532 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

The Tenant Domain That Didn't Renew: cert-manager vs Gardener vs certctl for Per-Tenant TLS
One certificate per tenant collides with Let's Encrypt's 50-per-week ceiling fast. A concrete comparison of cert-manager, Gardener cert-management, and certctl on challenges, secret distribution, and renewal failure modes — plus which one a self-hosted PaaS should default to.

ClawBleed: How One Clicked Link Turned 40,000 Self-Hosted Agent Gateways Into Remote Shells
CVE-2026-25253 let one malicious link steal an OpenClaw gateway token and take over the host. The kill chain, the 40,000 exposed instances, and the gateway-auth checklist for anything an agent can deploy through.

Coolify's MCP Server Just Made Deploy-From-Chat Table Stakes: What 'Ask Claude to Ship It' Really Covers (and What It Doesn't)
Coolify's native read-only MCP endpoint plus 42-tool community servers let agents deploy to self-hosted infrastructure from chat. A labeled walkthrough of the Postgres-to-FastAPI loop, and the five governance controls a fast follower needs.

Coolify Fixed 11 Critical CVEs in v4.0.0 — How to Audit Any Self-Hosted PaaS Before Trusting It With Secrets
Coolify's v4.0.0 release rolled up fixes for 11 critical CVEs, several scoring CVSS 10.0. A breakdown of what the flaws allowed, the patterns they share, and a six-point checklist for auditing any self-hosted platform before it holds your secrets.

Your Ingress-Nginx Has an Expiry Date: What Moving to Gateway API Actually Takes
ingress-nginx maintenance ended in March 2026 and the last vendor patch bridge runs out in November 2026. A before/after resource map, a four-phase migration with no flag day, and the full TLS story for self-hosted fleets.

kuberc Is On by Default: Your kubectl Habits Finally Move Out of the Kubeconfig
Kubernetes 1.36 keeps kuberc beta and on by default, adds a real management CLI, and turns the credential-plugin allowlist rename into a hard error. What the preferences/kubeconfig split means for a shared ops box.

Six Days to Renew: What Let's Encrypt's Short-Lived Certificates Do to Your Renewal Margin
Let's Encrypt's 160-hour shortlived certificates cut renewal slack from 30 days to about 53 hours. The before/after margin math, plus the automation, monitoring, and default-or-opt-in checklist a self-hosted platform needs first.

The Gate That Wasn't There: What Nomad's CVE-2026-14891 Teaches About Scheduler Isolation
Nomad 2.0.4 fixed a CVE that let any job submitter land a container in the host's PID, network, or IPC namespaces — because the allow_privileged check was never evaluated. What the bug, its two sibling fixes, and Kubernetes' admission-time enforcement say about choosing a scheduler for untrusting tenants.

Your npm Token Is the Next Supply-Chain Incident: A Tokenless Publishing Playbook for Git-Push Pipelines
npm's OIDC trusted publishing replaces the long-lived NPM_TOKEN with per-run workload identity and automatic provenance. A six-step migration checklist with version floors and failure modes, the 2026 enforcement timeline through January 2027, and what the pattern means for a self-hosted build pipeline.