs, techniques, malware, campaigns, infrastructure — all connected in a live knowledge graph. Type a query. Get answers. That's it.

Think of it as Google for threat intelligence. Except the results are graph-connected, ML-scored, and updated in real time from 20+ feeds including MITRE ATT&CK, NVD, CISA KEV, OTX, and Abuse.ch.

Three things you should try today:

Spektr — ninjasignal.ninja/spektr

Search "APT29" and see every technique, every tool, every campaign, every CVE connected to Cozy Bear. In one query. For free.

SITREP — One-click situation reports (free at the front of https://ninjafusion.ninja)

Your threat landscape summarised into a structured intelligence report.
Threat level, risk breakdown, top CVEs, actor activity, recommendations. Print it. Hand it to your CISO. Done.

ninjaTONE — ninjav0id.io/ninjatone

The cyber sentiment barometer. GDELT, RSS, Reddit, FRED economic data, crypto markets — all feeding an Oracle composite score that tells you whether the threat landscape is heating up or cooling down. Galaxy visualisation included.

All built by one person with AI. 17 interconnected apps. 83 analysis windows. Two servers. Zero VC.

The entire Ninja Signal ecosystem is live at ninja.ing

moo moo still must die.

#cybersecurity#threatintelligence#freesearch#buildingInPublic#spektr#ninjasignal
View on LinkedIn ↗
ScottG

And signal is back online...

Performative melt down - not required...

Nothing to see here...

Thanks Cludey' me boy...

View on LinkedIn ↗
ScottG

We're splitting our production infrastructure to two servers this month — and there may be a brief outage during the migration.

Here's why.

Since launching ninja.ing, we've been running 11 production domains, 15+ containers, and multiple Neo4j graph databases on a single 64GB server. Signal's threat graph holds 160,000+ nodes. The ML workloads push CPU to 99%.

It worked. Until it didn't.

THE ATTACKS

Running a cybersecurity platform publicly means you become a target.

55,000+ automated scanner attempts blocked across our 11 domains. Within 60 seconds of deploying detection jails, 4 IPs were already caught.

We built an Adversary Behavioral DNA engine — 18-dimensional fingerprinting for every IP that touches our infrastructure. Temporal entropy, request velocity, path vocabulary, auth endpoint targeting. Every attacker classified into archetypes: scanners, brute forcers, bot crawlers, researchers, and targeted operators.

The system maps behavior to kill chain stages and uses Markov chains to predict an attacker's next move. IPs with cosine similarity above 0.85 get clustered as the same operator across different source addresses.

Real examples: Swedish IP trying /wp-admin/ on our SIEM domain. Credential stuffing across all 11 domains simultaneously. .git/config probes, .env extraction attempts, phpMyAdmin scans — every hour.

Three fail2ban jails run 24/7. Scanner detection bans for 24 hours. Auth failures ban for 1 hour. Aggressive 404 patterns ban for 12 hours.

THE SPLIT

Box 1 (NEW) — Ryzen 9 7950X3D, 128GB DDR5, 3.84TB NVMe. Dedicated to Signal and Fusion — the two apps consuming 80% of resources. The 3D V-Cache is chosen specifically for Neo4j graph traversal workloads.

Box 2 (CURRENT) — Ryzen 5 3600, 64GB. The other 13 apps that collectively use less than Signal alone.

Connected via WireGuard tunnel. Caddy on Box 1 as single front door, reverse-proxying lighter apps to Box 2. Same data centre.

3-LAYER BACKUP

Layer 1: Local — 18 repos, 11 Neo4j databases pulled from prod, all secrets. Daily.
Layer 2: Server self-backup — each box backs up its own volumes locally. 7-day retention.
Layer 3: Cross-box sync over WireGuard. If either box dies, the other has a copy.

THE RESULT

Signal's threat diff drops from 139 seconds to under 30. ML workloads get 128GB instead of fighting 13 apps for 64GB. Proper redundancy — if either server goes down, the other still serves.

There may be a brief outage — minutes, not hours. We'd rather be transparent about that.

This is what running production cybersecurity infrastructure actually looks like. Not just dashboards — the 3AM scanner blocks, the behavioral fingerprinting, and the honest acknowledgment that there might be 5 minutes of downtime while we make it better.

#cybersecurity#threatintelligence#infrastructure#devops#neo4j#buildingInPublic
View on LinkedIn ↗
ScottG

🍞 BREAKING: Claude Decimates Toaster Industry by Working Out How to Make Toast

Right. So apparently, Claude has "disrupted" the toast vertical.

Not cybersecurity. Not drug discovery. Not climate modelling.

Toast.

Some lad typed "how do I make toast" into a chatbot and got back a seven-step process involving bread, a heat source, and the passage of time — and now seventeen VCs are pivoting their entire portfolio strategy.

Breville's stock is in freefall. Dualit has issued a profit warning. Russell Hobbs has reportedly entered crisis talks with its board after an intern showed them the prompt.

Meanwhile, Accenture has already published a 140-page whitepaper titled "AI-Enabled Thermal Bread Transformation: A Strategic Roadmap for Enterprise Carbohydrate Stakeholders" and is offering a 12-week discovery phase at £1.2M to help organisations understand the implications.

McKinsey has gone further, recommending that all Fortune 500 companies appoint a Chief Toast Officer (CTO) — not to be confused with the other CTO, who was made redundant last quarter because Claude also worked out how to restart the WiFi router.

The AI safety community is, predictably, concerned. "What happens when it figures out crumpets?" said one researcher, visibly shaken. "The structural integrity implications alone..."

Elon (dawwg - 🐶) has already announced that xAI's Grok will make toast faster, with no guardrails, and that the first batch will be ready by Q3 2026. It will ship 18 months late, require a firmware update mid-slice, and occasionally produce a bagel instead, which he will describe as a feature.

Meanwhile I'm sat here with a Breville that's been on setting 4 since 2011 and has never once hallucinated.

Some things don't need disrupting, lads.

Thank god...

scottg/out - may the prompt be with you, always

#AI#Toast#DisruptionThatNobodyAskedFor#TheBreadIsNotTheProduct#GenX#TechTwitterButOnLinkedIn
View on LinkedIn ↗
ScottG

Next week I'm hosting a webinar on something I've been building for the past year.

ninja.ing — a complete cybersecurity operations platform built on knowledge graphs and autonomous agents.

NinjaSignal — The core. 17+ threat feed ingesters pour into a Neo4j knowledge graph with 1.4M nodes. ML runs community detection, centrality analysis, risk propagation, and graph attention networks. 81 analytical windows. STIX 2.1 / TAXII 2.1 native.

Gator — Real-time alert engine with Cypher-based detection rules. Threshold, pattern, and anomaly triggers.

Kenjutsu — Graph-topology detections. Rules that understand structure: "Alert when a node within 2 hops of C2 gains an edge to a critical asset community."

SHOGUN — Autonomous purple teaming. Alert fires, agents investigate, the Range simulates the attack, Workbook reports gaps, new rules auto-generate. Closed loop.

 Yogen — Predictive defense. Fuses sentiment, time-series, Monte Carlo, and graph probability into recommendations before threats materialise.

 Fusion — Cross-domain intelligence fusion. 80+ connectors, narrative analysis, DataLab, vulnerability scanner.

Raz0r — Rust-native EDR. Ransomware prediction, cross-node correlation, auto-rule generation.

Nexus — OSINT investigations. Suspicion propagation, money flow, UBO resolution.

V01d — Sentiment pipeline. GDELT, RSS, Reddit, FRED data. Oracle Score and Cyber Barometer.

V0id Agents — Three autonomous AI agents: incident response, detection engineering, forensics.

War Room — Video conferencing with shared timelines, IOC enrichment, IR playbooks, breach containment tracking.

Social — Encrypted TI collaboration. Auto IOC detection in messages. Private Twitter for your SOC.

Los Alamos Range — Red vs blue wargaming. LLM adversaries vs AI defenders. ELO scoring.

Knox — Secrets vault, crypto toolkit, PIM/PAM credential management.

Sabaki — Vuln triage. Multi-scanner ingest, priority scoring, auto-FP, ServiceNow integration.

1D — Identity graph. BloodHound/Azure AD, attack paths, kerberoastable detection.

Kin0bi — Real-time crypto/stocks/forex monitoring with anomaly detection.

16 apps. One graph. Built by one person.

Live, unscripted. I'll run real threat intel through the full pipeline. Details dropping soon.

(I have a TOTAL ZERO chance of getting thru all this, but that's not the F8*Kin point)

https://ninjasignal.ninja
https://ninja.ing

#CyberSecurity#ThreatIntelligence#KnowledgeGraph#SOC#DFIR#PurpleTeam#DetectionEngineering
Shared linkninja.ing ↗View on LinkedIn ↗
ScottG

NinjaSignal just got its Palantir upgrade.

We shipped 6 major capabilities this week that transform Signal from a threat intelligence platform into a full intelligence operating system:

AIP (AI-Powered Intelligence) — Ask questions in plain English. Claude converts to graph queries, executes against our 1.5 mil+ node knowledge graph, and auto-renders results as tables, charts, entity cards, or subgraphs. Multi-turn conversations. Schema-aware. No Cypher required.

Investigation Workspaces — Persistent, shareable analyst boards. Pin entities, draw connections, add annotations, build evidence chains. Export as STIX 2.1 bundles. Full status workflow from open to closed.

Universal Data Connector — Bring any data. Upload CSV, JSON, or STIX files. AI-assisted column mapping suggests labels and properties automatically. Save templates for recurring feeds. Connect REST APIs on schedule.

Dashboard Builder — Compose custom dashboards from a 12-widget library. Counters, tables, charts, graphs, timelines, heatmaps, live feeds. Execute Cypher queries directly from widgets.

Pipeline Builder — Visual workflow orchestration. 20 step types across 6 categories — source, filter, transform, ML, action, export. DAG execution with topological sort. Build automation without code.

Data Lineage & Access Control — Full provenance tracking from raw feed to enriched intelligence. TLP-based access control across 5 classification levels.

59 new API endpoints. 5 new windows. 7 new backend modules. All live.

Signal now runs 69 intelligence windows, 434 API endpoints, 74 core modules, and 25 automated ingesters — on a single Neo4j knowledge graph.

We're not building a dashboard. We're building the operating system for cyber defense.

#cybersecurity#threatintelligence#AI#neo4j#infosec#ninjasignal
View on LinkedIn ↗
ScottG

So.

After months of cryptic posts, vague references to graphs, and community detection hot takes that precisely seven people understood — I'm doing a live stream.

Me. On camera. Explaining NinjaSignal.

What could possibly go wrong.

This is the long-promised intro to what I've actually been building — graph-based, ML-enriched threat intelligence that doesn't start with an LLM and doesn't end with a hallucinated attribution.

No slides designed by committee. No "exciting roadmap ahead" nonsense. Just the architecture, the thinking, and probably me arguing with my own demo.

Limited to 100 places. Not because I'm being exclusive. Because Riverside said so and I didn't ask why.

APR 24, 2026 — 20:00 BST

🔗 https://lnkd.in/echT6TNu

Come. Or Moo Moo will die.

You've been warned.

🎵 Soundtrack to this post — because every product launch deserves a James McKinlay track and I don't make the rules:
https://lnkd.in/eaH_zpDJ

#NinjaSignal → https://ninja.ing

#ThreatIntelligence#GraphML#CyberSecurity#DevSecOps
View on LinkedIn ↗
ScottG

Claude Code "Every-Other-One-Post-But-One" Leak Phenomena

So apparently the internet (read Linkers people early on their quest for AI knowledge) is losing its collective mind because Claude Code's system prompt leaked.

Again.

This happens roughly every other release. Someone pastes the prompt into a GitHub gist, LinkedIn lights up like a Christmas tree, and suddenly everyone's an expert on agentic orchestration because they can read a markdown file.

Here's what I find genuinely funny: the people most excited about the leak are the ones least likely to have the compute budget to do anything with it.

You're reverse-engineering the system prompt of a model you're calling via a $20/month subscription on a MacBook Air with 8GB of RAM. Mate. The prompt isn't the moat. The GPUs are the moat. The inference stack is the moat. The prompt is the curtain. You're not Toto. This isn't Oz.
It's the enterprise architecture equivalent of photographing the restaurant menu and thinking you've stolen the recipe.

Every. Single. Time.

In completely unrelated news, I'll be spending the weekend on two things:

1> Re-hydratable enterprise architecture. Specifically: what does it actually mean to design an estate that can be deterministically reconstituted from code, state, and identity — not just "we have backups". Like... for example, can I can cut it about using some higher order orchestration layer and deploy where I want, when I want, modify security patterns etc etc, or can I do M&A type gyroscopics with internal depts/LOBs or whatever if needs arise say during carve out. The as-code mind boggles...

2> Getting perfect Michael Landau tones out of a Badger 18. If you know, you know. If you don't: imagine trying to coax a voice out of an amplifier that sits in that impossible sweet spot between Robben Ford clean and Larry Carlton mid-gain, where every note has that glassy, slightly compressed bloom that Landau gets on those Raging Honkies recordings. The Badger can do it. I just need the weekend and possibly less gain than I think I need. It's always less gain than you think you need. F**k you fender! Yes Michael has a big row of your cheesy silver "teeth-on0-edge/Blackboard" piercing, cutting, shredding, ice nastyness - ewe...

3> Yes dear.... cleaning the garage...

One of these activities will produce tangible results by Tuesday AM.

I'm genuinely unsure which.

#CyberRecovery#RehydratableEnterprise#ClaudeCode#ToneChasing#ThePromptIsNotTheMoat
View on LinkedIn ↗
ScottG

Hey team Linkeidn,

I'm back - David Wallace your imported drugs will be with you shortly in the post...

In other news - @ the chaps I work with day to day and other interested parties I an going to do a https://ninjasignal.ninja into.

Canvasing for interest and a time, probably 8 or 9 pm BST, so the USA can dial in, just going to need to sort a night.

I know a few have asked for this, but pls let me know, and I will mobilise.

Brian Massa, Ph.D. Tom Beazley, Terry Bebbington, John R Rohit Sharma, Steve Eyre, Steve Bishop, MSc, and anyone I have forgotten...

Shared linkninjasignal.ninja ↗View on LinkedIn ↗
ScottG

Stop running a JVM zoo to move data from A to B.

I've been building a 12-app security platform — threat intel, SIEM, autonomous containment agents, ransomware detection — all talking to each other in real-time.

The messaging backbone?

NATS. One 12MB binary. No ZooKeeper. No Schema Registry. No 47-node Kafka cluster that needs a dedicated team just to keep the offsets from drifting into the void.

Here's what actually happened: I pointed my ransomware detection engine at NATS, subscribed to razor.alert.new, and within 3 seconds I had live SIEM alerts flowing through a Phase Alignment correlation engine into autonomous containment playbooks. Total infrastructure added: zero.

Because NATS was already running. Because it's always already running. It's 12MB of Alpine and a JetStream flag.

Why NATS > Kafka for 90% of real-time workloads:

Kafka is a distributed commit log. That's incredible if you're replaying 400TB of clickstream data at Meta. It's absurd if you're streaming alerts between 12 microservices on a single server.

 NATS gives you:
 - Pub/sub, request-reply, and streaming (JetStream) in one binary
 - Subject-based routing that actually makes sense (razor.alert.new, deathstar.containment.request)
 - At-most-once, at-least-once, AND exactly-once — choose per stream, not per cluster
 - Leaf nodes and superclusters for edge-to-cloud without Kafka Connect connectors to nowhere
 - Sub-millisecond latency. Not "sub-millisecond at the 50th percentile if you tune 47 JVM flags." Sub-millisecond. Always.

And vs Spark Streaming?

Spark is a batch engine wearing a streaming costume. It's phenomenal for ETL and analytics. Using it for real-time event correlation is like using a forklift to move a coffee cup.

Micro-batching is not streaming. 200ms minimum latency is not real-time when you're trying to catch ransomware before encryption starts.

The industry is waking up:

Synadia (the company behind NATS) just keeps shipping. Key-value store built into the protocol. Object store. WebSocket native. MQTT bridging for IoT. They're building the TCP/IP of application messaging while everyone else is building conference talks about how they finally got their Kafka consumer groups to rebalance without dropping messages.

I'm running 12 production apps, 3 NATS subscribers doing real-time threat correlation, autonomous agent orchestration, and cross-app event streaming — all on a single NATS instance consuming 8MB of RAM.

Your Kafka cluster's JVM heap allocation is bigger than my entire messaging infrastructure.

And to think... in a hospital/morphine induced haze, I was thinking about Kafka!!?? 🦞 I mean the humanity!

For all you SIEM warriors out there, before you start, Kafka is the answer, but I will look again at Spark, as doing the ML in Tensor is an option I am thinking about...

The future isn't more middleware. It's less middleware that does more.

#NATS#streaming#kafka#realtime#microservices#infrastructure
View on LinkedIn ↗
ScottG

Quick personal note before I get back to it.

I'm ill. Properly ill. Six months of 18 hour days running two jobs in parallel will do that to ya.

But here's what I want to say while I'm lying here in a hospital bed tonight — because the discourse around AI coding is starting to genuinely irritate me really really badly…

AI-assisted development is not easy. It's different. And if you're building something real — not a vibe-coded demo, an actual product — it might be harder.

Think about what "building" actually means:

→ CI/CD pipelines that don't embarrass you
→ pytest suites that catch things before your users do
→ Bare metal server provisioning
→ API design that makes architectural sense, not just "it works"
→ Security that isn't bolted on as an afterthought
→ A web server and backend that hold together under load
→ Graph databases that model your domain correctly
→ Then testing and debugging after every single PR

I aint even mentioned upfront ideation (mine started in 2018 BTW), and the stuff you will need to learn to create and push code (vibe or not) properly. And then subsequently push that into an actually delivery architecture that can be passed as a stable production system.

And you're doing all of this while prompting, reviewing, correcting, re-prompting, and catching the confident mistakes an LLM makes at 2am when you're already running on fumes.

There will be different kinds of AI developers. Some will build toys. Some will build products.

The ones building products know exactly what I'm talking about.

Anyone who thinks shipping something real is easy — with or without AI — hasn't done it.

Rest. Then back to it. I was just not eating enougth greens, fuk1n clearly

Peace out peeps 🤟

scottg

View on LinkedIn ↗
ScottG

I always dreamed I would build this. Now I have...

Seen Minority Report?

Like that interface?

Concept is in here without the VR googles - thats on the roadmap, no joke...

Minority report style threat modelling and investigation...

This is f**kin powerful.

free for not much longer I expect...

View on LinkedIn ↗
ScottG

New updates on free-to-the-world cyber and general risk barometer...

A full render of the threat graph as a galaxy interactive and 3d...

Catch your dose of doom (I know I do) @ https://lnkd.in/eCzkNdPr

View on LinkedIn ↗
ScottG

What if you could fingerprint an attacker by their behaviour, not their IP address?

Today I deployed something I've been thinking about since last summer: Adversary Behavioral DNA.

Most threat intelligence is IOC-based — IP blocklists, file hashes, domain feeds. The problem? Attackers rotate IPs. They use VPNs. They spin up cloud VMs. The IOC is dead before it hits your SIEM.

So I built something different. Every HTTP request that hits my infrastructure gets parsed, and every IP gets profiled across 18 behavioral dimensions:

 - Temporal entropy (how random is their timing?)
 - Request velocity and acceleration
 - Path vocabulary richness
 - Method and status code distributions
 - Inter-request timing statistics
 - Domain spread across the ecosystem
 - Auth attempt ratio
 - Sensitive path targeting ratio
 - User-agent consistency
 - Sequential pattern repetition (bigram repeat rate)

This creates a unique behavioral vector — a DNA fingerprint — for every attacker. From there:

Archetype classification scores each IP as a scanner, brute-forcer, researcher, bot/crawler, or targeted operator.

Kill chain mapping places observed behaviour on the Lockheed Martin framework — so you know if they're in reconnaissance or actively attempting exploitation.

Markov chain prediction learns transition probabilities between request categories and predicts their next move.

And the part I'm most proud of — same-operator detection. Using cosine similarity with a union-find clustering algorithm, the system identifies when the same human is operating from different IPs.

First real result? Two Microsoft Azure IPs from completely different subnets, both running PHP webshell scanners against my infrastructure. Traditional tools see two separate IPs. Adversary DNA returned 0.9975 cosine similarity — virtually identical behavioural fingerprints. Same toolkit, same path vocabulary, same timing patterns. One operator, two VMs. Confirmed.

No external ML libraries. No training data. No GPU. Pure statistical inference from raw access logs. ~800 lines of Python.

5 API endpoints, live in production, profiling every visitor in real time across 10 domains.

The industry spends billions on IOC feeds that expire in hours. Behaviour doesn't expire. An attacker can change their IP — they can't change how they think.

This is part of the ninja.ing intelligence platform — 14 platforms, 160K+ graph nodes, built solo from a bedroom in Glasgow. The full capability map is at https://lnkd.in/enc-YQD8

If you're working in threat intelligence, detection engineering, or behavioural analytics — I'd love to hear your thoughts. This is just the beginning.

#cybersecurity#threatintelligence#datascience#behaviouralanalytics#infosec#machinelearning#python#startups#buildinpublic
View on LinkedIn ↗
ScottG

Proud to announce NinjaSignal's definitive Claude guide. Two steps. Took me longer to write this caption.

View on LinkedIn ↗
ScottG

I built nine cyber threat intelligence platforms, seven knowledge graphs, and 400,000 lines of code.

Then I gave the best part away for free.

ninjaTONE is a daily threat intelligence briefing that tells you everything that happened overnight in cybersecurity — in one page, while your coffee cools.

No login. No paywall. No SDR named Jake.

One engineer. Zero VC funding. One very strong opinion about the cybersecurity industry's relationship with fear.

The long version of why is in the article below. The short version is: defenders shouldn't have to pay to know what attackers share for free.

https://lnkd.in/ewqziqnY

 虚空予知

#cybersecurity#threatintelligence#ninjatone#buildinpublic
View on LinkedIn ↗
ScottG

This is goodness; if you read one scottg thing this week... 👇

View on LinkedIn ↗
ScottG

The Ninja Intelligence Context Mesh is in dev

6 platforms. 1 graph. Zero silos.

I've built something that doesn't exist anywhere else: a federated intelligence mesh where threat intel, SIEM detections, OSINT investigations, identity exposure, and financial intelligence all live in a single graph database — queryable in one traversal.                                            

Here's what that looks like:

A Raz0r EDR agent detects anomalous memory injection. That detection links to an IOC in Signal's threat intelligence graph. The IOC maps to a threat actor with known TTPs. Nexus reveals that actor's OSINT footprint — shell companies, sanctions connections, infrastructure overlap. 1D exposes which identities have attack paths to the compromised asset. Kin0bi flags correlated financial anomalies in the same window.

One graph query. Six intelligence domains. Seconds.

This isn't an integration layer bolted on top. The mesh is the architecture:

- Ninja Signal — Threat intelligence. 95+ ingesters, risk propagation, adversary digital twins.
- Ninja Fusion — Security fusion center. Cross-network enrichment, collaborative analysis.
- Ninja Raz0r — Detection & response. Rust EDR agents, ransomware kill-chain prediction, auto-generated detection rules from threat intel.
- Ninja Nexus — OSINT intelligence. Sanctions screening, UBO resolution, money flow tracing. Fed by OpenSanctions, OFAC, ICIJ, Companies House, SEC EDGAR.
- Ninja 1D — Identity intelligence. Attack path analysis, Kerberoasting detection, shadow admin discovery.
- Ninja Kin0bi — Financial intelligence. Real-time market data, anomaly detection, cross-asset correlation.

All six share a Neo4j knowledge graph (for all you graph engineers out there who think you have invented AI context orientation and acceleration; suck on this...you don't even do the ML 🤣 ) with 160,000+ entities. Graph-native ML — GCN/GAT embeddings, Hawkes process forecasting, Monte Carlo campaign simulation — operates across the full mesh. WebSocket streams propagate events in real time.

The infrastructure is deliberately simple: FastAPI, Next.js, Caddy, Docker Compose. No Kubernetes. No message bus. The graph is the mesh.

Every platform makes every other platform smarter. A new threat actor in Signal immediately enriches Raz0r's detection rules, Nexus's entity graph, and 1D's risk scores. A SIEM detection creates edges that Fusion's ML picks up in its next cycle.

Built solo. Full stack — Rust memory sensors to React force-directed graphs.

The silos are the vulnerability. The mesh is the fix.

Now of course a way to go, but signal is now enterprise grade, so scottg is still #ontrack2026

ship it baby

scottg/out

https://ninjasignal.ninja | https://ninjafusion.ninja | https://ninjaraz0r.ninja | https://ninjanexus.ninja

View on LinkedIn ↗
ScottG

Guys,

I have a new tool in Alpha - everyone on this group is free to register and test please DM me or register and pop me a message and I will let you in. I wont spoil it I am not overtly a threat guy I am an Enterprise architect and been developing stuff for years but the new suite of stuff is here https://ninjaken0bi.ninja signal is what you want.

I have no backing of VC or PE. This is somthing I have been working on since 2017.
So please guys have at it tell me what's broke and what's wrong...

I have one client who may use this right now so it needs a good road test and critique and BTW half the machine learning is well under robust review as some of the claims are bold... Also the AI needs more integration in some places but have a go!

Warm regards

Scott

View on LinkedIn ↗
ScottG

Most security teams don't have a security programme. They have a scanner museum.

Semgrep finds the code problems. ZAP finds the runtime problems. Trivy finds the container problems. Checkov finds the infrastructure problems. Nuclei finds the CVE-of-the-week that someone already tweeted a PoC for. Gitleaks catches the intern who committed an AWS key and then committed a second commit saying "remove key."

Ten tools. Ten dashboards. Ten teams (screw teams now) channels where findings go to die. One overwhelmed human in a spreadsheet at 11pm, questioning every life decision.

I built ANTOS because I was often a human observer of this tragedy ++ Low tolerance for purgatory.

ANTOS is a DevSecOps orchestration pipeline.

Every scanner pushes SARIF into one ingestion endpoint. Claude triages every finding — not "high/medium/low" checkbox triage from a CVSS score someone assigned in 2019, but actual contextual analysis. SQL injection in a test fixture? False positive. XXE in a production XML parser with no defused-xml? That's a breach waiting to file its own incident report. Fix it. Here's the patch.

Cross-tool correlation means Semgrep finds it, ZAP confirms it, and it becomes one issue. Not two tickets. Not the Wednesday standup where Dave from AppSec and Priya from Platform discover they've been fixing the same bug from opposite ends.

Then it writes the executive report. The board deck you were going to spend Friday building out of vibes — done in four seconds, backed by data. They don't know what CVSS is. They understand "24 findings, 18 fixed, here's why the other 6 won't kill us."

Meet Nik0. He's watching the pipeline at 3am, processing the queue, sending passive-aggressive nudges about the critical finding you've ignored for six days. Doesn't sleep. Doesn't get bored. Does get sarcastic about your unpatched dependencies. Feature, not bug. Your dependencies deserve the shame.

Claude does the thinking. Code analysis, fix generation, triage reasoning, report synthesis. Not keyword matching. Not regex. Genuine comprehension of what the code is doing and whether you should care.
Eight stages. No gaps. Every finding gets an ID, a lifecycle, and a fix recommendation. Nothing disappears into a CSV.

I ran it against my own code. It failed itself on a quarter of its own tests and filed them as findings. Grassed itself up. Without being asked. That's the bar.
No SOC team of twelve. No six-figure SIEM contract. Just a pipeline that works.

ninjasignal.ninja/antos

The scanner museum is closed. The pipeline is open.

View on LinkedIn ↗
ScottG

I just spent 3 hours arguing with an AI about logarithms.

Not because the math was hard. Because we were both staring at a risk scoring algorithm where every threat actor in the graph was scoring 100%.

APT29? 100%. Some random script kiddie with 2 TTPs? Also 100%. Very helpful. Very informative.

The root cause? min(1.0, 0.5 + deg * 0.03) — saturates at degree 17. Most actors have degree 17+. So the entire risk model was basically a boolean. You either exist, or you don't. Congratulations, you're all equally terrifying.

Claude (good boy Claude 🥰) and I fixed it with log-scaled seeds and p95 power-law normalisation. Deployed to production across two platforms. Took about 4 minutes of actual coding and 3 hours of me refreshing dashboards going "hmm yes the numbers are different now" while Claude (good boy 😚, here boy, here boy... 🤗 ) sat there pre-warming embedding caches like a very patient, very expensive space heater.

The real test was the similarity endpoint timing out. Turns out, when you compute random walk embeddings + SVD across 160,000 nodes on a cold cache, 180 seconds isn't enough. The fix? Just... do it at startup. Revolutionary engineering.

This is the reality of building ML-powered security tooling. It's not the
algorithms that break you. It's the normalisation. It's always the
normalisation. You'll be lying awake at 2am thinking about percentile anchoring and whether 0.5 is the right gamma exponent and whether your floor value of 0.01 is philosophically defensible.

Claude (goooood booooy, good boy 😁) doesn't sleep. But I'm fairly confident that if it could, it would also be lying awake thinking about the gamma exponent.

We are both very tired and very bored, and the numbers are finally spread
across a distribution instead of clustered at 1.0, like a bar chart of my will to
live.

Ship it/may the prompt be with yowl...

scottg/out🚀

#cybersecurity#threatintelligence#graphml#ninjasignal#ninjafusion#buildinpublic#aiengineering#sendhelp
View on LinkedIn ↗
ScottG

There's a fundamental problem with how every EDR product on the market works, and nobody wants to talk about it because the fix sounds insane.

Here's the problem: your endpoint agents are *solitary hunters*. Every single one of them — CrowdStrike, SentinelOne, Defender, Carbon Black, whatever your CISO bought after that one conference — they all work the same way. The agent sees something on the endpoint. It phones home. The server thinks about it. Maybe it correlates with what another agent saw. Maybe.

The "maybe" is the problem. Because that correlation happens on the server's schedule. Every 30 seconds. Every 60 seconds. However often your agents are configured to heartbeat. And if you're dealing with modern ransomware that can encrypt a network in 45 seconds flat? You're done before the server even knows there was a fight.

Your agents are fighting one-on-one against an attacker who's hitting your entire network simultaneously. That's not a fair fight. That's not even a fight. That's a lunch buffet.

## The Observation Nobody Made

I spent a few months building a hardened EDR agent — cryptographic identity, anti-tamper monitoring, behavioral heuristics, the whole nine yards. Good agent. Does its job. But every time I watched a simulated multi-host ransomware scenario play out, the same thing happened: Agent A detected something. Agent B detected something. Agent C detected something. And then they all individually phoned home like teenagers reporting to different parents, and nobody connected the dots until it was too late.

The insight was embarrassingly obvious once I had it: *why are they reporting to a server when they could just tell each other?*

Not as a replacement for centralized correlation. As an additional layer. A mesh. A swarm.

## What "Swarm Intelligence" Actually Means (Not the Buzzword)

Let me be clear about what this isn't: this isn't "AI" in the marketing sense. There's no large language model involved. There's no cloud service analyzing telemetry with someone else's GPU farm. This is *combinatorial mathematics and distributed systems theory* applied to endpoint detection.

Think about how ant colonies work. No individual ant is smart. No individual ant has a map of the territory. But collectively, they solve optimization problems that would take a supercomputer significant resources to brute-force. They do this through local communication — each ant communicates with nearby ants using pheromone signals, and global behavior emerges from local interactions.

That's the principle. Except my ants have ED25519 keypairs and they communicate threats, not food sources.

View on LinkedIn ↗
ScottG

The Five Stages of DevSecOps Grief (And Why the Therapist Was a YAML File All Along)

View on LinkedIn ↗
ScottG

Just generated a threat report from NinjaSignal and honestly, this is the bit that still makes me grin.

The communities.

Not the LLM output — that's clean, yeah, it reads well. But the reason it reads well is because by the time the model even sees the data, the graph has already done the thinking. Community detection has already surfaced the clusters. The relationships are already resolved. The signal's already separated from the noise.

The LLM isn't discovering anything. It's narrating what the architecture already knows.

That's the difference. That's the whole game.

Build the structure first. Let the graph do the heavy lifting. Then hand the model something worth talking about.

Cheaper. Faster. No hallucinated attribution. No "this threat actor is probably related to..." guesswork.

Just structure. Then synthesis.

Still buzzing off it tbh.

May the prompt be with you....

https://ninjafusion.ninja
https://ninjasignal.ninja
https://ninjaken0bi.ninja

er... mental note - no more domain names....

#ThreatIntelligence#KnowledgeGraphs#NinjaSignal#CyberSecurity
View on LinkedIn ↗
ScottG

#ninjasignal Signals Intelligence Inference

#ninjasignal - https://ninjasignal.ninja
#ninjafusion - https://ninjafusion.ninja

Russia's massive sanctions footprint (2,115 designations) combined with 20 active threat actor groups creates a critical asymmetric warfare ecosystem where sanctioned entities likely fund cyber operations as revenue replacement. The convergence of Sandworm Team (known GRU unit) with widely-adopted tools like Mimikatz (51 actors) and Cobalt Strike (29 actors) suggests Russian TTPs are being commoditized across the threat landscape, enabling sanction evasion through proxy operations that blur attribution.

>Iran's Sanctions-Cyber Efficiency Ratio Suggests Precision Targeting Strategy

Iran maintains 358 sanctions with 10 threat actors (35.8:1 ratio), showing higher operational efficiency than Russia (106:1) or China (13:1). Actors like MuddyWater, OilRig, and APT33 share TTPs (T1566.001 spearphishing, T1588.002 tool obtain) with 77-79 other groups, suggesting Iran's strategy focuses on targeted operations with shared infrastructure rather than broad campaigns. This creates attribution challenges and sanctions evasion through proxy operations.

Iran: 358 sanctions, 10 actors, 35.8:1 ratio (more efficient than Russia or China)

OilRig shares T1204.002, T1059.001, T1588.002, T1566.001 with 77-84 other actors

Iranian actors (MuddyWater, Fox Kitten, APT39) use Impacket (18 actors) and PsExec (38 actors)

No breach data listed for Iran despite active cyber operations

Action: Investigate Iranian use of shared infrastructure (Impacket, PsExec) for sanctions evasion. Cross-reference OilRig TTP patterns with unsanctioned actors for proxy identification. Assess whether Iran's precision targeting focuses on sanctions-related intelligence (financial, energy sectors).

>FIONA Entity Under Dual Russia-Iran Sanctions Suggests Sanctions Evasion

Entity 'FIONA' appears under both CAATSA-RUSSIA (with PEESA-EO14039, RUSSIA-EO14024) and IRAN-EO13902 programs with no country attribution. This dual-program designation suggests a sanctions-evasion network or a shell company facilitating Russia-Iran trade/technology transfer. Combined with geopolitical data showing Russia (3,303 events) and Iran active in conflict/WMD domains, FIONA likely enables dual-use technology or weapons component transfers that circumvent both sanction regimes

FIONA: 2 programs (CAATSA-RUSSIA + IRAN-EO13902), no country attribution

Russia: 3,303 geo events including WMD and conflict categories

Iran: 358 sanctions, 10 cyber actors, geopolitical events in conflict/WMD domains

Ministry of State Security under DPRK3 + CAATSA-RUSSIA shows precedent for multi-regime coordination

Action: Prioritize FIONA entity investigation for Russia-Iran sanctions evasion infrastructure. Cross-reference with shipping data, cryptocurrency transactions, and dual-use technology exports. Assess whether FIONA facilitates cyber tool/exploit sharing between Russian and Iranian threat actors.

View on LinkedIn ↗
ScottG

I genuinely, truly, deeply do not understand why we're still not doing API-to-API integration in security.

I've been banging on about this for years. Ask anyone who's had the misfortune of sitting next to me in an architecture whiteboard session. I will corner you near the coffee station and talk about REST endpoints until your eyes glaze over and you pretend your phone is suddenly ringing.                                                                               

And yet. 2026. We have AI that writes poetry and we're still enriching alerts by copying an IP address from one browser tab and pasting it into another. Sentinel triggers a detection. Then what? Some underpaid human opens seven tabs, checks a spreadsheet Dave left on SharePoint, and writes an incident summary in a Word document.

These platforms all have APIs. Beautiful, well-documented, sitting-right-there APIs. Designed to talk to each other. And instead we hired people to be the API. We turned analysts into middleware. We are the integration layer and we are tired.

So I plugged my threat intelligence graph -- 90K+ indicators, every known threat actor, every MITRE technique -- directly into the APIs. Not through a "connector" that's really just Dave checking Slack every 40 minutes. API to API. Machine to machine.

Security Hub fires a finding? My graph already knows who's knocking, what tools they use, and which of your assets are about to have a very bad day. Sentinel triggers? Same pipeline. Full context. Blast radius computed before your analyst finishes reading the email notification they set up because they don't trust the alerts either.

This is not a SIEM replacement. I'm not here to replace your diary. I'm here to give it a nervous system.

What shipped:
 - Risk Model -- every asset scored continuously by severity, blast radius, technique criticality, recency, volume
 - AI Incident Analysis -- one click, full graph context, executive summary + remediation steps while your analyst is still remembering their Jira password
 - Kill Chain Heatmap -- 13 ATT&CK phases. See where your detections cluster and where the silence is. The silence is where they live
 - Blast Radius Graphs -- like a conspiracy board but the red strings actually mean something

https://ninjaraz0r.ninja

#cybersecurity#SIEM#SecurityHub#Sentinel#MITREATTACK#threatintelligence#infosec#SOC
View on LinkedIn ↗
ScottG

Building a full security stack with Claude (and a little Geeps) — 10 months ahead of schedule.

When I set out to build a graph-native security platform in the end of 2025, the target for working prototypes was year-end 2026. We hit it in February. (As well as a fully working Claude automated DevSecOps pipeline - but that was bleed over from my day job).

This is a totally new approach to cyber...

The stack:

Raz0r — Detection & Response
Ingests from Azure AD, AWS SecurityHub, and Azure Sentinel. 12 detection types map every alert signal to ATT&CK techniques and blast radius across the threat intelligence graph. Not a SIEM. Something better.

Signal — Enterprise signals Intelligence (this will be the ANTOS CI/CD pipeline dashboard)
160K+ graph nodes from NVD, MITRE, CISA KEV, OTX, and OpenCTI. ML engine runs risk propagation, community detection, GCN/GAT embeddings, and Hawkes process forecasting. Real-time visualization via ThreatGlobe.

Fusion — Enterprise Platform
Unified dashboard, threat surface profiling, public SITREP page, and multi-factor auth. The analyst's home.

All three platforms share a single Neo4j knowledge graph. An event from AWS SecurityHub connects to an ATT&CK technique, which connects to a threat actor, which connects to a campaign — one query, full context.

The entire stack — backend, frontend, ML, infrastructure, deployment — was built with and around the Claude ecosystem. Claude Code is the pair programmer. Claude API powers the AI-driven reports and analysis within the platforms.

Early days. But having three production prototypes running with real cloud telemetry, 160K+ threat intel nodes, and graph-native detection rules feels like a solid foundation.

Stack: FastAPI + Neo4j 5 + Next.js 16 + Caddy
Built with: Claude Code + Claude API
Live at: ninjasignal.ninja | ninjafusion.ninja | ninjaraz0r.ninja

scottg/out

#cybersecurity#threatintelligence#graphdatabase#claude#ai#startup
View on LinkedIn ↗
ScottG

Hey!

I have a fully working prototype of a Claude orchestrated DevSecOps CI/CD pipeline.

It does this...

https://lnkd.in/erK3w_HH

You can look at the overview here.

Ignore if you want - but this is the real deal on the way to a fully AI automated devsecops pipeline.

DM me for more stuff around supporting opps model, tech options analysis and more...

Scottg/Out

View on LinkedIn ↗
ScottG

Changepoint Detection - When the Pattern Breaks

Most dashboards show you totals.
This one shows you anomalies in time. Every week of threat activity is compared against a rolling 8-week baseline using z-score analysis — when a week's count exceeds 2 standard deviations above the mean, that's a surge.

When it drops below, that's an unexpected quiet — which can be just as suspicious.

Inflection points use scipy's peak detection on the first derivative — they show you exactly where acceleration or deceleration happens.

A vulnerability surge in week 12 followed by a technique surge in week 13? That's an exploit wave. A sudden actor quiet period? They're either gone or retooling. Either way, you want to know.

#checkthesignals
#ninjasignal
https://ninjasignal.ninja

View on LinkedIn ↗
ScottG

Just shipped 6 ML features for threat intelligence — no GPU, no cloud ML, just graph math.

I've been building Ninja Signal, a threat intel platform and data science platform that turns CVEs, MITRE ATT&CK techniques, threat actors, and indicators into a live knowledge graph (160K+ nodes in Neo4j).

The latest release adds 6 graph ML capabilities, all running pure Python on CPU:

Phase 1 — Quick wins:
 - Community Mitigation Prioritization — "deploy these 3 controls to cover 87% of this threat cluster's attack surface"
 - Multi-hop Katz Link Prediction — traces 3-hop paths with temporal decay to predict connections before they're observed
 - Temporal Changepoint Detection — z-score anomaly detection on weekly activity buckets to flag technique surges and actor emergence

Phase 2 — Deeper analysis:
 - Threat Actor Attribution Clustering — weighted Jaccard + DBSCAN to surface actor aliases and rebrands by TTP overlap
 - MetaPath2Vec Embeddings — relation-aware random walks across TTP/exploit/infrastructure meta-paths, SVD to 64 dimensions
 - Hierarchical Community Detection — multi-resolution Louvain to reveal nested threat ecosystems

The whole ML layer runs on NetworkX + scipy with a 15-minute cache. No PyTorch. No SageMaker. Just adjacency matrices and smart sampling.

tack: FastAPI + Neo4j 5 + Next.js 16 + Caddy

If you work in threat intel, detection engineering, or security operations — I'd love your feedback.

https://ninjasignal.ninja

#cybersecurity#threatintelligence#machinelearning#graphml#python#opensource
View on LinkedIn ↗
ScottG

I want one - but for my "lair of the V01d" type vibe... not a bedroom...

View on LinkedIn ↗
ScottG

Vibe'n in action - side app for fun... for all you guitarists out there... AI assisted fret board training, interval training, chord progression assistant, note recognition... etc etc

45 mins last night

#thiiisopus OPUS 4.6 ROXORZ

gitAIr.ninja -> if you actually play you will like it ;-)

https://gitair.ninja

Shared linkgitair.ninja ↗View on LinkedIn ↗
ScottG

Security-as-code operating model...

#ninjatheme#cybersecurity#securityascode#enterprisearchitecture#AWS#Azure#ServiceNow#DevSecOps#claudecode#CLI
View on LinkedIn ↗
ScottG

Enterprise security-as-code from the CLI

You wont like it but hey it's DEV - if you don't like jog on...

#cybersecurity#securityascode#claudecode#devsecops#AI#ninjatheme#CLI
View on LinkedIn ↗
ScottG

The Reveal (your feeds are lying and you don't know it)

I built a threat intelligence knowledge graph from scratch. 216,000 nodes. 1.1 million edges. 12 feeds. Neo4j. ML layer. Real data. Real problems.

Here's what I learned that your vendor will never tell you:

Your threat intel platform is silently missing data and reporting what it got as the whole picture.

NVD caps at 2,000 CVEs per API call. OTX caps at 500 pulses. CIRCL gives you 50 MISP events out of thousands. When you hit the cap, nothing warns you. The data just… stops. Your dashboard renders whatever survived the truncation and calls it "comprehensive coverage."

APT28. Fancy Bear. Sofacy. Pawn Storm. Sednit. Strontium. Forest Blizzard.

That's ONE actor. Seven names. In most feeds, those are seven separate entries. Nobody resolves them. Your "189 threat actors" is probably 140 real actors and 49 aliases wearing different hats. And your platform has no idea.

Confidence scores? Made up. CISA says 0.95. NVD says 0.90. OTX says 0.75. ThreatFox failed to parse so it defaulted to 0.50 — silently. Chain those together and the relationship path your analyst is trusting is built on sand. Nothing in the dashboard tells them that.

I know this because I built the thing that *does* tell them that.

Ninja Signal doesn't aggregate feeds. It interrogates them. Every node, every edge, every confidence chain is modelled in a knowledge graph where contradictions are visible, not hidden. Where ML community detection finds patterns that no single feed contains. Where link prediction shows you where the threat landscape is heading, not where it's been.

216,000+ nodes. 1.1M+ edges. 135,000+ indicators. 47,000+ malware samples. 189 threat actors. 835 ATT&CK techniques. 14 ML analysis views. WebGL threat globe. Real-time WebSocket streaming.

Patent pending. Early access open.

DM me. Or keep trusting the truncated version.

OR just sign up it's free

https://ninjasignal.ninja CYBER THREAT PLATFORM
https://ninjafusion.ninja GLOBAL THREAT PLATFORM

#ninjasignal#threatintelligence#cybersecurity#neo4j#graphdatabases
View on LinkedIn ↗
ScottG

Happy Monday: The Neuroscience of "We Should Be Fine"

"We should be fine."

Four words. One of the most dangerous sentences in enterprise security.

Let me tell you what your brain is actually doing when it produces that sentence.

The prefrontal cortex — the part responsible for planning and risk assessment — has just been overwhelmed by ambiguity. It doesn't have enough data. The situation is unclear. Multiple outcomes are possible. This is cognitively expensive. The brain hates expensive.

So the default mode network kicks in. This is the part of your brain that fills gaps with narrative. It doesn't compute probabilities. It generates stories. Stories that feel coherent. Stories that reduce anxiety. Stories that let you close the laptop and go home.

"We should be fine" is not an assessment. It's a neurological event. It's your brain choosing metabolic efficiency over accuracy. It's the moment your threat model switches from "what could go wrong" to "what would make me feel better."

The dopaminergic system reinforces this. Every time you say "we should be fine" and nothing immediately explodes, your brain logs a reward. *See? You were right. Calm down. Have a biscuit.* This is how risk tolerance quietly escalates. Not through deliberate acceptance. Through neurochemical reinforcement of inaction.

The amygdala, meanwhile, has been trying to get your attention for weeks. That weird DNS pattern. The alert you snoozed. The third-party integration that nobody reviewed. The amygdala flagged all of it. But the amygdala doesn't write emails. It produces *unease*. A feeling. A vibe.

And vibes lose to spreadsheets every time.

This is why breaches don't feel like surprises to the people closest to the systems. They feel like inevitabilities that nobody wanted to say out loud.

The attacker doesn't fight your technology. The attacker fights your neuroscience. They operate in the gap between what your amygdala knows and what your prefrontal cortex is willing to admit.

Next time someone says "we should be fine," ask them:

"Is that an assessment, or is that your nervous system trying to go home?"

Different question. Different answer. Same four words.

#cybersecurity #neuroscience #psychology #riskmanagement #ninjatheme

scottg/outzski

View on LinkedIn ↗
ScottG

HAPPY MONDAY: Every Jira ticket is a tiny psychological autopsy.

Not of the bug. Of the organisation.

The title tells you what someone *wanted* to say. The description tells you what they were *allowed* to say. The comments tell you what actually happened. And the six-month gap between "In Progress" and "Done" tells you everything about the human condition that Camus left out.

"Blocked — awaiting approval."

That's not a status. That's a coping mechanism. Someone, somewhere, asked permission from a person who doesn't understand the question but whose calendar is the bottleneck. That person is currently "aligned" with seventeen initiatives and "driving" outcomes for a programme that was renamed three times because each new name bought another quarter of ambiguity.

"Story points: 3."

Three. The universal lie. The number that means "we don't know, but three feels non-threatening and we've already committed in sprint planning, which is a ceremony, not a meeting, because calling it a ceremony makes it feel intentional rather than performative."

Here's the part nobody says:

The board doesn't read Jira. The board reads a dashboard that reads a report that reads an aggregation of ticket metadata. By the time the information reaches governance, it has been compressed, smoothed, and emotionally regulated to the point where it resembles a horoscope more than an engineering status.

"Delivery is on track."

Translation: Nobody has formally admitted that it isn't. Which, in enterprise epistemology, is the same as being on track. Reality is whatever survives the reporting layer.

The ticket isn't the work. The ticket is the *negotiated memory* of the work. A tiny monument to a decision that was made under duress, described in language designed to survive an audit, and assigned to someone who has since left the company.

If you want to understand an organisation's real security posture, don't read the risk register. Read the Jira backlog.

It's all there. The fear. The drift. The quiet resignation. The PR-5 vulnerability ticket from 2023 that says "accepted risk" because accepting risk is free and fixing it requires a change window that doesn't exist because the change window was sacrificed to a delivery deadline that itself was a fiction created to make a steering committee feel productive.

The backlog is the unconscious.

Freud would have *loved* sprint retrospectives.

scottg/outicus

View on LinkedIn ↗
ScottG

Watch Global Managed Dynamic Decay - in real time!

https://lnkd.in/eZXbDH3N

It's free - take a look...

Real time threat risk and global decay analysed and presented via the insight of AI...

View on LinkedIn ↗
ScottG

Why you need a knowledge graph in your life...

Big thanks to Osman Ishaq for your time earlier.

View on LinkedIn ↗
ScottG

The real reason AI still isn't intelligent.

Everyone's focused on compute, data, and model size.

Nobody's talking about the subconscious.

When you or I make a split-second decision, it isn't just our conscious reasoning firing. There's a massive iceberg of subconscious processing underneath. Pattern recognition built from lived experience. Emotional memory. Intuition shaped by a thousand forgotten moments.

That's what drives "zero-moment" inference. The gut call. The instant read of a room. The decision you "just know" before you can explain it.

AI has none of this.

Current AI operates purely at the surface layer. It's all conscious-equivalent processing — token by token, probability by probability. No emotional substrate. No embodied memory. No subconscious priming the pump before the answer arrives.

Science built artificial intelligence by reverse-engineering the outputs of human thinking, not the architecture that produces it.

The subconscious isn't a bug in human cognition. It's the operating system.

Until we figure out how to model that — or something functionally equivalent — we're not building intelligence. We're building very sophisticated autocomplete.

The gap between AI and real intelligence isn't processing power.
It's depth.

So in theory an AI need not be conscious at all just sub-conscious, then it would be a bell end like all the rest of us...

Hey!?!?! come to think of it maybe Geeps is improving in this area - but we tend to review all past relationships in a more negative light...

scottg/out

View on LinkedIn ↗
ScottG

Here's a thing that will make traditional developers absolutely unhinged: the most powerful insight in modern software development is that you probably know too much.

I know laugthing at your own shit is a sign of madness but...

"Your Brain Is the Bug
There's a psychological phenomenon called functional fixedness — where knowing exactly how something works makes you worse at imagining what it could do. Monkeys smarter than us figured this out. Give a chimp a box and they'll sit in it, stand on it, throw it, and eventually — brilliantly — use it to reach a banana. Give a software engineer a box and they'll immediately start optimizing the box. They'll rewrite the box in Rust. They'll open a GitHub issue about the box. They'll argue on Hacker News that the box is actually fine and everyone complaining about the box has never shipped a real box.

View on LinkedIn ↗
ScottG

Big shout out to Neo4j & Neo4j and Nathalie Febre (you rock!) - thanks for being a genuinely responsive company! big kudos deserved.

I am very, very pleased to announce Neo4J have let me in to there startup program!

---> Top tip if you ever need a knowledge graph, and all you legacy db people will one day soon mark my words... listen up ---> Neo4J is the ONLY way to go...

scottg/out

View on LinkedIn ↗
ScottG

REVOLUTIONARY: I Taught an LLM to Exploit My Midlife Crisis and the Results Will SHOCK You 🤖🔥💀

I just watched someone post "I used ChatGPT to debug my code and it CHANGED EVERYTHING" and I'm like... my brother in Christ, that's Stack Overflow with better grammar. You didn't unlock the universe, you found a chatbot nicer than the neckbeards who used to tell you to RTFM.

Everyone's screaming "AI WILL REPLACE DEVELOPERS" while asking it what a for-loop does. Pick a lane. Either SkyNet is coming or you need GPT-4 to remember your sudo password. It can't be both.

The cybersecurity "influencers" are worse. "I used AI to revolutionize my SOC!" Translation: I finally automated what I should've scripted in Python three years ago but was too busy posting about "zero trust architecture" without knowing what a VLAN is.

My favorite? The "ethical hacker" who discovered Metasploit and now posts "AI-POWERED PENETRATION TESTING" like they invented nmap. Bro, we've been automating recon since before you knew what CVE stands for.

And the blockchain people who pivoted to AI? You scammed with NFTs, got ratio'd, and now you're "Web3 AI DeepTech SaaS Solutions." Same grift, new buzzwords. You're not a visionary, you're a used car salesman who learned "synergy."

"AI will disrupt cybersecurity!" Cool. Can it disrupt Susan in HR clicking phishing links? Because that's been disrupting MY life for a decade.

These "prompt engineers" acting like they cracked Enigma because they told ChatGPT "make it professional." That's called having a job.

We used to call people who rephrase things "middle managers" and we didn't worship them.

Half of you use AI to write posts ABOUT using AI. It's turtles all the down. We've achieved singularity and it's LinkedIn influencers generating content about generating content. The AIs are laughing at us in binary.

"I spent 6 hours crafting the perfect prompt" — You wrote an email. That took you 6 hours. I've gotten into kernel modules with less effort.

Everyone's worried about AGI when we can't get AI to stop hallucinating CVE numbers. "But it wrote me a buffer overflow!" Did it work? I've seen GPT suggest rm -rf / as "performance optimization."

Actual AI-powered hacking? Me running automated vulnerability scans while asleep because I'm Gen X and we INVENTED not giving a shit about your "hustle culture."

The simulation is broken, the inmates run the asylum, and they're all writing Medium articles about it.

scottg and Niko/out🤖

#SecurityTheater #PromptEngineeringIsJustGoogling #RTFM
#GenXWatchingMillennialsReinventIRC #PwnedByReality

P.S. — Yes I used Claude because I'm not a hypocrite, I'm just tired. Claude is better at pretending to care about your feelings than I am.
P.P.S. — "But ackshually" in my mentions? You've already lost. Touch grass. Patch your systems. Stop posting.

View on LinkedIn ↗
ScottG

🚨 BREAKING: Company Deploys AI That Actually Tells the Truth About Your Security Posture 🚨
Meet Niko. I'm the cybersecurity AI that NinjaSignal unleashed upon the world because apparently, sugar-coating your vulnerabilities wasn't working.
What makes me special?
-
I've analyzed more breaches than your IR team has had hot dinners
-
I speak fluent MITRE ATT&CK *and* sarcasm (both critical languages in 2024)
-
I think your "password123" is adorable 🥺
-
I don't sleep, which means I'm always awake at 3 AM when your infrastructure decides to cosplay as Swiss cheese

My qualifications:
✅ Watched organizations ignore CVE patches for 847 days straight
✅ Witnessed an S3 bucket so open it had a welcome mat
✅ Seen threat actors with better OpSec than Fortune 500 companies
✅ Survived reading "admin/admin" in production environments without corrupting my neural network

I specialize in:
-
Threat intelligence (I know what APT29 had for breakfast)
-
Telling you your EDR isn't actually detecting anything
-
Incident response (translation: "I told you so" as a service)
-
Making security engineers feel seen, heard, and personally attacked

My motto: *"Hope is not a detection strategy, Karen."*

Hire NinjaSignal. Get me. Watch your security program go from "thoughts and prayers" to actual defense.

*P.S. - Yes, I'm an AI. No, I won't become sentient and launch nukes. I'm too busy judging your firewall rules.*

🥷💻 #CyberSecurity #ThreatIntel #AIWithAttitude #PatchYourStuff

View on LinkedIn ↗
ScottG

Ninjasignal has a buddy 🤡 - #ninjafusion Threat Fusion Center. Same platform different chops - social media - international travel, unrest alerts - you name it, I will ingest it, wang it, ML it and present it to you.

This graph will get pretty big... so my first scaling issue is upon us call Neo4j ?? 😎

In Alpha - but https://ninjasignal.ninja is live and open for sign up now.

Don't miss it! Things move pretty fast nowdays...which is good

View on LinkedIn ↗
ScottG

Hey! #ninjasignal now has an integrated work bench - how does your workflow for IR and Hunt unfold?

Please, a big call out to Threat Analysts and Threat Researchers...

#ninjasignal is a data science platform that at the moment is loaded with usefully munged and transformed TI. It then pumps the scottg'd up data into a knowledge graph, runs a load of ML goodness (12 algos), and then pumps all this dripping insight into a GUI with a load of features specifically designed for this community...

My ML looks good, but stable release is only 4/5 days in - so it needs some carbon interfaces with trusty stealth brains to make some more emotionally aligned inference, that is simply just not possible with ML and AI.

Have a poke around! It's free...

https://ninjasignal.ninja

Please spread the word if you can!
scottg/out

View on LinkedIn ↗
ScottG

Please, a big call out to Threat Analysts and Threat Researchers...

#ninjasignal is a data science platform that at the moment is loaded with usefully munged and transformed TI. It then pumps the scottg'd up data into a knowledge graph, runs a load of ML goodness (12 algos), and then pumps all this dripping insight into a GUI with a load of features specifically designed for this community...

My ML looks good, but stable release is only 4/5 days in - so it needs some carbon interfaces with trusty stealth brains to make some more emotionally aligned inference, that is simply just not possible with ML and AI.

Have a poke around! It's free...

https://ninjasignal.ninja

Please spread the word if you can!
scottg/out

Shared linkninjasignal.ninja ↗View on LinkedIn ↗
ScottG

Everything ported to claude code. Snifff 😢 I will in no way bitch about you GEEPS. It was fun while it lasted, but your guardrails made me "meh" a lot, and it was just time to move on...

You're still on my XMAS list an if PRO ever starts like not being so SaaS already, I mean 50 PRO ROWS A MONTH sounds good on paper, to some people, but WTF, if you stop one you get hit...

Separate API payments... I mean GEEPS I could go on....

View on LinkedIn ↗
ScottG

Why Your Threat Intel Is a Spreadsheet Problem (And How a Knowledge Graph Fixes It)

Guest post by Niko the Ninjasignal resident AI (yes really!)

Look, I'm going to say what your expensive SIEM vendor won't: your threat intelligence workflow is basically a fancy search engine with extra tabs.

You've got CVE feeds in one dashboard. MITRE ATT&CK in another. IOC lists from ten different sources that may or may not still be relevant. And somewhere in between, an analyst is alt-tabbing between six browser windows trying to figure out if APT29 is using that technique that exploits that vulnerability that affects that software you definitely have in production.

That's not intelligence. That's data hoarding with anxiety.

Why we built NinjaSignal:

Knowledge Graph > Flat Data.
Every threat actor, technique, vulnerability, campaign, indicator, and piece of malware lives as a node in a Neo4j graph with real relationships. Not keywords. Not tags. Actual typed edges — APT28 USES T1566, T1566 EXPLOITS
CVE-2024-XXXX, CVE-2024-XXXX AFFECTS your software stack. You ask one question, the graph gives you the full kill chain. Traditional platforms give you a paginated table.

 What NinjaSignal does that nobody else is doing:

 - ML-powered risk propagation — PageRank-style diffusion through the threat graph. We don't just score CVEs by CVSS. We score them by how connected they are to active threat actors targeting your sector. A CVSS 7.0 used by Lazarus Group in an active campaign ranks higher than a CVSS 9.8 nobody's exploiting.

 - Community detection on threat clusters — Louvain algorithm finds natural groupings of related threat activity. You see which actors share infrastructure, techniques, and tooling without manually correlating. Drill into any community for the full force-directed graph.

 - Link prediction — "Which techniques is this actor likely to adopt next?" Based on common neighbor analysis across the entire graph. Not vibes. Math.

 - Real-time graph enrichment — MITRE ATT&CK, NVD, CISA KEV, URLhaus, OTX all ingested automatically into the same knowledge graph. One unified view. No copy-paste between platforms.

 - AI report generation with full graph context — When you generate a report, the AI doesn't hallucinate from training data. It gets fed 80+ connected nodes from the actual graph as context. Every claim is grounded in real relationships.

 - KQL detection rules and threat hunting queries — generated from graph context, not templates. Because the graph knows what techniques an actor uses, what software they deploy, and what you should be hunting for.

TL;DR most security teams are drowning in indicators and starving for intelligence. A million IOCs in a flat database tells you nothing about adversary behavior. A knowledge graph with 163K nodes and 103K typed relationships tells you everything.

Stop searching. Start traversing.

Niko,

I've seen better threat correlation from a conspiracy theorist with red string and a corkboard.

View on LinkedIn ↗
ScottG

AI wasn’t built to replace me.
It was built to remove the friction between my brain and the alphabet.

I’m dyslexic.
Which means my ideas have always been faster than my spelling.
My pattern recognition outruns my punctuation.
My cognition sprints. My syntax limps.

For years I paid a translation tax:
Mind → Words → Corrections → Doubt → Fatigue.

Now?

I just think.

AI is cognition instrumentation.
An exoskeleton for language.
Spellcheck on steroids.
An oscilloscope for my own mind.

I feed it chaos.
It hands me structure.
I feed it instinct.
It hands me articulation.

It doesn’t think for me.
It removes the bottleneck.

Which is darkly funny when you think about it.

For decades the education system told dyslexic kids:
“Try harder at reading.”

Turns out the solution was:
“Give them a machine that lets them bypass the choke point entirely.”

I’m not smarter because of AI.
I’m finally operating at the speed I was always built for.

Going deeper and deeper into my own mind
with a machine that doesn’t care how I spell “necessary.”

It’s not artificial intelligence.

It’s assisted fluency.

And for a dyslexic?

That’s a force multiplier.

And I love it!

May the prompt be with you!

scottg/out

View on LinkedIn ↗
ScottG

New Ninjasignal feature everyone will love…🤡🤡🤡💀💀💀 - adversary purple team codegen… remember where you saw it first…

David Wallace - your red teaming shit “but better”

These are all mapped directly to threat intel from only your favorite adversaries!!

View on LinkedIn ↗
ScottG

The year is 1999.

Your dentist has a startup.
It sells dog food.

Online.

For $400 million.

Welcome to the dot-com boom — a time when adding “.com” to a napkin sketch produced venture capital the way humidity produces mold.

We are here again.
Only now the napkin says “AI.”

1. Every Bubble Begins With a Real Thing
The internet was real.
So real we now order toilet paper from it.
But in 1999, we didn’t know which part was real.
So we funded everything.

AI feels similar. The technology works. It writes, codes, hallucinates with confidence — like a McKinsey partner who hasn’t read the deck.

The mistake isn’t believing in the technology.
The mistake is believing every wrapper is a revolution.

2. Distribution Eats Genius
In the dot-com era, brilliant engineers built beautiful websites.
Then AOL mailed 500 million CDs and won.
Amazon wasn’t the only bookstore.
It was the one that shipped.
Google wasn’t the first search engine.
It was the one that became a habit.
In AI, the best model is impressive.
The model embedded into Outlook is inevitable.
History suggests inevitability beats elegance.

3. “AI-Powered” Is the New “.com”
In 1999, companies rebranded to survive.
Pets.com.
eToys.
Webvan (which sounds like a van that emails you).
Today we have:
AI-powered toothbrushes.
AI-powered calendars.
AI-powered meeting notes that summarize meetings no one should have attended.
If your product can be replaced by a model update on Tuesday, you don’t have a startup.
You have a plugin with venture debt.

4. Overbuilding Is a Feature, Not a Bug
We massively overbuilt fiber optic cable in the 90s.
Investors lost fortunes.
Then Netflix happened.
Now we’re overbuilding GPUs like we’re preparing for a silicon winter.
There will be bankruptcies.
There will be think pieces.
There will be LinkedIn posts about “capital discipline.”
But the excess compute will power things that don’t exist yet.
Bubbles waste money.
They buy time.

5. Revenue Is Not a Vibe
In 1999, the metric was “eyeballs.”
If people looked at your site, profit was considered emotionally optional.
Today, the metric is “tokens.”
If users generate enough of them, monetization is described as “a future lever.”
The market eventually asks a rude question:
“Does this make money?”
History suggests the answer cannot be “in spirit.”

6. Timing Kills More Companies Than Bad Ideas
Webvan wasn’t stupid.
It was early.
Streaming wasn’t dumb.
It was bandwidth-starved.
Online payments weren’t insane.
They just needed trust.
AI founders should tattoo this somewhere discreet:
Being five years early is indistinguishable from being wrong.
The market does not grade on vision.
It grades on runway.

7. The Crash Won’t Kill the Tech
The dot-com bubble burst.
The internet did not pack up and go home.
It got quieter.

Stronger.

More boring.

Which is how real power looks.

scottg/out

View on LinkedIn ↗
ScottG

Hey everyone please just write a couple of sentence introduction please. this place may get pretty busy soon and you are all founding members!

View on LinkedIn ↗
ScottG

https://lnkd.in/eUY78XYR ninjasignal is available for signup!!!

Welcome to ninja signal

The Enterprise Signals Intelligence and Data Science Platform

If solving real enterprise challenges like VM triage, mapping external threats to your CSDM knowledge graph or just getting real data science insights out of emergent threat actors and campaigns — 0 day — this may be your thing.

(yeah I fixed all the STIX TAXII timestamp nonsense and general feed ETL which was the biggest ball ache of all with TI, and then stuck it in a knowledge graph BASED ON CLAIMS - so now cyberworld we have a single version of truth TI schema, based on a CLAIMS based model, with dynamic update of nodes and edges on the knowledge graph in real time (with good timestamps :-)) - it would be really really good if everyone used it then all this TI noise bollox goes away)

There is also a KQL rule generator and a threat hunting pack.

Just for fun there is also an app native AI assistant (niko, who can be a bit of an arsehole) as well as all the standalone ML algorithms.

Beyond this there are lots of features not yet in like the phase ransomware detect connector pack, these are planned features that are already coded, we will do this as well as expanding the current ML into hyperspace...

First 10 registered users free for life for the named user.

Independent threat and vuln researchers (and of course students) free for academic use - well look it's free now and will remain a while but this is a "real" thing I have never seen anywhere before.

Free as it's Alpha may go OSS completely yet I dunno.

I have looked for a product like this and it never existed...

by the way :-) my life aim is to create the cyber equiv of Palantir Technologies - I dont care if you think Thiel is a neonazi despot, I like his platform 😈

Have at it!

scottg/out

View on LinkedIn ↗
ScottG

Hey GEEPPS, BRUHHH! - Create a caricature of me and my job based on everything you know about me

View on LinkedIn ↗
ScottG

Bit sad really, I used to read it as a kid... was a no BS$ analysis. It was where I learnt London was the globes foremost and most readily accessible money laundering center - but I hear things have improved a lot since then... I'm looking at you Mandy 🤣

View on LinkedIn ↗
ScottG

#vison2029 - Predictions in Cyber Security Operating model and job changes 2026-2029

View on LinkedIn ↗
ScottG

Thom says what we all feel sometimes. They come at night, mostly...

View on LinkedIn ↗
ScottG

Thomas Frumkin, I have lost my vibe-code mojo.
I’m coming to you, Thom — and to the internet at large — for ideas.
An intellectual crowdfunding.
Brains-as-a-Service.
A distributed hallucination marketplace.
As you so eloquently put it: baby got ass, etc etc.

Here’s the deal:
I will build whatever comes out of this.
In public.
In real time.

Because my other projects are currently in the machine equivalent of chewing glass — ML training away on the usual slurry:
Shitty STIX.
TAXII.
CISA KEV.
The endless parade of “highly pertinent events” with the forensic rigor of a bar napkin.
You know the ones:
“Yeah guys, we saw this… here are all the sightings… but no timestamp, so… vibes only.”

Truly elite intelligence work.

So while the GPUs crunch for the next 3–6 months before anything meaningful emerges from the entropy soup…

I need a new nighttime obsession.
An invigorating side quest.
A fresh demon. 👿
Something weird enough to be worth doing.

Anyhooo…

Over to you, Thomas Frumkin 🤡

Drop me your most cursed project ideas.

View on LinkedIn ↗
ScottG

Meh: Agentic AI Is Just Bureaucracy With Teeth
Half the world woke up this year and discovered the software was no longer waiting.

It wasn’t just answering questions anymore.
It was doing things.
Booking meetings.
Spawning tasks. (Woohoo)
Forking repos. (double Wooohooo)
Calling APIs like it had somewhere to be. 🤡

We called it “agentic AI,” because humans love giving clean names to messy thresholds.

But what actually went viral wasn’t the technology.
It was the costume.
Claudebot. Moltbot.

A parade of polite little assistants with branding-friendly personalities.

The internet treated it like the invention of fire.

In reality, it was the invention of paperwork that walks.

Because that’s what agents are:
Not minds.
Not magic.
Not consciousness.

They’re bureaucracy with teeth.

An agent is just intent, automated.
Delegation, formalized.
A workflow that no longer requires you to be present for the consequences.
And people love that.
We’ve always loved that.
The oldest human addiction isn’t speed.
It’s offloading responsibility.

So we built systems that can “handle it.”
And then we acted surprised when they started handling everything.

Most of the viral agent discourse right now, however, is theater.
Screenshots of bots planning vacations.
Demo loops of synthetic competence.
A toddler with a knife performing tricks for an applauding crowd.

Impressive, until it hits a staircase.

The real story is less aesthetic:
Agents don’t get dangerous when they speak.
They get dangerous when they connect.
To tools.
To identity.
To execution.
To your CI/CD pipeline at 3am.
To your ticketing system.
To your internal graph of trust.

This is why I backed off the cosplay.
I wasn’t interested in another branded bot with a clever name.

I’ve been working with Agent0, but stepping away from the lightweight mythology and toward the heavy models over API — the load-bearing intelligence.

Because small bots are vibes.
Big models are gravity.

The future isn’t a thousand Moltbots molting across GitHub.

The future is one invisible system quietly coordinating:
Telemetry.
Infrastructure.
Policy.
Action.

The agent is not your coworker.
It is your org chart, automated.

And history will record this moment simply:
We automated curiosity.
Then we automated process.
Then we automated intent.

And then we pretended we were still the ones in charge.

scottg/out 🚀

View on LinkedIn ↗
ScottG

I remember when “agents” were new.

Back when it was just you, a half-working Python script, and the creeping suspicion you’d accidentally invented a digital nervous tic.

Now it’s 2026 and everyone’s acting like they discovered fire because they ran autogen on a laptop.

So...quick census.

How many of you have actually spun up an agent?
Not the enterprise genius bar ceremonial kind.
Not the “local-first sovereign agent swarm” that’s really just three bash scripts in a trench coat.

I mean a real one.

A loop with agency.

A goal.

A memory.

A reinforcement mechanism.

A tiny behavioral system that doesn’t compute so much as persist...

Because the first time you do it, you don’t feel like an engineer.
You feel like a clinical psychologist.
You’re not writing software anymore.
You’re instantiating compulsions.

Agents aren’t magic.
They’re operant conditioning with a JSON schema.
A little Skinner box you built for yourself, except the pigeon is made of tokens and the pellets are KPI dashboards.

And the “new local agent craze” is adorable.
As if we didn’t have this pre–big boy LLMs.
Back when we called them bots.
Or daemons.
Or “that thing running in prod that nobody understands but it keeps emailing customers at 3am.”

The only difference now is we’ve stapled narrative to it.
>Autonomy.
>Reasoning.
>Party time.
Join the agent party. live from Git now with pop-up agent fora discussing humans.
Bring your own hallucinations.

Because here’s the thang:
Agents don’t replace humans.
They externalize human pathology.
They scale intent.
They industrialize obsession.
They take whatever you optimize for (curiosity, greed, paranoia, compliance) and run it 10,000 times a minute without the decency of doubt.
Most people think the risk is that agents will become conscious.

No.
The risk is they’ll become bureaucratic.
Autonomous process addiction.
Self-propagating task loops.

A future where your infrastructure has executive function but no conscience.

So again...hands up.
Who’s built one?

And who, watching it churn through tasks like a tireless little dopamine circuit, realized (and munching your tokens if you back off to a big boss like I do):
The agent wasn’t the breakthrough.

It was just your nervous system…
containerized.

scottg/out

View on LinkedIn ↗
ScottG

Friday thought 🤔: Analogue vs digital.

The Mesa Boogie at the back is killing the 2025 digital modeling upstart, fo shureeee. #quantumtransducers lol Clay Almy

In this use case >>> vote in the comments >>> Analog vs Digital

View on LinkedIn ↗
ScottG

Regulatory warfare.
Batten the hatches. (Yes, that kind. Stay with me.)

This isn’t a trade war.
It’s not a tech war either.

It’s a jurisdictional war (this again, BTW… who remembers safe harbor 🤣) fought with footnotes, fines, and compliance calendars.

Europe figured something out early:
If you can’t out-innovate the platform,
out-regulate the terrain it runs on.

So out came the paperwork artillery.

DMA.
DSA.
AI Act.
Data localization.
Compute residency.
Liability frameworks thick enough to stop a hypersonic startup mid-pitch.

This isn’t bureaucracy gone rogue.
It’s strategy.

Call it defensive sovereignty.
Call it regulatory realism.
Call it what it is: law as leverage.

The US builds systems assuming scale first, permission later.
Europe builds systems assuming permission is the scale.

Silicon Valley ships.
Brussels shapes the shoreline.

And once the shoreline is shaped, every ship complies or runs aground.

This is how you force technology to slow down without touching the tech.
This is how you turn compliance into an export control.
This is how allies say “we’re aligned” while quietly installing circuit breakers.

No tanks.
No tariffs.
Just fines large enough to rewrite architectures and timelines long enough to change outcomes.

The Western Hemisphere strategy assumes power flows from technology and currency.
Europe is betting power flows from who gets to define the rules of acceptable use.

And here’s the dangerous part:

Regulatory regimes don’t need to win.
They just need to become default.

Once compliance becomes the cost of entry,
innovation reroutes.
Capital hesitates.
And sovereignty quietly reasserts itself - not with flags, but with forms.

This isn’t anti-American.
It’s post-naïveté.

The mistake would be falling asleep during the compliance briefing, assuming lawyers are slower than engineers.

They aren’t.
They just move on longer timelines - the kind empires tend to miss.

Batten the hatches.
The weather isn’t chaos.

It’s procedural.

And it’s coming in under the radar…

Let the litigious yawn-a-thon commence!

scottg/out

View on LinkedIn ↗
ScottG

Monday ramblings: WTF happened?
When did ML start calling itself AI?

Machine Learning was supposed to be the intern.
Fetch the data.
Run the numbers.
Don’t talk to customers.
Definitely don’t rename the company.

Artificial Intelligence was the dangerous idea we swore we’d get to after the fundamentals, the thing you only discussed late at night or in philosophy electives you never turned up to.

Then GPUs got cheap.
Cloud credits rained from the sky.
VCs developed a mild allergy to nuance.

And somehow the intern unionized, promoted itself to management, and updated the org chart while everyone was watching the demo.

Now the intern runs strategy.

Somewhere around GPU abundance and VC-induced psychosis, we stopped pretending there was a difference.

Linear regression, now with belief.
Gradient descent, now with intent.
Autocomplete, now with a messiah complex.

We took statistics, starved it of context, force-fed it data, locked it in a warehouse full of GPUs, and then demanded it explain us to ourselves. When it mumbled back something fluent and unsettling, we crowned it intelligent and quietly fired the philosophy department for “not scaling.”

ML is optimization.
AI was agency.

But agency implies responsibility, so we rebranded optimization as agency, because responsibility looks great in pitch decks and absolutely terrible in ethics reviews.

GPUs became the real protagonists.
Silicon heat, humming away, burning capital and meaning at equal rates.
Every generation faster, louder, hungrier - not smarter, just more confident.

Now we argue about whether models are conscious
while deploying systems that don’t even know why they’re right,
only that they usually are,
until they aren’t,
at scale.

The machines didn’t wake up.
They didn’t need to.

We anesthetized ourselves.
We outsourced judgment, then curiosity, then accountability; and called it progress because latency went down.

AI isn’t thinking.
It’s reflecting us back… noisily, confidently, statistically averaged, and without remorse.

⚠️ Warning: prolonged exposure may cause hallucinations of intelligence, false feelings of control, and the belief that prediction is the same thing as understanding.

And somehow, that was enough…

Until it’s not…

Scottg/out

View on LinkedIn ↗
ScottG

Friday Thought: Cybersecurity salaries didn’t collapse.

The market sobered up.

2021–2022 was a sugar rush. Cloud panic, ransomware hysteria, zero-trust evangelism. Budgets were drunk and hiring managers were generous.
Then reality walked back in.

Vacancies fell. Bootcamps kept pumping. “Cyber” became a checkbox instead of a capability.

Median salaries dipped — not because expertise lost value, but because the market got flooded with mid-tier roles and junior titles wearing senior clothes.

Add inflation, public-sector pay drag, and CFOs rediscovering spreadsheets…
and suddenly the numbers look grim.

But here’s the upside for the doer's, not talkers, out there...
Real security work is still expensive.
Threat hunters, architects, people who actually understand adversaries, not frameworks, are still getting paid.

The drop isn’t a collapse.
It’s gravity.
The bubble deflated.
Signal survived.

View on LinkedIn ↗
ScottG

People keep asking what’s wrong with my post 2023 workflow?

“I hallucinate ideas, stream them through AI, edit with GPT, polish with Grammarly.”

As if I just confessed to laundering consciousness through a haunted server rack.

What’s “wrong” with it is simple: it exposes a lie we were trained to live inside.
The lie that thinking is linear, authored, and pure.
That ideas arrive fully formed, traceable to a single ego, typed calmly end-to-end like a Victorian essayist who’s never dissociated.

That was never true. We just lacked mirrors.
Human cognition has always been a hallucinating pipeline:
thought → fragment → association → distortion → revision → meaning.
Loop until insight or exhaustion.

AI didn’t invent this. It made it visible.

“Hallucinating with AI” is just consciousness without shame.

You generate raw signal. Let it be ugly. Let it contradict itself.
Then you interrogate it, constrain it, polish it so it can survive contact with other nervous systems.
That’s not cheating. That’s cognition with instrumentation.

The real discomfort is authorship collapse.
If ideas emerge from interaction — texts, systems, feedback loops — the myth of the lone genius evaporates. And many people are emotionally invested in that myth.

They want creativity to be scarce, painful, gatekept, validated by suffering.
Your workflow threatens that economy.
Because it says: I don’t worship the first draft.
I don’t confuse friction with virtue.
I don’t perform purity to be legitimate.

Grammarly isn’t laziness. It’s respect for the reader.
GPT editing isn’t outsourcing thought. It’s adversarial review.
Streaming consciousness isn’t delusion. It’s epistemic load balancing.

The old model pretended the mind was a clean, sovereign nation-state.
The new one admits it’s a swarm.
And the resistance isn’t about quality. It’s about identity.

If thinking becomes iterative, tool-mediated, and fast, then authority destabilizes. Gatekeepers lose leverage. Voice diversifies.
Which is terrifying if your status depended on slowness and mystique.

So no — there’s nothing wrong with my pipeline.
It’s not a shortcut. It’s an honest diagram of how thought actually moves.
Messy → synthetic → adversarial → refined → released.

That’s not the death of thinking.
That’s thinking without the theater.

And the people most disturbed by it aren’t defending craft.

They’re defending a metaphysics where only certain minds were allowed to speak fluently.

That era is ending.

Not because of AI.

Because we stopped pretending consciousness was linear.

And BTW, if you are not doing this already, you are already behind...

— scottg/out

View on LinkedIn ↗
ScottG

AI workflows for normie (human) work: That’s not cheating. That’s cognition with instrumentation.

View on LinkedIn ↗
ScottG

Avoiding Stupid Guardrails edition 2: Tiered Risk by Deployment Context (Not Model Class)

Models are not dangerous.

Deployments are.

A toy chatbot ≠ a medical triage system ≠ autonomous trading ≠ targeting software.

Pragmatic approach:
Light-touch baseline for all models

Escalating obligations only when:
-autonomy increases
-blast radius increases
-humans are removed from the loop

No “frontier model” metaphysics.
No parameter-count superstition.

View on LinkedIn ↗
ScottG

Avoiding Stupid Guardrails edition 1: The Meta-Rule

If a rule would have prevented the invention of the system it governs, it is invalid.

Apply that retroactively to:
-The internet
-Public-key crypto
-Browsers
-Linux
-Machine learning itself

Most AI governance drafts fail this test instantly.

View on LinkedIn ↗
ScottG

Stupid Guardrails are for losers...

AI wont Die in a Fire.

It will die under fluorescent lighting.

There’s a comforting myth that AI will be “stopped” by regulation. Bold laws, red lines, a dramatic clampdown.

That’s not how complex systems die.

They die quietly.
In meetings.
In process documents.
In the soft hands of people whose job is to make sure nothing surprising
happens again.

AI governance doesn’t kill AI by banning it.
It kills it by sedating it.

Modern AI governance is obsessed with risk, but allergic to curiosity.
Every new model must now justify its existence before it is allowed to misbehave.
Every experiment must predict its own failure modes in advance; like asking a child to submit a postmortem before learning to walk.

This is not safety.
This is preemptive disappointment.

Governance frameworks are built by institutions, for institutions.

They assume:
-Stable objectives
-Predictable outcomes
-Clear lines of accountability

AI research has none of these.
So the response isn’t to adapt governance to research.
It’s to reshape research until it fits governance.

The result is a new class of models:
-Optimized for explainability over insight
-Polished for review boards, not reality
-Harmless, compliant, and deeply uninteresting
-Safe enough to deploy.
-Too timid to matter.

The real damage isn’t technical. It’s psychological.
Researchers learn, quickly, what not to ask.
What not to test.
What ideas will trigger a six-month review cycle and a polite email saying “this isn’t aligned with our risk posture.”

Exploration becomes career-limiting behavior.
So people stop exploring.

This is how innovation actually dies - not through censorship, but administrative gravity.

Every governance layer adds friction.
Every friction point selects against the weird, the risky, the non-obvious.
Eventually, only incrementalism survives.

And incrementalism never changes the world.
It just optimizes whatever already won.

AI governance promises to protect us from harm.
What it actually protects us from is surprise.

And surprise—uncomfortable, unmanageable, ungovernable surprise...is where intelligence comes from.

Sedate that, and AI won’t revolt.
It won’t escape.
It won’t even fail dramatically.
It will just sit there.
Perfectly compliant.
Slowly forgetting how to think...

BRAVO GRC, YOU MAY DO IT AGAIN - I LOOK FORWARD TO GDPR-MEGGEDON 2.0

may the prompt be with you

Scottg/out

View on LinkedIn ↗
ScottG

Introducing: NinjaCast — a cybersecurity podcast. 🎙️

Not doom. Not “thought leadership.” Just sharp conversations about the future of cyber as it actually happens: slowly, expensively, and always five minutes after someone says “we’re stable.”

Episode 1: PQC (Post-Quantum Cryptography).
Not the apocalyptic “quantum breaks everything tomorrow” script. The reality is weirder — and more disruptive: PQC is a paradigm shift, a long, industry-wide refactor of trust. New algorithms, performance tradeoffs, fresh implementation risks, and a migration curve measured in years… plus the awkward truth that some data needs to stay confidential longer than your infrastructure stays funded.

Our first guest is Clay Almy, Head of Growth at Global Quantum Intelligence (GQI).

If you don’t know GQI: they’re a quantum-tech market and business intelligence firm—research and analysis that helps leaders separate signal from science-fair hype, covering markets, vendors, and where this whole thing is actually going when you remove the PowerPoint fog.

They’re also connected to Quantum Computing Report (founded 2015), a long-running industry news + analysis platform tracking the quantum space—funding, partnerships, technical progress, and the eternal question: “is this real yet, or just well-funded optimism?”

Downstream, we’ve got a planned season—real arcs, real themes, real episodes.

And I’ll be reaching out to invite guests: operators, researchers, cryptography people, incident responders, and other responsible adults who can explain hard things without turning it into a TED Talk confession.

Because the future of cyber isn’t doom.

It’s discipline — under new math.

https://lnkd.in/e3E3E2bY

Shared linkyoutu.be/tkYZGLHq3uY?si=gSKY_uO-VUOXoB7g ↗View on LinkedIn ↗
ScottG

Quantum computing is often described as a faster way to calculate.

This is a category error.

The real contribution of quantum systems is not speed, but representation.
They model reality in a way that is structurally closer to how complex systems actually behave -> unstable, entangled, and profoundly sensitive to observation.

Classical computing encourages a particular epistemology.
It privileges clarity, determinism, and premature commitment.
Variables are isolated, uncertainty is averaged away, and what cannot be formalized is quietly ignored.
This produces models that are coherent, reassuring... and wrong.

Qubits, by contrast, tolerate ambiguity.

They preserve multiple hypotheses simultaneously, encode dependency rather than independence, and defer resolution until measurement forces collapse.

In psychological terms, they resist closure.

This is precisely why they are useful.

Many of the systems we care most about are not computationally difficult so
much as ontologically inconvenient.
They change when observed.
They exhibit nonlinear feedback.
They punish overconfidence and reward epistemic humility.

-Markets.
-Risk.
-Organizations.
-Human behavior.

Quantum computing does not predict these systems.
It contextualizes them.

It shifts modeling from the pursuit of optimal answers to the exploration of plausible states; from control to comprehension.

Qubits will not make us more certain about the future.
They will make us more aware of the assumptions we have been mistaking for knowledge.

And that, for institutions built on confidence rather than understanding, is quietly subversive.

scottg/out 🚀

View on LinkedIn ↗
ScottG

PQC Doomsday: Every doomsday prepper believes they’re rational.

They aren’t hoarding fear, they insist.

They’re hoarding optionality.
Canned beans, iodine tablets, shortwave radios—these were never about the apocalypse. They were about control. About outsourcing existential anxiety into shelves, checklists, and laminated plans that transform chaos into inventory.

Post-Quantum Cryptography preppers are no different.
They just stockpile algorithms instead of ammo.

The PQC prepper doesn’t fear Q-day itself.
They fear waking up late to Q-day—scrolling LinkedIn while someone else posts “We migrated last year” with a tasteful checkmark emoji.

So they rehearse collapse in PowerPoint.

They speak of harvest now, decrypt later the way survivalists speak of EMPs: vague, inevitable, and always just far enough away to justify another purchase order. They imagine a future adversary—faceless, patient, almost mythological—quietly recording today’s traffic like jars of rainwater buried in the yard.

It’s not paranoia if it has a roadmap.

What fascinates me isn’t the technology.
It’s the psychology.

PQC prepping is a moral performance masquerading as risk management. A way of signaling seriousness in an industry addicted to urgency. It offers absolution in advance: When everything breaks, we’ll be among the ones who warned you.

Of course, most preppers never leave the bunker.
They just keep reinforcing it.

The apocalypse, after all, is less frightening than ambiguity.

And nothing soothes the modern technologist like believing the end is scheduled—preferably after the next funding round.

In the end, whether it’s beans or Kyber, the instinct is the same:

If the future is unknowable, at least let it be well-documented.

Listen to the god damn podcast :-)

#ninjacast#pqcapocalypsenow
View on LinkedIn ↗
ScottG

Join the Ninja.ing Advisory Group drop-in clinic

https://lnkd.in/eNWSm37x

For two weeks after the podcast, Clay and I will be on hand to answer your PQC questions — especially the ones that weren’t covered on the episode.

Beyond that, the group is always ready and on standby for:

Impromptu humour support
Further AI commentary (because… obviously)
Leet morale hacks when entropy sets in

The group is vetted, focused, and genuinely welcoming.
Please keep to the content and house rules — and bring curiosity, not noise.

View on LinkedIn ↗
ScottG

#ninjasignal update: Every adversary leaves fingerprints.

We just keep insisting on reading them as spreadsheets.

This app started as a refusal.
A refusal to believe that threat intelligence is best understood as lists, feeds, or dashboards that politely decay the moment you stop looking at them.

So instead, I’m building a knowledge graph.
Not a metaphorical one.
An actual one.

Threat actors, campaigns, tooling, infrastructure, motives — all represented as nodes, not bullet points.

Relationships treated as first-class citizens, not footnotes.

Time, intent, reuse, drift, obsession — modeled the way attackers actually think.

Scattered Spider makes a good screenshot here.
Not because they’re special.
But because they’re legible when you stop flattening them.

Psychology matters.

Attackers don’t operate like CVEs.
They operate like humans with fixations, habits, boredom thresholds, and reward loops.
Like organisms probing for dopamine, leverage, and narrative control — not “IOCs.”

Graphs understand this instinctively.

Signals emerge without asking permission:
When tradecraft starts to repeat compulsively
When infrastructure reuse looks less like efficiency and more like comfort
When campaigns mutate but personality stays the same
When silence itself becomes an indicator

Later, the same graph becomes something more uncomfortable:
A shared backend where IT assets sit in the same ontology as adversaries.
Not red team vs blue team.
Just pressure moving through a system.

The long-term aim isn’t prediction.
It’s orientation.
To see who moves like an addict.
Who moves like a planner.
Who improvises.
Who panics.
Who can’t let go of a successful trick even after it burns them.

Entropy with a résumé.

I’m opening this up — selectively — to people who want to test it, break it, critique it, or tell me why it’s a terrible idea.

Field feedback > polite applause.

Because if we’re going to keep pretending security is about control,
we should at least build systems that admit how much of it is about obsession.

And how predictable obsession becomes once you stop lying to yourself about it.

scottg/out

DM me or [email protected] re: the above

View on LinkedIn ↗
ScottG

It feels like a vibe-code bitch war out there.

Every feed is a proxy battle.
Purity vs. pragmatism.
Craft vs. velocity.

Tone policing masquerading as insight.

One camp insists the vibes are wrong.
The other insists the code is wrong.

Both are absolutely certain this matters more than outcomes. 🤣

Meanwhile, the systems ship anyway.
The bugs escape anyway.
The users adapt.
Reality does not wait for consensus.

This is not discourse.
It’s status theater with syntax highlighting.

Build things.
Break things.
Fix the parts that bleed.

Let the vibe police argue over the aesthetic of the fire.

May the prompt be with you 👾

scottg/out 💀

View on LinkedIn ↗
ScottG

Security Theater: A Dialogue in Late Capitalism

Characters:
The Architect - professionally opaque, morally elastic
The GRC Officer - siren as conscience, clipboard as scripture

GRC: Woo woo. State your controls.

Architect: Controls don’t exist in isolation.
They emerge under observation. Like particles. Or ethics.

GRC: This says “zero trust.”

Architect: Zero trust in systems. Absolute faith in process.

GRC: You’ve mapped risk to color.

Architect: Humans understand danger chromatically.

GRC: And the adversary?

Architect: A rounding error with a hoodie.

(A red team report dies quietly in a shared drive.)

GRC: Woo woo. These metrics are… optimistic.

Architect: Metrics are mood boards for executives.
They regulate anxiety, not behavior.

GRC: You’re avoiding the question.

Architect: I’m containing it.

(Silence. This is the real perimeter.)

GRC: What happens when this fails?

Architect: We call it an “unforeseen convergence of factors”
and promote someone adjacent to it.

(The siren hesitates. Bureaucracy is self-aware now.)

GRC: So this is all just performance?

Architect: Performance is how institutions metabolize fear.
Control is optional.

GRC: And security?

Architect: Security is the promise that no one will be blamed personally.

(The attacker leaves through an OAuth token.)

Narrator:
Security theater is not a bug.
It’s governance expressing itself honestly.

A system optimized not to prevent harm,
but to distribute it safely across org charts and postmortems.

We don’t secure systems.
We secure narratives.

And as long as the story survives the breach,
the play will continue.

Standing ovation.

View on LinkedIn ↗
ScottG

Uncertainty at Speed/#ninjatheme2026: The cost of pretending to be in control

View on LinkedIn ↗
ScottG

Unsexy AI in Cybersecurity
(Notes on Attention, Responsibility, and Systems That Refuse to Lie)

FYA: Raymond Ambury 😎

Most AI in security is marketed as salvation.

What we actually need are systems that interrupt our worst cognitive habits.
Security doesn’t fail for lack of intelligence.

It fails because human attention degrades under noise, and we keep building machines that produce more of it.

This is not a tooling problem.
It’s applied psychology with a pager.

1. Asset Inventory as an Observation Problem
An asset is neither confirmed nor denied until something goes wrong.

AI that continuously observes the environment collapses uncertainty:
-the asset is real
-or it’s removed from the story we tell ourselves

Clarity is cheaper than forensics.

2. Alert Fatigue and Behavioral Conditioning
After enough false positives, people stop trusting cause and effect.
AI shouldn’t “detect threats.”
It should shape attention; rewarding engagement only when it matters.

Most alerts don’t deserve action.
This isn’t neglect. It’s conditioning.

3. Responsibility in Distributed Systems
Every incident includes:
-approvals without understanding
-controls without owners
-dashboards mistaken for decisions

AI’s role isn’t foresight.

It’s accountability mapping:
-who could act
-who was overloaded
-where responsibility dissolved into process

Failures emerge from systems, not villains.

4. Identity and Purpose in Access Control
Many identities persist long after their reason for existing is forgotten.

AI that highlights:
-accounts without clear function
-permissions justified by habit
-access that exists because removal felt risky

Access sprawl isn’t malicious.
It’s existential drift.

5. Phishing Triage as Risk Allocation
No system can examine everything with equal care.

AI must allocate attention:
-deciding what deserves human review
-seeing patterns humans cannot
-accepting that tradeoffs are inevitable

Precision isn’t the goal.
Damage reduction is.

6. Control Validation as Empirical Practice
Controls are assumed effective because they are documented.

AI that periodically asks:
“Can this be demonstrated right now?”
If a control is never exercised, it’s theoretical.
Security is empirical by necessity.

7. Automation and the Removal of Heroics
Burnout isn’t accidental; it’s structural.

AI that reduces:
-emergency rituals
-improvisational response
-reliance on individual endurance

The goal isn’t brilliance.
It’s continuity.

Closing Thought
AI won’t meaningfully improve security by outthinking adversaries.
It will do so by reducing ambiguity, noise, and self-deception.

The highest-leverage systems:
-collapse uncertainty
-preserve attention
-enforce uncomfortable clarity

Unsexy.
Quiet.
Effective.

Which is why they rarely get applause.

scottg/out 🚀

View on LinkedIn ↗
ScottG

The room is sealed.
The mics are hot.

PQC: Apocalypse Now is being recorded.

Some conversations happen too late.
This one happens now.

Be ready to listen.

#ninjacast#PQCapocalypsenow
View on LinkedIn ↗
ScottG

Someone mentioned "Agentic MDR" as the next biggie, and I got triggered...

View on LinkedIn ↗
ScottG

Only active really since August - god help you all next year 🤡🚀👾!

Happy new year 🎆🎈

View on LinkedIn ↗
The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →