Complete static archive of GigaTap articles about VPN, privacy, OPSEC, and security.
- Risky Business #840: disclosure risk becomes operational - Risky Business #840 shows why Microsoft’s researcher walk-back matters beyond drama: disclosure posture, location data, backups, and open-source supply cha
- Tails 7.8 Fixes a Security Weak Point - Tails 7.8 addresses privilege-escalation vulnerabilities and changes how Thunderbird updates are delivered to reduce security lag.
- TeamPCP shows why trusted packages are not safe by default - A reported TeamPCP wave hit VS Code, PyPI, and npm paths in the same week. The common failure was trust: verified publishers, official packages, and auto-u
- UK tokenization plan: innovation, but inside the rails - The FCA and Bank of England are treating tokenization and stablecoins as market infrastructure questions, not a loose crypto experiment.
- Verizon VoLTE Signaling Risk: What VU#615987 Actually Shows - CERT/CC says Verizon VoLTE SIP signaling has lacked IPsec integrity protection. The useful question is not panic, but what evidence proves mitigation.
- VPN bans would hit more than age-gate evasion - Freedom of the Press Foundation warns that restricting VPNs would weaken tools journalists use to research sensitive targets, protect sources, and reduce n
- When settlements become political leverage - FPF argues that Paramount’s Trump settlement and weak attorney discipline helped normalize a dangerous use of courts and regulators as political pressure t
- 2026 MASA Assessment Confirms Android App Security Updates - Mullvad’s Android app passes MASA for the second time, fixing minor UI and data handling issues while improving transparency and compliance.
- ADK for Kotlin brings agents closer to Android data - Google’s ADK for Kotlin and Android 0.1.0 can reduce agent orchestration work, but teams still need to verify data flow, tool scope, logs, and cloud fallba
- Age Checks Turn Web Access Into Identity Exposure - EFF warns that age verification mandates create new privacy risk by forcing users to disclose sensitive identity data just to access the web.
- AI Opt-Outs Are Starting to Look Like Data-Broker Playbooks - A new study argues that major AI providers are adopting privacy opt-out patterns long criticized in the data-broker industry. The key issue is not whether
- Android VPN leaks can still happen below the app layer - Mullvad says an Android 16 bug can let apps send certain QUIC traffic outside the VPN tunnel, even with Android’s strongest VPN blocking settings enabled.
- Android’s AI shift creates a new app trust boundary - Google’s I/O 2026 Android AI updates are more than model news. AppFunctions, on-device inference, and hybrid routing change how apps expose tools, data, an
- Anthropic-Cybersecurity-Skills: useful, but verify first - mukul975/Anthropic-Cybersecurity-Skills packages 754 security skills for AI agents. Treat it as structured material to inspect, not proof of safe automatio
- Apple’s 26.6 betas are a compatibility warning - Apple has released 26.6 betas across iOS, macOS, watchOS, visionOS, tvOS, and iPadOS. The notice is short, but the testing window matters for apps with sec
- AWS CIRT update: know the help boundary before an incident - AWS updated its CIRT guidance with clearer engagement paths, TTC threat intelligence, and tooling. The useful work is checking support, logs, and DFIR gaps
- C/C++ checks fail when API contracts are missed - Trail of Bits’ challenge walkthrough shows how static buffers and unchecked Windows registry queries can turn reasonable-looking validation into exploitabl
- Chrome Dev Advances: Signal, Not Security Verdict - Chrome's Dev channel moved to a new desktop build. The announcement is brief, but it offers an early operational signal for teams tracking browser changes.
- Copilot Usage Metrics Move Beyond Active User Counts - GitHub's new Copilot usage cohorts help organizations distinguish basic activity from deeper agent workflow adoption.
- Encrypted Messaging Got a Win. Check the Fine Print - EFF’s latest note highlights progress for end-to-end encrypted messaging. The real question is where the protection starts, where it stops, and what users
- Evidential Survivability: Ethereum’s Verification Bet - OCP frames Ethereum as durable verification infrastructure for AI-era systems. The useful test is what evidence survives when tools, vendors, and runtimes
- Exploitability Is Becoming the AppSec Filter - Snyk’s Continuous Offensive Security pitch points to a real shift: teams need fewer abstract findings and better proof of what can actually be exploited.
- Florida Sues OpenAI: A Test of AI Accountability - Florida’s lawsuit against OpenAI is less about a single incident and more about whether AI companies can be held accountable for foreseeable harms.
- Kazuar shows why old backdoors become harder to kill - Microsoft describes Kazuar as a Russian-linked espionage malware family that has evolved from a backdoor into a modular P2P botnet ecosystem.