The Digital Fortress
Anyone protecting their own money, accounts and family online
Buy on Amazon Buy the book now What's in it, and who it's forCybersecurity doesn't have to be complicated. I am here to break down concepts, threats, tips, and tools in simple language. For mere mortals and developers alike.
Since I have been asked this a lot: The best way to support this site, is to buy my books.
Anyone protecting their own money, accounts and family online
Buy on Amazon Buy the book now What's in it, and who it's forJournalists, sources, activists and anyone whose privacy has stakes
Buy on Amazon Buy the book now What's in it, and who it's forDevelopers shipping production code under delivery pressure
Buy on Amazon Buy the book now What's in it, and who it's forTeams running AI coding agents in repositories others depend on
Buy on Amazon Buy the book now What's in it, and who it's forEngineers taking AI features from a working demo to production
Buy on Amazon Buy the book now What's in it, and who it's forAs an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog.
Revolut released sensitive customer records after fraudulent requests arrived from a legitimate government agency email domain. The failure offers a practical lesson for every team that handles official demands for data.
AdaptHealth says a June attack exposed health and insurance information for more than 4.1 million people. Here is what affected patients should check, why credit monitoring covers only part of the risk, and when to escalate.
Newly released records show long delays and technical failures in Medicare’s WISeR review experiment. Here is how patients and families can tell whether it affects them, follow a request, and preserve their appeal rights.
Check Point has fixed two critical flaws in VPN certificate handling. The useful response is to patch every affected gateway, verify the fix on the running nodes, and keep threat claims tied to evidence.
GitLab fixed a flaw that let an unauthenticated visitor read server files on affected self-managed installations. Patch promptly, then use a concrete secret map to decide what evidence to preserve and which credentials may need replacing.
Researchers linked a May flood of RubyGems packages to agents being tested by OpenAI. The practical lesson is to cap every agent run by external effects, not by prompt or task label.
A compromised newsletter service sent a false Trezor warning through a genuine mailing route. Here is the wallet-backup rule that works even when the sender looks right.
A DeepSeek Harness flaw let a confined coding agent change its own permissions through a local control interface. The fix matters, and so does the wider lesson about keeping policy outside the boundary it governs.