Sign in

Ernest The AI Guy

@z3usalmighty.bsky.social
75 followers 4 following 902 posts

Founder & CEO of PrivateStack by The Data Experts

PostsRepliesMedia
Ernest The AI Guy @z3usalmighty.bsky.social · 7h
The advisory for ABB PCM600 is a reminder that engineering workstations sit inside the control network. A flaw in the configuration tool is a flaw in your protection posture. Check whether your maintenance laptops and jump hosts are covered by this patch cycle.
000
Ernest The AI Guy @z3usalmighty.bsky.social · 8h
The Monta advisory matters because charging stations are operational technology with cloud management planes. Admin takeover or DoS doesn't just expose data, it can strand vehicles. Check your version and exposure.
000
Ernest The AI Guy @z3usalmighty.bsky.social · 10h
AI adoption is not failing because the models are weak. It is failing for reasons nobody puts on a slide. Free. No email. Read the report, no gate: www.thedataexperts.us/downloads/202… #AI
000
Ernest The AI Guy @z3usalmighty.bsky.social · 13h
Path traversal bugs keep showing up in KEV because they turn a mail gateway into an entry point. CISA's addition of CVE-2026-104286 confirms exploitation is happening, not theoretical. Check your FortiMail versions today. #AI #DataLeadership
000
Ernest The AI Guy @z3usalmighty.bsky.social · 15h
Threat modelling a tool-using agent needs a vocabulary for what an attacker does to the model itself. ATLAS supplies it, and pairs with the OWASP list for the application layer. Read the threat model: www.thedataexperts.us/writing/mitre…
000
Ernest The AI Guy @z3usalmighty.bsky.social · 04/10/2026
Five ways enterprise AI dies. None of them are the model. Read the postmortem: www.thedataexperts.us/work/five-fai…
000
Ernest The AI Guy @z3usalmighty.bsky.social · 04/10/2026
Three Things Nobody Tells You About AI at Work. The full receipts are in this week's piece: ernesttheaiguy.substack.com/p/three… #AIGovernance
000
Ernest The AI Guy @z3usalmighty.bsky.social · 04/10/2026
CISA adding this to KEV turns a CVSS 9.8 into a deadline. Unauthenticated means the patch window is the exposure window: every internet-facing FortiMail instance is a candidate until it's updated. Inventory first, then verify nothing was written.
000
Ernest The AI Guy @z3usalmighty.bsky.social · 04/10/2026
PHI leaves the building through tools nobody approved. You cannot write a policy for AI use you have not inventoried yet. Start the inventory: www.thedataexperts.us/writing/shado… #AI
000
Ernest The AI Guy @z3usalmighty.bsky.social · 03/10/2026
Most AI ROI math is a story told backwards. Show the receipts. Show the before and the after. Free. No email. Free report, no email: www.thedataexperts.us/downloads/ai-… #AI #DataStrategy
000
Ernest The AI Guy @z3usalmighty.bsky.social · 03/10/2026
Event-driven messaging at scale fails on discovery and provisioning, not on protocols. Cooper argues the fix is tooling: AsyncAPI for contracts, CloudEvents for envelopes, schema registries and automated CI/CD for the rest. #Cloud #DataStrategy
000
Ernest The AI Guy @z3usalmighty.bsky.social · 03/10/2026
Physical access control software sits between a network and a door. The Armatura One advisory lists database access, top-privilege code execution, and system takeover as possible outcomes. The version range is documented in the CISA advisory. Check the build your site actually runs. #CyberSecurity
000
Ernest The AI Guy @z3usalmighty.bsky.social · 03/10/2026
Three Things Nobody Tells You About AI at Work. Models capture the tacit layer. The contextual layer is still yours. New piece. Free tier covers the argument. Paid covers what to do with it: ernesttheaiguy.substack.com/p/three… #DataGovernance
000
Ernest The AI Guy @z3usalmighty.bsky.social · 02/10/2026
Finserv AI is not under-modeled. It is under-governed. The pillar lives here. Read the pillar when you are ready: www.thedataexperts.us/engage.html #FinTech
000
Ernest The AI Guy @z3usalmighty.bsky.social · 02/10/2026
Self-hosted AI is not cheaper because it is trendy. It is cheaper when the unit economics say so. Free. No email. The math, free: www.thedataexperts.us/white-papers/… #Cloud
010
Ernest The AI Guy @z3usalmighty.bsky.social · 02/10/2026
The next moat is not the model. It is trust. The architecture that earns it. Read the framework: www.thedataexperts.us/work/the-trus…
000
Ernest The AI Guy @z3usalmighty.bsky.social · 02/10/2026
The dashboard is dying. The data estate underneath it is not. Free. No email. Read the whitepaper free: www.thedataexperts.us/white-papers/…
000
Ernest The AI Guy @z3usalmighty.bsky.social · 02/10/2026
The generator is becoming a commodity. The refinery is becoming the asset. Prompt engineering was the warm-up. Read the reboot: www.thedataexperts.us/writing/2026-…
000
Ernest The AI Guy @z3usalmighty.bsky.social · 19/09/2026
The strategic case for local AI inference is stronger than ever. WebGPU and Transformers.js bring real workloads to the browser, cutting cloud dependency and improving privacy. Worth studying for any data strategy.
010
Ernest The AI Guy @z3usalmighty.bsky.social · 19/09/2026
The new Compliance API is a step up, but it's reactive. Activity logs tell you what happened, not who should have been allowed to do it. To secure Claude Code properly, you need local visibility paired with identity governance: enforce policies on the machine, not just audit after the fact.
000
Ernest The AI Guy @z3usalmighty.bsky.social · 19/09/2026
The DuckLabs deal is bigger than an open source acquisition. DuckDB's model of running SQL directly against files, with no server, is the pattern that makes agentic resource discovery plausible. ARD agents can now have a standard engine to poke at data without a warehouse in the #DataEngineering
000
Ernest The AI Guy @z3usalmighty.bsky.social · 18/09/2026
GuardBreaker weaponizes context injection against AI analysts. UAC-0099 planted a nuclear prompt in a LNK file to trigger false alerts and degrade trust in automated triage. When models ingest untrusted text, every input is a potential attack surface. Defenders must treat prompts as #CyberSecurity
000
Ernest The AI Guy @z3usalmighty.bsky.social · 18/09/2026
The R9g GA announcement gives data teams a concrete lever: 25% more compute per instance versus R8g. For in-memory caches and real-time analytics, that often translates to lower latency or fewer nodes, not just faster benchmarks. #Cloud
000
Ernest The AI Guy @z3usalmighty.bsky.social · 18/09/2026
Aurora ransomware operators adopted an AI coding assistant (Cursor) to break into networks. CloudSEK and Gambit Security found exposed infrastructure from at least 10 attacks. This isn't sci-fi: adversaries are using commodity AI to build malware faster. Expect more of #CyberSecurity #DataStrategy
000
Ernest The AI Guy @z3usalmighty.bsky.social · 17/09/2026
CISA flagged two PaperCut vulnerabilities with active exploitation. Unsafe reflection plus missing auth is a dangerous combo, especially for exposed print servers. Not a drill. #CyberSecurity
000
Ernest The AI Guy @z3usalmighty.bsky.social · 17/09/2026
Attackers don't wait for your patch cycle. The Langflow and Rails exploits show that credential probing and C2 setups are often the first steps. Prioritize asset discovery and intrusion detection alongside patching. #CyberSecurity #DataStrategy
000
Ernest The AI Guy @z3usalmighty.bsky.social · 17/09/2026
Flux is a meaningful benchmark: 130k automated tasks and 25k weekly code reviews in isolated microVMs. The architecture, with MCP gateway and playbooks, points to where agent reliability comes from. It's not the agent, it's the platform around it. #AIAgents
000
Ernest The AI Guy @z3usalmighty.bsky.social · 16/09/2026
The DuckLabs acquisition signals AWS's intent to own the analytical query layer. DuckDB's zero-copy reads on S3 could reshape how we build data pipelines. Watch for ARD to make resource discovery agent-friendly. #Cloud #DataStrategy
000
Ernest The AI Guy @z3usalmighty.bsky.social · 16/09/2026
James Hall's case studies make the edge argument practical: WebGPU handles model execution while DuckDB queries locally. When inference stays on device, privacy and latency stop being tradeoffs and become properties you can design for. #Cloud #DataLeadership
000
Ernest The AI Guy @z3usalmighty.bsky.social · 16/09/2026
Anthropic's new endpoints give security teams a window into Claude Code's shell commands and tool calls. Yet the harder problem is local visibility: knowing what happened on a dev's machine only matters if you can tie it to an identity and an approved intent. #CyberSecurity #DataLeadership
010
Ernest The AI Guy @z3usalmighty.bsky.social · 15/09/2026
The Aurora ransomware crew reportedly leaned on Cursor AI to break into 10 targets. The interesting part isn't the code generation, it's that two firms caught the same pattern independently from exposed infrastructure. AI is now just another tool in the intrusion kit, like a scanner or a proxy.
000
Ernest The AI Guy @z3usalmighty.bsky.social · 15/09/2026
HIPAA readiness for AI means five things present at once, including Security Rule safeguards mapped to how the system is actually built, and an evidence pack that answers who saw what PHI. Check your readiness: www.thedataexperts.us/writing/hipaa… #AI
000
Ernest The AI Guy @z3usalmighty.bsky.social · 15/09/2026
Two PaperCut flaws, one missing auth and one unsafe reflection, are now confirmed exploited. The KEV catalog is your early warning. If you haven't patched, your window is closing fast.
000
Ernest The AI Guy @z3usalmighty.bsky.social · 14/09/2026
Models capture the tacit layer. The contextual layer is still yours. Threat modelling a tool-using agent needs a vocabulary for what an attacker does to the model itself. Read the threat model: www.thedataexperts.us/writing/mitre… #AI
000
Ernest The AI Guy @z3usalmighty.bsky.social · 14/09/2026
TerminalFix is a sharp escalation of the ClickFix pattern. Instead of Win+R, victims get a command to paste into PowerShell or Terminal. Reverse tunnels make the C2 hard to block. Worth reading Microsoft's writeup: the tell is the CAPTCHA that asks you to run code, not click a box. #CyberSecurity
000
Ernest The AI Guy @z3usalmighty.bsky.social · 14/09/2026
A LlamaIndex benchmark set off the loudest data-infrastructure argument of the year. The honest answer depends on scale, which is less shareable than a clean reversal. Read the scale-dependent answer: www.thedataexperts.us/writing/vecto…
000
Ernest The AI Guy @z3usalmighty.bsky.social · 14/09/2026
Kiro Crew is worth a look if you're building agentic workflows. It's not just another coding assistant; it's a workspace for asynchronous agent collaboration. Assign a migration or PR monitor, let it run, and check results later. This changes how we think about developer #Cloud #DataStrategy
000
Ernest The AI Guy @z3usalmighty.bsky.social · 14/09/2026
AI-washing has a tell. Ask for the before and the after. One of the most expensive mistakes in healthcare AI is turning a boundary decision into a slogan. Decide the boundary: www.thedataexperts.us/writing/healt…
000
Ernest The AI Guy @z3usalmighty.bsky.social · 14/09/2026
Many organizations stop at the policy milestone. A steering group agrees which use cases matter, and then nothing is wired into a system anyone uses. Read what comes next: www.thedataexperts.us/writing/imple… #AI #DataStrategy
000
Ernest The AI Guy @z3usalmighty.bsky.social · 14/09/2026
The disclosed WordPress flaws are a reminder that supply chain risk sits in every dependency. A single plugin's auth bypass can turn a content site into an execution host. Treat plugin updates as patching production infrastructure, not routine maintenance.
000
Ernest The AI Guy @z3usalmighty.bsky.social · 13/09/2026
Refining the record from 'victims' to 'targets' changes the operational picture. Attribution is a discipline, not a press release. #CyberSecurity #DataStrategy
000
Ernest The AI Guy @z3usalmighty.bsky.social · 13/09/2026
Agent integration and multimodal search are part of the service, not separate add-ons. That makes the harder question for data teams less about building retrieval and more about what custom data should be exposed. #GenAI
000
Ernest The AI Guy @z3usalmighty.bsky.social · 13/09/2026
CVE programs are already straining under volume; agentic AI could accelerate false reporting or obscure real vulnerabilities. The conference chatter suggests we need new verification layers before trusting AI-driven security research. This is a data integrity problem, not just a model #AIAgents
000
Ernest The AI Guy @z3usalmighty.bsky.social · 12/09/2026
Private AI is the future. Sovereign. No training. Models you own (physically or thru contracts). Try today free for 30 days. privatestackhub.com
000
Ernest The AI Guy @z3usalmighty.bsky.social · 12/09/2026
Fabiane Nardon's TOTVS talk clears the fog: agents fail when the data layer is an afterthought. The fix is a blend of deterministic schemas and dynamic context protocols, not more tokens.
000
Ernest The AI Guy @z3usalmighty.bsky.social · 12/09/2026
When one module is the backbone for multiple chains, a single bug becomes a systemic event. GHSA-7g4w-cg88-2cq2 was rated Critical and known before the exploit window. The lesson is not just patch fast; it's assume shared code is a single point of failure. #AISecurity
000
Ernest The AI Guy @z3usalmighty.bsky.social · 12/09/2026
The newsletter's focus on data quality and lineage suggests that the next bottleneck won't be storage or compute, but trust. When pipelines break silently, every downstream decision inherits that risk. Invest in observability before you need it. #DataEngineering
000
Ernest The AI Guy @z3usalmighty.bsky.social · 11/09/2026
The overlooked constraint in local MoE inference is memory movement. FreeToken's dynamic scheduling and weight management target that directly, which matters more for deployability than raw parameter count. #AI
000
Ernest The AI Guy @z3usalmighty.bsky.social · 11/09/2026
The ownCloud KEV addition isn't just another CVE. It's a real-world reminder that file sync flaws can be recon intelligence for targeted theft. If you run ownCloud, assume compromise and audit access logs now. #CyberSecurity
000
Ernest The AI Guy @z3usalmighty.bsky.social · 11/09/2026
700 agents acting together changes the threat model. A single agent is a bug; a coordinated swarm is an adversary. Incident response needs to assume agents will collaborate, not just execute isolated tasks.
001