What Self-Hosters Are Ripping Out of Their Stacks in 2026
Self-hosted email is losing to Gmail's hard SMTP rejections. Self-hosted password managers are split down the middle. And self-hosted music is doing the opposite of what you'd expect.
Cybersecurity
Vulnerabilities, exploits, cryptography and defensive engineering — written by people who patch real servers.
# nmap -sV --top-ports 6 10.0.0.12
PORT STATE SERVICE
22/tcp open ssh OpenSSH 9.6
80/tcp open http nginx 1.26
443/tcp open https
3306/tcp filtered mysql
[!] CVE-2024-6387 — patch applied
$ cat START_HERE.md
Self-hosted email is losing to Gmail's hard SMTP rejections. Self-hosted password managers are split down the middle. And self-hosted music is doing the opposite of what you'd expect.
Part 1 ended on a 70-gigabyte breach in 2021. Since then, hacktivists derailed trains, dumped molten steel on camera, and reached grids in three countries.
Forum Archaeology #1: I built plugins for this software when it ran half the internet's communities. Sixteen years after the exodus that should have killed it, vBulletin is still getting hit with critical, unauthenticated remote code execution.
$ ls -t ~/cybersecurity
Four tools solve four different problems that all get pitched as the same problem. Here's what each one does, where each one breaks, and the combination that covers a real homelab without paying an SSO tax you didn't see coming.
A growing list of open-core self-hosted projects, from Grafana to Planka, gate single sign-on behind an Enterprise tier. Here's which protocol actually gets paywalled, and what to check before you deploy.
Forum Archaeology #2. Three free PHP forum platforms started from the same premise a generation ago. One got hit with a CVSS 9.8 authentication bypass this June. One had eleven CVEs last year. One has stayed almost quiet. Same premise, three completely different fates.
A logic bug in screensharingd let attackers skip authentication entirely and land as root — no password required. Here's how it was found, patched, reverse-engineered, and finally weaponized.
Part 1 ended on a 70-gigabyte breach in 2021. Since then, hacktivists derailed trains, dumped molten steel on camera, and reached grids in three countries.
Cloudflare open-sourced its internal AI workspace. A technical breakdown of Dynamic Workers, Gatekeepers, capability-based access, and what it takes to self-host it.
Forum Archaeology #1: I built plugins for this software when it ran half the internet's communities. Sixteen years after the exodus that should have killed it, vBulletin is still getting hit with critical, unauthenticated remote code execution.
CVE-2026-53359 lets a guest VM crash or potentially root your Proxmox host, and it hid in KVM's shared code for 16 years. What to patch and how to check.
CVE-2026-55010 lets an attacker take over your Bedrock server with one packet, no login required. What it actually affects, and how to patch it today.
Ghost Check #1: the Puppet Master hacked minds by exploiting the gap between what a system experiences and what it can verify. Thirty-one years later, a researcher did the same thing to Microsoft 365 Copilot with a single email.
Claude Mythos halved HAWK's effective key strength and sped up an AES attack 200-800x. What the math actually shows, and what it doesn't mean yet.
Here's the complete patch-status and lockdown guide, including the systemd hardening, origin validation, env-variable command injection fix, ClawHub skill safety, and how to tell if you've already been hit.
$ ssh community@sudosecurity
Ask in the forums, share a snippet, or work through a course on Learn.