HTTPS and the padlock: what website security actually protects
That little padlock in the address bar isn't decoration. Here's what it does, what it doesn't, and why every site needs it now.
AI is making phishing cheaper. The fixes haven't changed.
Attackers now use AI to target small teams, but the basics, MFA, backups, and updates, still stop the vast majority of it.
A PeopleSoft zero-day hit over 100 organizations
An unpatched Oracle PeopleSoft flaw let an extortion crew break into more than 100 organizations, mostly universities, before a fix existed.
The SharePoint bug Microsoft forgot to announce
A SharePoint remote-code flaw got patched in May 2026 but wasn't disclosed for weeks, and it was later confirmed to be under active attack.
A poisoned axios update slipped into npm
Attackers hijacked the maintainer account behind axios and pushed two backdoored versions of one of JavaScript's most-used libraries.
One phone call cost Figure nearly a million records
Fintech lender Figure lost roughly 967,000 customer records after attackers talked an employee into handing over access, no exploit required.
React2Shell: a critical flaw in React servers
CVE-2025-55182 lets attackers run code on servers using React Server Components, and exploitation started within days of disclosure.
Chrome moves toward warning on every non-HTTPS site
Google announced Chrome will start warning users before loading sites that still run on plain HTTP, making an SSL certificate non-optional.
Millions of attacks hit outdated WordPress plugins
Security firm Wordfence blocked millions of attacks in October 2025 targeting known flaws in unpatched WordPress plugins.
A self-spreading worm hit the npm ecosystem
The Shai-Hulud worm compromised over 180 npm packages, stealing developer credentials and using them to spread itself.
Passkeys go mainstream as passwords fall behind
2025 was the year passkeys reached everyday use, offering small businesses a login that resists the phishing that beats passwords.
Ivanti EPMM flaws chained for remote takeover
Two Ivanti Endpoint Manager Mobile bugs could be chained for unauthenticated remote code execution, and attackers were already using them.
PowerSchool breach exposes millions of students
A single stolen support-portal credential let attackers reach personal records for tens of millions of students and teachers.
A new accessibility rule is a good reason to check your site
The Justice Department's April 2024 web accessibility rule targets government sites, but it signals a standard every business site should be measuring itself against.
The night the internet learned about worms
On November 2, 1988, one program, the Morris Worm, jammed thousands of the internet's computers overnight and put security on the map for good.
Next step
Reading is good. Building is better.
Got something you're dreaming up? Tell us about it and we'll map a course, no pressure.