Discover
plain.txt
plain.txt
Author: ctrl:cyber
Subscribed: 14Played: 312Subscribe
Share
© ctrl:cyber
Description
Making sense of the stories shaping cybersecurity, privacy, AI, and everything in between.
plain.txt unpacks what matters as we navigate an increasingly complex digital landscape – for individuals, organisations, and society alike – cutting through noise to focus on what’s actually happening, and what it means in practice.
Hosted by Arjun Ramachandran and Jordan Wilson-Otto, bringing a practitioner-led perspective from their work at ctrl:cyber, an Australian cybersecurity firm helping organisations manage cyber risk across the full security lifecycle.
plain.txt unpacks what matters as we navigate an increasingly complex digital landscape – for individuals, organisations, and society alike – cutting through noise to focus on what’s actually happening, and what it means in practice.
Hosted by Arjun Ramachandran and Jordan Wilson-Otto, bringing a practitioner-led perspective from their work at ctrl:cyber, an Australian cybersecurity firm helping organisations manage cyber risk across the full security lifecycle.
162 Episodes
Reverse
Typically, when we're discussing the lessons to be learned about a cyber or privacy incident, we’re working backwards from a negative ruling.In this episode, we discuss the OAIC's favourable ruling about Qantas' mid-2025 cyber-related data breach that affected millions of customers.While the OAIC's investigation largely clears Qantas of wrongdoing, the report highlights plenty of lessons for organisations seeking to understand what the regulator expects when it comes to taking "reasonable steps" to protect personal information.LinksFull report into preliminary inquiries of Qantas (OAIC) https://www.oaic.gov.au/privacy/privacy-assessments-and-decisions/privacy-decisions/Investigation-i…OAIC media statement https://www.oaic.gov.au/news/media-centre/privacy-commissioner-completes-preliminary-inquiries-into…Media article at time of incident (ABC News) https://www.abc.net.au/news/2025-07-02/qantas-cyber-attack-significant-data-stolen/105484720Article about summary of OAIC findings (Mi3) https://www.mi-3.com.au/17-07-2026/qantas-cleared-privacy-law-breach-2025-data-incidentOAIC's Australian Clinical Labs ruling (OAIC) https://www.oaic.gov.au/news/media-centre/australian-clinical-labs-ordered-to-pay-penalties-in-rela…CreditsEditing and post-production by Martin Franklin (East Coast Studio) www.eastcoaststudio.com.au
*** This is part two of our two-part series on how frontier AI is reshaping cyber risk. See part one here: https://podcasts.apple.com/au/podcast/158-cyber-breakout-what-frontier-ai-means-for-cyber/id1616386… ***Over recent weeks a wave of disclosures have lit up the technology industry about the prospect of "rogue AI". OpenAI first revealed a frontier model had broken out of its sandbox during a test and hacked into Hugging Face's network. Shortly after, Anthropic surfaced three similar incidents from its own test logs. Meta and the UK AI Security Institute admitted similar observations, while a Melbourne man made the news after claiming his AI agent hacked his gym's booking system to move him up the waitlist by cancelling someone else's reservation.We discuss what this all means, including what the cyber security industry has made of these incidents and the lessons they are drawing about how to stay safe from autonomous AI. We also deconstruct the language and framing being used to describe these events - with phrases like "cheating" and "going rogue" investing AI with a sense of agency. The episode closes with a view of how these incidents much shape the broader public policy debate about proprietary vs open-weight models . LinksArticle about OpenAI / Hugging Face containment incident (TechCrunch) https://techcrunch.com/2026/07/10/openai-agent-escaped-sandbox-hacked-hugging-face/OpenAI disclosure https://openai.com/index/hugging-face-model-evaluation-security-incident/OpenAI's technical recounting of the incident at Black Hat https://www.youtube.com/watch?v=87DyyMV0kCYAnthropic disclosure https://www.anthropic.com/research/containment-disclosureUK AI Security Institute disclosure https://www.aisi.gov.ukArticle about gym incident (ABC News) https://www.abc.net.au/news/science/2026/andrew-ai-agent-gym-booking-hack/Marcus Hutchins on agentic AI attacks at Black Hat https://www.linkedin.com/posts/malwaretech_one-of-the-interesting-takeaways-from-black-share-749306…Open letter on open weight model access https://www.microsoft.com/en-us/corporate-responsibility/wp-content/uploads/2026/07/open-weight-mod…plain.txt Episode 158 — Part 1: Frontier AI and the pressure on cyber fundamentals https://podcasts.apple.com/au/podcast/this-week-in-digital-trust/id1616386683 CreditsEditing and post-production by Martin Franklin (East Coast Studio) www.eastcoaststudio.com.au
*** This is the first part of a two-part series on how frontier AI is reshaping cyber risk. ***In recent months the cyber security industry has been grappling with a key question: how do highly capable frontier AI models change the threat environment?In this episode we break this question down by looking at how AI has affected the cat and mouse game between attackers and defenders, and the operational reality facing most organisations. In turns out that, while the technologies behind this disruption are undoubtedly advanced, many of the lessons for businesses are pretty old school.In part two we'll explore the growing coverage of so-called "autonomous AI security incidents".LinksAnthropic - Project Glasswing overview https://www.anthropic.com/glasswingUK AI Security Institute independent evaluation of frontier AI cyber capabilities https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilitiesMozilla vulnerability findings using Mythos (Wired) https://www.wired.com/story/anthropic-claude-ai-model-mozilla-firefox-vulnerabilities/Why AI has not yet meant more hacks (Risky Business podcast) https://risky.bizAPRA letter to regulated entities on frontier AI and cyber risk https://www.apra.gov.au/news-and-publications/apra-letter-industry-artificial-intelligence-aiASIC letter to licensees and directors about cyber risk https://download.asic.gov.au/media/xhrf1w0e/26-092mr-open-letter-to-afs-licensees-and-market-participants.pdfTrump executive order https://www.cnbc.com/2026/06/02/trump-executive-order-ai.htmlCreditsEditing and post-production by Martin Franklin (East Coast Studio) www.eastcoaststudio.com.au
This week we check in on what we've previously called the "AI pendulum" - the swing between a pro-safety, pro-regulation instinct that marked AI conversations a couple of years ago to the hands-off, innovation-first mindset dominating the last 12 months.Recent events indicate the pendulum may be swinging back towards a more cautious and considered view of AI. The most striking incursion came from the Vatican, with Pope Leo XIV issuing "Magnifica Humanitas" a 42,000-word encyclical on the moral challenges of AI. We also explore the Trump Administration's recent executive orders and other moves to bring more government scrutiny to frontier models, and new research from the Tech Policy Design Institute that shows strong support by Australians for AI regulation.LinksFull encyclical — Magnifica Humanitas https://www.vatican.va/content/leo-xiv/en/encyclicals/documents/20260515-magnifica-humanitas.htmlArticle about AI encyclical (Time) https://time.com/article/2026/05/25/pope-leo-encyclical-ai-magnifica-humanitas/Analysis of AI encyclical (Brookings) https://www.brookings.edu/articles/understanding-pope-leos-ai-encyclical/Article about Trump executive order (CNBC) https://www.cnbc.com/2026/06/02/trump-executive-order-ai.htmlTPDi report — Earning Trust: Unlocking AI Adoption for Australians https://techpolicy.au/news/earning-trustTPDi — AI Agency Tool and 2025 Australia AI Agency Assessment https://techpolicy.auCreditsEditing and post-production by Martin Franklin (East Coast Studio) www.eastcoaststudio.com.au
In this episode we break down the OAIC's determination against Australia's largest rental technology platform ("RentTech") 2Apply.After a year-long investigation, Privacy Commissioner Carly Kind found that 2Apply collected personal information far beyond what was reasonably necessary, and via means deemed unfair. The ruling is another example of the Commissioner's more assertive enforcement posture.Noting the challenges in the housing market facing renters, we unpack how this determination might also matter more broadly to any situation where there's an imbalance of power. We also explore how the ruling applies the concept of "online choice architecture", in which the design of digital platforms can shape the decisions people make.LinksOAIC media release https://www.oaic.gov.au/news/media-centre/renttech-platforms-must-stop-unfair-and-excessive-personal-information-collection,-says-privacy-commissionerFull determination https://www.oaic.gov.au/__data/assets/pdf_file/0022/263254/IRE-Pty-Ltd-Privacy-2026-AICmr-24.pdfReporting on poor real estate agent cybersecurity (Josh Taylor, The Guardian) https://www.theguardian.com/australia-news/2026/feb/02/real-estate-agents-in-australia-using-apps-that-leave-millions-of-lease-documents-at-risk-digital-researcher-saysPrevious plain.txt interview with Commissioner Carly Kind https://podcasts.apple.com/au/podcast/151-trust-is-built-here-privacy-awareness-week-with/id16163866...CreditsEditing and post-production by Martin Franklin (East Coast Studio) www.eastcoaststudio.com.au








