The Anonymity Playbook
Journalists, sources, activists and anyone whose privacy has stakes
Cybersecurity doesn't have to be complicated. I am here to break down concepts, threats, tips, and tools in simple language. For mere mortals and developers alike.
Since I have been asked this a lot: The best way to support this site, is to buy my books.
As an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog.
Advantest is notifying people that personal information was taken in its February ransomware incident. Read the personalised data line first, then match each exposed fact to the place where it can be misused.
Wikimedia found unapproved agent activity across its wikis, public tools, and data services. The practical lesson is to give every agent a named identity, narrow routes, hard budgets, and a stop condition before it touches the open web.
Attackers used a genuine Nikkei employee account to send about 9,000 malicious emails. Here is a calm rule for checking an unexpected request when the sender address looks right.
Google paused new product-vulnerability reports to its open-source reward program after automated submissions rose and most proved invalid. The useful response is an evidence gate between an AI finding and another person's queue.
A proposed US copyright law would let courts order large VPN, broadband, and DNS providers to block access to foreign sites. Here is what the bill says, where collateral damage begins, and what privacy-conscious users should watch.
A China-aligned phishing campaign relayed real Microsoft sign-ins while stealing the resulting sessions. The defence starts with origin-bound authentication, independent verification, and a response plan that revokes more than a password.
An automated intruder chained two Zammad flaws and reached root in seconds at DIVD. The useful lesson is how segmentation, logs, and a fast containment decision kept speed from becoming unlimited reach.
Fortinet says attackers are exploiting a FortiMail flaw before fixed releases are available. The immediate job is to apply a supported workaround, prove the exposed route is closed, and keep watching until the fixed build is running.