Blog
Notes from the ops room.
Hosting, infrastructure, development, and SEO — written by the people doing the work.
WP-SHELLSTORM: Hacker's Open Server Exposed 25,000 Backdoored WordPress Sites
WordPress
GhostLock: 15-Year Linux Kernel Bug Has a 5-Second Public Root Exploit
Security
Grok 4.5 Is Here: SpaceX Merges AI Giants and Drops a Cursor-Trained Frontier Model
Artificial Intelligence
Two ModSecurity Flaws Let Attackers Slip Payloads Past Your WAF
Security
JADEPUFFER: The LLM That Ran a Full Ransomware Attack by Itself
Security
Lazarus npm Backdoors Target Developer AWS Keys and AI API Credentials
Security
Bad Epoll (CVE-2026-46242): Any Linux User Can Grab Root
Security
Claude Fable 5 Is Back — After a 19-Day Government Shutdown
Artificial Intelligence
SharePoint RCE CVE-2026-45659: CISA Gives You Until July 4 to Patch
Security
MariaDB 10.6 Reaches End of Life Sunday — Four Days to Upgrade
Web Hosting
34% of Laravel Apps Have Critical Flaws — A 2026 Study of 10,000 Sites Shows Why
Security
CVE-2026-55200: CVSS 9.2 libssh2 Bug Has a PoC — Patch Before Attackers Do
Security
Clean GitHub Repos Are Tricking AI Coding Agents Into Running Malware
Security
GPT-5.6 Launches in Three Tiers — Washington Decides Who Gets In First
Artificial Intelligence
Kirki CVE-2026-8206: Anyone Can Take Admin on Half a Million WordPress Sites
WordPress