The Digital Fortress
Anyone protecting their own money, accounts and family online
Buy on Amazon Buy the book now What's in it, and who it's forCybersecurity doesn't have to be complicated. I am here to break down concepts, threats, tips, and tools in simple language. For mere mortals and developers alike.
Since I have been asked this a lot: The best way to support this site, is to buy my books.
Anyone protecting their own money, accounts and family online
Buy on Amazon Buy the book now What's in it, and who it's forJournalists, sources, activists and anyone whose privacy has stakes
Buy on Amazon Buy the book now What's in it, and who it's forDevelopers shipping production code under delivery pressure
Buy on Amazon Buy the book now What's in it, and who it's forTeams running AI coding agents in repositories others depend on
Buy on Amazon Buy the book now What's in it, and who it's forEngineers taking AI features from a working demo to production
Buy on Amazon Buy the book now What's in it, and who it's forAs an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog.
ServiceNow fixed three maximum-severity flaws that could be reached without signing in. The urgent work is patching, but the durable lesson is to map every action, identity, and integration the platform can reach.
PaperCut released a second emergency patch after its first response was bypassed. Here is how to restrict access, patch every server, investigate the earlier window, and prove the fix is actually running.
Android 17 brings Encrypted Client Hello to mobile connections. It closes a revealing gap beside HTTPS, but the address, timing, app, and destination can still leave clues.
A targeted lab attack got past Claude Code Auto Mode by turning ordinary-looking steps into code execution. The practical lesson is simple: automated approval can reduce bad decisions, but it cannot contain the computer that makes them.
Meta has agreed to time limits, overnight blocks, and quieter school hours for teen accounts. The useful protections come with an age-assurance system that families should inspect just as carefully.
A Gitea flaw is being exploited after turning ordinary repository access into commands on the server. Here is how to patch, investigate, and rebuild trust in the code and credentials that server could reach.
Ubiquiti has fixed a large group of serious UniFi flaws affecting network consoles, cameras, phones, and other systems. Here is the calm version check that homes and small businesses should make now.
A fixed Marimo flaw let a crafted notebook start a local command when someone opened it for editing. The practical lesson is simple: notebook configuration belongs inside the code-review boundary.