Human Security VPN: myths and facts. Does it really protect you?
Ads promise a VPN gives anonymity and total security. We explain what a VPN really does, what it doesn't protect against and when it's worth using.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Human Security Ads promise a VPN gives anonymity and total security. We explain what a VPN really does, what it doesn't protect against and when it's worth using.
Threats and Incidents What to do when a data breach happens — from confirming the incident, through limiting the impact, to GDPR obligations.
Penetration Testing and AppSec Understand prototype pollution in JavaScript and Node.js, trace pollution sources and gadgets, test safely, and harden applications effectively.
Penetration Testing and AppSec Learn how web race conditions and TOCTOU flaws break business logic, how to test concurrency safely, and which atomic controls actually fix them.
Identity and Access Shared passwords in a spreadsheet are a ticking bomb. How a business password manager works, how to choose one and roll it out to teams.
Threats and Incidents Engineer reliable Sigma rules for SIEM: hypotheses, logsource contracts, correlation, filters, backend tests, tuning, metrics and purple-team validation.
Threats and Incidents Detect DNS tunneling and C2 beaconing through label entropy, query length, NXDOMAIN ratios, record types, timing and endpoint-to-resolver correlation.
Human Security Seniors are fraudsters' most common target: fake grandchild, police or bank staff. Learn the schemes and how to protect parents and grandparents.
Cloud, Infrastructure and DevSecOps The 'hard shell, soft centre' model no longer works. We explain what Zero Trust is, where to start a rollout and what to avoid.
Vulnerabilities and CVEs Technical CopyFail analysis: CVE-2026-31431, algif_aead, splice, page-cache overwrite, affected Linux systems, safe PoC, detection and remediation.
Identity and Access Technical SAML 2.0 testing for XML signatures, wrapping, Audience, Destination, Recipient, replay, RelayState and identity-provider key rotation.
Human Security A hacked friend's account asks for a BLIK code or a scan of your ID. We explain how account takeovers happen and why the chain of trust is the weakest link.
Identity and Access Audit TLS 1.3, mutual TLS and PKI: protocol negotiation, identity validation, certificate paths, revocation, 0-RTT and key rotation.
Governance and Compliance 'Appropriate technical measures' — but which exactly? GDPR Article 32 as an IT checklist: encryption, access, logs, backups and testing.
Cloud, Infrastructure and DevSecOps Replace static CI/CD cloud keys with OIDC, restrict trust by audience, subject and environment, and test AWS, Azure and Google Cloud federation.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.