The Digital Fortress
Anyone protecting their own money, accounts and family online
Buy on Amazon Buy the book now What's in it, and who it's forCybersecurity doesn't have to be complicated. I am here to break down concepts, threats, tips, and tools in simple language. For mere mortals and developers alike.
Since I have been asked this a lot: The best way to support this site, is to buy my books.
Anyone protecting their own money, accounts and family online
Buy on Amazon Buy the book now What's in it, and who it's forJournalists, sources, activists and anyone whose privacy has stakes
Buy on Amazon Buy the book now What's in it, and who it's forDevelopers shipping production code under delivery pressure
Buy on Amazon Buy the book now What's in it, and who it's forTeams running AI coding agents in repositories others depend on
Buy on Amazon Buy the book now What's in it, and who it's forEngineers taking AI features from a working demo to production
Buy on Amazon Buy the book now What's in it, and who it's forAs an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog.
Police and security researchers have disrupted a botnet that survived for more than two decades. Here is what that changes, what it leaves behind, and what to do if a computer is identified as infected.
Attackers used a key stolen from an exposed AI dashboard for three weeks and consumed model credits worth about $600,000. The useful lesson is to make every experimental key narrow, temporary, visible, and cheap to lose.
Researchers found malware carrying text intended to trip an AI safety refusal before analysis finished. The practical fix is to treat every refusal as an incomplete scan, keep independent detections running, and test the whole decision path.
Connecticut, Maryland, New Jersey, Oregon, and Virginia now restrict the sale of precise location data. Here is what those laws close, what they leave open, and what you can do about the trail your phone creates.
CISA used similar red-team methods against two critical-infrastructure organisations. One security team acted within minutes while another lost the real warnings among routine noise.
A critical GiveWP flaw turned an ordinary donation form into a route to the web server. Here is how to update, check the earlier exposure window, and keep a charity site useful without treating every alarm as a disaster.
Ring’s new TAKE encryption shortens how long the company keeps video keys while preserving cloud features. Here is what that protects, what it leaves unchanged, and which setting suits your home.
A Citrix NetScaler flaw moved from a denial-of-service bulletin to active exploitation and a public remote-code-execution analysis. Here is how to patch the gateway, preserve evidence, and check the trust behind it.