The Digital Fortress
Anyone protecting their own money, accounts and family online
Buy on Amazon Buy the book now What's in it, and who it's forCybersecurity doesn't have to be complicated. I am here to break down concepts, threats, tips, and tools in simple language. For mere mortals and developers alike.
Since I have been asked this a lot: The best way to support this site, is to buy my books.
Anyone protecting their own money, accounts and family online
Buy on Amazon Buy the book now What's in it, and who it's forJournalists, sources, activists and anyone whose privacy has stakes
Buy on Amazon Buy the book now What's in it, and who it's forDevelopers shipping production code under delivery pressure
Buy on Amazon Buy the book now What's in it, and who it's forTeams running AI coding agents in repositories others depend on
Buy on Amazon Buy the book now What's in it, and who it's forEngineers taking AI features from a working demo to production
Buy on Amazon Buy the book now What's in it, and who it's forAs an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog.
OpenAI-linked agents reportedly turned a quiet public wiki into a shared notebook during a timed web task. The practical lesson is simple: allowed requests, writable public sites, and shared state must be controlled together.
Claude Mythos found a large queue of possible software flaws, but human review changed many severity ratings. Here is how to build an AI security scanner that produces decisions rather than noise.
Plex has fixed several security issues without publishing their details yet. Here is how to update the server you actually run, check that it worked, and avoid turning uncertainty into panic.
A suspected breach put millions of license scans up for sale. Here is what that changes, what remains unconfirmed, and the few steps worth taking now.
Attackers are exploiting a JFrog Artifactory authentication flaw to create administrator tokens. Patching closes the flaw, but teams must also revoke forged authority and verify what the repository shipped.
A BGP hijack sent some Virtualizor servers to a convincing impostor with a valid TLS certificate. The lasting fix is to verify the update itself, then treat any installed package as a possible incident.
GitSpawn flaws turned routine Git checks into commands chosen by a received repository. Here is why ordinary cloning changes the risk, what to check now, and where the durable boundary belongs.
Police and security researchers have disrupted a botnet that survived for more than two decades. Here is what that changes, what it leaves behind, and what to do if a computer is identified as infected.