Security
Generate MD5, SHA-1, SHA-256 and SHA-512 hashes instantly — for passwords, files and data integrity.
Generate strong, random passwords with custom length and character rules.
zxcvbn-style entropy + crack-time at 4 attack profiles · browser-only
Find the homoglyphs — UTS #39 skeletons, scripts and punycode for any string
Qihoo 360's LLM family
Automated code-quality and security gates for pull requests
Acquired by Datadog in 2023 — standalone code analysis shut down
Dark-web threat intel, now Bitsight's CTI engine.
Agentless DSPM that maps sensitive data in a day.
AI SOC analyst that investigates every alert end-to-end
UEBA-first SIEM that auto-builds the incident timeline
Next-gen SIEM with built-in detection and correlation.
ML-based DLP tuned for SaaS, email, and AI apps.
MIT-licensed LLM eval and red-teaming CLI, now owned by OpenAI
Autonomous AI SOC that triages every alert, escalates the real ones
Blocks malicious npm/PyPI packages at PR time.
Runtime CNAPP unifying cloud and AI-workload defense
No-code security automation with an autonomous SOC agent
The DMARC tag that meant 10% of the time now means all the time
RFC 9989 removed the pct tag in May 2026, and the same document says receivers must ignore tags that are not r...
KE
4 Sep
The lookalike domain that is blocked on .com and shown on .ru
The famous all-Cyrillic apple.com impersonation was patched in 2017 and the matter filed as closed. Both major...
KE
1 Sep
How to Self-Host Gitea or Forgejo with Docker
The environment variable that closes public registration was renamed, so copying an older tutorial leaves your...
KE
31 Aug
What an ID number's check digit actually proves
The last character of most identity numbers is computed from the ones before it, using a published formula any...
PR
31 Aug
How to Set Up Caddy as a Reverse Proxy with Docker
Caddy gets certificates without being asked, which is why it is the right first reverse proxy. The confusion s...
KE
31 Aug
How to Self-Host Vaultwarden with Docker
The compose file is trivial. The admin token is not: it wants an Argon2 hash rather than a password, and the h...
KE
30 Aug
How to Stop ChatGPT, Claude, Gemini and Grok Training on Your Chats (2026)
Four switches with almost the same name, doing four different things. Three are on by default. One also sets y...
PR
29 Aug
Why CSV Libraries Do Not Stop Formula Injection
The same six values written by Python, by PHP, and by joining strings with commas. The libraries fix the comma...
EV
25 Aug
Which Image Operations Strip Metadata
A source image with six identifying tags and GPS coordinates, put through eight operations. Pillow drops every...
PR
25 Aug
What Your Rate Limit Actually Limits
A route limited to 30 a minute and one limited to 60 turned out to share a single counter, because the framewo...
KE
22 Aug
How to Stop an Agent Returning Documents the User Should Not See
A vector search scoped three ways, and measured each time. Unfiltered, four in five results belonged to anothe...
PR
21 Aug
How Old Is the Code You Installed?
The median package in this site's tree was published 286 days ago — but one in five has seen no release in two...
KE
20 Aug
What Installing an Agent Toolkit Actually Grants
Giving an agent tools is one line of configuration, and that line does not say what any of them can do. We rea...
KE
20 Aug
Three DNS Records Almost Nobody Publishes
DNSSEC, CAA and MTA-STS each protect people who will never know they exist. Across 18 major ASEAN banks, gover...
KE
19 Aug
Can You Prove an Attack Was Prevented?
Early warning is what threat intelligence is sold on, and prevention is the least verifiable claim in security...
PR
19 Aug
Who Sells Threat Intelligence
Four quite different businesses use the same phrase, which is most of why the market is confusing. A map of th...
PR
19 Aug
What Your Own Domain Tells a Stranger
OSINT needs no budget and no access. We ran it against our own domain and found 26 robots.txt rules naming /ad...
KE
19 Aug
What a Threat Actor Name Buys You
Reporting names adversaries with real confidence — APT29, Lazarus, Sandworm — and it is worth asking how much...
KE
19 Aug
From Feed to Decision
Buying a threat feed is the easy part. We work through the filtering that free public data already does to a s...
PR
19 Aug
What Threat Intelligence Actually Is
380,235 vulnerabilities have been published. 1,670 are confirmed to be exploited in the wild — about one in 22...
PR
19 Aug
Many Security Policies Permit the Attacks They Are Meant to Block
Eighteen ASEAN banks, government portals and telcos send a mean of 3.7 of 5 browser-protection headers, which...
KE
19 Aug
Signed Is Not the Same as Traceable
Every package npm serves carries a registry signature, so 100% of our dependencies look verified. Only 10.8% o...
PR
19 Aug
Your Bank Is Still on IPv4
We asked DNS whether 18 institutions across six ASEAN economies — the largest bank, the government portal and...
MA
19 Aug
Most of an AI Attack Is an Ordinary Attack
MITRE's AI threat matrix, ATLAS, shares 13 of its 16 tactics with classical ATT&CK. Only two are genuinely new...
PR
19 Aug