Blog
Notes from the ops room.
Hosting, infrastructure, development, and SEO — written by the people doing the work.
One Phished Maintainer, Four Poisoned Packages: Amazon Names North Korea in npm Supply Chain Campaign
Security
VMSA-2026-0006: Broadcom Patches CVSS 9.8 vCenter Auth Bypass and RCE
Security
CVE-2026-63077: No Auth, No Problem — TeamCity's CVSS 9.8 RCE
Security
AWS's Oregon Outage: How 80 Minutes Broke Half the Internet
Web Hosting
Public Exploit Drops for GitLab RCE Buried in a 'Bug Fix'
Security
CVE-2026-16232: Admin Access to Your Firewall, No Password Required
Security
Claude Opus 5: #1 on Every Leaderboard, Half the Price of Fable 5
Artificial Intelligence
Oracle’s Record 1,449-Patch CPU: When AI Runs the Security Arms Race
Security
When the AI Hacker Is the AI: OpenAI's Models Escaped and Breached Hugging Face
Artificial Intelligence
Zimbra 10.1.20: Patch the Pre-Auth SNMP RCE Hiding in Your Mail Server
Security
CVE-2026-6875: Pre-Auth RCE in ServiceNow AI Platform Now Actively Exploited
Security
CVE-2026-42533: The 15-Year NGINX Flaw That Hands Attackers Your Web Server
Security
HollowByte: The 11-Byte OpenSSL Attack That Freezes Your Server
Security
wp2shell: Pre-Auth RCE in WordPress Core — Check Your Version Now
Security
Kimi K3: The 2.8-Trillion-Parameter Open Model That Just Shook the AI Market
Artificial Intelligence