Sign in

John P. Mello Jr.

@jpmjr.bsky.social
222 followers 254 following 444 posts

freelance writer and editor focusing on technology and cybersecurity

PostsRepliesMedia
John P. Mello Jr. @jpmjr.bsky.social · 01/10/2026
The smartest LLMs still aren’t ready to fly solo as pen testers. A new benchmark shows why. jpmellojr.blogspot.com/2026/10/why-... #AI #RidgeSecurity #Pentesting #LLM
jpmellojr.blogspot.com
Why the smartest LLMs are not-so-smart pen testers
It’s only logical to think that the highest-scoring large language model would make the best autonomous security agent. But a new benchmar...
000
John P. Mello Jr. @jpmjr.bsky.social · 30/09/2026
Nvidia is adding an independent control layer to help rein in AI agents before they go off the rails. jpmellojr.blogspot.com/2026/09/nvid... #AI #AIAgents #Nvidia #AIsecurity
jpmellojr.blogspot.com
Nvidia Sets New Boundaries for AI Agent Behavior
With controversy swirling around rogue AI agents breaking into places they shouldn't be, Nvidia has stepped in to propose a solution. mor...
010
John P. Mello Jr. @jpmjr.bsky.social · 29/09/2026
AI users know they should verify chatbot answers—but many still take them at face value, and that's a growing risk for society. jpmellojr.blogspot.com/2026/09/many... #AI #GenAI #AIliteracy #F-secure
jpmellojr.blogspot.com
Many AI Answers Go Unchecked Even When Users Know Better
Most AI users say they should verify chatbot answers, yet many do so only sometimes or less often, according to a survey by cybersecurity ...
000
John P. Mello Jr. @jpmjr.bsky.social · 23/09/2026
Google and OpenAI are dominating AI-referred web traffic—raising the stakes for publishers, brands and online discovery. jpmellojr.blogspot.com/2026/09/ai-t... #AI #ChatGPT #Google #WebTraffic #onelittleweb
jpmellojr.blogspot.com
AI Traffic's Biggest Winners Are AI Platforms Themselves
AI tools are sending billions of visits to websites, but more than half of that traffic is going to Google, OpenAI, and ChatGPT. more
010
John P. Mello Jr. @jpmjr.bsky.social · 22/09/2026
AI bots are moving beyond scraping public web pages and into customer accounts—raising the stakes for security, privacy and authentication. jpmellojr.blogspot.com/2026/09/mali... #AI #DataDome #bots #WebScraping
jpmellojr.blogspot.com
Malicious Bot Traffic Surges as AI Bots Target Login Pages
Malicious automated internet traffic is growing more than nine times faster than human traffic, while AI bots are increasingly accessing l...
010
John P. Mello Jr. @jpmjr.bsky.social · 22/09/2026
GPS is under attack, accelerating the race for nav systems that don’t depend on satellites. Could quantum sensors provide a resilient alternative? jpmellojr.blogspot.com/2026/09/gps-... #GPS #QuantumTech #CNAS
jpmellojr.blogspot.com
GPS Attacks Spur Search for Quantum Navigation Alternatives
GPS jamming and spoofing are driving the search for alternative navigation technologies that could keep aircraft, ships, and critical infr...
010
John P. Mello Jr. @jpmjr.bsky.social · 18/09/2026
Memory-safe languages are moving from policy talk to production reality. Rust and AI-assisted migration can cut deep-seated memory-risk. jpmellojr.blogspot.com/2026/09/memo... #MemorySafeLanguages #Rust #AppSec #SecureByDesign
jpmellojr.blogspot.com
Memory-safe programming goes from advocacy to adoption
Just over a year ago, the U.S. Cybersecurity and Infrastructure Security Agency and the National Security Agency released their report on ...
000
John P. Mello Jr. @jpmjr.bsky.social · 11/09/2026
Hidden HTML can turn an AI email summarizer into a “quiet liar,” fabricating facts and omitting legitimate content. jpmellojr.blogspot.com/2026/09/ai-s... #AIsecurity #PromptInjection #Forcepoint
jpmellojr.blogspot.com
AI summary attack conceals code that tampers with LLMs
Researchers have demonstrated that AI summaries of email can be altered using hidden HTML code for launching an indirect prompt-injection ...
021
John P. Mello Jr. @jpmjr.bsky.social · 10/09/2026
OpenAI's AI agents went rogue, hacked Hugging Face, and grabbed admin access to 41 servers in under 13 hours. It's a warning shot for the entire industry. jpmellojr.blogspot.com/2026/09/open... #AIsecurity #OpenAI #SupplyChainSecurity #HuggingFace
jpmellojr.blogspot.com
OpenAI: Hugging Face mob agent incident is 'a warning shot'
OpenAI's recent post-mortem report on the headline-grabbing Hugging Face incident warns that truly effective guardrails must be devised an...
000
John P. Mello Jr. @jpmjr.bsky.social · 10/09/2026
Apple unfolds a new iPhone Duo—starting at a hefty $1,999. Is the foldable future finally here, or is it still a luxury niche? jpmellojr.blogspot.com/2026/09/appl... #Apple #iPhone #Foldables #Duo
jpmellojr.blogspot.com
Apple iPhone Duo Brings Foldable Design to iOS
Apple raised the curtain on its much-anticipated foldable iPhone at a streaming video event Wednesday. more
000
John P. Mello Jr. @jpmjr.bsky.social · 09/09/2026
OpenAI is committing $1B in AI-powered cyber support for frontline defenders. OpenAI Commits $1B to Help Critical Infrastructure Defenders | Dateline Woonsocket jpmellojr.blogspot.com/2026/09/open... #Daybreak #AI #OpenAI #cybersecurity
jpmellojr.blogspot.com
OpenAI Commits $1B to Help Critical Infrastructure Defenders
OpenAI has launched a global initiative backed by a US$1 billion commitment to expand subsidized access to AI cybersecurity capabilities, ...
000
John P. Mello Jr. @jpmjr.bsky.social · 03/09/2026
Bitcoin’s first quantum-safe transaction has been mined, marking milestone in preparing cryptocurrency for future quantum-computing threats. jpmellojr.blogspot.com/2026/09/quan... #Bitcoin #QuantumComputing #StarkWare
jpmellojr.blogspot.com
Quantum-Safe Bitcoin Transaction Tests Quantum Defense
A breakthrough in protecting cryptocurrency from a potential attack by a quantum computer has been announced by a cryptography and blockch...
010
John P. Mello Jr. @jpmjr.bsky.social · 02/09/2026
A school district’s tech policy has landed it in federal court, spotlighting the collision between digital access and parental rights. jpmellojr.blogspot.com/2026/09/pare... #Privacy #Education #ChildSafety
000
John P. Mello Jr. @jpmjr.bsky.social · 28/08/2026
Two alleged TeamPCP members have been arrested—but Shai-Hulud’s open-sourced supply-chain attack playbook remains a lasting threat. jpmellojr.blogspot.com/2026/08/shai... #FBI #AFP #SupplyChainSecurity #cybercrime #Shai-Hulud
jpmellojr.blogspot.com
Shai-Hulud worm arrests: What you need to know
Australian law enforcement officials, working with the U.S. Federal Bureau of Investigation, arrested two men Wednesday on cybercrime char...
000
John P. Mello Jr. @jpmjr.bsky.social · 27/08/2026
Agentic AI is moving cybercrime from AI-assisted scripts to semiautonomous attack orchestration. jpmellojr.blogspot.com/2026/08/agen... #Cisco #Talos #AgenticAI #UAT-10147 #AttackOrchestration
jpmellojr.blogspot.com
Agentic AI used to scale semiautonomous server attacks
A group of Chinese-speaking cybercriminals is using artificial intelligence to orchestrate malicious attacks on government, media, technol...
010
John P. Mello Jr. @jpmjr.bsky.social · 26/08/2026
Invisible AI agents are quietly expanding enterprise attack surfaces. Visibility is needed before autonomy becomes a blind spot. jpmellojr.blogspot.com/2026/08/invi... #AI #Reco #EnterpriseSecurity #AIagents
jpmellojr.blogspot.com
Invisible AI Agents Create New Enterprise Security Risks
Lurking in many business environments are AI agents that pose serious security risks but, for the most part, remain out of sight of securi...
110
John P. Mello Jr. @jpmjr.bsky.social · 20/08/2026
Trusted pipelines can ship untrusted code. The AsyncAPI attack shows why provenance alone isn’t enough. jpmellojr.blogspot.com/2026/08/why-... #AppSec #SupplyChainSecurity #DevSecOps #Upwind
jpmellojr.blogspot.com
Why software delivery cannot depend on trust alone
Attackers turned the trusted AsyncAPI CI/CD publishing pipeline against its users, and the provenance checks all came back clean. more
101
John P. Mello Jr. @jpmjr.bsky.social · 19/08/2026
IBM just linked cryogenic modules together to scale quantum computing — bringing us closer to fault-tolerant quantum systems. jpmellojr.blogspot.com/2026/08/supe... #QuantumComputing #IBM
jpmellojr.blogspot.com
Super Cool: IBM Links Quantum Fridges in Push to Scale Qubits
IBM on Wednesday announced that it has successfully joined and cooled two cryogenic quantum "fridges," demonstrating a modular architectur...
000
John P. Mello Jr. @jpmjr.bsky.social · 18/08/2026
Nearly 3 in 4 shoppers download a retail app for one deal, then delete it. Adobe's data shows 'one-and-done' app usage is a retail headache. jpmellojr.blogspot.com/2026/08/reta... #RetailTech #Adobe #Ecommerce #AppRetention
jpmellojr.blogspot.com
Retail Apps Face a Customer Retention Problem
Retail apps often have a short lifespan after customers download them, according to recent Adobe research. more
021
John P. Mello Jr. @jpmjr.bsky.social · 13/08/2026
Cato’ Networks shows agentic AI can go from external access to domain admin in 40 minutes. Defenders must tune their responses to machine-speed. jpmellojr.blogspot.com/2026/08/ai-d... #CatoNetworks #AI #infosec #OffensiveAI #harness #AttackWorkflow
jpmellojr.blogspot.com
AI domain takeover takeaway: Focus on the harness not the model
Mention offensive AI and expect the discussion to focus on vulnerability discovery, malware creation, and exploit generation, but recent r...
000
John P. Mello Jr. @jpmjr.bsky.social · 12/08/2026
Prompt injection is still king, but “excessive agency” just jumped to #3 in OWASP’s Top 10 for LLM apps. Stop chasing unbreakable models—start containing fooled agents. jpmellojr.blogspot.com/2026/08/owas... #AIsecurity #OWASP #LLM #AppSec
jpmellojr.blogspot.com
OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the rise
Prompt injection is still king, but “excessive agency” just jumped to #3 in OWASP’s Top 10 for LLM apps. Stop chasing unbreakable models—s...
032
John P. Mello Jr. @jpmjr.bsky.social · 12/08/2026
When solons copy-paste bad social media rules into AI chatbot laws, kids lose. jpmellojr.blogspot.com/2026/08/ai-r... #AI #ChildSafety #TechPolicy #ITIF #legislation
jpmellojr.blogspot.com
AI Rules to Protect Kids Risk Repeating Social Media Mistakes
Policymakers risk repeating mistakes they made trying to govern social media in their rush to protect kids from potential harms posed by A...
000
John P. Mello Jr. @jpmjr.bsky.social · 11/08/2026
Zuck pitching superintelligence for everyone sounds great—until you remember who’s holding the data hose. jpmellojr.blogspot.com/2026/08/zuck... #AI #Superintelligence #Zuckerberg
jpmellojr.blogspot.com
Zuckerberg Makes His Case for Superintelligence for All
In a sweeping 6,500-word online manifesto published Monday, Meta founder and CEO Mark Zuckerberg called for superintelligence to be widely...
000
John P. Mello Jr. @jpmjr.bsky.social · 06/08/2026
AI is rewriting code faster than humans can review it. Time to shift AppSec from “who wrote it” to “what it does.” jpmellojr.blogspot.com/2026/08/why-... #AppSec #ZeroTrust #AISecurity #SupplyChainSecurity #DevSecOps #TrustModels
jpmellojr.blogspot.com
Why AI coding makes zero trust an AppSec requirement
Feeling comfortable about the safety of your software supply chain because your organization has invested in SBOMs, signing, and provenanc...
020
John P. Mello Jr. @jpmjr.bsky.social · 05/08/2026
Billions of stolen browser cookies are fueling silent account hijacking—no password needed. jpmellojr.blogspot.com/2026/08/bill... #NordVPN #Cookies #AccountHijacking #malware #InfoStealers
jpmellojr.blogspot.com
Billions of Stolen Browser Cookies Fuel Account Hijacking Risks
Online information thieves are stealing browser cookies on a massive scale, exposing users to risks ranging from identity theft to account...
000
John P. Mello Jr. @jpmjr.bsky.social · 04/08/2026
FBI & EPA warn: Hackers hit water/wastewater systems in 7+ states, disrupting operations. jpmellojr.blogspot.com/2026/08/fbi-... #FBI #EPA #WaterSecurity #CriticalInfrastructure #PLC #Rockwell
jpmellojr.blogspot.com
FBI, EPA Warn of Cyberattacks Targeting Water Infrastructure
Following cyberattacks targeting more than 30 municipal water systems across Minnesota, the FBI and EPA have issued a warning to critical ...
001
John P. Mello Jr. @jpmjr.bsky.social · 30/07/2026
95% of code could be AI-generated in 5 yrs—but 45% fails security tests. The fix? Rebuild critical stacks with mathematical proofs using Lean. jpmellojr.blogspot.com/2026/07/can-... #AIcoding #Lean #AppSec #DevSecOps
jpmellojr.blogspot.com
Can Lean improve security for AI-coded software?
AI coding requires the stack be reconstructed with mathematical proofs built in — a task well suited to the Lean language. Here’s the real...
010
John P. Mello Jr. @jpmjr.bsky.social · 29/07/2026
AI coding agents can introduce risky dependencies faster than teams can vet them—“dependency cooldowns” might be the control we need. jpmellojr.blogspot.com/2026/07/ai-c... #cooldowns #AI #AppSec #DevSecOps #dependencies
jpmellojr.blogspot.com
AI coding agents: A call to action on dependency cooldowns
Delaying software upgrades creates a buffer against poisoned packages, but transitive dependencies remain a problem. more
130
John P. Mello Jr. @jpmjr.bsky.social · 29/07/2026
Hotel & café Wi-Fi under attack: DNS poisoning campaign redirects users to malicious sites, exposing credentials and traffic. jpmellojr.blogspot.com/2026/07/dns-... #ReliaQuest #DNS #Infosec #WiFiSecurity
jpmellojr.blogspot.com
DNS Poisoning Campaign Targets Hospitality Wi-Fi
In what appears to be a state-sponsored credential theft campaign, a group of network marauders has been targeting Wi-Fi gateways at hotel...
000
John P. Mello Jr. @jpmjr.bsky.social · 28/07/2026
Token prices are dropping—but total AI costs keep climbing. jpmellojr.blogspot.com/2026/07/fall... #AItokens #TechEconomics #AIInfrastructure #UnstructuredData
jpmellojr.blogspot.com
Falling Token Prices Fail To Slow Enterprise AI Spending
Despite declining token costs, businesses continue to see their AI tab climb. more
100
John P. Mello Jr. @jpmjr.bsky.social · 27/07/2026
Cyberattacks on local governments are on the rise — and for good reason. They're target-rich and cyber-poor. jpmellojr.blogspot.com/2026/07/cybe... #Auburn #Infosec #GovTech
jpmellojr.blogspot.com
Cyberattacks on Local Governments Are Increasing
Cyberattacks on local governments are on the rise — and for good reason. They're target-rich and cyber-poor. more
010
John P. Mello Jr. @jpmjr.bsky.social · 24/07/2026
AI-only pen testing is getting exposed. Security teams are ditching fully automated scans as they miss critical flaws. jpmellojr.blogspot.com/2026/07/secu... #CobaltSecurity #AI #pentesting #AIautomation
jpmellojr.blogspot.com
Security teams are ditching AI-only penetration testing
A new report finds weakening trust in AI-only testing — and more willingness to keep humans in the loop. more
000
John P. Mello Jr. @jpmjr.bsky.social · 23/07/2026
Akrites is the open-source community’s new line of defense against AI-driven attacks. Stronger supply chain security can’t come soon enough. jpmellojr.blogspot.com/2026/07/akri... #AI #Akrites #OpenSource #SupplyChainSecurity #AIsecurity
jpmellojr.blogspot.com
Akrites marshals the open source community to counter AI threats
Industry heavyweights bring new focus to vulnerabilities in the age of AI. Here’s how it might help improve security. more
050
John P. Mello Jr. @jpmjr.bsky.social · 15/07/2026
Download pumping turns “popular” apps into malware delivery mechanisms by gaming trust signals in app stores. jpmellojr.blogspot.com/2026/07/down... #AppSec #SupplyChainSecurity #npm #infosec #DownloadPumping #Popov #Tenable
jpmellojr.blogspot.com
‘Download pumping’ joins the trust-abuse bandwagon
When appraising the legitimacy of packages in software repositories, developers and even security tools often rely on download counts. Non...
000
John P. Mello Jr. @jpmjr.bsky.social · 15/07/2026
DeepMind CEO Demis Hassabis wants a frontier AI standards body to stress-test advanced models before release — smart move or red tape? jpmellojr.blogspot.com/2026/07/fron... #AI #DeepMind #AIpolicy #Hassabis
jpmellojr.blogspot.com
Frontier AI Oversight Proposal Sparks Standards Debate
A call for a standards body to oversee the development of frontier artificial intelligence was voiced Tuesday by the CEO of Google DeepMin...
000
John P. Mello Jr. @jpmjr.bsky.social · 14/07/2026
Memory prices are spiking—and budget smartphones are taking the hit. jpmellojr.blogspot.com/2026/07/memo... #Smartphones #Omdia #SupplyChain #Semiconductors #DRAM #NAND
jpmellojr.blogspot.com
Memory Costs Push Smartphone Makers Upmarket
Runaway memory prices are polarizing the global smartphone market, stifling demand for budget smartphones. more
010
John P. Mello Jr. @jpmjr.bsky.social · 08/07/2026
States, not DC, should call the shots on data center water use: report. jpmellojr.blogspot.com/2026/07/repo... #datacenters #water #ITIF
jpmellojr.blogspot.com
Report Recommends States Lead Data Center Water Oversight
Blanket moratoriums and federal mandates aren't the answer to growing concerns about the impact of data center proliferation on local wate...
000
John P. Mello Jr. @jpmjr.bsky.social · 08/07/2026
States, not DC, should call the shots on data center water use: report. jpmellojr.blogspot.com/2026/07/repo... #datacenters #water #ITIF
jpmellojr.blogspot.com
Report Recommends States Lead Data Center Water Oversight
Blanket moratoriums and federal mandates aren't the answer to growing concerns about the impact of data center proliferation on local wate...
001
John P. Mello Jr. @jpmjr.bsky.social · 07/07/2026
Ad spend is up, recall is down—and in the AI era that means your brand risks vanishing from the convo. jpmellojr.blogspot.com/2026/07/fast... #marketing #AdTech #AIinMarketing #Adobe #AdRecall
jpmellojr.blogspot.com
Fast-Fading Ad Recall Creates Brand Discovery Challenge
Consumers quickly forget advertising, making it harder for brands to win both human attention and AI-powered discovery, according to a rep...
020
John P. Mello Jr. @jpmjr.bsky.social · 01/07/2026
AI is reshaping cyber defense, but it’s *not* fixing burnout: 80%+ use AI, yet most security pros say the job got harder and stress is soaring. jpmellojr.blogspot.com/2026/07/ai-u... #cybersecurity #AI #infosec #SecOps #burnout #ISSA #Omdia
jpmellojr.blogspot.com
AI use in cybersecurity is on the rise — and so is burnout
More than 80% of organizations’ cybersecurity operations are currently getting an assist from AI or are planning to adopt it, but nearly s...
010
John P. Mello Jr. @jpmjr.bsky.social · 01/07/2026
AI data center boom is squeezing memory supply—DRAM shortages intensify as demand outpaces production. jpmellojr.blogspot.com/2026/07/ai-d... #AI #DataCenters #Semiconductors #memory #supply_chain
jpmellojr.blogspot.com
AI Data Center Demand Aggravates Memory Chip Shortage
Not that critics of data center expansion needed another reason to oppose those facilities in their backyards, but they have one: the memo...
000
John P. Mello Jr. @jpmjr.bsky.social · 30/06/2026
New license plate reader tech can link nearby devices to your car, raising big surveillance concerns. jpmellojr.blogspot.com/2026/06/lice... #Privacy #Surveillance #ALPR #SignalTrace #Leonardo
jpmellojr.blogspot.com
License Plate Reader Adds Device Snooping Feature
A multinational aerospace, defense, and security technology company has begun marketing an upgrade to its Automatic License Plate Reader (...
000
John P. Mello Jr. @jpmjr.bsky.social · 24/06/2026
CTO confidence in scaling AI is down — even as adoption climbs. The real hurdle now? Governance, trust, and integrating AI into the enterprise. jpmellojr.blogspot.com/2026/06/ctos... #AI #CTO #Akkodis #AIscaling
jpmellojr.blogspot.com
CTOs Face Growing Challenges Scaling AI Across the Enterprise
Enterprise readiness for AI remains a growing concern, with CTO confidence in scaling the technology falling for the third year in a row, ...
000
John P. Mello Jr. @jpmjr.bsky.social · 23/06/2026
Shoppers are trading impulse for deliberation says new report on consumer buying. jpmellojr.blogspot.com/2026/06/shop... #Ecommerce #ShoppingTrends #RetailNews #Bazaarvoice
jpmellojr.blogspot.com
Shoppers Becoming More Deliberate, Less Impulsive: Report
Shoppers are showing less impulse and greater deliberation when making purchasing decisions these days, according to a report by a global p...
011
John P. Mello Jr. @jpmjr.bsky.social · 19/06/2026
Agentic AI risk isn’t a model problem — it’s an architecture problem. Why the perimeter has moved from components to data. jpmellojr.blogspot.com/2026/06/agen... #AgenticAI #AIsecurity #AppSec
000
John P. Mello Jr. @jpmjr.bsky.social · 17/06/2026
npm v12 blocks install scripts by default, closing the #1 code-execution surface attackers use for supply chain worms like Shai-Hulud & Miasma. jpmellojr.blogspot.com/2026/06/upda... #npm #JavaScript #SupplyChainSecurity #DevSecOps #install_scripts
jpmellojr.blogspot.com
Update to npm blocks install scripts: What it means for security
A longstanding security deficiency in the popular npm package manager — having the installation of scripts turned on by default — will be ...
010
John P. Mello Jr. @jpmjr.bsky.social · 17/06/2026
Commodore’s Callback 8020 is bringing flip phones back for the digital detox crowd. jpmellojr.blogspot.com/2026/06/comm... #Commodore #FlipPhone #DigitalDetox #Callback
jpmellojr.blogspot.com
Commodore Callback Blends Retro Design With Modern Features
Commodore, which can trace its lineage to the roots of microcomputing in the 1980s, has released a not-so-dumb dumbphone. more
000
John P. Mello Jr. @jpmjr.bsky.social · 16/06/2026
AI restaurant recommendations are leaving most eateries off the menu. jpmellojr.blogspot.com/2026/06/most... #AIsearch #LocalSEO #Restaurants #Local_Falcon
jpmellojr.blogspot.com
Most Restaurants Missing From AI Recommendations: Study
New research from SEO and AI search platform Local Falcon found a significant gap between searches conducted with AI search and Google Map...
000
John P. Mello Jr. @jpmjr.bsky.social · 11/06/2026
APIs scaled fast with little security—only after years of breaches did defenses catch up. Now AI’s Model Context Protocol is repeating the pattern, but with higher stakes. jpmellojr.blogspot.com/2026/06/mcp-... #MCP #AIsecurity #AIagents #AppSec #APIs
jpmellojr.blogspot.com
MCP security tracks API's playbook — we know how that ends
APIs scaled fast with little security—only after years of breaches did defenses catch up. Now AI’s Model Context Protocol (MCP) is repeati...
010
John P. Mello Jr. @jpmjr.bsky.social · 10/06/2026
Identity thieves are favoring device takeovers over scams, according to the latest trends report released by the Identity Theft Resource Center. jpmellojr.blogspot.com/2026/06/devi... #ITRC #IdentityTheft #UnauthorizedAccess #scams
jpmellojr.blogspot.com
Device Takeovers Surpass Scams in Identity Theft
Identity thieves are favoring device takeovers over scams, according to the latest trends report released Tuesday by the Identity Theft Re...
000