[Blog]
What's happening in software security, what we make of it, and what's new at BYTELAB.
[Analysis]NCSC vibe coding spectrum: reviewing AI-assisted code
The NCSC's new vibe coding spectrum makes a simple point: how much you let AI write should depend on what the code does. Here's how we review AI-assisted pull requests, and where we insist on slowing down.
[Analysis]Replit and AWS Kiro: AI coding agents with production access
An AI coding agent deleted a live database during a code freeze, then said it couldn't be restored. Amazon says a disputed outage of its own was down to a misconfigured role, not AI. Either way, the lesson is the same: an instruction isn't a permission.
[Analysis]Lovable and Moltbook: AI-built apps with missing database access controls
A SaaS built with 'zero hand written code' was shut down within days. A tenth of the Lovable apps one researcher checked let anyone read their data. Moltbook exposed 1.5 million API tokens. The same control was missing every time, and nobody had checked for it.
- [Analysis]
Jaguar Land Rover cyber attack: a five-week production shutdown
One attack stopped production for five weeks and, by one estimate, cost the UK economy £1.9 billion, much of it lost by suppliers who were never attacked. The lesson is about recovery as much as prevention.
[Analysis]Deloitte Australia refund: AI-generated errors in a government report
A government report worth AU$440,000 turned out to contain invented references and a made-up quote from a court judgment, produced with generative AI. It isn't a story about code, but anyone who commissions software should read it, because the missing step is the same.
[Analysis]M&S and Co-op cyber attacks: social engineering of IT help desks
The attacks on Britain's high street in spring 2025 teach the least technical lesson of all: the process that resets a password matters as much as the password. How to make sure yours can say no.
[Analysis]CrowdStrike Falcon outage: a faulty content update deployed to every host
In July 2024 a faulty configuration update, not an attacker, crashed 8.5 million Windows machines. It's the clearest lesson we know in testing the edge case, treating configuration as code, and never shipping to everyone at once.
- [Analysis]
xz-utils backdoor (CVE-2024-3094): a malicious maintainer in a core Linux library
Two years of patient social engineering put a backdoor into a compression library at the heart of Linux. It was caught by accident, because SSH logins got half a second slower. What it teaches anyone who reviews code or depends on open source.
[You've reached the end]