Blog - Security

Short version: On 8 September 2026 Microsoft shipped the largest Patch Tuesday so far – about 974 CVEs, including two actively exploited zero-days and several critical bugs in Remote Desktop (RDP). If you run a Windows V-Server or root server, update today and reboot. Not “s...

On September 1, 2026, Mozilla released several security updates for Firefox and Thunderbird. A total of 29 security vulnerabilities were closed in the browser and 30 in the mail client – including 13 classified as "high" severity.   Risks and Poten...

Quick reality check: WordPress 7.1 “Mary Lou” shipped on 19 August 2026. This is not a security drop like 7.0.4. It is a feature release — and on a chunk of VPS sites the only thing left was “There has been a critical error on this website”. Not because core is broken. Becau...

Quick reality check: WordPress 7.0.4 shipped on 12 August 2026 — not a feature release, a security fix. CVE-2026-65640 (GHSA-8vr3-7mxf-gx8w) is remote code execution through a file upload. The prerequisites are an Author or higher account plus Imagick and Ghostscript on the...

Quick reality check: Linux 7.2 went stable on 16 August 2026. Desktop blogs will talk HDMI and laptops. Hosting should talk about something else: the scheduler finally understands modern Ryzen and EPYC chiplets, KVM gets stricter, and Landlock can constrain UDP — the layer g...

Quick reality check: “Local AI” sounds like privacy. In practice, tens of thousands of VPS instances just hang port 11434 on the internet — with no login. Then Ollama is not a private model. It is a public API. Bleeding Llama (CVE-2026-7482) made that brutally obvious in May...

Quick reality check: A DDoS against an online shop often just makes the site “slow”. Against a game server it makes the match unplayable. In 2026 that is not vibes — it is what communities deal with every week. Shops sit behind HTTP, CDNs and WAFs. Minecraft, CS2, Rust, Five...

Quick reality check: A cheap game server or VPS looks great — until the first DDoS hits. Then slot counts and marketing badges do not matter. Reachability does. What often happens on budget hosts Players see timeouts, packet loss and dead voice channels. Some providers only...

Aktuell wurde eine Sicherheitslücke im Linux-KVM-Virtualisierungsbereich bekannt. Die Schwachstelle CVE-2026-53359 betrifft die KVM-Virtualisierungsschicht und kann unter bestimmten Voraussetzungen die Isolation zwischen einer virtuellen Maschine und dem darunterliegend...

Categories

Security

Archive

2026