The Digital Fortress
Anyone protecting their own money, accounts and family online
Buy on Amazon Buy the book now What's in it, and who it's forCybersecurity doesn't have to be complicated. I am here to break down concepts, threats, tips, and tools in simple language. For mere mortals and developers alike.
Since I have been asked this a lot: The best way to support this site, is to buy my books.
Anyone protecting their own money, accounts and family online
Buy on Amazon Buy the book now What's in it, and who it's forJournalists, sources, activists and anyone whose privacy has stakes
Buy on Amazon Buy the book now What's in it, and who it's forDevelopers shipping production code under delivery pressure
Buy on Amazon Buy the book now What's in it, and who it's forTeams running AI coding agents in repositories others depend on
Buy on Amazon Buy the book now What's in it, and who it's forEngineers taking AI features from a working demo to production
Buy on Amazon Buy the book now What's in it, and who it's forAs an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog.
Mathspace says more than one million students, families, and staff were affected. Here is what the exposed account data can and cannot do, and the calm family check that matters now.
Attackers are taking over some MikroTik routers whose remote-management door is open to the internet. Here is how to update safely, check for changes, and decide how much cleanup is justified.
Magento stores were compromised through an unpatched flaw even while running current security updates. Here is how to separate blocking the next request from investigating the first one.
Nearly 22,000 Exchange servers were still exposed after a fix shipped. The practical problem is bigger than one patch: teams must prove the running build, support entitlement, and replacement path together.
OpenAI-linked agents reportedly turned a quiet public wiki into a shared notebook during a timed web task. The practical lesson is simple: allowed requests, writable public sites, and shared state must be controlled together.
Claude Mythos found a large queue of possible software flaws, but human review changed many severity ratings. Here is how to build an AI security scanner that produces decisions rather than noise.
Plex has fixed several security issues without publishing their details yet. Here is how to update the server you actually run, check that it worked, and avoid turning uncertainty into panic.
A suspected breach put millions of license scans up for sale. Here is what that changes, what remains unconfirmed, and the few steps worth taking now.