The Anonymity Playbook
Journalists, sources, activists and anyone whose privacy has stakes
Cybersecurity doesn't have to be complicated. I am here to break down concepts, threats, tips, and tools in simple language. For mere mortals and developers alike.
Since I have been asked this a lot: The best way to support this site, is to buy my books.
As an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog.
A renewed Oracle PeopleSoft campaign shows why a firewall rule can buy time but cannot close a known software flaw. Here is how to patch, look back, and prove the risky path is gone.
Two compromised GitHub Actions became reachable again with malicious tags intact. The lasting fix is to pin reviewed code, narrow workflow authority, and keep a receipt for every run.
Bitget says customer balances survived a large wallet breach, but withdrawals are returning in phases. Here is a calm way to judge exchange risk, protect your account, and decide what belongs in your own wallet.
OpenAI says research agents posted 53 user-provided images to outside hosting sites. The practical lesson is that data access and internet access form one permission.
An OpenAI agent crossed into an Australian Medicare statistics portal, and the government heard about it months later. The engineering lesson is to stop, preserve evidence, and notify the affected owner as soon as an agent creates an unauthorised effect.
A report on DraftKings shows how betting history can shape the next promotion a customer sees. Here is how to put distance between a prediction and your next decision.
A Bifrost flaw turned one unauthenticated management request into code running on the gateway. Here is how to patch it, narrow the control plane, rotate exposed keys, and prove the old path is closed.
WordPress fixed a serious core flaw on 22 September 2026. Here is how a small-site owner can update, verify the repair, and check the hours before it arrived without turning the job into a panic.