The Open Secure AI Alliance: 52 Companies, and Four Conspicuous Absences
The Open Secure AI Alliance launched on July 27 with NVIDIA convening a coalition to build and share open tooling for securing…
Information security is the practice of protecting systems, data, and users from compromise and loss. Articles in this category cover threat models, social engineering, authentication, compliance considerations, and the operational habits that keep an organization defensible at scale.
The Open Secure AI Alliance launched on July 27 with NVIDIA convening a coalition to build and share open tooling for securing…
Buried in Hugging Face’s disclosure of the July 2026 breach of its infrastructure is a detail that most follow-up coverage has skipped,…
wp2shell is the name given to a pair of chained vulnerabilities in WordPress core that together let an unauthenticated attacker run code…
WordPress secrets have historically lived in places that any security review would flag: the WordPress options table, plugin-specific tables, individual user meta…
In mid-July 2026, Hugging Face reported that an autonomous AI agent had broken into part of its production infrastructure. A few days…
Passkeys are the post-password authentication credential. They replace both the traditional password and the additional MFA code that authenticator apps produce, with…
The question that comes up almost every time someone configures their first authenticator app is the right question to start this post…
The Global Device Identifier, or GDID, is a hidden identifier that Microsoft assigns to a Windows device. It is not a hardware…
A WordPress backup is one of the largest exfiltration targets on any site. A full backup contains the database (which holds user…
Pantheon Secrets is the credential-management feature that Pantheon-hosted WordPress sites use to store API keys, OAuth tokens, database credentials, encryption keys, and…