The Digital Fortress
Anyone protecting their own money, accounts and family online
Buy on Amazon Buy the book now What's in it, and who it's forCybersecurity doesn't have to be complicated. I am here to break down concepts, threats, tips, and tools in simple language. For mere mortals and developers alike.
Since I have been asked this a lot: The best way to support this site, is to buy my books.
Anyone protecting their own money, accounts and family online
Buy on Amazon Buy the book now What's in it, and who it's forJournalists, sources, activists and anyone whose privacy has stakes
Buy on Amazon Buy the book now What's in it, and who it's forDevelopers shipping production code under delivery pressure
Buy on Amazon Buy the book now What's in it, and who it's forTeams running AI coding agents in repositories others depend on
Buy on Amazon Buy the book now What's in it, and who it's forEngineers taking AI features from a working demo to production
Buy on Amazon Buy the book now What's in it, and who it's forAs an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog.
Nottinghamshire Police has begun scanning faces in public against a watchlist. Here is what the system does, what deletion cannot undo, and which records the public should demand before the next deployment.
A new Grok proof of concept hid instructions inside encrypted text, then used the model’s own runtime to reveal and act on them. The durable fix is to distrust derived content and control what tools can do with it.
Researchers revived some expired Visa contactless cards by changing the date a checkout terminal read. The practical lesson is simple: report missing cards and destroy the chip in old ones.
Researchers found malware delivered through the updater on some DoFun-based Android car screens. Here is what owners should check, without treating every dashboard as a driving emergency.
Apple sent mercenary-spyware warnings across 110 countries, and investigators saw a record response. Here is how to verify the alert, reduce exposure, protect other people, and get expert help without destroying useful evidence.
A poisoned Rust package disappeared quickly, but code compiled during that window could have exposed developer and CI credentials. Here is how to check the right evidence and rebuild trust.
US agencies say attackers are using AI-written scripts against exposed industrial controllers. Here is what the warning means for the water coming from your tap, and what residents can reasonably ask their utility.
An actively exploited MLflow flaw turned webhook delivery into a route toward internal services. Here is how to patch it and reduce what an AI engineering server can reach.