Complete static archive of GigaTap articles about VPN, privacy, OPSEC, and security.
- Chrome 148 for iOS lands: update, but don’t overread it - Google released Chrome Stable 148 for iOS with stability and performance improvements. The note does not name a CVE or active exploit.
- Civic space pressure in Kenya and Rwanda reaches ACHPR - ARTICLE 19 used the African Commission sessions to warn about protest policing, surveillance, cybercrime laws, and media pressure in Kenya and Rwanda.
- Copilot can now propose fixes for failed Actions - GitHub added a one-click Copilot cloud agent flow for failed Actions jobs. Useful for CI triage, but teams should keep review boundaries clear.
- CRA readiness is becoming an open source supply-chain test - OpenSSF’s CRA warning points to a practical gap: teams need inventory, vulnerability handling, and clear responsibility for OSS in products.
- Critical lwIP SNMP bug: check embedded exposure - CVE-2026-8836 affects lwIP up to 2.2.1 in SNMPv3 USM parsing. The key question is whether vulnerable SNMP code is present and reachable.
- Security Changed. Neglected Basics Still Break It - A Dark Reading retrospective shows how cyber models evolved while many breaches still exploit old hygiene gaps.
- Surveillance Pricing Moves Into New Jersey’s Policy Lane - EPIC backed a New Jersey bill targeting surveillance pricing. The key issue is not only data collection, but how hidden profiling can shape the price a con
- TeamPCP Hits the Build Chain Again - SANS ISC reports a confirmed Checkmarx Jenkins plugin compromise and a new self-spreading Mini Shai-Hulud worm across npm and PyPI.
- YellowKey Shows the Risk in Default BitLocker - A reported BitLocker zero-day requires physical access, but that is exactly the scenario full-disk encryption is supposed to handle. The key issue is TPM-o
- AI-Assisted Exploits Move From Theory to Operations - GTIG says it identified a zero-day believed to be AI-developed, pointing to a more mature phase of AI use in adversary workflows.
- AI code review meets live infrastructure - Cloudflare tested Mythos and other security LLMs on live infrastructure code. The useful lesson is not autonomy, but where model-assisted review needs cont
- AI makes basic SaaS security harder to ignore - Microsoft’s guidance for growing businesses is vendor-led, but the practical point is real: AI tools inherit your identity, access, and data-control mistak
- Amazon’s tariff refund lawsuit tests who owns the rebate - A proposed class action says Amazon passed tariff costs to customers but did not refund them after the tariffs were ruled unlawful. The claim is still unpr
- EFF’s email tracking change tests consent in practice - EFF says most privacy policy changes are clarifications, but one new option matters: explicit opt-in tracking for email opens and clicks.
- ICE detention expansion raises a capacity and abuse risk - The ACLU says ICE detention is being scaled toward 96,000 people despite deaths and severe conditions. The core issue is capacity without matching accounta
- KernelSU and F-Droid: the real issue is build trust - A short F-Droid Forum question about KernelSU points to a larger Android root-tool problem: users are not only choosing features, but deciding which build
- LibrePlan 1.6.0 improves the work around the plan - The open-source project management platform adds email workflows, risk tracking, and broader language support. The useful question is how much friction it
- MiniPlasma PoC puts Windows SYSTEM access in play - A public PoC for the MiniPlasma Windows zero-day reportedly gives SYSTEM privileges on fully patched systems. Treat it as a post-compromise accelerant, not
- Shittier: an unconventional formatter worth checking carefully - Shittier is a TypeScript code formatter project with visible GitHub interest. The useful question is not hype, but whether its behavior fits your workflow.
- Short dramas show where AI media scales first - China’s short-drama boom shows why AI fits high-volume entertainment: the format is already fast, modular, trope-heavy, and built for constant testing.
- Siri auto-delete could make Apple’s AI pitch clearer - Apple’s reported auto-delete option for future Siri chats would fit its privacy strategy, but the real test is what gets deleted, when, and by default.
- Surveillance Abuse Needs Hard Limits - EFF’s new guide argues that weak oversight, vague laws, and poor remedies are letting digital surveillance abuses become routine in the Americas.
- Teams loses Together Mode as Microsoft trims the interface - Microsoft is retiring Teams’ pandemic-era Together Mode. The change looks less like a crisis and more like product cleanup after the remote-work surge.
- Terraria cross-play is finally moving closer - Re-Logic says cross-play is “on deck soon” as Terraria turns 15, with update 1.4.6, collector items, and a retrospective book also in view.