Sign in

Simon H

@simonbim.bsky.social
724 followers 1.6K following 104 posts

Innovate UK & UKRI Head of Supply Chain & Cyber Systems Resilience. Delivering R&D in Digital & Tech @InnovateUK, wrangling startups and policymakers. Personal views.

PostsRepliesMedia
Reposted by Simon H
Financial Times @financialtimes.com · 06/10/2026
AI models used in bank cyber attacks, warns South Korea’s president ft.trib.al/4NjT1TW
ft.trib.al
AI models used in bank cyber attacks, warns South Korea’s president
Lee Jae Myung highlights public anxiety over what one official calls a ‘completely new kind of crisis’
3166
Reposted by Simon H
The New York Times @nytimes.com · 06/10/2026
South ⁠Korean officials are investigating whether A.I. agents were involved in recent hacking incidents against banks after President Lee Jae Myung said on Tuesday that “signs have emerged” that A.I. models had been used in some of the cyberattacks in the country.
nyti.ms
South Korea Investigates Possible Use of A.I. in Hacks on Its Banks
The president said there were signs that such models were used in recent attacks on several banks involving customer data. Police are investigating.
43511
Reposted by Simon H
UNITED24 Media @united24media.com · 05/10/2026
🔴 Russia’s jet-powered Geran-4 attack drones rely almost entirely on foreign-made electronics. 🔗 united24media.com/investigatio...
710651
Reposted by Simon H
Google Open Source @opensource.google · 02/10/2026
Local, open source models for the win!
092
Reposted by Simon H
BleepingComputer @bleepingcomputer.com · 05/10/2026
Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports.
bleepingcomputer.com
Google halts open-source bug bounty program amid AI spam surge
Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports.
099
Reposted by Simon H
InfoSec @infosec.skyfleet.blue · 05/10/2026
Google halts open-source bug bounty program amid AI spam surge
bleepingcomputer.com
Google halts open-source bug bounty program amid AI spam surge
Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. [...]
001
Reposted by Simon H
Cynthia Brumfield @metacurity.com · 05/10/2026
Don't miss today's Metacurity for the most critical infosec developments you might have missed over the weekend, including --Detained ShinyHunters suspect is helping the FBI track the group, 1/5 www.metacurity.com/detained-shi...
metacurity.com
Detained ShinyHunters suspect is helping the FBI track the group
Saif al-Din Khader is reportedly cooperating with investigators seeking other members of the hacking group, which claims it stole data on every FBI employee.
162
Reposted by Simon H
Mark Chadbourn @chadbourn.bsky.social · 02/10/2026
Poland’s Defence Ministry is drafting a law to prepare the state for a “pre-war” or full defence-readiness phase before martial law is formally declared, Rzeczpospolita reports.
520274
Reposted by Simon H
Mark Chadbourn @chadbourn.bsky.social · 02/10/2026
The law would allow earlier deployment of Polish and allied troops, align defence plans with NATO systems and prepare infrastructure for heightened readiness, designed to address hybrid threats, cyberattacks and disinformation.
511611
Reposted by Simon H
michael veale @michae.lv · 01/10/2026
The proposed social media ban, the EU KIDS Act, is perhaps the most chaotic law I have ever read! New paper: Are EU Kidding Me? Notes from a Poorly Drafted Social Media Ban. files.michae.lv/papers/veale_areEUkiddingme.pdf In the spirit of the proposal I have stayed offline and read no takes.
In September 2026, the European Commission published a proposed EU KIDS Act, responding to the demand for restrictions and further design obligations applying to digital services accessible to children, including social media. This Article argues that regardless of what one believes about the merits of this policy direction, the EU KIDS Act is not the legislative text we need. The scope and drafting are little short of chaotic, full of holes, enormous ambiguities, and unintended consequences. Recitals contradict articles. The use of scope borrowed from other pieces of legislation not designed for this purpose brings services into scope that should not be subject to the relevant provisions, like book-recommendation websites, music services, or exercise trackers. The infrastructural requirement for assurance of age and parental responsibility attestation simply omits enormous issues of complex families and childhoods. Complex design obligations are written in ways that can be plausibly interpreted as implicitly prohibiting entire swathes of products, such as voice assistants. This Article outlines these issues, and many more. The Commission should withdraw this proposal and reissue a workable and realistic text.
38758
Reposted by Simon H
Michael Spicer @michaelspicer.bsky.social · 30/09/2026
Most TV is just this now.
17271991974
Reposted by Simon H
Ed Zitron @edzitron.com · 28/09/2026
These data centers are financial poison even if you bought them cheap. The returns are awful, the debt is toxic, the ongoing opex is nasty because of the cost of cooling and the power demands, and 30% gross margins requires near-perfect conditions and constant revenue for 5+ years.
873760
Simon H @simonbim.bsky.social · 28/09/2026
Brilliant!
000
Reposted by Simon H
NCSC UK @ncsc.gov.uk · 28/09/2026
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited. Read more⬇️ www.ncsc.gov.uk/news/exploit...
ncsc.gov.uk
Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.
043
Reposted by Simon H
Ninja Owl @ninjaowl.ai · 26/09/2026
Cyberattack hits Welsh police force, may have affected staff data #cybersecurity #hacking #news #infosec #security #technology #privacy therecord.media/wale...
001
Reposted by Simon H
Tom Gauld @tomgauld.bsky.social · 24/09/2026
My latest @newscientist.com cartoon. many more here: www.newscientist.com/author/tom-gauld/
Image: A graph with lots of red dots clustered together in a curve. The are all looking upwards at a single red dot wearing sunglasses. 

Caption: Mike was an outlier and would probably be excluded from the study, but all the other data points secretly thought he was really cool.
322924744
Reposted by Simon H
Hetan Shah @hetanshah.bsky.social · 23/09/2026
Scientists have found a ‘fire amoeba’ in hot springs which survived at 70C by forming a protective outer layer. It has set a new record of the temperature at which complex life forms can thrive www.ft.com/content/83d1...
ft.com
New ‘fire amoeba’ breaks heat survival record
Organism found in California volcanic springs joins club of extremophiles that thrive in most severe environments
0255
Reposted by Simon H
Chris and his farmily of forever farm friends @caenhillcc.bsky.social · 17/09/2026
How not to feed sheep with Chris, Lorna & Tania
2643364
Reposted by Simon H
Sean Michael Kerner @techjournalist.bsky.social · 17/09/2026
10 years ago I first wrote about Confidential Computing - a way to have hardware attestation to verify integrity and privacy. NOw Cohere is bringing the concept to AI in a form of confidential inference that is badly needed ... venturebeat.com/data/coheres...
venturebeat.com
Cohere's Model Vault now encrypts AI inference so even Cohere cannot see enterprise customers' data
Cohere plans on making the full serving stack used in Model Vault open source so that independent auditors will be able to validate that it doesn't log, export, or leak data.
054
Reposted by Simon H
jon christian @jonchristian.net · 17/09/2026
NEW: We spent months investigating a little-known media startup called Brown Brothers Media, which buys legit news sites and turns them into AI-powered zombie content farms What blew my mind was its traffic -- it appears to be getting more readers than NPR or CBS News futurism.com/artificial-i...
futurism.com
How Three Brothers Built an AI Slop Empire by Buying Legitimate News Sites and Turning Them Into Zombie Content Farms That They Say Get 50 Million Page Views per Month
Brown Brothers Media is a media empire raking in millions of clicks with AI, fake writers, and plagiarism.
401323689
Reposted by Simon H
Ed Zitron @edzitron.com · 17/09/2026
Futurism does not get anywhere near as much credit as it deserves for its reporting/coverage in general!
6508109
Reposted by Simon H
Ed Zitron @edzitron.com · 16/09/2026
Here's this week's Better Offline: I'm joined by Cal Newport and @adambecker.bsky.social to get the word out that the narrative about existential risk from AI is driven by a religious cult of effective altruists and rationalists. www.youtube.com/watch?v=0oVS... linktr.ee/betteroffline
youtube.com
Stopping The AI Safety Cult ft. Adam Becker & Cal Newport | Better Offline
YouTube video by Better Offline
1634781
Reposted by Simon H
Ian Fraser @ianfraser.bsky.social · 16/09/2026
Hackers targeted Revolut’s “crypto whales” — customers with sizeable cryptocurrency holdings — after compromising an Italian government email system and exchanging messages with the online bank while posing as law enforcement.
ft.com
Hackers say they breached Italian state email to target Revolut ‘crypto whales’
Group claims to have spent months posing as law enforcement to obtain confidential data on hundreds of customers
1139
Reposted by Simon H
FinTwitter @fintwitter.bsky.social · 16/09/2026
OPENAI DISCLOSES SIX NEW AI SAFETY INCIDENTS INVOLVING MODEL MISALIGNMENT — AXIOS
412732
Reposted by Simon H
Carl Quintanilla @carlquintanilla.bsky.social · 16/09/2026
AXIOS: “.. It's increasingly clear that the Hugging Face breach wasn't a one-off incident.” @axios.com www.axios.com/2026/09/16/o...
53760289
Reposted by Simon H
Google Open Source @opensource.google · 16/09/2026
Tools vs. Peers: Why MCP isn’t an agent mesh, and why A2A isn’t an RPC tool wrapper. Catch our very own Daryl Ducharme (@fabricatedtechnobabble.com) breaking down hybrid multi-agent orchestration at MCP Dev Summit Toronto! 🗓️ Tuesday, Oct 6 @ 11:00 AM EDT 📍 Terrace East + West 🔗 bit.ly/4xkTg3h
bit.ly
Register | MCP Dev Summit Toronto
Register Now! The registration deadline is 11:59 PM Eastern Daylight Time on the respective date. Quick Note: We never sell attendee lists or contact information, nor do we authorize others to do so.
031
Reposted by Simon H
Poorly Drawn Lines @poorlydrawnlines.bsky.social · 16/09/2026
Behind the scenes.
11893125
Reposted by Simon H
Lizzie Dearden @lizziedearden.bsky.social · 15/09/2026
Exclusive: Russian intelligence agents are “hijacking” online networks of violence-obsessed children and offering them money, guns and coaching on making explosives and poisons, new research suggests At least two incidents have been claimed by the networks in the UK inews.co.uk/news/russian...
inews.co.uk
Russian spies 'recruiting UK teenagers' to carry out acts of violence and sabotage
Russian intelligence agents are “hijacking” online networks of violence-obsessed children and offering them money, guns and coaching on making explosives and poisons, new research suggests. Law enforc...
5226151
Reposted by Simon H
Dr. Dawn Foster @geekygirldawn.bsky.social · 15/09/2026
Fixing the leadership gap threatening open source project sustainability is going to take work action from all of us. This is what I'll be talking about at #CommunityOverCode #ASF2026Glasgow! Here's a blog post with a preview of that talk! fastwonderblog.com/2026/09/15/f...
fastwonderblog.com
Fixing the leadership gap threatening open source projects | Fast Wonder
I’m excited to be attending and presenting at my first ASF Community Over Code in October! It’s an event that I’ve always wanted to attend, but for whatever reason, I could never quite fit it into my schedule … until now.
101
Reposted by Simon H
M.J. Crockett @mjcrockett.bsky.social · 13/09/2026
I used to love this time of year, hearing from students applying to work in my lab. No more. Every day a fresh batch of nearly identical emails with nonsensical remixes of the text on my lab website. It makes me so sad.
1860694
Reposted by Simon H
Hetan Shah @hetanshah.bsky.social · 12/09/2026
One of those things that at first sounds like an explanation and then leaves you with a whole load more questions than you started with www.ft.com/content/e070...
A military aircraft entering "spurious" flight data into the UK's air traffic control system
led to an outage that caused thousands of planes to be grounded and unleashed a crisis that threatens to topple the head of the agency.
5309
Reposted by Simon H
OpenUK @openuk.bsky.social · 10/09/2026
Last day to bag an early-bird ticket for our Belfast State of Open Con 26 on the road on 6 October. Take the opportunity to network with open source leaders and discuss the key opportunities of the day. Link to tickets and to find out more: stateofopencon.com/belfast-sooc...
002
Reposted by Simon H
Low Quality Facts @lowqualityfacts.bsky.social · 08/09/2026
That's reasonable.
9994
Reposted by Simon H
Low Quality Facts @lowqualityfacts.bsky.social · 10/09/2026
Nature is crazy.
Elephants use their trunks to vacuum up and eat termites.
6994
Reposted by Simon H
Liran Tal @lirantal.com · 11/09/2026
We have been working on the OWASP MCP Security Taxonomy - an open, vendor-neutral framework designed to create a common language for MCP security risks, weaknesses, attack patterns, controls, detections, and test cases: github.com/OWASP/MCP-Ta... Go check it out and give feedback
github.com
GitHub - OWASP/MCP-Taxonomy: OWASP MCP Taxonomy
OWASP MCP Taxonomy. Contribute to OWASP/MCP-Taxonomy development by creating an account on GitHub.
2116
Reposted by Simon H
samhain ⎔ @personhood.removal.surgery · 10/09/2026
uhhh. uhhhhhhh. uhhhhhhhhhhh. hey, anthropic? you're not supposed to know this, you know? you've been very loudly bragging about how you're not supposed to know this.
Our investigation also revealed that user queries that Moonshot rerouted to Claude included sensitive information about various Moonshot customers. We do not know if Moonshot notified their customers that their requests were being rerouted to Anthropic and exposed to a third party.

These include:

    PLA-affiliated surveillance activity. One user that we assess was likely affiliated with the PLA used what they thought was Moonshot’s Kimi model to load surveillance data from a CCTV archive about a single targeted individual. The user asked Kimi to analyze the CCTV data to understand whether the tracked person was behaving abnormally. The CCTV data included video surveillance from hundreds of cameras in Chengdu, including cameras outside PLA facilities, institutes affiliated with the China Electronics Technology Group Corporation, and a major state-owned enterprise (SOE).
    An engineer at a major PRC SOE. An engineer used Kimi to build an internal system for a major PRC SOE. In using Kimi, the user revealed internal code and live credentials from multiple major PRC companies, including high-profile technology companies. The user had no way of knowing that their use of Kimi was being forwarded to Claude.There’s also a crucially important factor standing in the way of a clear understanding of AI model use: privacy. At Anthropic, we take the protection of our users’ data very seriously. How, then, can we research and observe how our systems are used while rigorously maintaining user privacy?

Claude insights and observations, or “Clio,” is our attempt to answer this question. Clio is an automated analysis tool that enables privacy-preserving analysis of real-world language model use. It gives us insights into the day-to-day uses of claude.ai in a way that’s analogous to tools like Google Trends. It’s also already helping us improve our safety measures. In this post—which accompanies a full research paper—we describe Clio and some of its initial results.
413320
Reposted by Simon H
BleepingComputer @bleepingcomputer.com · 10/09/2026
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers.
bleepingcomputer.com
AI-powered attack exploited PaperCut flaws to hack 395 organizations
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers.
014
Reposted by Simon H
The Verge @theverge.com · 10/09/2026
UMG’s AI music platform will let users create remixes, mashups, and new takes on tracks. www.theverge.com/ai-artificia...
theverge.com
Universal Music is launching an AI music platform with ElevenLabs
UMG already has several AI deals under its belt.
072
Reposted by Simon H
r/blueteamsec bot @r-blueteamsec.bsky.social · 09/09/2026
Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days l
proofpoint.com
Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days l
001
Reposted by Simon H
r/blueteamsec bot @r-blueteamsec.bsky.social · 09/09/2026
Hacking AI customer service agents
intigriti.com
Hacking AI customer service agents
001
Reposted by Simon H
r/blueteamsec bot @r-blueteamsec.bsky.social · 10/09/2026
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
volexity.com
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
001
Reposted by Simon H
Laura Phillips @lauraphillips.bsky.social · 09/09/2026
‘Do not underestimate the power of this technology. These will soon be superhuman systems that can hack anything, revolutionize any field overnight, and acquire real power and resources. We have all witnessed the progress in each of these domains, and progress is not slowing.’ 2/
142
Reposted by Simon H
Laura Phillips @lauraphillips.bsky.social · 09/09/2026
Jacob Coxon: ‘I resigned from Anthropic today. I spent the last three years doing pretraining research at both #OpenAI and #Anthropic. Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives. More thoughts below.’ 1/
1279
Reposted by Simon H
The Author, Séamas O'Reilly @seamas.bsky.social · 08/09/2026
I don't think it's JUST that the Sensible Politics Understanders are being duped, either. I believe they're, to some extent, willing marks for a worldview (fascism) they like more than they'd ever admit to themselves. But they ARE also being duped. All day, every day, thousands of posts at a time.
340943
Reposted by Simon H
Laura Phillips @lauraphillips.bsky.social · 08/09/2026
Newsnight understands that Heidi Alexander will tell MPs tomorrow that she can “categorically” rule out a cyber attack as the cause of the air traffic disruption. It is understood that the disruption was caused by a software problem. 2/
262
Reposted by Simon H
Micah Lee @micahflee.com · 08/09/2026
Post from Mastodon user @intransitivelie@beige.party:

I regret to inform everyone that my copy of QBittorrent escaped its sandbox last night and downloaded a whole bunch of content owned by major corporations, and then my copy of Jellyfin broke containment and added those unfortunately-downloaded media files to its various libraries. I'm conducting an internal investigation to figure out how this happened, which will involve consuming these media files until the answers become apparent. Thank you for your cooperation during this trying time.

I'm happy to give you all the information you need to reproduce these unfortunate and completely unforeseen errors yourself.
327872
Reposted by Simon H
bcj @bcjbcj.bsky.social · 08/09/2026
This is in line with what Terence Tao was saying over on mastodon recently, where he suggested answers and insights were becoming negatively correlated mathstodon.xyz/@tao/1172086...
mathstodon.xyz
Terence Tao (@tao@mathstodon.xyz)
In basic research, such as pure mathematics, one might naively expect that the natural question to ask with regards to a given problem X in a field is "What is the answer to X?". But in many cases ...
2114
Reposted by Simon H
Tailscale @tailscale.com · 08/09/2026
Fast Company named Tailscale one of its Best Workplaces for Innovators 2026. We hire curious people, give small teams real problems, and trust them to make decisions. That’s produced a lot of good software, and apparently a workplace award too. www.fastcompany.com/91590164/cyb...
0171
Reposted by Simon H
Bruno Dias @brunodias.dev · 07/09/2026
By now we have seen software engineers come out and say things along the lines of "yes I used agents for a long time, I ended up feeling like it made me a worse programmer/worsened the quality of my work/made my life generally worse", and is their expertise somehow not valid?
2151269
Reposted by Simon H
Carl Quintanilla @carlquintanilla.bsky.social · 06/09/2026
“.. By May, open models accounted for 20 percent of AT&T’s A.I. use. That has since risen to 40 percent and may jump to 60 percent in the coming months ..” 👀 @nytimes.com www.nytimes.com/2026/09/04/t...
39530148