Please turn JavaScript on
Attomus icon

Attomus

Welcome to Attomus’s blog - Cybersecurity, Advanced technology and Security discussions from around the globe.

Click on “Follow” and decide if you want to get news from Attomus via RSS, as email newsletter, via mobile or on your personal news page.

Subscription to Attomus comes without risk as you can unsubscribe instantly at any time.

You can also filter the feed to your needs via topics and keywords so that you only receive the news from Attomus which you are really interested in. Click on the blue “Filter” button below to get started.

Title: Attomus

Publisher:  attomus
Message frequency:  0.1 / day

Message History

Generative AI is already part of day-to-day business. Staff use it to summarise meetings, draft documents, write code, analyse data, speed up research, and automate routine tasks. Some of that use is sanctioned. Some of it is not.

That is the problem with shadow AI. It gives employees a useful shortcut, but it can also move client information, source code, personal dat...


Read full story

For years, security teams were taught to think in terms of edges, boundaries, and the network perimeter. That made sense when most users, systems, and data sat inside infrastructure the organisation owned and controlled. It makes far less sense now. Staff work remotely, applications live across cloud platforms, suppliers plug directly into shared systems, and automation now a...


Read full story

There is a question that comes up constantly in Android security engineering, usually phrased something along the lines of: “how do I prove to my server that this AES key is hardware-backed?” The common answers to this question are often wrong in that they make you think you have a guarantee that you do not have.

The short answer is: you cannot prove an AES key...


Read full story

Authenticator apps look simple. They generate six-digit codes. The cryptographic building blocks are mature with a protocol from an IETF RFC from 2011. The core algorithm is not especially difficult to implement.

The genuinely hard part is not the TOTP mathematics. It is a design tension built into the product category itself: one every authent...


Read full story
The Cybersecurity Paradox: Investing in What Organisations Hope to Never Need

A peculiar tension plays out in boardrooms across every sector: cybersecurity represents one of the most critical investments an organisation can make, yet it delivers none of the excitement that typically drives corporate spending decisions. This paradox has become a defining challenge for modern c...


Read full story