Complete static archive of GigaTap articles about VPN, privacy, OPSEC, and security.
- Identity Checks Need Device Trust Too - Stolen sessions and compromised endpoints can make valid logins look safe. Device verification helps close that gap, but it is not a silver bullet.
- Internet Shutdowns Need a Plan Before the Cut - EFF’s guide is less about one magic app and more about preparation: radios, mesh tools, email fallbacks, satellite links, and the limits of each.
- Kimwolf arrest shows the cost of forgotten IoT devices - Canadian authorities arrested an Ottawa man accused of operating Kimwolf, an IoT botnet tied to massive DDoS attacks. The case is still alleged, but the ri
- Laravel Lang attack shows how package tags can betray trust - Snyk says hundreds of historical Packagist versions for Laravel localization packages were republished with credential-stealing malware. The key failure wa
- Meta reach blocks put rights speech in the dark - Access Now says Meta blocked human rights accounts from reaching audiences in Saudi Arabia and the UAE. The key issue is not only the block, but the lack o
- Microsoft Security’s May update points at AI-era control - Microsoft’s May 2026 security roundup signals a continued push toward visibility, control, and protection across expanding cloud, SaaS, and AI-driven envir
- Mini Shai-Hulud hits npm and CI trust paths - A fresh Mini Shai-Hulud campaign compromised npm packages, GitHub Actions, and PyPI entries, turning maintainer trust and CI secrets into the attack surfac
- Mullvad Exit IP Fingerprinting: Small Signal, Real Linkability - Mullvad disclosed a VPN exit IP assignment issue that may let sites correlate sessions across servers without exposing identity.
- OmniRoute looks useful. Review it like infrastructure - OmniRoute promises one endpoint for many AI providers and coding tools. Before adopting it, review deployment, keys, fallback, compression, and failure mod
- SAST, SCA, DAST: Know What Each Tool Can Actually See - SAST, SCA, and DAST are not interchangeable AppSec tools. Each sees a different layer of software risk: proprietary code, dependencies, and runtime behavio
- Shai-Hulud Shows the Weak Link: Maintainer Trust - Sonatype says a new npm compromise wave abused trusted maintainer access and install-time hooks. The risk is not just bad packages, but stolen CI/CD secret
- SonicWall MFA bypass shows the patch gap - Attackers reportedly bypassed MFA on SonicWall Gen6 SSL-VPN devices where firmware was updated but required LDAP remediation was not completed.
- thesvg: a useful icon package with a clear trust boundary - thesvg offers thousands of brand SVG icons for modern frontend stacks. The useful part is obvious; the package and licensing checks still matter.
- Tor Browser 15.0.14: a small update worth installing - Tor Browser 15.0.14 brings Firefox ESR and GeckoView updates plus security backports. It is a maintenance release, but users should patch promptly.
- AI Wants a World Model Now - AI companies are looking beyond fluent chatbots toward systems that can model the physical world. The promise is real, but so are the limits.
- AI-written code is becoming normal. Review is the bottleneck - Anthropic’s developer event showed how far AI coding has moved from autocomplete to delegation. The hard question is whether teams can still review what th
- Canvas breach turns platform trust into a school outage problem - A Canvas extortion incident disrupted schools during exams. The confirmed data categories are narrower than attacker claims, but the operational risk is al
- CISA GitHub Leak Shows the Cost of Exposed Build Secrets - A contractor-maintained public repository reportedly exposed privileged AWS GovCloud credentials and CISA internal system details. The known facts are seri
- Compromised npm packages put CI/CD secrets at risk - Microsoft says malicious @antv npm packages targeted GitHub Actions and cloud credentials through install-time execution.
- Copy.Fail Shows Why “Local” Linux Bugs Are Not Local - Copy.Fail is reported as a Linux kernel privilege escalation with a working PoC. The risk is not just root on one box, but shared kernels across containers
- CVEScannerV2: Nmap findings need verification - CVEScannerV2 maps Nmap-discovered services to probable vulnerability leads. Useful for triage, but its output should be verified before any security conclu
- Grafana breach shows how one CI token keeps access alive - Grafana says attackers downloaded code and internal GitHub data after the TanStack supply-chain attack. Production systems and Grafana Cloud were not affec
- Local Government Cyber Risk Is Now a Data-Rights Fight - CDT’s House testimony frames state and local cybersecurity as a privacy and public trust issue, especially if federal support weakens.
- Microsoft’s agent safety tools move testing into CI - RAMPART and Clarity show how agent safety is becoming an engineering workflow: test scenarios, design checks, and reproducible incident handling.