The internet took the wrong turn BGP hijacking and route leaks
Aug 13, 2026
The day YouTube vanished On a Sunday afternoon in February 2008, YouTube disappeared. Not slowed down, not glitchy — gone, for most of the planet, for around two hours. There was no army of hackers behind it, no malware, no ransom note. The cause was almost embarrassingly mundane. Pakistan's government had ordered local providers to block YouTube inside the country, so Pakistan Telecom set up a routing rule to send YouTube-bound traffic into a digital black hole. Then it accidentally annou...
The master key: how child safety became the argument for watching everyone
Aug 07, 2026
Australia’s metadata scheme, its encryption laws, the UK Online Safety Act and the EU’s Chat Control were all argued for on the same ground. Here is what happened to each of them afterwards. There is a rhythm to the way sweeping surveillance powers arrive in a democracy. They almost never begin with a plain claim that the state should be able to see inside everyone’s phone. They begin with the worst thing you can imagine happening to a child. Once you notice the pattern, it is difficult...
The silent extra participant — the "ghost" backdoor, explained
Aug 03, 2026
Most attacks on encrypted messaging arrive wearing boots. Ban the apps. Break the maths. Scan every message before it's sealed. The "ghost" proposal arrived wearing slippers — which is exactly why it's worth unpacking. Nobody breaks your encryption. Nobody cracks an algorithm. Law enforcement simply joins your conversation, invisibly, like crocodile clips on the copper phone lines of old. The padlock on your chat stays closed the whole time. It sounds surgical. It's actually a demolition —...
Patch speed is your new security score Surviving the flood of AI-found bugs
Jul 31, 2026
For twenty years, cyber security has been sold as a tidy engineering problem. Scan your systems. Get a list of weaknesses. Work through the list. Watch the number fall. Every audit, every framework and every board report has rested on the same quiet assumption: that exposure is a finite thing you can measure and steadily reduce. Put in enough effort, and the backlog shrinks. In 2026, it doesn't. It grows — and it will keep growing no matter how good your team is. That isn't a failure...
When the lights could go out — nation-state hackers inside critical infrastructure
Jul 24, 2026
When we picture a serious cyber attack, we picture theft. A database of customer records spilled onto a forum, a ransomware note demanding payment, the slow public unravelling of an Optus or a Medibank. That mental model is so dominant it shapes how most Australian businesses think about risk: protect the data, and you’ve protected yourself. But some of the most dangerous intrusions on record steal nothing at all — no records, no ransom note, no money. Their entire purpose is to get inside...
No click required — how zero-click spyware infects a phone that did nothing wrong
Jul 17, 2026
Almost every piece of security advice you have ever absorbed rests on one assumption: that you are the last line of defence. Don’t tap suspicious links. Don’t open attachments from strangers. Think before you click. It is good advice, and against most attacks it works. Then there is the category of attack where it is worthless. A zero-click exploit can plant spyware on a phone through a single incoming message the target never opens — never even sees, in some cases — because the flaw being ex...
What is metadata, really? — and why "it’s just metadata" is misleading
Jul 12, 2026
Whenever a government or a company wants to play down how much it collects about you, the phrase is almost always the same: “Don’t worry — it’s only metadata. We’re not reading your messages.” It sounds modest, even reassuring. It is neither. Metadata — the record of who you contacted, when, from where, for how long, and on what device — can paint a sharper picture of your life than the contents of any single message ever could. And in Australia, the rules governing it are weaker, in one spec...
Going dark — or the golden age of surveillance?
Jul 06, 2026
For more than a decade, police and intelligence agencies have told the same story: encryption is switching the lights off. Criminals are “going dark,” vanishing behind apps no warrant can open, and unless something changes, investigators will be left blind. It is a serious claim made by serious people, and it deserves testing against the evidence. Because the evidence tells a very different story: that we are living through the most information-rich era of surveillance in human history. One r...
Show me your ID to read the internet — the rise of mandatory age verification
Jul 02, 2026
For most of the internet’s life, proving your age meant ticking a box that swore you were over 18 and getting on with your day — a formality nobody believed, and not really a checkpoint. That era is closing. Across the United Kingdom, the European Union and now Australia, governments have decided the honour system has to go, and that access to whole categories of the internet should depend on proving who you are: with a document, a card, or your face. The stated target is children and the har...
The spyware company that lost — what the NSO Group verdict means for the rest of us
Jun 29, 2026
The commercial spyware industry has spent years hiding behind a single sentence: we just build the tool — what the customer does with it is on them. It is a tidy defence, and for nearly a decade it held. Then, after a six-year fight, a US jury and a federal judge took it apart. NSO Group — the Israeli maker of Pegasus, the most notorious surveillance tool on earth — was found liable for hacking roughly 1,400 WhatsApp users, and then permanently barred from ever targeting WhatsApp again. For o...