532 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

Railway's December 16 Cryptominer Incident: How Under 10% Infected Workloads Degraded 100% of Regions
Railway's December 16, 2025 postmortem shows how a Next.js RCE that infected under 10% of workloads still degraded every region — and what CPU-isolation guarantees a shared-compute PaaS needs to keep one tenant's breach from becoming everyone else's incident.

SafeLine's 20,900-Star Self-Hosted WAF Claims 99.995% Accuracy: What It Actually Buys You Over Cloudflare
SafeLine's self-hosted WAF claims 99.995% accuracy against SQL injection and DDoS traffic — here's the real cost comparison against Cloudflare, why Hetzner already covers the DDoS part for free, and what a self-hosted PaaS actually gains by shipping one as an ingress default.

SPIFFE/SPIRE for AI Agents: Cryptographic Workload Identity Instead of Long-Lived Service Account Tokens
A hands-on look at issuing an AI deploy-agent a cryptographic identity distinct from a human's with SPIFFE/SPIRE — and the honest operational cost next to the Vault/External-Secrets-Operator setup most self-hosted platforms already run.

Talos Linux's No-Shell Design Barely Scratched by CVE-2026-31431
A 732-byte exploit roots most major Linux distros — here's exactly why Sidero Labs says it barely touches Talos Linux, backed by the binary counts and CVE benchmarks that make the claim checkable.

Vercel Made DDoS Traffic Free in May 2026 — So Why Did a Site Still Get Billed $231.71 for an Attack in June?
Vercel made firewall-blocked DDoS traffic free on May 18, 2026 — but a customer still got hit with a $231.71 bill for a June attack. Here's the exact carve-out in Vercel's policy that still leaves teams exposed, and what changes on owned hardware.

Coolify Shipped an MCP Server. It Still Can't Deploy Your App.
Coolify's official MCP server is strictly read-only — the write-capable 'AI deploys your app' story everyone cites comes from a third-party wrapper holding your API token. Here's the concrete tool-by-tool split, why it matters, and where bex's own MCP server stands on the same line.

One DV Certificate Per Tenant Domain vs Wildcard TLS: The Multi-Tenant Pattern a Self-Hosted PaaS Actually Needs
Wildcard TLS stops covering anything the moment a tenant brings their own domain. Here's the concrete cert-manager and acme.sh architecture — bind-time issuance, renewal fan-out, and offboarding revocation — that replaces it, with the Let's Encrypt rate limits and 45-day certificate timeline that make it non-negotiable.

Self-Hosted Kubernetes Installs Don't Stall on Kubernetes — They Stall on Your Registry, Network, and Approval Chain
Fairwinds' CTO named the real reason self-hosted Kubernetes installs drag on for months — and it's rarely Kubernetes. Here's what that means for any Cluster-API PaaS that might one day sell into a customer's own infrastructure.

Kata Containers vs gVisor: A RuntimeClass Decision Framework for Multi-Tenant Kubernetes
runC's 2025-2026 escape vulnerabilities settled the question of whether untrusted multi-tenant workloads need stronger isolation. This is the decision framework for which one, per workload, actually pays off.