Complete static archive of GigaTap articles about VPN, privacy, OPSEC, and security.
- Patch Tuesday gets quieter, but the patch race speeds up - Microsoft’s May 2026 update has no cited zero-days, but 118 fixes and broader vendor patch surges show how AI-assisted bug discovery may be changing securi
- Secure file sharing is only useful if it can be proven - Many businesses claim secure file sharing. The real test is whether access, encryption, link expiry, logging, and offboarding hold up in daily work.
- Snyk’s AI Security Push Moves Closer to the Code - Snyk is betting that AI-generated code needs security controls inside developer workflows, backed by partners who can implement governance at enterprise sc
- Storm-2949 shows how identity becomes the cloud perimeter - Microsoft says Storm-2949 used stolen credentials to turn identity compromise into a cloud-wide breach without malware. The lesson is narrow but important:
- The ACLU’s case for suing federal agents - The ACLU wants Congress to restore legal paths for people to sue federal officers and agencies when constitutional rights are allegedly violated.
- The web’s JavaScript trust gap - Mozilla’s new post points at a hard problem for sensitive web apps: browsers can isolate code, but users still have to trust what the server just delivered
- RightsCon Cancellation: A Lost Coordination Layer - RightsCon’s cancellation matters not only as an event loss, but as a blow to digital rights coordination infrastructure.
- AntV npm packages hit by maintainer account compromise - Snyk reports 300+ malicious package versions across the AntV ecosystem. The useful question is whether your builds installed them and what secrets were exp
- Boston Metal’s critical-metals bet is about survival - The green-steel startup raised $75 million after delays in Brazil. Its near-term test is whether higher-value metals can prove the technology before steel
- Evidence needs an archive, not just a feed - OpenArchive’s Save app shows why mobile evidence needs privacy, provenance, redundancy, and community control before platforms or devices fail.
- Fox Tempest shows why signed malware still matters - Microsoft says Fox Tempest ran a malware-signing service used by other criminal groups. The lesson is narrow but important: signatures help trust, but they
- Microsoft’s accountability signal for cloud and AI vendors - EFF points to Microsoft’s Israel controversy as a sign that human rights commitments need consequences, not just review paperwork.
- Musk Lost Against OpenAI. The Governance Fight Did Not End - Musk’s lawsuit over OpenAI’s nonprofit founding commitments failed, but the result should be read narrowly unless the court record says more.
- Musk lost to OpenAI. The governance question did not - MIT Technology Review says Musk lost his suit over OpenAI’s nonprofit status. The ruling narrows one legal fight, but the trust model around AI labs remain
- Open Source Security Needs More Than Code - An OpenSSF podcast episode shows why public learning, documentation, and community work are real supply chain security contributions.
- Policy as code works best before cloud changes ship - AWS’s guidance on pattern-based policy as code shows how teams can catch routine cloud governance failures before deployment, without pretending pre-deploy
- Privacy Should Not Be Set in a Product Meeting - EFF’s latest note is a reminder that privacy risk is often decided before users see the product. The issue is bigger than one Meta feature.
- Tor tests crypto funding for internet freedom tools - Tor and Funding the Commons launched a crypto-native matching campaign for privacy, anti-censorship, and public-interest infrastructure projects.
- AI agents need architecture, not bigger prompts - Google’s Agent Bake-Off lessons point to a practical pattern: split agents into scoped parts, design for replacement, use protocols, and keep deterministic
- AI coding agents need boundaries, not just prompts - Docker’s warning is vendor-framed, but the core issue is real: coding agents often inherit developer privileges and can act faster than teams can review.
- Arti 2.3.0 pushes Tor’s Rust rewrite deeper - The Tor Project’s Arti 2.3.0 release adds logging and RPC work, raises macOS support requirements, and continues development toward relay and directory aut
- Azure Local CVSS 10: check disconnected deployments - NVD lists CVE-2026-42822 as a maximum-severity improper authentication flaw in Azure Local Disconnected Operations. The public detail is thin, but the expo
- Canada’s Bill C-22 tests the line on encrypted messages - Bill C-22 is moving through Canada’s Parliament with lawful-access powers that CDT says could threaten end-to-end encryption through secret compelled acces
- Censorship needs evidence before it can be challenged - Tor Project’s OONI work shows why public internet measurements matter when blocks, throttling, and shutdowns are made to look like ordinary failure.