Complete static archive of GigaTap articles about VPN, privacy, OPSEC, and security.
- AWS KY3P report gives customers a cleaner risk evidence path - AWS has completed its S&P Global KY3P assessment. The report can help customers reduce duplicated supplier due diligence, but it does not replace their own
- AWS Managed AD gets API-driven identity controls - AWS now lets teams manage AWS Managed Microsoft AD users and groups through Directory Service Data APIs. The useful shift is not just automation, but faste
- Chinese PhaaS moves past password theft - GTIG says Chinese-language phishing services are maturing into real-time MFA interception platforms, making OTP-based defenses a weaker line.
- ChromeOS LTS gets a quiet but serious security update - ChromeOS LTS-144 version 144.0.7559.252 fixes multiple high-severity flaws across Navigation, Blink, Viz, CSS, Media, Extensions, Web Speech, and WebCodecs
- Docker’s Gordon brings AI into the container workflow - Docker’s new Gordon agent can inspect logs, Compose files, images, and local Docker state, then propose approved fixes. The value is context; the risk is h
- Drupal SQL Injection Bug Is Already Being Probed - CVE-2026-9082 affects PostgreSQL-backed Drupal sites. Exploit attempts are now being detected, making patch status and database backend checks urgent.
- EOL Dependencies Need Their Own Risk View - Sonatype’s HeroDevs dashboard points to a real supply-chain gap: unsupported dependencies are not just old packages, and CVE workflows alone may not resolv
- GitHub’s probe puts repository trust back in focus - GitHub said it was investigating unauthorized access to internal repositories. The current facts are narrow, but the operational lesson is broad: repositor
- Kali365 Shows the New MFA Phishing Problem - The FBI says Kali365 abuses Microsoft’s device code login flow to hijack Microsoft 365 sessions. The risk is not just stolen passwords. It is users authori
- Kenya’s protest rights face continental scrutiny - ARTICLE 19 used an African Commission session to raise concerns over Kenya’s digital freedom, media freedom, and the right to peaceful assembly.
- Laravel Lang Backdoor: Check Composer Before Secrets Leak - Socket reports a compromise in third-party Laravel Lang packages, with malicious Composer autoload code able to execute and harvest cloud, CI/CD, and devel
- Laravel-Lang compromise shows the risk inside release tags - A reported compromise of Laravel-Lang PHP packages used rewritten git tags and Composer autoload behavior to run a cross-platform credential stealer.
- Packagist attack shows a blind spot in mixed PHP builds - Eight Packagist packages were reportedly modified to run a Linux binary via GitHub Releases, with malicious code placed in package.json rather than compose
- Pixel TPU access gets a real developer workflow - Google’s Tensor ML SDK beta gives developers a LiteRT path to run supported ML and GenAI models on Pixel 10 TPUs, with real promise and clear limits.
- TeamPCP shows how trusted developer updates fail - A reported TeamPCP wave hit VS Code, PyPI, and npm paths in one week. The lesson is release-level trust, not publisher badges.
- TrapDoor Shows How Package Malware Hunts Developer Secrets - Socket reports an active cross-registry campaign using npm, PyPI, and Crates.io packages to steal wallets, tokens, SSH keys, cloud credentials, and develop
- Underminr Shows a CDN Trust Gap Defenders Can’t Ignore - A reported CDN routing weakness can make malicious traffic look like it is going to trusted domains. The risk is not just domain fronting. It is broken cor
- A Judge, a Trump Lawsuit, and a Recusal Question - FPF says a Florida judge ruled for Trump in a Pulitzer-related defamation case while seeking a federal judgeship from Trump’s administration.
- AI-assisted macOS exploit work is the real signal - A short Schneier item claims Anthropic’s Mythos model was used in work on a macOS kernel memory corruption exploit. The useful takeaway is not panic, but a
- AI Security Risk Is Mostly Governance Failure - Zapier’s AI security checklist points to a practical problem: unmanaged tools, sensitive uploads, and weak account controls create more immediate risk than
- Fast16 and the old lesson in destructive malware - Risky Business #835 points to a useful warning: destructive malware is not only a current incident problem. It is also a history problem, and the timeline
- Fuel Tank Gauges Are a Quiet Infrastructure Risk - Internet-exposed automatic tank gauge systems can give attackers a low-cost path into fuel operations. The risk is less about drama and more about weak acc
- Gaming Security Is Bigger Than Player Accounts - Microsoft’s gaming security framing shows why platforms, studios, commerce, identity, player safety, and unreleased IP must be treated as one connected ris
- GitHub’s poisoned extension incident shows a quiet supply-chain gap - GitHub says a malicious third-party VS Code extension compromised an employee device and led to exfiltration of internal repositories. Customer repository