Cyber is having a moment
Across 21 major software companies, including Apple, AWS, Microsoft, and Google:
- Reported critical vulnerabilities never cleared 100 per month in four years
- Since spring they've jumped to over 600 per month
Charts of the Week: https://t.co/4dgNGwG5Nx
Ok whats the alternative, then? In today’s society its nearly impossible to live like that, unless you’re willing to move to an isolated island or into the woods and cut yourself off from technology and society. Including things we take for granted..
The reality is almost anyone can be traced if someone really wants to find them, whether you’re careful or not.
The uncomfortable truth is most type 2 founders don’t catch up.
You only win from behind if the problem is simple enough to brute-force and you’ve been actually in the trenches for a while. But in complex markets, the founder who already knows or is the user, buyer, and understands the pain intimately has an unfair advantage.
I was in the same camp and really believed in the power of principled builders in the space to takes us to that future. But eventually reality hits hard, markets and power structures were always gonna change this space toward extraction unfortunately. I just refused to see it earlier
>Non technical teams are now shipping production code
looking forward to all the upcoming data leaks that put each Coinbase user at risk.
oh and btw Brian, did you coin your amazing content here on Base already??
@pcaversaccio Lol. this supply chain risks are becoming a plague. I’ve never really been sold on checkmarx (and the likes). These tools end up used for compliance optics more than real appsec capabilities
Now you can finally vibe-secure the app you vibe-coded!
> AI writes the code
> AI reviews the code
> AI secures it
Humans cheering from the sidelines 😎
Introducing Claude Code Security, now in limited research preview.
It scans codebases for vulnerabilities and suggests targeted software patches for human review, allowing teams to find and fix issues that traditional tools often miss.
Learn more: https://t.co/n4SZ9EIklG
AI can make work faster, but a fear is that relying on it may make it harder to learn new skills on the job.
We ran an experiment with software engineers to learn more. Coding with AI led to a decrease in mastery—but this depended on how people used it.
https://t.co/lbxgP11I4I
New Anthropic Research: Disempowerment patterns in real-world AI assistant interactions.
As AI becomes embedded in daily life, one risk is it can distort rather than inform—shaping beliefs, values, or actions in ways users may later regret.
Read more: https://t.co/gyMB2AtOuq
@pcaversaccio I’ve been flagging this for a while, not about end users but builders relying on hot wallets as a relay when designing payment processing workflows.
The Sha1-Hulud attack campaign is another reminder that supply-chain risk is really about the maintainers and their workflows!
Even with SBOMs, SCA and layers of CI/CD guardrails, these kind of attacks still slip through and package managers naturally create a global blast radius.
It might be time to rethink both maintainer dependency-publishing processes and the package manager trust model with stronger zero-trust mechanisms.
🚨 New Shai-Hulud-style npm attack hitting 25k+ repos and growing fast.
Devs & CI/CD exposed via malicious preinstall. Wiz Research has detection + mitigation.
Details: https://t.co/vmAdV6kwtI
This weekend marks a major milestone in payments: the coexistence period between MT and ISO 20022 message standards ends. From 22 November 2025, all FI-to-FI payment instruction messages will be delivered only in ISO 20022 format.
ISO 20022 brings richer data, better compliance, and improved automation - but preparation is key to avoid NAK’ed messages and operational delays.
Be prepared for the weekend.
All FIN and FINplus Users are strongly advised not to send any message from Saturday 15:00 GMT till Sunday 05:00 GMT and to check Swift Knowledge Base for full details, troubleshooting guides, and contingency processing information.
Find resources and support here: https://t.co/toQEO4G1gp
👉 Questions? Contact your account manager or visit the Swift KB articles for detailed guidance.
#ISO20022
Coinbase launched UK savings accounts, 3.75% AER. Daily interest. Instant access.
FSCS protected to £85k via ClearBank.
Some thoughts...
Not the best market rate
- Chip's doing 4.35%, S
- Some easy-access accounts hit 4.5%.
- But better than most banks
But the rate isn't the story.
The story is what happens when your savings account has a "swap to crypto" button sitting right next to your balance.
---
Their ROI math is different to Fintech or Banks
Coinbase acquires a savings customer, monetizes through trading fees the moment they hit that swap button.
---
The goal is to be Revolut not Binance
Keith Grose, Coinbase UK CEO: "Our aim is building the UK's number 1 financial app."
That's the entire strategy in one sentence.
Just as it's Coinbase vs Robinhood in the US, it could be Coinbase vs Revolut in Europe.
---
Customer acquisition dynamics flip.
Every savings customer is a potential trading customer.
The CAC you pay to acquire someone for 3.75% savings gets recovered the first time they buy £100 of Bitcoin.
---
Banks face a choice.
Barclays, NatWest, HSBC can all match or beat 3.75%.
But none let you move GBP → BTC in the same app.
The infrastructure exists (ClearBank, Fireblocks, Circle).
The regulatory clarity is improving. Do they add crypto rails or watch Coinbase eat their lunch on the next generation of customers?
---
Everyone's converging on the same product: an app where GBP, BTC, and USDC are just different denominations of money.
In Europe, Santander and BBVA offer buy/sell/hold crypto
How long until the UK banks catch up?
If 70% of customers prefer their bank to offer it.
The time is now or never.
Picture this: you compromise the account of a NPM developer whose packages are downloaded more than 2 billion times per week. You could have unfettered access to millions of developer workstations. Untold riches await you. The world is your oyster.
You profit less than 50 USD.
Main takeaway from the Tornado Cash verdict: using new technologies like blockchains and smart contracts to build a money transfer business won't shield you from the money laundering statutes. The law is technologically neutral.