- This week: Your reputation depends on your suppliers, your AI chatbot may be your weakest security link, and US Gov tells Anthropic to block access to its latest AI model only days after its release.
- This week: Three stories from three different regulators.
- This week in 10 seconds: Your suppliers are your weak point, your staff are using unapproved AI tools, and don’t worry about advanced AI threats if you aren’t even doing the basics right.
- This week: The kids in a school photo end up in deepfake images. People are giving AI their bank details. And regulators remind us that the basics still matter.
- This week: A State body loses € 2.5 million through a phishing scam, kids defeat Age Verification with a marker, and we struggle to prove AI value because we're measuring the wrong thing.
- This week: Regulators struggle to keep up with the latest AI developments, an Irish bank is fined for getting the basics wrong, and it’s time to start planning for WHEN attackers have broken in.
- This week: An AI agent deleted a production database in seconds, “smart” AI can also be pretty “stupid”, and ransomware gangs may now target ‘little old you’ just because of the type of ‘security door
- This week: Europe launches a new DPIA template. Can your staff hand out door keys to anyone who asks? And your Governance Model is no match for Autonomous AI.
- This week: The world's fastest hacker may now be AI. Your CRM system may be a thing of the past. And confirmation that your AI chats are not confidential or legally-privileged.
- This week: €19 million shows the old scams still work, another bailout causes another moral hazard, and OpenAI says sayonara to Sora.
- This week: One compromised password compromises 200,000 devices. One compromised AI chatbot compromises 700 organisations. And one helpful AI agent compromises Meta's internal systems.
- This week: A cyber attack on Stryker is rumoured to have wiped 200,000 devices. And two stories to demonstrate why 'smart' devices are really surveillance devices.
- This week: LinkedIn Verification is a verified privacy disaster; The EU Parliament blocks the AI barn door after the horse has bolted; And how one error cost a crypto firm $120 million.
- This week: An Outlook add-in that opened the door for an attacker, Google's insights into how attackers are really using AI, and a viral post on how AI is a major risk to our livelihoods.
- This week: Anti-virus software becomes the virus, a parent's guide to Generative AI is a great guide for all of us, and what the arrival of ads on ChatGPT could mean for users.
- This week: Apple chooses Google Gemini for Apple Siri. Browser extensions are an open door for attackers. And GDPR hasn't gone away, you know.
- This week: Snapchat buys its way out of a court case, AI may not be impacting entry-level jobs (yet), and financial services firms remain cautious about AI adoption.
- This week: I seem to have written 'Cyber 3-2-1: The AI Edition'. In truth, it's simply because the 3 stories that caught my attention this week all happen to relate to AI risk.
- This week: Why QR Codes should be called RQ Codes, why you need to think about browser extensions, and why you can't insure your way out of doing the real work.
- This week: In the last Cyber 3-2-1 of 2025, I look back over the most popular topics of the newsletter this year.
Cyber 3-2-1 moved to Substack in September 2025.
Issues from before this date are available in a separate archive.