Blog
Notes from the ops room.
Hosting, infrastructure, development, and SEO — written by the people doing the work.
CVE-2026-42533: The 15-Year NGINX Flaw That Hands Attackers Your Web Server
Security
HollowByte: The 11-Byte OpenSSL Attack That Freezes Your Server
Security
wp2shell: Pre-Auth RCE in WordPress Core — Check Your Version Now
Security
Kimi K3: The 2.8-Trillion-Parameter Open Model That Just Shook the AI Market
Artificial Intelligence
AWS CloudFront Outage: How One Frankfurt AZ Broke Websites Worldwide
Web Hosting
SonicWall SMA1000 Zero-Days: CVSS 10.0 + RCE in Active Exploitation — Patch Before July 17
Security
127 Patches and No Rollback: July 2026 Patch Tuesday's Kerberos Breaking Change
Security
Two Joomla Page Builders Hit with CVSS 10.0 RCE — Actively Exploited
Security
CVE-2026-6722: PHP's SOAP RCE Has a Working Exploit — Patch Today
Security
WP-SHELLSTORM: Hacker's Open Server Exposed 25,000 Backdoored WordPress Sites
WordPress
GhostLock: 15-Year Linux Kernel Bug Has a 5-Second Public Root Exploit
Security
Grok 4.5 Is Here: SpaceX Merges AI Giants and Drops a Cursor-Trained Frontier Model
Artificial Intelligence
Two ModSecurity Flaws Let Attackers Slip Payloads Past Your WAF
Security
JADEPUFFER: The LLM That Ran a Full Ransomware Attack by Itself
Security
Lazarus npm Backdoors Target Developer AWS Keys and AI API Credentials
Security