Hardened Bastion on Debian 13: Extreme Hardening with KSPP, Seccomp-BPF and SIEM Telemetry
Most Linux distributions follow a default-permit model: everything is allowed until the administrator restricts it. This post inverts that m
Most Linux distributions follow a default-permit model: everything is allowed until the administrator restricts it. This post inverts that m
What is Fragnesia (CVE-2026-46300)
What is ssh-keysign-pwn (CVE-2026-46333)
What is Dirty Frag (CVE-2026-43284 + CVE-2026-43500)
What is Copy Fail (CVE-2026-31431)
1. Introduction: The Kernel Attack Surface
1. Introduction to OpenCode
USB devices are extremely convenient, but they are also very easy to lose. If your data is not encrypted, anyone could access it.
1. Introduction