Insights, tutorials and best practices from the world of Cloud, DevOps and Open Source
Security

Bleeding Llama (CVE-2026-7482): Why Self-Hosted AI Isn't Automatically Secure AI
Three unauthenticated API calls. No login, no exploit framework, no privilege escalation. Three POST requests to a default port, and the machine's memory is on...

Linux Kernel Vulnerabilities 2026: Why Patch Management Is Now a Board-Level Issue (Dirty Frag, Copy Fail & Co.)
Three critical Local Privilege Escalation vulnerabilities in the Linux kernel within two weeks — all three sitting in the code for nine to twelve years....

CVSS 9.9, CVSS 10.0, 1.5M Servers Affected: Why Enterprises Need CVE Monitoring
Three numbers from the last four months: - CVSS 9.9 — Jellyfin: Path Traversal → Remote Code Execution as Root - CVSS 10.0 — n8n: Unauthenticated...

Authentik vs. Zitadel 2026: Open-Source Identity Provider Comparison
If you're looking for an Okta or Auth0 alternative, two open-source projects quickly rise to the top: Authentik and Zitadel. Both solve the same problem...

Coolify CVE Overview 2025/2026: Critical Vulnerabilities and Urgent Update Required
Coolify is a popular self-hosted PaaS platform and alternative to Heroku, Netlify, or Vercel. The platform orchestrates deployments and server automation – which is exactly...

React2Shell: Critical Security Vulnerability in Next.js and React – Act Now!
On December 3, 2025, one of the most severe security vulnerabilities in recent years was disclosed in the JavaScript ecosystem: CVE-2025-55182, also known as React2Shell....
Let's Talk About Your Idea
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.





