Complete static archive of GigaTap articles about VPN, privacy, OPSEC, and security.
- Access Now’s NSO filing is about more than WhatsApp - Access Now wants the Ninth Circuit to preserve an injunction against NSO targeting WhatsApp users. The practical risk sits at the device layer.
- Agent CLIs Are Now a Supply Chain Check - JFrog’s agent-belt tests real coding-agent CLIs against real workflows, giving teams a way to catch behavior drift before it reaches users.
- Agentic coding needs workflow context - GitLab’s argument is practical: coding agents are useful only when they can see the issues, merge requests, pipelines, and policies that decide what ships.
- AI Coding Needs Supply Chain Controls at Commit Time - Relay Network’s Snyk case study shows a practical pattern for AI coding: approved tools, early security feedback, and pre-commit checks before risk reaches
- AI’s Find Out Stage Is an Access-Control Problem - Stack Overflow’s HumanX note points to the real production test for AI agents: governed data, supply chain visibility, orchestration, and identity attribut
- AWS Network Firewall gets a cleaner policy lever - AWS’s URL and domain category filtering can reduce brittle domain-list work, but teams still need clear scope, exception handling, and logging.
- Azure Files Entra-Only identities shift the trust boundary - Azure Files can now use Entra-Only identities for SMB. The gain is less hybrid identity infrastructure; the risk moves into Entra governance, ACLs, and end
- Azure Fleet Manager Gets Cross-Cluster Networking - Microsoft’s Cilium-based cross-cluster networking can reduce AKS fleet complexity, but teams still need to test policy, observability, failover, and data b
- Bitcoin Miners Face an AI Capacity Squeeze - Fidelity’s signal is not a Bitcoin security panic. It is an operational warning: AI may now compete with bitcoin miners for power, sites, and capital.
- Bitcoin Optech #407: the Core Lightning crash risk to check - Bitcoin Optech #407 flags a responsibly disclosed Core Lightning denial-of-service bug and several infrastructure changes operators should verify.
- Building cloud platforms: the checks that matter - CNCF’s platform design is useful because it focuses on drift, artifact trust, and operational evidence — not because Kubernetes alone solves delivery risk.
- Chrome Beta 149: A Browser Security Checkpoint - Chrome Beta 149 for Android is out. No CVE claim is made in the source, but teams should review linked changes before stable rollout.
- Claude Opus 4.8 on GitLab: What to Check First - Claude Opus 4.8 is now available in GitLab Duo Agent Platform. The useful question is not hype; it is how teams verify long-running agent work without loos
- EPIC Coalition Targets ALPR Creep With a Tolling-Only Line - EPIC and more than 40 groups are urging Congress to limit automatic license plate readers to tolling. The practical issue is purpose control, not just data
- EPIC’s Roblox FTC Call Targets Design Risk - EPIC and child safety groups asked the FTC to investigate Roblox. The operational issue is design risk: engagement loops, currency flows, and child chat ex
- F-Droid’s Week 20 Update Shows Where Mobile Security Breaks - F-Droid’s latest news highlights a lost signing key, a new app ID, and faster CoMaps map updates. The practical lesson is to check update paths, permission
- GCHQ’s Russia warning is an operations problem - GCHQ’s warning is not a new CVE. It is a security advisory for teams that depend on UK infrastructure, suppliers, and response paths.
- Glean’s $300M signal: AI search is now a budget tool - Glean’s reported top line shows enterprise AI search moving from productivity pitch to budget-control claim. That raises harder checks for security, privac
- How Pope Leo XIV frames AI as non-neutral infrastructure - MIT Technology Review highlights one line from Magnifica Humanitas that technologists should not dodge: technology is never neutral.
- MariaDB Server 12.3 LTS: Check Before You Move - MariaDB Server 12.3 LTS is available, with 12.3.2 as the first GA. Treat it as an operations trigger: review notes, test paths, and avoid upgrade assumptio
- OpenViking makes agent memory an ops problem - OpenViking is an open-source context database for AI agents. The useful question is not hype; it is what teams must check before trusting agent memory, res
- Physical integrity is the hard part of permissionless TEEs - TEE attestation does not settle the trust question for decentralized networks. Physical integrity, verifier opacity, and operator control define the real r
- Pwn2Own Berlin shows AI tooling is now security-critical - Day One results from Pwn2Own Berlin 2026 highlight exploit work against AI tooling, local inference stacks, NVIDIA products, browsers, and OS privilege bou
- Redis May recap: what’s new, and what to verify - Redis published its May 2026 update recap. Treat it as a release-triage signal: check what changed, what affects your stack, and what not to overclaim.