peter bassill · operator

Peter Bassill — latest writing on cyber security

peter@hardened:~$ tail -f /var/log/writing
Threats

Critical is not the same as urgent: what 70,686 CVEs in 2026 actually ask of you

· 19 min read
Threats

The 999 lines held: Dyfed-Powys Police and the staff question

· 10 min read
Threats

Somebody else's problem: the lockbox codes, the reporting tool, and the supplier review

· 19 min read
Threats

Aimed at a person, not a network: Iran's CHOSEN BRICK

· 17 min read

Latest articles

  • The week in cyber — 21 to 25 September 2026

    A BIG-IP zero-day already under attack, Revolut's second breach this month, prompt-injected AI agents at Salesforce, an AI phishing service dismantled by Microsoft and the Met, and a whisky retailer undone by a bolt-on app — five stories, all about trust handed to someone else.

    • 6 min read
  • The week in cyber — 7 to 11 September 2026

    The EU’s vulnerability clock started, Microsoft shipped a record Patch Tuesday, CrowdStrike’s sensor became an escalation path, and Parliament said no to personal director liability — four things, each with a decision attached.

    • 5 min read
  • What shipped, and when did you know: the Cyber Resilience Act's clock starts tomorrow

    From 11 September 2026, anyone selling software or connected hardware into the EU has 24 hours from the moment they know a flaw is being exploited to tell a national CSIRT. What that means, what it does not yet mean, and why it reaches British firms that never signed up to it.

    • 22 min read
  • No personal liability, no change: the Cyber Security and Resilience Bill misses the one lever that works

    Peers asked why the Cyber Security and Resilience Bill lets executives off the personal liability hook. The Government said corporate fines are enough. Thirty years of watching boards tells me they are not, and here is why.

    • 9 min read
  • Trezor, ShipMonk, and the deletion that never happened

    Trezor's shipping partner was breached through a Metabase zero-day in August. This week the count reached 81,000, because 67,000 records came from 2019 to 2021 orders ShipMonk had confirmed in writing were deleted. A timeline, and what it teaches about supplier assurances.

    • 15 min read
  • The unmarkable exam: the child-safety law no one is allowed to grade

    The Children's Commissioner told a Lords committee that children say the Online Safety Act has made "absolutely no difference" — and that she can't judge it, because Ofcom won't release the platforms' risk assessments. A law built to be unmarkable has already told you something.

    • 6 min read
  • The week in cyber — 31 August to 4 September 2026

    Parliament writes a 24-hour clock into law while attackers work through the appliances at your network edge — four things from the week, each with a decision attached.

    • 6 min read
  • The consent nobody sought: Britain says no to the keys

    Someone finally asked the public — and across every party, Britain said it would not trust the state with the keys to its private life. A sidebar to the series that goes to the foundation the whole age-verification project rests on: a consent never sought, and never given.

    • 12 min read
  • The UK threat landscape: August 2026

    The first of a monthly series. In August, 8.7 million airport customers, more than a thousand charities and a national police database lost data through exposed keys and open portals rather than exploits; a small power generator went dark; and the patch window shrank to days.

    • 33 min read
  • The honeypot changes address

    Part 11: Meta settles the US child-safety case for up to $18bn and the UN comes out against outright bans — the week the ban model lost the argument. But the age check just moved from the platform to the app store, and the identity honeypot moved with it.

    • 6 min read
  • AI-generated harm against children in 2026

    Revisiting the September 2024 post on deepfakes and children. UK law has criminalised creation of intimate deepfakes of minors. Schools have policies. The IWF reports massive growth in AI-generated CSAM. Voice clone fraud is mature. What has actually changed and what to do.

    • 8 min read
  • Struck down before the start: France's court reads the argument back

    Part 10: eighteen days before launch, France's Constitutional Council struck the under-15 ban down — on the grounds this series pressed: disproportion, and age verification with no guarantees for private life. A reprieve, but the redraft is already commissioned.

    • 7 min read
  • Gaming and online communities in 2026: what changed

    Revisiting the 2023 post on gaming, voice chat, and the communities that look least like social media. Three years of platform safety overhauls, AI moderation, AI voice in games, and the new financial and AI-companion risks that did not exist last time.

    • 7 min read
  • The first hour

    Part 3: a child has just told you they are being extorted over an image. What to do, in what order, in the hour that follows. Why not to pay, why not to block before you capture, what Report Remove actually does, and why the image is not the emergency.

    • 10 min read
  • The first message is always kind

    Part 2: how contact with a child actually starts. Not a stranger saying something obviously wrong, but attention, aimed at a child having a bad week. The pattern, the four things that stop them telling you, and the sentence to say before anything happens.

    • 9 min read
$ finger peter

Get in touch

Email is fastest. If your message says who you are, what you would like, and a rough sense of when, you will get a useful answer within two working days.
EMAILcomms [at] peterbassill {dot} com
GITHUB@pbassill
CRESTEuropean Council · IR Pan Europe
LOCATIONUnited Kingdom · en_GB
no tracking · no third parties · stored only in my inbox
anti-abuse check: waiting for the form…