Newsletter
Subscribe our newsletter
Get new infrastructure guides, comparison reports, and migration notes in your inbox.
Tag
Security
44 articles tagged Security, newest first.
VMware CVE-2026-59346 Can Reach the Host
CVE-2026-59346 is a critical VMware Workstation and Fusion flaw that can let a privileged VM user execute code on the host through VMXNET3.
Proxmox CVE-2023-54391: Upgrade PVE 7 Now
CVE-2023-54391 is a Proxmox VE authentication bypass affecting old libpve-access-control builds, with real compromises reported in September 2026.
PostgreSQL CVE-2026-6471 Turns Replication Into RCE
CVE-2026-6471 lets a PostgreSQL role with REPLICATION privilege load arbitrary server-visible code, turning a backup-style account into host RCE.
Kubernetes 1.37 Makes Rootless Kubelet Beta
Kubernetes 1.37 promotes KubeletInUserNamespace to beta, letting node components run as a non-root host user and reducing breakout impact.
NetBackup Smartcard Authentication: What to Check
If NetBackup basic authentication through LDAP works but smartcard authentication does not, focus on the certificate authentication path rather than reb...
LockBit 5.0 Is Back in Europe’s Ransomware Top Five
LockBit 5.0 is active again and has returned to the top tier of European ransomware activity.
SharePoint CVE-2026-45659 Is Now a Ransomware Risk
CVE-2026-45659 has crossed the line from a SharePoint patching problem into a ransomware problem.
Shell Investigates Clop Claim of 89GB Data Theft
Shell has confirmed that it is investigating a potential security incident after the Clop group claimed it stole 89GB of data.
Trezor Breach Exposes 13,689 Customer Records
A breach at Trezor shipping provider ShipMonk exposed personal data for approximately 13,689 Trezor customers.
Veeam Security: 9.9 CVEs and Exposed Backup Servers
Veeam security problems in 2026 make one point very clear: patching the backup server is necessary, but patching alone does not define whether the backu...
SolarWinds’ 2026 Price Hike Has Customers Asking the One Question Vendors Fear Most: Why Are We Still Paying?
There’s a certain kind of vendor call that starts out boring and ends up becoming a budget emergency.
SolarWinds Customers Are Furious: The Subscription Shift Feels Less Like Progress and More Like a Shakedown
There’s a special kind of panic that hits when a vendor stops sounding like a partner and starts sounding like a toll booth.
The Homelab Debate Got Ugly Because IncusOS Hit a Nerve
A quiet homelab experiment turned into a surprisingly emotional fight about trust, polish, and what people actually want from their virtualization stack.
Proxmox Finally Has an Official Mobile App, and Half the Community Somehow Missed It
The discovery landed with the perfect kind of homelab confusion: wait, Proxmox has an official iOS app now?
Proxmox Kernel Updates Are Exhausting, But Ignoring Them Feels Even Worse
Kernel updates have been coming fast enough lately that even patient Proxmox users are starting to feel the grind.
Proxmox Mail Gateway 9.1 Is a Boring Release in the Best Possible Way
Proxmox Mail Gateway 9.1 didn’t spark a sprawling argument, which almost feels strange for infrastructure software.
He Got the Data Center Job. Now Comes the Part Nobody Puts in the Offer Letter
Getting hired into a Microsoft contract data center technician role at 21 is the kind of career moment that hits different.
The Data Center Panic Is Overblown, But the Bill Is Still Coming
The phrase “data-center panic” sounds like something cooked up by people who just discovered the cloud has walls, wires, and utility bills.
The Free Data Center Course Everyone Was Desperate to Find
For people trying to break into data center work, the hardest part often isn’t motivation.
Proxmox Quietly Dropped an iOS App, and Homelab Owners Are Feeling Weirdly Seen
A strange little jolt hits when a tool you use every day quietly appears somewhere you didn’t expect.
VMware’s VCF 9.1 Requirements Feel Like a Door Slamming Shut on Smaller Labs
There’s a specific kind of frustration that hits when a platform you’ve invested time, hardware, and patience into suddenly decides your environment isn...
Golden Cages and Quiet Regret: Why Walking Away From Data Centers Feels Impossible — Until It Isn’t
**“Golden Cages and Quiet Regret: Why Walking Away From Data Centers Feels Impossible — Until It Isn’t”** ## The Job Everyone Wants to Leave — But Can’...
Kubernetes’ Quiet Security Revolution Is Here—and It Might Break Everything Before It Fixes Anything
Six years of development, testing, iteration, and probably a lot of second-guessing, and user namespaces in Kubernetes didn’t arrive with fireworks.
Kubernetes Wants You to Move On From Ingress, Yet Gateway API Feels Like a Puzzle Nobody Asked For
**“Kubernetes Wants You to Move On From Ingress, Yet Gateway API Feels Like a Puzzle Nobody Asked For”** ## A Better Idea Trapped Behind a Worse Experi...
Six Years of Silence Explodes Into One Feature That Could Quietly Rewrite Kubernetes Security Forever
**“Six Years of Silence Explodes Into One Feature That Could Quietly Rewrite Kubernetes Security Forever”** ## A Feature Years in the Making Finally Su...
Your Digital Life Will Outlive You—And You’re Probably Handling It Completely Wrong
**“Your Digital Life Will Outlive You—And You’re Probably Handling It Completely Wrong”** ## The Quiet Panic Behind a Simple Question It starts innoce...
Your Server in Your Pocket Sounds Amazing — Until You Realize What You’re Actually Trusting
ProxMan’s Android release promises full Proxmox control from a phone, but it also raises uncomfortable questions about trust, transparency, and mobile ops convenience.
That One Curl Command Could Own Your Server: The Quiet Fear Behind Proxmox Setup Scripts
Why convenience scripts feel irresistible in Proxmox homelabs, and why experienced admins stay wary of blindly running curl-piped setup commands as root.
CVE-2026-22039: How an admission controller vulnerability turned Kubernetes namespaces into a security illusion
Just saw this nasty Kyverno CVE that's a perfect example of why I'm skeptical of admission controllers with god-mode RBAC.
If It Ain't Broke, Don't Fix It... Or Should You? The Real Debate Around Upgrading to Proxmox 9
The debate around Proxmox 9 upgrades is less about shiny new features and more about how admins weigh stability, security updates, and long-term maintenance.
Wait... You Shouldn't Disable Root? The Surprisingly Confusing Reality of Hardening a Proxmox Server
Hardening Proxmox sounds straightforward until standard Linux advice collides with the way the platform actually works, especially around SSH and root access.
Once Your VMware License Expires, the Door Doesn’t Just Close. It Slams.
A March thread about expired vSphere support captures the new VMware reality: old licenses no longer feel like a safety net, they feel like a countdown.
YubiHSM 2 + cert-manager. Hardware-signed TLS certificates on Kubernetes
I built a cert-manager external issuer that signs TLS certificates using a private key inside a YubiHSM 2.
MinIO repo archived - spent 2 days testing K8s S3-compatible alternatives (Helm/Docker)
Hey, MinIO repo got archived on Feb 13, been hunting a K8s-ready S3 object storage for two days.
The Invisible Expired Certificate in vCenter - And Why You Can't See It in Certificate Management
Why the data-encipherment cert alert appears in vCenter even when Certificate Management looks healthy.
Microsoft Is Forcing MFA on 365 Admins, and Breaking Old Workflows in the Process
Microsoft's mandatory MFA enforcement for 365 admin accounts is catching teams off guard, breaking legacy workflows, and forcing overdue security cleanups across organizations of every size.
The End of kubernetes/ingress-nginx: Your March 2026 Migration Playbook
Hey everyone, sharing an article I wrote about the upcoming End-of-Life for the community-maintained kubernetes/ingress-nginx controller happening in March 2026.
Losing the Root Password on VMware ESXi Isn't a Bug — It's a One-Way Door
On modern ESXi, there's no recovery path for a lost root password. That's not an oversight — it's a deliberate security design that forces reinstallation over rescue.
Why Kubernetes 1.35 Feels Like a Security-First Release
Kubernetes 1.35 isn't your typical incremental update. With cgroup v1 dropped, hardened certificate validation, constrained impersonation, and user namespaces enabled by default, this release reads like the security overhaul the platform has needed for years.
Why Some Enterprises Still Ban Docker (and What Devs Are Doing About It)
While containers are mainstream, many large regulated organizations still ban Docker on developer machines. Here's why the restrictions exist and how dev teams work around them.
VMware's AI Integration Is Here—But Do Sysadmins Actually Want It?
VMware AI launches with Intelligent Assist in vDefend, but sysadmins are skeptical. Discover why the community is cautious about AI in production environments and what VMware needs to do to win their trust.
Docker in LXC on Proxmox: Risks, Tradeoffs, and Lessons
Running Docker inside LXC containers on Proxmox seems efficient, but is it safe? Community insights reveal the real risks and rewards of containers-in-containers.
Helper Scripts or Hidden Risks? The Ongoing Debate in the Proxmox Community
The Proxmox community is divided: are helper scripts the ultimate efficiency tool or a security risk waiting to happen? We explore both sides of the automation debate.
When Your Firewall Won't Listen: The Frustration of Locking Down Proxmox's Port 8006
A deep dive into why blocking Proxmox's port 8006 is harder than it looks, exploring the layers of virtual firewalls, VLANs, and the architecture that makes management port control so tricky.