The Digital Fortress
Anyone protecting their own money, accounts and family online
Buy on Amazon Buy the book now What's in it, and who it's forCybersecurity doesn't have to be complicated. I am here to break down concepts, threats, tips, and tools in simple language. For mere mortals and developers alike.
Since I have been asked this a lot: The best way to support this site, is to buy my books.
Anyone protecting their own money, accounts and family online
Buy on Amazon Buy the book now What's in it, and who it's forJournalists, sources, activists and anyone whose privacy has stakes
Buy on Amazon Buy the book now What's in it, and who it's forDevelopers shipping production code under delivery pressure
Buy on Amazon Buy the book now What's in it, and who it's forTeams running AI coding agents in repositories others depend on
Buy on Amazon Buy the book now What's in it, and who it's forEngineers taking AI features from a working demo to production
Buy on Amazon Buy the book now What's in it, and who it's forAs an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog.
Plex has fixed several security issues without publishing their details yet. Here is how to update the server you actually run, check that it worked, and avoid turning uncertainty into panic.
A suspected breach put millions of license scans up for sale. Here is what that changes, what remains unconfirmed, and the few steps worth taking now.
Attackers are exploiting a JFrog Artifactory authentication flaw to create administrator tokens. Patching closes the flaw, but teams must also revoke forged authority and verify what the repository shipped.
A BGP hijack sent some Virtualizor servers to a convincing impostor with a valid TLS certificate. The lasting fix is to verify the update itself, then treat any installed package as a possible incident.
GitSpawn flaws turned routine Git checks into commands chosen by a received repository. Here is why ordinary cloning changes the risk, what to check now, and where the durable boundary belongs.
Police and security researchers have disrupted a botnet that survived for more than two decades. Here is what that changes, what it leaves behind, and what to do if a computer is identified as infected.
Attackers used a key stolen from an exposed AI dashboard for three weeks and consumed model credits worth about $600,000. The useful lesson is to make every experimental key narrow, temporary, visible, and cheap to lose.
Researchers found malware carrying text intended to trip an AI safety refusal before analysis finished. The practical fix is to treat every refusal as an incomplete scan, keep independent detections running, and test the whole decision path.