Insights, tutorials and best practices from the world of Cloud, DevOps and Open Source
All Posts

cPanel CVE-2026-41940: 44,000 Servers Compromised — What Companies on Shared Hosting Need to Do Now
A cPanel vulnerability that has been actively exploited since 23 February 2026 is officially disclosed on 28 April 2026. By 5 May, more than 44,000...

Cisco ASA, ArcaneDoor & CVE-2025-20362: WireGuard and NetBird as a Modern VPN Stack
A Cisco ASA vulnerability from September 2025 is still being actively exploited in May 2026. Seven months after the patch, CrowdSec counts 292 source IPs...

Vaultwarden 1.36.0 & NIS2: Self-Hosted Password Management for SMBs
On 3 May 2026 the Vaultwarden maintainer team released version 1.36.0 — closing six security advisories, one of which is a server-side request forgery that...

Bleeding Llama (CVE-2026-7482): Why Self-Hosted AI Isn't Automatically Secure AI
Three unauthenticated API calls. No login, no exploit framework, no privilege escalation. Three POST requests to a default port, and the machine's memory is on...

Linux Kernel Vulnerabilities 2026: Why Patch Management Is Now a Board-Level Issue (Dirty Frag, Copy Fail & Co.)
Three critical Local Privilege Escalation vulnerabilities in the Linux kernel within two weeks — all three sitting in the code for nine to twelve years....

EU AI Act: High-Risk Obligations Deferred to December 2027 - What Still Starts in August 2026
The EU AI Act's high-risk obligations do not start on 2 August 2026. Stand-alone high-risk systems under Annex III now have until 2 December 2027,...
Let's Talk About Your Idea
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.





