Complete static archive of GigaTap articles about VPN, privacy, OPSEC, and security.
- AWS Maps ISO 42001 to Cloud Reality - AWS’s new ISO 42001 guide helps AI teams map governance controls to AWS services without confusing cloud support for compliance ownership.
- AWS WAF Makes AI Agent Traffic Measurable - AWS WAF’s AI Traffic Analysis dashboards turn mystery AI traffic into usable signals for policy, cost control, and endpoint strategy.
- CPS Reached OpenSSF Gold: the practices behind the badge - CPS says it achieved OpenSSF Best Practices Gold by enforcing review gates, deep CI testing, and security-in-pipeline controls—and by pushing org-wide chan
- Elementary-data’s bad release: quick triage for Python teams - Chainguard says its customers were not impacted, but anyone who pulled elementary-data 0.23.3 from PyPI (or a related Docker Hub image) should investigate
- Open Source Security as a Cost and Speed Advantage - Secure your open source supply chain to cut rework, lower incident costs, and help developers ship faster.
- OpenSSF’s April signal: make security artifacts operational - The April 2026 OpenSSF newsletter points to a clear shift: away from dead PDFs and one-time scans, toward runtime context, living SBOMs, and new AI-driven
- pwncat Practical Guide: Reverse Shell Handling, Enumeration, and Post-Exploitation - A hands-on guide to pwncat for stabilizing shells, enumerating hosts, and managing post-exploitation workflows.
- How to Use remnawave-api for Remnawave API Automation - A beginner-friendly guide to automating Remnawave tasks with Python, including setup, auth, and real-world API examples.
- When a Worm Hits npm, Scripts Become the Blast Radius - A reported npm worm targeting SAP-related packages shows why blocking install-time scripts and enforcing dependency controls can stop downstream fallout.
- ByeDPIManager on Windows: Run ByeDPI + ProxiFyre for App-Selective DPI Bypass - Beginner-friendly guide to install and use ByeDPIManager on Windows to run ByeDPI with ProxiFyre for per-app DPI bypass.
- Cloudflare’s Copy Fail Response: What Operators Should Infer - Cloudflare says it mitigated a critical Linux kernel priv-esc with zero customer impact; here’s what that does—and doesn’t—prove.
- Digital security in war and conflict: what civil society needs to prioritize - Access Now’s webinar announcement reflects a wider shift: digital harms are increasingly treated as part of conflict protection work. Here is what that fra
- ghostcp (GhosTCP) Beginner Guide: Hardening TCP Connections on Windows - Learn how to install and configure ghostcp (GhosTCP) on Windows to reduce TCP interference using WinDivert and simple rules.
- Malicious NuGet packages impersonate Chinese .NET libraries to deliver an infostealer - Socket reports five NuGet packages that mimic Chinese .NET UI/infrastructure libraries while shipping a .NET Reactor–protected stealer. The campaign uses u
- Malicious Ruby Gems and Go Modules Mimic Dev Tools to Steal Secrets and Tamper With CI - Socket reports a coordinated cluster of Ruby gems and Go modules published from a single GitHub account that looked like routine developer tooling, then la
- OpenSSF on the Hidden Costs of Running Package Registries - A brief note on OpenSSF’s argument that package registries are critical infrastructure with real, recurring operational and security costs—and what teams s
- Stateless Tor Relays: Why Tor Wants Seized Servers to Remember Nothing - Tor’s stateless relay model aims to make confiscated hardware far less useful by removing disk state from the trust equation.
- Surveillance for Sale Threatens Press Freedom - When agencies buy app-derived location data, they don’t just dodge warrants—they gain a map to journalists’ sources.
- Brave Brings Its “Shred” Site-Data Wipe Feature to Android - Brave for Android 1.89 adds a per-site “Shred” button and Auto Shred automation to delete site-stored data that can be used to re-identify you across visit
- Georgia’s media freedom crisis: what the latest warning says, and what to verify next - MFRR partners warn that press freedom in Georgia has deteriorated rapidly since the contested October 2024 elections. The available excerpt is sparse, so h
- pnpm 11 turns on default supply-chain protections - pnpm 11 makes safer installs the default with a 24-hour release delay, blocked exotic subdependencies, and clearer build-script controls.
- Psiphon How-To: Censorship Circumvention Basics for Privacy-Minded Users - Learn how to install and use Psiphon to bypass network censorship, understand what it protects (and what it doesn’t), and avoid common OPSEC mistakes.
- PyPI Fixed High-Severity Access Control Bugs Found in a Warehouse Security Audit - A Trail of Bits audit of PyPI’s Warehouse reported two high-severity access-control issues and an OIDC Trusted Publishing replay edge case. PyPI says it fi
- zapret2 (anti-DPI) Beginner Guide: Install, Intercept, and Apply Strategies Safely - A beginner-friendly zapret2 guide: install it, redirect only the right packets, and apply anti-DPI strategies on Linux/Windows.