Complete static archive of GigaTap articles about VPN, privacy, OPSEC, and security.
- AI Security Budgets Shift From Tools to Control - AI security budgets are moving toward lifecycle governance of agentic systems. Visibility is no longer enough without enforcement across development and pr
- Atomic Arch Shows How Orphaned AUR Packages Become Attack Paths - Atomic Arch targets abandoned AUR packages by modifying build scripts to install malicious npm or Bun dependencies during install, enabling credential thef
- California Targets Surveillance Pricing and Privacy Risk - A California bill would ban surveillance pricing, where personal data influences what customers pay for the same product.
- ChatGPhish Shows the Phishing Risk Inside AI Summaries - Permiso’s ChatGPhish disclosure points to a practical risk: trusted Markdown rendering can make AI web summaries part of the phishing surface.
- Cinemas as civic infrastructure when speech narrows - AIHRFF shows why film can matter in shrinking civic spaces: not as a magic route to policy change, but as a platform for testimony, coalition-building, and
- Coinbase Backs Ethena, but the Risk Is in the Product Details - Coinbase Ventures bought ENA as Ethena prepares for a Coinbase savings integration. The real issue is how clearly yield, custody, and stress risks are show
- Developer Credentials Become the Supply-Chain Target - IronWorm reportedly targets developers, steals credentials, and reuses trust relationships to move through the software supply chain.
- EFF restarts LGBT Q&A Season 2 for digital privacy questions - EFF brings back LGBT Q&A Season 2, focusing on privacy risks, surveillance exposure, and anonymous digital rights questions.
- F-Droid compatibility gaps with gnirehtet reverse tethering - Reverse tethering via gnirehtet exposes a mismatch in F-Droid update logic where connectivity exists but network validation fails, blocking repository refr
- LLM agents are delegated workflows, not smarter chatbots - LLM agents can plan, call tools, and execute multi-step tasks. The value is real, but so are the risks around permissions, memory, sources, and review.
- Lost Villages Show How Ground Truth Breaks in Rakhine - Bellingcat’s Rakhine investigation shows how destroyed villages can disappear from both the ground and the record. The practical issue is evidence discipli
- Mini Shai-Hulud: Where SLSA L2 Breaks - Valid SLSA attestations did not prevent a CI/CD compromise. Cache poisoning and token leakage exposed the limits of SLSA L2 isolation assumptions.
- Node-gyp Supply Chain Worm: Install-Time Execution Risk - A npm supply chain worm abuses node-gyp install-time builds via binding.gyp, bypassing lifecycle-script monitoring and exposing CI and cloud credentials.
- PoC-in-GitHub update: useful signal, weak proof - A fresh PoC-in-GitHub auto update is worth triage, but it does not prove exploitability, active abuse, or patch priority by itself.
- Push MFA Is the Weak Link Attackers Keep Pressing - Prompt bombing does not break MFA. It exploits weak MFA design, stolen passwords, and a user asked to approve a login with too little context.
- Reconstructing AI activity in security investigations - Microsoft defines a structured way to rebuild AI interactions into a coherent investigative timeline using scope, context, and signal across security telem
- ShinyHunters Exploit Hits PeopleSoft Before Patch Window Closed - UNC6240 activity shows zero-day exploitation of Oracle PeopleSoft Environment Management, heavily impacting higher education systems before advisory releas
- SignalTrace ALPR: From vehicle tracking to identity graphs - Roadside ALPR systems are merging plate reads with device signals, shifting surveillance from vehicles to probabilistic identity inference.
- Skill scanners fail against adaptive agent supply chain attacks - Static scanners for agent skills break under simple obfuscation and indirection, exposing structural limits in current software supply chain defenses.
- Skyway Model for OSS Security and Supply Chain Risk - OpenSSF Community Day 2026 reframes OSS security as a connected system problem across tooling, identity, and governance in the software supply chain.
- Supply-Chain Warnings Hide in Ordinary Access Sales - Underground GitHub access, leaked repositories, OAuth tokens, and API keys can become supply-chain risk when they touch trusted delivery paths.
- Tails 7.8.1 closes kernel escalation risk in anonymity stack - Emergency release fixes a Linux kernel privilege escalation flaw and Tor client vulnerabilities that could enable full system control under chained attacks
- TeamPCP supply chain shifts into reusable worm tradecraft - The TeamPCP campaign evolves from targeted intrusion into reusable supply-chain worming across npm and CI/CD pipelines, challenging provenance and attribut
- Turn specs into evals with ASSERT for agent testing - ASSERT converts natural-language behavior specs into executable evaluations for AI agents, aligning testing with real system intent and trace-level behavio