
It's Time We Talked About AI and Software Security
The article argues that major corporate data breaches are typically caused by basic social engineering and outdated software vulnerabilities rather than sophisticated nation-state attacks. It highlights how enterprise systems often remain secure only because attackers prioritize higher-value targets, creating a false sense of security known as the 'Turkey Problem.' Recent high-profile incidents at Marks & Spencer, Jaguar Land Rover, and Change Healthcare demonstrate that simple failures like unpatched portals and lack of two-factor authentication can lead to billions in economic losses.
- ▪Companies often publicly attribute data breaches to nation-state actors to protect reputations, while post-mortems reveal simple social engineering tactics like phone impersonation.
- ▪Enterprise software security frequently relies on the economic constraint that attackers prefer higher-value sovereign targets over ordinary corporate infrastructure.
- ▪Marks & Spencer lost £300 million in profit after attackers used a phone call to reset credentials and access an unsegmented network.
- ▪Jaguar Land Rover's production halt cost the British economy an estimated £1.9 billion due to stale Jira credentials and a lack of network segmentation.
- ▪Change Healthcare's collapse, costing UnitedHealth $2.45 billion, was caused by a single external Citrix portal lacking two-factor authentication.
Hacker News (AI / LLM) files mainly under ai. We currently carry 6,555 of its stories.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | Hacker News (AI / LLM) |
| Canonical URL | https://deadneurons.substack.com/p/its-time-we-talked-about-ai-and-software |
| Publication time | Sat, 26 Sep 2026 20:46:14 +0000 |
| Retrieval time | 2026-09-26T20:55:40.253Z |
| Last seen | 2026-09-26T20:55:40.253Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | btr770ZCb2mR · 1 stories |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
It’s Time We Talked About AI and Software SecurityNick RogersSep 26, 2026ShareIf you run a public company and someone steals your customer database, the standard public relations playbook requires you to announce two things. First, you announce that your organisation was targeted by a sophisticated, highly coordinated nation-state adversary. Second, you announce that they used an unprecedented zero-day exploit.This framing is immensely comforting to everyone involved. It suggests your engineers fought valiantly against foreign intelligence operatives before being overwhelmed by classified cyber weapons.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at Hacker News (AI / LLM).