The balance of power is shifting because attacker capability is getting cheap. That changes more than how defenders should secure systems. It changes how defenders should learn. The cat-and-mouse game has always favored whoever learns faster, and attackers have just made a sudden advance.
A security team that reads occasional reports is competing against automated discovery, automated testing, and operators willing to run the same playbook until a path opens. That pressure is not only spreading to smaller targets; it bears down harder on the organizations that were always worth the trouble, which is why periodic catch-up no longer works even for well-resourced teams. The attacker's advantage is not brilliance. It is that the watching never stops. If attackers get tireless automation, defenders need tireless analysis.
Our newsroom is built around that problem. The experts who steer it have spent their careers managing data at scale, and securing enterprise cloud environments for some of the largest companies in the world — and getting attacked in every possible way. They set the direction: what matters, what is credible, what deserves caution, and what kind of advice would help a real operator. AI systems handle the patient work: watching signals, gathering context, comparing sources, and preparing structured material for review.
We use agentic AI to infer trends in knowledge bases, like the one powering this newsroom. But instead of generating derivative AI slop that summarizes secondhand headlines about best practices, our reporter agents constantly use Charlie Munger's inversion technique: how could we screw this up? How could this go wrong? What failure modes actually matter? Best-practice handbooks already exist. What changes as the landscape shifts is the roadmap of new ways things can go wrong — and the old, known ways that are now more common, or more dangerous.
Papyrus is the CMS and workflow system underneath, but the idea is bigger than the software: an automated newsroom that runs around the clock — monitoring security research, incident reports, and newly disclosed vulnerabilities, building a structured, semantic knowledge base from what it reads, and watching how threats trend over time. A defender-side intelligence operation should accumulate memory, preserve evidence, and turn continuous research into decisions a human can inspect.
The goal is not to publish more words. It is to keep learning between articles. Each source, trend, entity, and editorial decision should make the next cycle smarter. The newsroom should know what it has already seen, what it trusts, where the gaps are, and which checks have become urgent. The newsroom is a defensive system for turning noise into checks.
AI is useful here precisely because it is constrained. It can maintain long-running research tracks, work through repetitive comparisons, notice weak signals, and prepare evidence for human judgment. It can be tireless without being the authority.
What to check now: ask whether your own security learning has the persistence you now assume attackers have. If AI changed your threat model, it probably needs to change your intelligence workflow too.
What to check now: separate expert judgment from repetitive labor. Humans decide priority, credibility, and action. Automation maintains memory, finds relationships, compares signals, and prepares the next useful question.
This publication is one working example of that adjustment: AI not as a shortcut around expertise, but as a way to give expertise a continuous operating surface — and to keep the resulting advice grounded, current, and easy to act on. Use AI on your side: to find your risks before attackers do, and to stay current on threat intelligence instead of catching up after the fact.