Insights, tutorials and best practices from the world of Cloud, DevOps and Open Source
Security

OpenBao or HashiCorp Vault: secrets management after the licence change
HashiCorp Vault has been the default answer to central management of credentials and certificates for years. Since the 2023 licence change, OpenBao sits alongside it,...

CRA reporting obligation from 11 September 2026: who reports, what and when
On 11 September 2026 the first operational obligation of the Cyber Resilience Act takes effect. It is narrowly scoped: it concerns reporting only, not conformity...

Metabase emergency patch: SQL injection rated CVSS 10.0 is being actively exploited
Metabase closed two critical vulnerabilities on 6 August 2026. The more severe one carries CVSS 10.0 and is, according to the vendor, being actively exploited:...

Zoom CVE-2026-53412: critical account takeover and sovereign alternatives
On 14 July 2026, Zoom disclosed a vulnerability rated critical in its Windows client: CVE-2026-53412 allows an unauthenticated attacker to take over an account through...

pedit COW & DirtyClone: Two Critical Linux Kernel Flaws in 2026
Within a few weeks in 2026, two Linux kernel local privilege-escalation flaws were published that work the same way: CVE-2026-46331 (nicknamed "pedit COW") and CVE-2026-43503...

Self-Host RustDesk 2026: the Sovereign TeamViewer Alternative Done Right
RustDesk has made unflattering headlines repeatedly in the first half of 2026: a botnet abusing the public server, a forced login on the demo server,...
Let's Talk About Your Idea
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.





