Complete static archive of GigaTap articles about VPN, privacy, OPSEC, and security.
- Koofr Vault and the Trust Shift Behind Zero-Knowledge Storage - A look at Koofr Vault's open-source, zero-knowledge design, what it changes in the trust model, and what users should verify before relying on it.
- Laravel Lang tag hijack turned old versions into malware - Attackers rewrote GitHub release tags for third-party Laravel Lang packages, causing Composer installs to pull credential-stealing malware from what looked
- NetBird v0.72.3 Focuses on VPN Reliability, Not New Features - NetBird v0.72.3 hardens routing, relay fallback behavior, DNS handling, and debug-data protection while adding experimental Kubernetes support.
- North Mini Code: the operational check behind the model release - Cohere’s North Mini Code gives developers an open coding model for agentic workflows. The real test is harness reliability, tool access, and privacy risk.
- PPE Bans Raise a Larger Risk Than Reporter Safety - Restrictions on protective gear at protests may affect more than journalists. They can reduce independent observation when public scrutiny matters most.
- Secret Scanning Is Only Useful If Teams Trust the Alerts - GitHub says it reduced secret-scanning false positives with context-aware LLM verification. The bigger story is signal quality in software supply chain sec
- DOJ Press Protection Questions Move Into Court - A new FOIA lawsuit seeks records that could reveal whether statutory protections for journalists were omitted during warrant applications.
- Malicious packages turn installs into credential theft - A Sicoob-themed NuGet package reportedly stole banking API material, while npm packages targeted cloud and CI/CD secrets. The operational fix starts with a
- Who Gets to Decide Who Counts as a Journalist? - A dispute in New Jersey highlights a broader press freedom question: can police decide who qualifies for journalistic protections?
- Turning Threat Signals Into Real-Time WAF Decisions - Cloudflare now lets customers use Cloudforce One intelligence directly inside WAF rules, reducing the gap between threat detection and enforcement.
- Dependency Confusion Still Works — and Attackers Know It - A malicious npm campaign used dependency confusion to profile developer and build environments, highlighting persistent supply-chain weaknesses.
- Microsoft Build 2026 turns AI security into an ops problem - Microsoft’s Build 2026 security announcements matter less as AI hype and more as an operational check on code, agents, data, and model risk.
- 2FA Apps Do Not Need Google to Be Trusted - A FLOSS authenticator can work across services because TOTP is a shared-secret standard, not because Google, Microsoft, or Proton approves each code.
- Age-Gates Turn Access Into a Privacy Check - Age-gates are expanding from youth-safety policy into an identity-exposure problem for ordinary internet users.
- When a Security Scanner Stops the Build Before Compilation - A recent F-Droid build failure shows how policy-driven security checks can block releases even when application code is not the problem.
- Gentlemen ransomware raises the blast-radius question - Microsoft’s analysis shows why The Gentlemen is not just another encryptor: its risk comes from self-propagation, credential reach, and double extortion pr
- Red Hat npm supply‑chain breach: credential‑stealing malware - Over 30 Red Hat npm packages were compromised in a supply‑chain attack distributing credential‑stealing malware with operational impact for security teams.
- AI-assisted ransomware lowers the cost of EDR evasion - Sophos found AI used to speed ransomware tooling, AD discovery, and EDR bypass testing. The risk is faster iteration, not autonomous malware.
- AI Coding Is Stress-Testing DeFi Security - OpenZeppelin rejects the claim that AI coding agents make all of DeFi indefensible. The more useful question is which teams can prove their review process
- AI Is Making Bug Hunting Faster - AI will not replace expert exploit work overnight. The sharper risk is speed: more actors can search, triage, and weaponize vulnerability leads faster.
- AI Surveillance Is Becoming State Infrastructure - A cited 2026 study says 11 African governments spent more than USD 2 billion on AI-powered surveillance. The risk is not just better tools, but weaker limi
- Auth0 scopes only work when the policy behind them is clear - Auth0 authorization depends on how roles, permissions, client grants, and scopes combine. The practical risk is trusting a token without checking the polic
- Colorado’s AI Law Gets Weaker Before It Starts - EPIC says Colorado lawmakers again amended the state’s landmark AI law, removing important requirements and delaying its effective date.
- Dual-Layer Phishing Raises the Cost of Detection - A reported espionage campaign uses layered spear-phishing and Azureveil malware, highlighting why defenders should validate detection across the full intru