Complete static archive of GigaTap articles about VPN, privacy, OPSEC, and security.
- Bill C-22 makes VPN metadata a security issue - Tailscale warns that Canada’s Bill C-22 could push secure services to collect more data, retain more metadata, and build new access paths.
- CDT Submits Comments: Teen Chatbots Need Rights, Not Bans - CDT’s filing offers a practical lens for governing teen chatbot access without reducing minors to a risk category.
- CERT-In’s 12-Hour Patch Window Is a Warning About Exposure - CERT-In is urging faster remediation for exploited internet-facing flaws as AI-assisted attack workflows compress defender response time.
- Charter Breach Claim Exposes a SaaS Identity Weak Spot - Charter confirms a security incident after a ShinyHunters extortion threat, but disputes claims that sensitive customer and CPNI data were stolen.
- Docker’s Copy Fail fix is about kernel surface, not a breach - Docker says CVE-2026-31431 does not compromise its infrastructure, but older Docker Engine profiles exposed the AF_ALG socket surface used by the exploit p
- First VPN takedown exposes the weak side of criminal anonymity - Law enforcement says First VPN was used by at least 25 ransomware gangs. The lesson is provider trust, seized data, and criminal-market dependency risk.
- GitHub Code Quality Gets an API for Repository Rollout - GitHub’s new public preview API lets teams enable, inspect, and configure Code Quality per repository. The real value is scale: inventory, drift detection,
- Glassworm Shows Why Developers Are the New Supply Chain Target - CrowdStrike, Google, and Shadowserver disrupted Glassworm infrastructure, but the deeper lesson is about developer accounts, extensions, ads, and release t
- Google and NVIDIA Push AI Builders Toward the Stack - The 100,000-member milestone is less important than the roadmap: more structured learning around LLM optimization, GPU analytics, and agentic AI.
- Grafana’s Missed Token Shows the Real CI/CD Risk - Grafana says one GitHub workflow token missed during post-TanStack incident response allowed attackers to access private repositories.
- IntelliJ IDEA 2026.2 EAP tests AI without dropping control - JetBrains opened the IntelliJ IDEA 2026.2 EAP with deeper agent hooks, better debugging visibility, dependency completion, migration tooling, and early pla
- Kubernetes CVEs will look louder because the records were wrong - Kubernetes is updating old CVE records to show several architectural risks remain unfixed across all versions. Scanner findings may increase, but the expos
- Linux gets age-check carve-outs as state laws meet reality - California and Colorado are revising age-verification rules so open-source operating systems, repositories, and container platforms are not treated like ce
- Malicious npm package went after Claude workspace files - A reported npm package used install-time execution to upload files from Claude’s local user-data directory to GitHub, showing how AI workspaces are becomin
- Old Nexus repositories are now supply-chain risk - Sonatype warns that older Nexus Repository deployments, especially OrientDB-era systems, face serious CVE exposure. The fix is not just patching; it is mod
- OSV’s 157 Withdrawn Malware Reports Show a CI/CD Risk - Automated false positives hit npm and PyPI packages, then flowed into OSV-consuming tools. The issue is not just bad data, but enforcement built on fast-mo
- Plate Readers Are Becoming School Residency Tools - EFF’s ALPR audit-log analysis shows police using Flock Safety data for school residency checks and other low-level matters, not only serious crime.
- Ruby 4.0.5 Fixes a Runtime Memory Safety Bug - Ruby 4.0.5 is a focused maintenance release: one CVE fix, one build regression fix, and a stable-release cadence teams can plan around.
- SharePoint RCE patch: low privilege is the real risk - Microsoft patched CVE-2026-45659, a SharePoint Server RCE reachable by authenticated Site Members. No active exploitation is confirmed, but the patch deser
- Supply chain attacks punish long-lived secrets - AWS’s latest guidance is a reminder that package attacks become worse when CI/CD and developer environments expose durable credentials.
- TanStack KEV entry turns npm trust into the real risk - CVE-2026-45321 is thin on technical detail but clear on impact: malicious npm publication under trusted identity and credential-stealing risk.
- AI agents expose the stack you avoided fixing - Elastic’s checklist is a useful reminder: agent failures often start in data quality, context retrieval, legacy integration, monitoring, and governance.
- AI coding agents now need a governed supply chain - JFrog’s OpenCode integration points to a real shift: agents that install packages, publish artifacts, and add MCP servers need deterministic trust paths, n
- Akamai Signals in Auth0: Edge Risk Meets Login Control - Auth0’s Akamai Supplemental Signals support lets teams use edge bot and account-risk telemetry inside identity flows for MFA, registration denial, and more