I write about security, privacy, and AI — the stuff that matters but rarely gets explained well. Practical, opinionated, honest.

No fear-mongering. No affiliate tax. Just the plain-English version.

§ 01

LATEST

56 articles and counting. Newest first.

012026
Security10 min read

When the Ransom Note Is a Distraction

Iran's MuddyWater group posed as a ransomware gang, used Microsoft Teams to social-engineer credentials, and deployed Chaos ransomware as cover. The real operation was espionage. Most victims never figured that out.

May 7, 2026READ →
022026
Privacy10 min read

275 Million Students Just Had Their Data Stolen. They Never Had a Say.

ShinyHunters breached Instructure's Canvas platform for the second time in eight months. The stolen data includes student messages, names, and IDs across 9,000 schools — from a system students were required to use.

May 6, 2026READ →
032026
AI Tools9 min read

AI Didn't Replace Hackers. It Built Them an Assembly Line.

Mandiant's M-Trends 2026 data shows AI in the attack chain at every stage — but the breaches still start with the same old failures. The uncomfortable truth is both things are true at once.

May 5, 2026READ →
042026
Security9 min read

Bitwarden's Own CLI Was Backdoored on npm for 93 Minutes

At 5:57 PM ET yesterday, attackers pushed a trojanized @bitwarden/cli@2026.4.0 to npm. It silently stole SSH keys, cloud credentials, and GitHub tokens — then used them to inject itself into every CI/CD pipeline it could reach.

Apr 24, 2026READ →
052026
Privacy11 min read

MSG Spent $6 Million on Facial Recognition. Staff Used It to Build Files on Critics.

Madison Square Garden's biometric system has been used to preemptively enroll critics who never visited, eject a 9-year-old because of her mother's law firm, and compile an 18-page surveillance dossier on a trans woman. A lawsuit put the specifics on paper.

Apr 23, 2026READ →
062026
Privacy11 min read

Europe Pulled the Plug on Mass Message Scanning. The Proposal Isn't Dead.

The EU Parliament voted to let the legal basis for mass-scanning private messages expire. Google, Meta, Microsoft, and Snap were all operating under that safe harbor. It's the most significant institutional win for encrypted communications in years — and the pressure hasn't dissolved.

Apr 22, 2026READ →
LIVE THREAT FEED · /THREATWATCH
ALL →
▸ STAY IN THE LOOP

Weekly. No spam. No fluff.