← The Log

Website security

Straight talk on keeping your site, your customers, and your data safe.

Security

HTTPS and the padlock: what website security actually protects

That little padlock in the address bar isn't decoration. Here's what it does, what it doesn't, and why every site needs it now.

Jul 26, 2026 · 2 min read
Security

AI is making phishing cheaper. The fixes haven't changed.

Attackers now use AI to target small teams, but the basics, MFA, backups, and updates, still stop the vast majority of it.

Jul 15, 2026 · 2 min read
Security

A PeopleSoft zero-day hit over 100 organizations

An unpatched Oracle PeopleSoft flaw let an extortion crew break into more than 100 organizations, mostly universities, before a fix existed.

Jun 10, 2026 · 2 min read
Security

The SharePoint bug Microsoft forgot to announce

A SharePoint remote-code flaw got patched in May 2026 but wasn't disclosed for weeks, and it was later confirmed to be under active attack.

Apr 29, 2026 · 2 min read
Security

A poisoned axios update slipped into npm

Attackers hijacked the maintainer account behind axios and pushed two backdoored versions of one of JavaScript's most-used libraries.

Apr 15, 2026 · 2 min read
Security

One phone call cost Figure nearly a million records

Fintech lender Figure lost roughly 967,000 customer records after attackers talked an employee into handing over access, no exploit required.

Apr 1, 2026 · 2 min read
Security

React2Shell: a critical flaw in React servers

CVE-2025-55182 lets attackers run code on servers using React Server Components, and exploitation started within days of disclosure.

Dec 10, 2025 · 2 min read
Security

Chrome moves toward warning on every non-HTTPS site

Google announced Chrome will start warning users before loading sites that still run on plain HTTP, making an SSL certificate non-optional.

Oct 22, 2025 · 2 min read
Security

Millions of attacks hit outdated WordPress plugins

Security firm Wordfence blocked millions of attacks in October 2025 targeting known flaws in unpatched WordPress plugins.

Oct 8, 2025 · 2 min read
Security

A self-spreading worm hit the npm ecosystem

The Shai-Hulud worm compromised over 180 npm packages, stealing developer credentials and using them to spread itself.

Sep 10, 2025 · 2 min read
Security

Passkeys go mainstream as passwords fall behind

2025 was the year passkeys reached everyday use, offering small businesses a login that resists the phishing that beats passwords.

Jul 8, 2025 · 2 min read
Security

Ivanti EPMM flaws chained for remote takeover

Two Ivanti Endpoint Manager Mobile bugs could be chained for unauthenticated remote code execution, and attackers were already using them.

May 27, 2025 · 2 min read
Security

PowerSchool breach exposes millions of students

A single stolen support-portal credential let attackers reach personal records for tens of millions of students and teachers.

Jan 20, 2025 · 2 min read
Security

A new accessibility rule is a good reason to check your site

The Justice Department's April 2024 web accessibility rule targets government sites, but it signals a standard every business site should be measuring itself against.

May 15, 2024 · 2 min read
Security

The night the internet learned about worms

On November 2, 1988, one program, the Morris Worm, jammed thousands of the internet's computers overnight and put security on the map for good.

Jun 20, 2023 · 2 min read

Next step

Reading is good. Building is better.

Got something you're dreaming up? Tell us about it and we'll map a course, no pressure.