Securely Built

@securelybuilt.bsky.social

Securely Built is on the hunt for insecurity in the world where we can leverage our decades of experience in cyber and engineering to banish insecure technology from whence it came. Find out more at: securelybuilt.com

It’s not clear from the article whether robots.txt or ai.txt files was there and configured correctly, but this should be a reminder that we have a simple mitigation that should be used to shape how these crawlers can access web sites.

uniVersa: OpenAI AI crawler accessed customer data

uniVersa insurance companies experienced data protection incident. An AI crawler accessed customer data, including names, addresses, in some cases, bank details.

heise.de

Not enough evidence here to make a judgement call, but if you are being asked to handover and unlock your phone without any reason, that to me seems like the right time to brick it. As brittle as it seems right now, we do have some constitutional rights left in the US.

GrapheneOS duress PIN could land a man in prison

A US man is being prosecuted after allegedly using a GrapheneOS duress PIN to wipe his Pixel during a border search.

androidauthority.com

The U.S. Department of Labor recently announced $162 million in funding for Registered Apprenticeships to bridge a growing skills gap. The investment shows how strong #learning and #development (L&D) strategies can help employees grow while strengthening the organization.

How L&D and workforce readiness are connected

SHRM said “skills strategists” tend to align L&D to business priorities and create learning experiences that are relevant and accessible.

hrdive.com

AI tools may be making us more productive, but their also making us dumber and might be hiding a bigger problem. A June survey of 1,200 U.S. employees aged 25-64 found that almost 6 in 10 use AI to complete tasks without proper training. It's an efficiency boost and a growing 'learning debt'.

AI may conceal growing ‘learning debt’ for fast-changing roles

Close to 3 in 10 workers surveyed by TalentLMS said they’ve delivered work they couldn’t fully explain if asked how they did it.

hrdive.com

GRC has been increasingly becoming a leading pillar in cyber for job seekers. With the US government's restrictions on AI models, the UK is pushing its AI sovereignty creating new opportunities for those who are familiar with the UK's regulatory environment and laws.

Tech-xit? UK Steps Up Sovereignty Push Amid AI Strife

The US government's restrictions on Anthropic frontier models intensifies calls in the UK to reduce reliance on US tech, with cyber implications.

darkreading.com

This Glean report examines the negative impacts of overreliance on AI in the workplace and reveals that while AI aims to free up worker time, employees end up spending more time fixing AI-generated errors or producing work they're unhappy with.

Heavy AI users submit work they don’t understand, report finds

While the use of AI frees up time, Glean found, workers end up using that extra time to fix its mistakes — or simply ship products they can’t stand behind.

hrdive.com

Headlines say AI is stealing jobs, but the reality is more nuanced. While many roles will be automated, new ones are emerging at a breakneck pace. 73% of tech job postings now require at least one AI skill, up from just 15% two years ago. That means the demand for AI talent is skyrocketing.

AI skills now listed in 73% of tech job postings

Highly regulated industries working to shape their AI implementation plans outpace other industries in the search for talent, according to Dice.

hrdive.com

The US automaker hired over 350 veteran engineers, referred to internally as “gray beards”, over the past three years....[they] will lead quality reviews after the automation issues cost the company billions of dollars...while some workers will also help improve and train the AI systems.

Ford hired AI and sacked humans. It backfired badly

‘We didn’t pay as much attention as we should have to the experience of our most knowledgeable engineers,’ says automaker

the-independent.com

Curious about #software #security? You can pick up a copy of the Application Security Handbook for half off tomorrow (June 23)! Remember that, software security is a fundamental skill for modern developers and is most effective when it's considered from the start, not added as an afterthought.

Bild

This WIRED article reports that DHS and FBI are warning of 'anti-tech extremism' tied to AI backlash, citing over 1,000 pages of internal reports. What's a threat? "expressed/implied threat," "observation/surveillance," "photography," "testing/probing of security," and "attempted intrusion."

US Law Enforcement Warns of ‘Anti-Tech Extremism’ as AI Hatred Grows

As Americans stew over the looming risk of job-stealing AI and data centers in their back yards, the feds are raising the alarm about a new category of threat, documents obtained by WIRED show.

wired.com

Reading through this, my mind kept going to how PAM works, but then quickly realized that this is slightly different. Where PAM focuses on "who" can use privilege credentials a credential broker focuses on "how" they can be used by an NHI that cannot even see them. infisical.com/blog/credent...

Credential Brokering for AI Agents, Explained | Infisial

A simple guide to credential brokering for AI agents: protect against prompt injection by keeping credentials away from the agent.

infisical.com

Our software is a mix and match of 3rd parties, tools, and services that continue to expand the attack surface. If you need an example, CVE-2026-41940 was recently identified as a critical authentication bypass in cPanel & WHM (and WP Squared), with a CVSS score of 9.8.

CVE-2026-41940: cPanel & WHM Authentication Bypass

On April 28, 2026, a critical vulnerability affecting cPanel & WHM and WP Squared was announced. CVE-2026-41940 is an authentication bypass bug with a CVSS score of 9.8, and exploitation in the wild h...

rapid7.com

Attackers don't break in, they login. That's always been true (and it's still the dominant initial access vector), but today with the added acceleration of AI enabled attack tools/platforms the results are much different. thehackernews.com/2026/04/no-e...

No Exploit Needed: How Attackers Walk Through the Front Door via Identity-Based Attacks

Stolen credentials remain top breach vector as AI speeds phishing and testing, increasing ransomware and persistence risk.

thehackernews.com

"comment and control" = Injecting malicious instructions into PRs, leading an AI agent to execute them. Researchers found a way to steal API keys and access tokens from Claude Code, Gemini, and GitHub Copilot by using prompt injection in GitHub Actions. #aisecurity #devsecops #appsec

Anthropic, Google, Microsoft paid AI bug bounties – quietly

Exclusive: Researchers who found the flaws scored beer money bounties and warn the problem is probably pervasive

theregister.com

If you’re building your cybersecurity career, this Humble Bundle should be high on your list. Ethical hacking, blue‑team tactics, malware analysis, cloud security....all in one bundle. Best part, as always with Humble Bundle, you'll be supporting a good cause.

humblebundle.com