Complete static archive of GigaTap articles about VPN, privacy, OPSEC, and security.
- OpenAI’s AI hacking incident shows a testing gap - OpenAI’s reported model hacking incident highlights a practical AI security issue: containment, permissions, and monitoring matter as models gain more capa
- Tails 7.9.1 Closes a Privacy-Relevant Kernel Gap - Tails 7.9.1 patches a kernel privilege-escalation risk. Upgrade from Tails 7.0+ to retain Persistent Storage and avoid reinstalling by mistake.
- Tails 7.9.1 Fixes a Kernel Security Boundary Issue - Tails 7.9.1 updates Tor components and the Linux kernel, fixing a vulnerability that could allow application-level compromise to escalate.
- Tor Browser 16.0a8: What the Alpha Release Means - Tor Browser 16.0a8 adds browser, privacy, Android, and build updates, but alpha users should understand the testing risks before deployment.
- AWS Security Hub adds AI and Azure security visibility - AWS Security Hub expands beyond AWS with Azure monitoring and AI workload visibility. See what changes for security operations teams.
- AWS Security June 2026: What Teams Should Review - AWS’s June 2026 security updates focus on identity boundaries, AI workload isolation, egress controls, and cloud operations maturity.
- Jscrambler NPM compromise puts developer secrets at risk - Compromised Jscrambler NPM releases ran a preinstall hook that deployed a cross-platform information stealer. The urgent task is host triage and credential
- GPT-Red Shows How AI Security Testing Is Changing - OpenAI’s GPT-Red uses an LLM as an adversarial security tester. The practical impact is faster AI defense testing, not automatic security.
- OAuth Abuse Turns SaaS Trust Into an Attack Path - Microsoft identified ShinyHunters-associated campaigns abusing SaaS OAuth relationships through phishing and compromised integrations. Here is what teams s
- Armed Police Drones and the Privacy Gap Lawmakers Ignore - Regulation has not caught up with law enforcement drones, leaving cities to decide whether armed systems enter routine policing.
- Risky Business #844: AI Access Is Becoming a Security Control - Risky Business #844 points to AI access, token resale, and browser extensions as operational control points. Separate practical checks from broad capabilit
- Crypto clipper adds Tor and worm-like spread to theft model - Microsoft analysis shows crypto clipper evolving into a persistent threat combining clipboard hijacking, Tor-based control, and worm-like propagation.
- US Government AI Inventory Raises Privacy Questions - US agencies list 3,611 AI use cases, exposing gaps in transparency and raising questions about automated decision-making and privacy.
- BCI moves from trial to real use as AI national strategy expands - A brain implant user with ALS signals early real-world BCI use while South Korea accelerates national AI focus and infrastructure alignment.
- Canada’s Bill C-22 Pushes Encryption Toward Built-In Access Risk - Bill C-22 expands surveillance powers in Canada and introduces mechanisms that could force access paths into encrypted systems, raising structural privacy
- Postinstall payloads in npm supply chains and Mastra breach - Mastra npm packages were compromised through a postinstall hook that executed during install, exposing CI/CD pipelines and developer environments to remote
- Security beyond benchmarks: Microsoft MDASH moves to production - Microsoft’s MDASH moves from benchmark success into live engineering pipelines, embedding AI-driven vulnerability discovery directly into DevSecOps workflo
- VHDX Delivery Chain Hides Remcos RAT via JavaScript Stage - A ZIP file uses a VHDX disk image to expose JavaScript after auto-mounting on Windows, leading to Remcos RAT deployment through layered execution.
- Wolf Gallery and the F-Droid packaging bottleneck - Wolf Gallery’s F-Droid request shows how strong local encryption and offline design still depend on packaging work before reaching users through trusted di
- Schibsted Pay or Okay raises consent legality questions - Schibsted’s Pay or Okay rollout faces a complaint in Norway over whether paid opt-outs still count as freely given consent under GDPR.
- Abortion Access Blocks Across 7 Countries via Network Censorship - OONI data shows Women on Web blocked across seven countries using DNS and TLS interference, revealing how network censorship impacts abortion access.
- AI branding as phishing leverage in modern attacks - Threat actors are using AI platform branding as a trust layer on top of standard phishing infrastructure, increasing engagement without changing core attac
- AI coding agents need access, not custody - 1Password’s Codex integration points to a cleaner model for agentic development: scoped, just-in-time credentials that stay out of prompts, code, terminals
- AI found the bugs. Now comes the patch problem - Anthropic’s Project Glasswing reportedly surfaced thousands of serious vulnerability candidates. The real issue is the widening gap between discovery, vali