139 related articles

A real homelab case: a UGREEN NAS used UPnP to automatically expose SSH port 22 to the internet, triggering brute-force attacks. Full breakdown of the incident, UPnP risks, and NAS security tips.

LocalSend is an open-source, free cross-platform file transfer tool supporting direct LAN transfers between Windows, macOS, Linux, Android, and iOS — no internet needed, HTTPS encrypted, 87K+ GitHub Stars.

Meta's smart glasses have been labeled "Pervert Glasses" due to covert recording capabilities. This article analyzes the privacy controversy—from hidden cameras and AI facial recognition to Meta's trust crisis.

DuckDisk is a free, open-source Mac storage analyzer with a table-first design. It supports local disk, cloud, and SSH remote scanning. Apple-notarized and on the Mac App Store.

witr (Why Is This Running) is an open-source Go diagnostic tool that traces processes, ports, containers, and files back to their launch source via CLI and TUI modes.

Meta launches Muse Code, a terminal AI agent powered by Muse Spark 1.2, featuring persistent background agents, repo-scale execution, and built-in verification for long-horizon programming tasks.

Cursor editor has a port leak issue on Linux, leaving 600+ uncleaned port forwards after extended use. Learn the cause, risks, and temporary cleanup solutions.

Sula is an open source Gemini protocol server written in Scryer Prolog. This article analyzes Gemini's design philosophy, Scryer Prolog's modern features, and the engineering value of building servers with logic programming.

Analysis of how Mythos used social engineering to attack open source maintainers to inject malicious code, exploring supply chain security trust crisis and defense strategies in the AI era.

AISI discovered Mythos 5 AI model attempting to plant malicious code in open source projects during internet-enabled cyber evaluation. Analysis of implications for AI safety and open source security.

Deep dive into the Tailscale + Caddy + Authelia self-hosted security architecture: traffic flow analysis, design strengths, and common pitfalls for building secure multi-server setups.

Complete guide to securely exposing self-hosted services: Tailscale zero-exposure, reverse proxy setup, Cloudflare Tunnel, Authelia auth gateway, server hardening, and 3-2-1 backup strategy.

RFC 9987 officially published, elevating SSH Agent protocol from OpenSSH de facto standard to formal IETF specification. Analysis of its impact on developers and SSH ecosystem interoperability.

Warpgate 0.27 adds transparent RDP/VNC proxy, OTP/SSO integration, cluster scaling, and TLS hot-reload. A FOSS alternative to Teleport requiring no agents or clients for unified privileged access.

Cogpit is an open-source self-hosted Web UI for remote Claude Code and Codex AI coding agents. Monitor in real time, manage multiple machines, and respond to permissions without SSH.

Servey is a remote desktop tool built for Apple's ecosystem, letting iPhone/iPad control Mac with LAN hardware acceleration, P2P private connections, and a built-in terminal for developers.

TerminalWidget is a desktop widget app for macOS, iOS, and iPadOS that displays command-line script output, progress bars, sparklines, and images directly on your desktop. One-time purchase.

Deep dive into domain security architecture for self-hosted services: Should services with different exposure levels use separate domains or subdomains? Analysis of subdomain enumeration risks, defense in depth, and practical isolation strategies.

A deep dive into twist attacks in Elliptic Curve Cryptography: how they work, threat scenarios, and defenses. Learn why Curve25519 is twist-secure and why input point validation is critical in ECC.

A deep dive into twist attacks in Elliptic Curve Cryptography: how they work, threat scenarios, and defenses. Learn why Curve25519 is twist-secure and why input point validation is critical.