Cybersecurity & Privacy
Trust is becoming the attack surface
The most dangerous scam is no longer the one that looks fake.
It is the one that contains enough truth to feel routine.
A message refers to your real hotel reservation. A WhatsApp request comes from a known contact. Software is downloaded from an official website. An artificial intelligence agent acts using permissions you knowingly granted.
Do you really need a VPN, and if so, when?
VPN advertising is everywhere: podcasts, YouTube, sports broadcasts, airport banners and influencer sponsorships.
The pitch is usually simple and alarming. Without a VPN, hackers can see everything you do. Your privacy is gone. Your data is being sold. You are exposed.
Most of that pitch is marketing, not security.
But VPNs are not useless either. A VPN is a specific tool for specific situations. Knowing whether those situations apply to you is worth more than any subscription discount.
Bevel turns Apple Watch data into useful health guidance
Apple Watch users generate more health data than most people know what to do with.
Apple Health collects the numbers. Bevel tries to explain what they mean.
That distinction matters. The Apple Watch already captures sleep, heart rate, heart rate variability, workouts, respiratory rate, wrist temperature and activity trends. The problem is not the absence of data. The problem is interpretation.
Do you need an RFID-blocking wallet? Probably not
RFID-blocking wallets are easy to sell because the story is easy to understand.
A stranger walks by you in a crowded airport, train station or shopping mall. A hidden reader in their bag silently scans your tap-enabled credit card. Your card details are stolen through your jacket. The solution, according to the ads, is a wallet lined with special material that blocks the signal.
Unwary Chinese Hackers Hardcoded Credentials into Backdoors Researchers discovered a Chinese nation-state threat actor, dubbed GopherWhisper, that carelessly hardcoded command and control credentials into backdoors written in the Go programming language. The group used platforms like Slack and Discord for C2 communications, with researchers recovering over 9,000 messages that revealed details about the attackers’ environment and activities.
TunnelCrack is not new — but it is still worth understanding
I am sharing this because, even though TunnelCrack is not new, I think many people will still find it interesting. It is one of those security stories that says something bigger than the headline itself. In this case, the real lesson is not about a brand-new exploit. It is about an old assumption many people still make about VPNs.
The Art of the Gray Man: How to Travel Smart, Stay Safe, and Experience More of the World
“Travel is fatal to prejudice, bigotry, and narrow-mindedness.”
— Mark Twain
Travel changes how we see the world.
It exposes us to new cultures, unfamiliar environments, and perspectives that challenge our assumptions. But the moment you leave home, one fundamental reality shifts:
You are playing an away game.
Different social norms. Different systems. Different risks.
You do not need to be paranoid when you travel.
You need to be deliberate.
Security professionals often use a concept known as the gray man. The philosophy is simple: blend into your environment so completely that you never attract attention in the first place.
The goal is not to hide.
The goal is to be so unremarkable that no one remembers you.
Most criminals are not looking for confrontation. They are looking for opportunity — someone distracted, uncertain, or visibly out of place.
The gray man approach simply removes that opportunity.
EmDash challenges the way WordPress has been secured
Cloudflare has introduced EmDash as a spiritual successor to WordPress. That is the headline. The more important issue is the architecture behind it.
For years, WordPress has balanced flexibility and scale against a plugin model built on a high degree of trust. That trade-off helped make it the dominant publishing platform on the web. It also contributed to one of its most persistent security weaknesses.
CodeWall says it hacked McKinsey’s AI platform. Here’s what holds up — and what doesn’t.
This reflects my personal assessment of publicly available reporting and CodeWall’s published blog post. I was not involved in the testing, I do not have access to McKinsey’s internal facts or forensic findings, and my views should be read as commentary and opinion rather than statements of verified fact.
A security startup called CodeWall claims its autonomous agent compromised McKinsey’s internal AI platform, Lilli, within two hours and gained unauthenticated read-write access to a production database containing tens of millions of consultant conversations. The vulnerability appears credible. The claimed scope of impact is not fully evidenced. The primary CodeWall post is here: codewall.ai/blog/how-… Independent reporting by Jessica Lyons in The Register is here: www.theregister.com/2026/03/0…
Your encrypted email is a neon sign: applying the grey man principle to digital privacy
Every security blog, podcast and YouTube channel gives you the same advice. Use ProtonMail. Switch to Signal. Route everything through Tor. Encrypt your hard drive. The message is always the same: encrypt everything and you will be safe.
I have spent more than 25 years in cybersecurity. I have built intelligence platforms for government agencies and I run security operations for a global enterprise. And I am going to tell you something most privacy guides will not: by following that advice to the letter, you may be making yourself a target instead of protecting yourself.