Articles
Fixing Mixed Content Warnings — Finishing the HTTPS Migration You Started
Active vs passive mixed content, how browsers treat each, finding hardcoded http:// URLs, CSP upgrade-insecure-requests, and staying clean after migration.
Kaseya VSA: When the Tool That Manages Everything Gets Hit
Ransomware pushed through Kaseya VSA over a holiday weekend reached businesses via their IT providers. What agencies and small teams should check now.
SolarWinds Orion: When the Monitoring Tool Is the Way In
A trojanized Orion update reached thousands of networks. What we know so far, and what it means for any tool that holds the keys to your infrastructure.
Chrome's SameSite Cookie Change Is Fully Live — What Silently Breaks
Chrome now treats cookies as SameSite=Lax by default, breaking cross-site POSTs, SSO and payment callbacks. What changed, what breaks, and how to fix it.
TLS 1.0 and 1.1 Are Being Shut Out — Time to Check What Your Server Negotiates
Chrome, Firefox and Edge now block TLS 1.0 and 1.1. How to test what your server negotiates, enable TLS 1.2/1.3 on nginx and Apache, and handle legacy clients.
Your VPN Is Production Now: Monitoring the Infrastructure Remote Work Depends On
A month into working from home, the VPN, SSO and internal tools are business-critical. What to monitor, and what not to expose in a hurry.
The Capital One Breach: SSRF, Metadata Endpoints and Over-Privileged Roles
A week after Capital One disclosed its breach, here's what the public record says, why SSRF keeps coming up, and what to check on your own cloud servers.
The .dev TLD Is Here, and It's HTTPS-Only by Design
Google's .dev domains open to the public this month, and the whole TLD is HSTS-preloaded. What preloading means, and how to launch HTTPS-only from day one.
TLS 1.3 Is Final: What RFC 8446 Changes and What to Do About It
TLS 1.3 is final as RFC 8446, after four years and 28 drafts. What changed, what was removed, and how to check what your servers negotiate.
Chrome 68 Is Here: Every HTTP Page Now Says “Not Secure”
Chrome 68 now labels every HTTP page Not Secure. A migration checklist covering free certificates, redirects, mixed content, HSTS and what comes after.
PCI's June 30 Deadline: Turning Off TLS 1.0 Without Locking Out Customers
PCI DSS requires SSL and early TLS to be gone from payment environments by June 30. How to check what you negotiate, change it safely, and spot who it breaks.
GDPR Lands in Three Days: A Practical Checklist for Website Operators
GDPR takes effect May 25. A practical, non-lawyer guide for site operators covering IP addresses, cookie consent, vendor inventories and the 72-hour breach clock.
More topics
Get notified when CompleteStatus opens
New accounts are closed while we're in private beta. Leave your email and we'll send one message the moment sign-ups open — nothing else.