Network Security

Network Security
Patch Tailscale 1.98.9: Audit SSH, Serve, Funnel, And Services

A documentation-backed, testable runbook for Patch Tailscale 1.98.9: Audit SSH, Serve, Funnel, And Services, with safe defaults, validation evidence, failure modes, rollback, and publication-day checks.

Read more
Network Security
OpenWrt 24.10.8 and 25.12 Migration Runbook: Patch, Backup, Sysupgrade, and Recovery

An OpenWrt router upgrade runbook for patching exposed services, preserving config, checking device support, testing DHCP, Wi-Fi, DNS, and keeping recovery ready.

Read more
Linux and Homelab
Keycloak 26.7.1 Security Response: Map the Fixes to the Features You Actually Use

Keycloak 26.7.1 includes many security fixes. This guide maps them to OIDC, SAML, FGAP, DCR, LDAP, metrics, and upgrade validation.

Read more
Linux and Homelab
Bazarr 1.6.1 Security Response: Patch or Isolate, Rotate Keys, and Check for RCE

A practical Bazarr response plan for the 1.6.1 authentication bypass chain: isolate exposure, patch, rotate secrets, review logs, and decide when to rebuild.

Read more
Linux and Homelab
Portainer 2.44 Security and Bootstrap Tokens: Secure First Run and Existing Installs

A Portainer security runbook for first-run exposure, setup tokens, agent trust, endpoint permissions, backups, and management-plane isolation.

Read more
Network Security
Entra Connect Sync September 30 Hard Stop

A documentation-backed, testable runbook for Entra Connect Sync September 30 Hard Stop, with safe defaults, validation evidence, failure modes, rollback, and publication-day checks.

Read more
Network Security
Audit Entra Password Reset Before September 7

A documentation-backed, testable runbook for Audit Entra Password Reset Before September 7, with safe defaults, validation evidence, failure modes, rollback, and publication-day checks.

Read more
Homelab
DNS Drift: Why Your Router, Browser, VPN, and Phone Use Different Resolvers

A detailed DNS audit for home networks and homelabs where router DHCP, browser Secure DNS, VPN clients, IPv6, and mobile Private DNS do not agree.

Read more
Homelab
Private DNS for Homelabs Without Leaking Internal Services

A private DNS guide for homelabs: use home.arpa, split-horizon DNS, VPN DNS, and DNS-01 certificates without leaking internal service inventory.

Read more
Homelab
It Is Always DNS: Pi-hole, AdGuard Home, Technitium, and the SPOF Problem

A practical DNS design guide for Pi-hole, AdGuard Home, and Technitium that avoids the single-point-of-failure trap.

Read more