Blog
Notes from the ops room.
Hosting, infrastructure, development, and SEO — written by the people doing the work.
CVE-2026-76461: Cisco’s Email Security Box Gets Rooted by Email
Security
LiteSpeed Enterprise's Root Access Flaw: One Tenant Can Own the Whole Server
Security
The AI Slowdown Pact: What 'Pace the Frontier' Actually Means
Artificial Intelligence
CVE-2026-85706: One HTTP Request Reads Your GitLab Secrets
Security
CVSS 9.9: cPanel's EmailTrack Flaw Puts Every Shared Hosting Tenant at Risk
Security
GitSpawn: The .git Config Trick That Hijacks AI Coding Agents
Security
BlueMoon: Nation-State Hackers Chain Three CVEs Through Chrome
Security
CVE-2026-86218: When Your MSP's RMM Tool Becomes the Attack Vector
Security
Record Patch Tuesday: 974 CVEs, Two Active Zero-Days, a Wormable DNS RCE
Security
MikroTrick: Two Chained SSH CVEs Are Hijacking MikroTik Routers Across 122,500 Exposed Networks
Security
StyleSmuggler: Magento Zero-Day Under Active Attack — No Patch Yet
Security
CVE-2026-19949: Your Backup Plugin Is Now an Attack Vector for 3.2 Million Sites
WordPress
SonicWall SMA1000's Third Zero-Day Chain: Patch Now — Then Check What July Left Behind
Security
GPT-6 Astra: OpenAI Ships Its First Critical-Rated Cybersecurity AI
Artificial Intelligence
Claude Fable 5.1: 75% Cheaper Cache, EU Watermarks, and a New Line on Security Work
Artificial Intelligence