Complete static archive of GigaTap articles about VPN, privacy, OPSEC, and security.
- Dirty Frag: a Linux root chain that sidesteps “safe defaults” - A reported unpatched Linux kernel LPE (CVE-2026-31431) chains xfrm/ESP and RxRPC page-cache writes, aiming to reach root across common distro configuration
- Exam Shutdowns Are a Bad Anti-Cheating Policy - Exam-related internet shutdowns are spreading despite thin evidence and broad social harm.
- Hysteria: a fast proxy project for hard networks - Hysteria is a Go-based open-source proxy project aimed at censorship resistance and difficult network conditions. Here is what the repository metadata supp
- Ireland’s Meta Probe Tests the DSA’s Real Force - Ireland is investigating whether Meta’s feed design blocks users from choosing non-profiled recommendations. The case could decide whether DSA rights becom
- MetInfo RCE Is Being Exploited. Patch Timing Matters - MetInfo CMS CVE-2026-29014 is now under active exploitation. Here is what the bug does, which versions are named, and what operators should verify next.
- PAN-OS RCE: Treat Edge Exposure as the Incident - CVE-2026-0300 shows why edge-device RCE demands fast exposure reduction, containment planning, and behavioral hunting.
- Signal on F-Droid? Reproducible Builds Are Only Step One - A new F-Droid forum thread points to reproducible Signal builds, but auditability is not the same as a safe Play Store replacement.
- Trivy scans the places modern security debt hides - A concise look at Aqua Security’s Trivy: what the open source scanner claims to cover, where it fits, and what teams should verify before relying on it.
- Vendor Says Daemon Tools Supply Chain Attack Contained - SecurityWeek reports the Daemon Tools vendor says it identified impacted systems, removed potentially compromised files, and validated installation package
- When an FBI Leak Probe Tests the First Amendment - A reported FBI probe into The Atlantic’s Patel coverage raises a core press-freedom question: leak enforcement or retaliation?
- 100% package test coverage is the point, not the slogan - Chainguard says its OS tests every package automatically, with 100% package test coverage. The useful question is not whether that sounds good, but what it
- A Free Signal Guide Worth Passing Along - EFF is offering a free Signal guide in English and Spanish, plus short companion guides, to make secure messaging easier to adopt and share.
- Air-Gapped Software Deployment: What Zarf Tries to Standardize - An OpenSSF podcast episode outlines Zarf’s goal: package images, charts, and supporting files into a transferable bundle for air-gapped environments—and us
- Beelzebub: AI-shaped deception worth testing carefully - Beelzebub is a Go-based deception and honeypot framework with AI and LLM security framing. It is interesting for research, but teams should verify isolatio
- Chrome 149 hits Beta — what desktop users should watch - Chrome 149 is now in Beta for Windows, Mac, and Linux. Google’s note is sparse, so the main takeaway is the channel shift and what testers should verify ne
- Chrome Beta 149 lands on iOS, details still thin - Google has released Chrome Beta 149 for iOS, but the public note is brief: build 149.0.7827.2 is rolling into the App Store, with only a partial Git log fo
- CMMC Phase 2: The New Contract Gate for CUI - CMMC Phase 2 turns NIST 800-171 into a contract condition, while GSA awards are already enforcing the same baseline.
- Dify: a large agent workflow stack, not a small library - GitHub metadata points to Dify as a platform for agentic workflow development, with low-code/no-code, orchestration, RAG, and MCP in scope. Here is what th
- DRØGR asks F-Droid for help without giving up opsec - A developer is asking the F-Droid community to package DRØGR, a serverless P2P messenger that claims zero-persistence design and traffic-resistance feature
- Email Phishing Is Moving to Links—Here’s Why It Matters - Microsoft’s Q1 2026 telemetry shows phishing shifting toward links, QR lures, CAPTCHA gates, and resilient PhaaS operations.
- Equinox OSGi console exposure can turn into remote code execution - NVD flags CVE-2023-54344 as a critical RCE risk in Eclipse Equinox OSGi 3.7.2 and earlier. The key question is simple: is the OSGi console port reachable a
- Equinox OSGi console RCE: check if telnet is exposed - NVD describes an unauthenticated RCE path in Eclipse Equinox OSGi (3.8–3.18) via the console’s fork command over telnet. The key question: is your OSGi con
- Exposed ADB is still a botnet on-ramp for DDoS - Researchers say a Mirai-derived botnet, xlabs_v1, targets internet-exposed ADB (TCP/5555) on Android/IoT devices to build rentable DDoS capacity aimed at g
- GPU Rowhammer on NVIDIA Ampere: When GDDR Bit Flips Can Threaten Host Memory - Researchers reportedly demonstrated GPU Rowhammer attacks on two NVIDIA Ampere cards that use GDDR bit flips to gain control of CPU memory—if IOMMU protect