The Anonymity Playbook
Journalists, sources, activists and anyone whose privacy has stakes
Cybersecurity doesn't have to be complicated. I am here to break down concepts, threats, tips, and tools in simple language. For mere mortals and developers alike.
Since I have been asked this a lot: The best way to support this site, is to buy my books.
As an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog.
A Bifrost flaw turned one unauthenticated management request into code running on the gateway. Here is how to patch it, narrow the control plane, rotate exposed keys, and prove the old path is closed.
WordPress fixed a serious core flaw on 22 September 2026. Here is how a small-site owner can update, verify the repair, and check the hours before it arrived without turning the job into a panic.
A September Windows update stopped File History from creating or restoring some backups. Here is how to install the repair, prove a fresh copy exists, and test one harmless restore.
Attackers extracted configurations and hashed root credentials from 996 Zyxel switches. Updating closes the flaw, but operators still need to reset exposed trust and prove the management path is clean.
A critical flaw has been reported in one D-Link router model, but the vendor is still checking which revisions and regions are affected. Here is how to identify the box you own, reduce its exposure, and make a calm replace-or-wait decision.
CISA added three exploited Linux kernel flaws to its catalogue on 18 September 2026. The practical response is to prove which kernel each host is running, not merely which package was installed.
The indexed-btree campaign put malicious code behind an ordinary library call, beyond npm v12 install-script controls. Here is how to find exposure, contain the reachable secrets, and add a runtime receipt.
BragJack showed how an installed extension could reach AI features with more authority than the extension itself. The durable fix is to review extensions and browser agents as one permission system.