The Digital Fortress
Anyone protecting their own money, accounts and family online
Buy on Amazon Buy the book now What's in it, and who it's forCybersecurity doesn't have to be complicated. I am here to break down concepts, threats, tips, and tools in simple language. For mere mortals and developers alike.
Since I have been asked this a lot: The best way to support this site, is to buy my books.
Anyone protecting their own money, accounts and family online
Buy on Amazon Buy the book now What's in it, and who it's forJournalists, sources, activists and anyone whose privacy has stakes
Buy on Amazon Buy the book now What's in it, and who it's forDevelopers shipping production code under delivery pressure
Buy on Amazon Buy the book now What's in it, and who it's forTeams running AI coding agents in repositories others depend on
Buy on Amazon Buy the book now What's in it, and who it's forEngineers taking AI features from a working demo to production
Buy on Amazon Buy the book now What's in it, and who it's forAs an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog.
Researchers revived some expired Visa contactless cards by changing the date a checkout terminal read. The practical lesson is simple: report missing cards and destroy the chip in old ones.
Researchers found malware delivered through the updater on some DoFun-based Android car screens. Here is what owners should check, without treating every dashboard as a driving emergency.
Apple sent mercenary-spyware warnings across 110 countries, and investigators saw a record response. Here is how to verify the alert, reduce exposure, protect other people, and get expert help without destroying useful evidence.
A poisoned Rust package disappeared quickly, but code compiled during that window could have exposed developer and CI credentials. Here is how to check the right evidence and rebuild trust.
US agencies say attackers are using AI-written scripts against exposed industrial controllers. Here is what the warning means for the water coming from your tap, and what residents can reasonably ask their utility.
An actively exploited MLflow flaw turned webhook delivery into a route toward internal services. Here is how to patch it and reduce what an AI engineering server can reach.
Google says its agent system found more than 100 critical vulnerabilities in two days. The useful lesson for engineering teams is the measured pipeline around the model.
A newly documented campaign reached more than 14,000 Dahua cameras through old passwords, old software flaws, and remote-access features. Here is the calm check that camera owners and small businesses should make now.