Security Response
Frigate 0.17.2 Security And Exposure AuditNew!!
A documentation-backed, testable runbook for Frigate 0.17.2 Security And Exposure Audit, with safe defaults, validation evidence, failure modes, rollback, and publication-day checks.
Recyclarr 8.7 Security Response: Treat Template Sources as a Write BoundaryNew!!
A Recyclarr security-response guide for template-provider path traversal: upgrade, inventory providers, protect secrets, compare generated files, and test safely.
Jellyfin 10.11.10+ Security: Treat Media as Untrusted InputNew!!
Contain untrusted Jellyfin media, preserve evidence, patch to the current stable release, restrict writable paths, validate clients, and recover without returning to a vulnerable version.
Patch Tailscale 1.98.9: Audit SSH, Serve, Funnel, And ServicesNew!!
A documentation-backed, testable runbook for Patch Tailscale 1.98.9: Audit SSH, Serve, Funnel, And Services, with safe defaults, validation evidence, failure modes, rollback, and publication-day checks.
Bazarr 1.6.1 Security Response: Patch or Isolate, Rotate Keys, and Check for RCE
A practical Bazarr response plan for the 1.6.1 authentication bypass chain: isolate exposure, patch, rotate secrets, review logs, and decide when to rebuild.
Portainer 2.44 Security and Bootstrap Tokens: Secure First Run and Existing Installs
A Portainer security runbook for first-run exposure, setup tokens, agent trust, endpoint permissions, backups, and management-plane isolation.







