Complete static archive of GigaTap articles about VPN, privacy, OPSEC, and security.
- Hysteria Proxy: What to Check Before You Deploy - Hysteria is a popular Go proxy project with recent activity and a censorship-circumvention focus. Before adopting it, treat the repository as a starting po
- Microsoft flags a phishing run that stole auth tokens - Microsoft says a large phishing campaign used code-of-conduct themes and legitimate email services to steer users to attacker-controlled domains. The main
- node-ipc compromise puts npm trust back under stress - Socket says malicious `node-ipc` versions show obfuscated stealer/backdoor behavior. Developers should audit recent installs, block affected versions, and
- Node-ipc compromise turns installs into credential theft risk - Three malicious node-ipc versions reportedly targeted cloud secrets, SSH keys, Kubernetes configs, CI variables, and AI API keys. Treat affected installs a
- NVD Enrichment Is Narrowing: What Container Teams Should Recheck - NIST will still publish most CVEs, but fewer will receive the enrichment many scanners and compliance workflows rely on. Container teams should review scor
- Online Tracking Is Becoming a Surveillance Pipeline - EFF’s warning is not just about creepy ads. Commercial trackers and data brokers can turn ordinary browsing and location data into a shortcut for governmen
- Scaling LinkedIn Lead Gen Requires Better Signals, Not More Clicks - Zapier argues that most B2B LinkedIn Ads programs suffer from a growing “signal gap”: downstream outcomes like qualification and pipeline never make it bac
- SpiderFoot maps public attack surface, but verify the output - SpiderFoot is a Python OSINT automation project for threat intelligence and attack-surface mapping. Its value is faster recon, not automatic truth.
- SuperAGI: open source agents need a trust model - SuperAGI is a Python-based open source framework for autonomous AI agents. It is worth evaluating, but teams should verify maintenance, permissions, data f
- Supply-chain attacks become a leaderboard - TeamPCP and BreachForums are reportedly promoting a $1,000 contest for Shai-Hulud package compromises. The prize is small. The copycat incentive is the pro
- Supply Chain Security Starts Before the Build - Sonatype’s playbook points to a practical shift: secure the inputs, pipelines, identities, and trust paths that produce software before release.
- Swat River vs hydropower: a Torwali test of consent and safeguards - Torwali communities say the Swat River is being treated as infrastructure, not a living system. A reported cabinet withdrawal is a win — but the financing,
- The Hidden Tax of Broken LinkedIn Ad Attribution - Broken attribution is not just a reporting annoyance. It drains team time, weakens LinkedIn optimization signals, and turns performance reporting into a we
- The new ~/Projects default and a week of Linux supply-chain reality - A new standard Projects directory is meant to become an app default, not just a personal habit. The same weekly digest also flags a PyPI workflow breach, a
- Trivy adoption checklist: what to verify before rollout - Trivy has broad scanning scope and active public repository signals. Before adopting it, teams should check deployment model, maintenance cadence, output h
- When F-Droid Misses Tags, Updates Go Dark - A small F-Droid tag detection issue shows why Android update delivery is a security trust chain, not just a build step.
- agenticSeek and the local AI agent trade-off - agenticSeek promises a local autonomous AI agent without paid APIs. The useful question is not the pitch, but what users should verify before trusting it.
- AWS code scanning preview targets whole-repo security gaps - AWS Security Agent now has a preview full-repository scanning feature. The key shift is context-aware review across code paths, not just pattern matching.
- Beelzebub: what to check before deploying AI deception - Beelzebub is an open source Go deception framework with AI and honeypot positioning. Here is what teams should verify before treating it as operational infrastructure.
- Canada’s C-22 Revives the Backdoor Fight - EFF says Canada’s Bill C-22 keeps core risks from an earlier surveillance bill: metadata retention, secret access orders, and unclear limits around encrypt
- Canvas portals defaced again — the real risk is user trust - ShinyHunters is reported to have breached Instructure again, exploiting a vulnerability to deface Canvas login portals for hundreds of institutions. What’s
- CISA KEV Alert: Skia and V8 Bugs Are Not Just Browser Problems - CISA added exploited Skia and V8 flaws to KEV, raising urgency for browsers, Electron/CEF apps, and rendering services.
- Composer token leak risk: update before CI logs bite - A GitHub token format change exposed a Composer error path that could print Actions tokens into CI logs. PHP teams should update Composer and review recent
- Digital Harm Is Protection Work in Conflict Zones - Access Now’s May 19 webinar highlights why civil society groups must treat digital risk as a core protection issue in crises.