I write about security, privacy, and AI — the stuff that matters but rarely gets explained well. Practical, opinionated, honest.

No fear-mongering. No affiliate tax. Just the plain-English version.

§ 01

LATEST

78 articles and counting. Newest first.

012026
Privacy5 min read

Section 702 Expired. Do Not Trade It Back for Nothing.

EFF says Section 702 expired on June 12 after Congress failed to renew it. The next fight is whether warrantless backdoor searches come back under a different deadline.

Jun 15, 2026READ →
022026
AI Tools4 min read

Your AI Report Needs a Receipt Drawer

KPMG pulled an AI usage report after apparent hallucinations. EFF keeps finding fake staff quoted by AI slop sites. The fix is boring: citations, owners, and a human who checks the receipts.

Jun 14, 2026READ →
032026
Security5 min read

Your AUR Helper Is Not a Trust Boundary

The Arch User Repository hijack is a reminder that developer package feeds are not harmless convenience. Build scripts run code, and abandoned packages inherit trust too easily.

Jun 13, 2026READ →
042026
Privacy5 min read

The AI Act Is Being Weakened Before It Starts

EDRi says the EU AI Omnibus would delay high-risk AI safeguards and reduce public transparency. That is not boring Brussels plumbing. It is where accountability disappears.

Jun 12, 2026READ →
052026
AI Tools5 min read

AI Builders Are Production Servers Now

Langflow exploitation is a reminder that low-code AI builders, agent frameworks, and model gateways are not experiments once they touch the internet. They are production attack surface.

Jun 11, 2026READ →
062026
Security4 min read

The Schema Was Not Supposed to Run Code

Six protobuf.js bugs are a useful warning for Node teams: parsers, schemas, and generated code are now part of your execution boundary. Treat them that way.

Jun 10, 2026READ →
LIVE THREAT FEED · /THREATWATCH
ALL →