Security Response

Network Security
Patching Is Not Eradication: When An Edge Appliance Must Be Rebuilt

Decide whether supported remediation can restore trust in a compromised edge appliance. Coordinate containment, evidence preservation, configuration review and credential changes before rebuilding or reconnecting it.

Read this guide
Network Security
When The Firewall Is Compromised, What Else Must Be Rotated?

Map firewall sessions, tokens, VPN secrets, certificates and connected identity services after compromise. Rotate affected trust in dependency order while separating confirmed exposure from systems that were merely reachable.

Read this guide
Network Security
Your Network Configuration Is A Security Log

Use preserved configuration exports and normalized comparisons to detect changes in network access, routing and logging. Correlate differences with identity and runtime evidence; a clean diff does not prove a clean device.

Read this guide
Network Security
The First 60 Minutes Of A Small-Office Cyber Incident

Organize the first hour around clean communications, safety-aware containment, backup protection and an evidence timeline. Prepare a responder handoff without confusing isolation or elapsed time with completed recovery.

Read this guide
Network Security
Frigate 0.17.2 Security And Exposure Audit

Frigate 0.17.2 does not resolve every viewer-access issue identified in its release notes. Review public exposure, authenticated access and camera permissions without treating the update as an all-clear.

Read this guide
Linux and Homelab
Recyclarr 8.7 Security Response: Treat Template Sources as a Write Boundary

A Recyclarr security-response guide for template-provider path traversal: upgrade, inventory providers, protect secrets, compare generated files, and test safely.

Read this guide
Network Security
Authentik 2026 Security Response

Separate Authentik OAuth secret disclosure from inbound SAML account-mapping risks. Plan applicable updates, affected secret and session invalidation, and relying-application identity checks while retaining clean emergency administration.

Read this guide
Network Security
Jellyfin Security: Treat Media as Untrusted Input

Contain untrusted Jellyfin media, preserve evidence, patch to the current stable release, restrict writable paths, validate clients, and recover without returning to a vulnerable version.

Read this guide
Network Security
Tailscale Security Updates: Audit SSH, Serve, Funnel, and Services

Review Tailscale nodes and enabled features against current security bulletins rather than stopping at a historical fixed release. Assess SSH, Services, private Serve and public Funnel as separate exposure paths.

Read this guide
Linux and Homelab
Bazarr 1.6.1 Security Response: Patch or Isolate, Rotate Keys, and Check for RCE

For affected Bazarr builds, isolate untrusted access, preserve evidence and verify a current fixed release. Review exposed secrets and logs before reopening access, distinguishing reasons to investigate from evidence that warrants rebuilding.

Read this guide