search
Server administration
Trends
- 1AI scrapers are straining Mastodon serversโ๐ค Anche Mastodon sta pagando a caro prezzo la corsa all'AI. Negli ultimi mesi diverse istanze Mastodon hanno subito picc
Several Mastodon instances have reported abnormal spikes in storage use and traffic in recent months, caused by bots and crawlers scraping public pages to collect content, reportedly for training AI systems. Instance administrators are raising alarms about the growing costs and technical burden that the AI data rush is imposing on volunteer-run, decentralised social media infrastructure.
- 2Mastodon.energy server funding drive stalls as no new donors step upโผMaybe we should sell tote bags or t-shirts ;) 0 new users have stepped forward to chip in towards server costs since Jul
The mastodon.energy server administrator says no new users have contributed to server costs since July, despite ongoing fundraising that began in 2024, jokingly suggesting the instance might sell tote bags or t-shirts to close the gap. Six regular donors are thanked for keeping the climate-focused Mastodon server running, and the admin's appeal highlights the broader financial strain on volunteer-run social media instances.
- 3Pocketty launches iPhone SSH terminal that pings when agents stallโShow HN: Pocketty โ iPhone SSH terminal that pings you when an agent is blocked
A developer has released Pocketty, an iPhone SSH terminal designed for managing remote servers from a phone. Its distinguishing feature is notifications that alert users when an AI coding agent gets blocked and needs input, letting them step away while long-running tasks proceed. The launch is drawing attention among developers interested in mobile workflows and agent-assisted coding, with discussion centering on whether phone-based server administration is practical.
- 4Nvidia patches high-severity GPU monitoring flawโHigh-severity Nvidia bug could crash GPU monitoring on exposed servers The GPU giant released a fix for the flaw, tracke
Nvidia has released a fix for a high-severity vulnerability, tracked as CVE-2026-47483, that could crash GPU monitoring software on servers exposed to the network. Security outlets are covering the flaw and urging administrators running GPU workloads on public-facing servers to apply the patch promptly to avoid monitoring outages.
- 5
The OpenSSH project has released version 10.6, updating its widely used secure shell software for encrypted remote access. The release notes are published on the official OpenSSH site. Developers and system administrators are discussing the update, as OpenSSH runs on most servers and new releases typically bring security hardening and bug fixes that teams need to apply quickly.
- 6Attackers Exploit Critical Rejetto HFS Session Forgery Flawโผโ ๏ธ CRITICAL: Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE Rejetto HFS vulnerability CVE-
A critical vulnerability in Rejetto HTTP File Server, tracked as CVE-2026-61500, lets attackers forge admin sessions and achieve remote code execution through weakly signed session cookies. Security researchers report active exploitation detected in October 2026, with warnings circulating urging administrators to patch exposed HFS servers immediately.
- 7OpenSSH 10.6 released with security updatesโopenssh-10.6 released https://www. undeadly.org/cgi?action=articl e;sid=20261007052827 # openbsd # openssh # ssh # secur
The OpenSSH project has released version 10.6, the widely used secure shell tool for encrypted remote logins. The release was announced via the OpenBSD community's Undeadly news site and is being shared among system administrators and security professionals, who track OpenSSH updates closely because the software is deployed on millions of servers worldwide.
- 8User quits Mastodon over instance censorship complaintsโI'm leaving Mastodon. Two censoring instances in a row is two too many. If I find an instance that DOESN'T censor, I may
A Mastodon user says they are leaving the decentralised social network, citing moderation by two consecutive instances as unacceptable censorship. They plan to post on DreamWidth for now and may return if they find an instance that does not moderate content, asking others for recommendations. The complaint highlights ongoing debate over how much moderation power instance administrators should hold on Mastodon, where rules vary widely between servers.
- 9Discord bot Double Counter breach exposes one million emailsโผA security breach has compromised the Discord protection bot Double Counter, resulting in the exposure of approximately 1 million email addresses
A security breach has hit Double Counter, a widely used Discord bot that blocks alt accounts, exposing the email addresses of roughly one million users. The incident raises concerns about how third-party Discord bots store user data, since many servers rely on such verification tools without auditing their security practices.
- 10OpenSSL 4.0.3 Released as Security Patch, Update Nowโ# OpenSSL 4.0.3 Is Out as Another # Security Patch Release, Update Now https:// 9to5linux.com/openssl-4-0-3-is -out-as-a
The OpenSSL project has released version 4.0.3, another security patch release addressing vulnerabilities in the widely used encryption library. The news is spreading through the free and open source software community, where users are being urged to update their systems promptly. As OpenSSL underpins encrypted connections across much of the internet, admins of Linux servers and other deployments are expected to apply the patch quickly.
- 11CISA adds five exploited server flaws to must-patch listโ๐ด EXPLOITED CISA added five old self-hosted server bugs to its must-patch list: BIND, ProFTPD, Struts, ONLYOFFICE, Strap
CISA has added five actively exploited vulnerabilities in widely used self-hosted server software to its Known Exploited Vulnerabilities catalog: BIND, ProFTPD, Apache Struts, ONLYOFFICE and Strapi. Some of the flaws date back to 2015, and China-linked scanning activity is reported to be hitting them at scale. US federal agencies must apply fixes by October 11. Security practitioners are urging self-hosters to patch quickly.
- 12Veeam Patches Critical RCE Flaw in Backup & Replication SoftwareโVeeam Patches Critical Remote Code Execution Flaw in Backup & Replication Software Veeam patched four vulnerabilities in
Veeam has released security updates for Backup & Replication version 12, fixing four vulnerabilities. The most serious, tracked as CVE-2025-64393, is a critical remote code execution flaw that could let low-privileged users take control of the backup server. Security professionals are urging administrators to apply the patches quickly, since backup infrastructure is a frequent target in ransomware attacks.
- 13What's New in OpenBSD's httpd and relaydโHeaders Up! What's New in httpd and relayd https://rsadowski.de/posts/2026/update-relayd-and-httpd/ # OpenSource # WebDe
A new write-up by Rainer Sadowski covers recent changes to OpenBSD's httpd web server and relayd load balancer, with a focus on header handling. The post walks through what has been updated in the two lightweight daemons and what administrators should know when running them. Discussion is drawing interest from the sysadmin and web development community.
- 14Double Counter Discord Breach Exposes Millions of User RecordsโผDouble Counter Discord Breach Exposes Millions of User Records | Outlook Respawn
Double Counter, a widely used Discord bot, has reportedly suffered a data breach exposing records belonging to millions of users. The incident adds to a string of security problems affecting third-party Discord tools, raising concerns about how bot developers store and protect user data. Discord users and security watchers are urging server administrators to review permissions and reconsider which bots they keep installed.
- 15Mastodon's moderation power draws authoritarianism criticismโMastodon is a great idea, but it has a fatal flaw: authoritarianism. Mods and admins are free to censor posts and users
Critics of Mastodon are arguing that the decentralized social network suffers from a fundamental flaw: moderators and server administrators can censor posts and remove users at will, with little oversight or appeal. The complaint holds that too many moderators exercise this power eagerly and arbitrarily, and some are calling for a Mastodon instance governed more democratically, where users have a real say in moderation decisions.
- 16Veganism.social emerges as a dedicated vegan Mastodon serverโVeganism.social is a Mastodon server for vegans to make friends and interact with the wider Fediverse. This server has a
Veganism.social is being highlighted as a Mastodon server where vegans can connect, make friends and interact with the wider Fediverse. The server allows posts of up to 10,000 characters, longer than many mainstream platforms permit, and directs newcomers to its about page for details on joining and contacting its administrator.
- 17Privilege vulnerability flagged in Progress Telerik Report Serverโ๐จ EUVD-2026-95523 ๐ Score: 7.1/10 (CVSS v3.1) ๐ฆ Product: Telerik Report Server ๐ข Vendor: Progress Software ๐ Updated: 20
A medium-severity vulnerability, tracked as EUVD-2026-95523 with a CVSS score of 7.1, has been disclosed in Progress Software's Telerik Report Server. The flaw stems from incorrect privilege assignment in the service-agent SignalR hub and affects all versions prior to 12.2.26.1007. Users are advised to update their installations to the patched release to close the gap.
- 18High-severity stored XSS flaw found in Telerik Report Serverโ๐จ EUVD-2026-95524 ๐ Score: 8.9/10 (CVSS v3.1) ๐ฆ Product: Telerik Report Server ๐ข Vendor: Progress Software ๐ Updated: 20
A new vulnerability, EUVD-2026-95524, has been catalogued affecting Progress Software's Telerik Report Server. Versions prior to 12.2.26.1007 contain a stored cross-site scripting flaw in the shared reporting engine, rated 8.9 out of 10 on the CVSS v3.1 scale. Administrators running affected versions are advised to update to the patched release.
- 19Umbrel 2.0 wins over a Fedora server adminโI have really liked what # Umbrel 2.0 has done. So much so that I moved my data and wiped my main Fedora server and inst
Umbrel 2.0 is drawing praise from self-hosting enthusiasts. One administrator says the release impressed him enough that he wiped his main Fedora server, installed Umbrel in its place, and has run it for about two weeks. He is now weighing whether to consolidate his scattered data silos and build a new NAS or homelab setup around the platform.
- 20Critical Rejetto HFS Flaw Actively Exploited for Remote Code ExecutionโผVulnerability in Rejetto HFS Leads to Remote Code Execution, Actively Exploited A critical authentication bypass is repo
A critical authentication bypass in Rejetto HFS, tracked as CVE-2026-61500, allows attackers to forge administrator sessions and achieve remote code execution. Security researchers report the flaw is being actively exploited in the wild, letting intruders take full control of affected file servers. Administrators are urged to patch exposed HFS instances immediately.
- 21X.Org Foundation patches 12 critical vulnerabilities in X ServerโX.Org Foundation Patches 12 Critical Vulnerabilities in X Server and Xwayland X.Org released security updates for X.Org
The X.Org Foundation has released security updates for X.Org Server and Xwayland fixing 12 critical vulnerabilities rated 9.1 on the CVSS scale. The flaws could allow arbitrary code execution, server crashes and information disclosure. Users are urged to update their systems promptly, and the disclosure is drawing attention in the security community.
- 22Microsoft fixes heap buffer overflow in Windows Program Compatibility Assistantโ๐จ EUVD-2026-73016 ๐ Score: 7.0/10 (CVSS v3.1) ๐ฆ Product: Windows Server 2019, Windows 11 Version 25H2, Windows 10 Versio
A newly catalogued vulnerability, EUVD-2026-73016, describes a heap-based buffer overflow in the Windows Program Compatibility Assistant affecting Microsoft Windows Server 2019, Windows 11 Version 25H2, Windows 10 Version 21H2 and more than a dozen other Windows versions. The flaw carries a CVSS v3.1 severity score of 7.0, classifying it as high severity. It was published on 8 September 2026 and updated on 7 October 2026, and security teams are being urged to check their systems for patched versions.
- 23Discord bot Double Counter breach exposes one million email addressesโ๐ฎ Discord protection bot Double Counter hit by breach exposing around 1 million email addresses Double Counter, a servic
Double Counter, a bot used by Discord server administrators to block raids and alt accounts, has suffered a data breach exposing roughly one million email addresses along with Discord user IDs. The incident raises concerns about security practices for third-party bots with access to large community data, and affected users are being warned to stay alert for phishing attempts using their exposed details.
- 24Guide: Installing DNSControl on Ubuntu VPS for PowerDNS ManagementโHow to Install # DNSControl on # Ubuntu # VPS to Manage # PowerDNS This article demonstrates how to install DNSControl o
A new tutorial walks through installing DNSControl, an open-source tool for managing DNS records across multiple providers, on an Ubuntu VPS and configuring it to control PowerDNS servers. The guide covers what DNSControl is, the installation steps, and how to connect it to PowerDNS, aimed at administrators who want to automate and centralize DNS management from the command line.
- 25Atlassian products hit by critical vulnerability scoring 9.3โผ๐จ EUVD-2026-92807 ๐ Score: 9.3/10 (CVSS v3.1) ๐ฆ Product: Bitbucket Data Center, Crowd Server, Crucible Data Center (+13
Atlassian has a critical vulnerability, tracked as EUVD-2026-92807, affecting a range of its enterprise products including Bitbucket Data Center, Crowd Server, Crucible Data Center, Confluence Data Center and Jira Service Management. The flaw carries a CVSS v3.1 severity score of 9.3 out of 10, putting it in the critical range. The advisory was updated on 5 October 2026, and security teams are being urged to check whether their deployments of the affected Atlassian products are exposed.
- 26Microsoft Windows vulnerability EUVD-2026-73018 rated 5.7โ๐จ EUVD-2026-73018 ๐ Score: 5.7/10 (CVSS v3.1) ๐ฆ Product: Windows 10 Version 1809, Windows 10 Version 21H2, Windows Serve
A medium-severity vulnerability, tracked as EUVD-2026-73018 and scored 5.7 out of 10 under CVSS v3.1, affects Microsoft Windows 10 versions 1809 and 21H2, Windows Server 2019 and more than a dozen other Microsoft products. The flaw involves the generation of error messages containing sensitive information. The advisory was published on 8 September 2026 and updated on 7 October 2026, and administrators are being urged to review whether their systems need patching.
- 27Linux security updates released for WednesdayโSecurity updates for Wednesday https:// lwn.net/Articles/1099202/ # tech # linux
LWN.net has published its regular Wednesday roundup of security updates for Linux distributions. The digest collects advisories and patched packages from distros such as Debian, Fedora, Ubuntu and openSUSE, covering vulnerabilities fixed across a range of software. System administrators typically use these roundups to plan patching and keep servers current with the latest fixes.
- 28Microsoft Windows Server flaw logged as EUVD-2026-73019โ๐จ EUVD-2026-73019 ๐ Score: 5.5/10 (CVSS v3.1) ๐ฆ Product: Windows Server 2025, Windows Server 2016 (Server Core installat
A medium-severity vulnerability affecting Microsoft Windows Server editions has been catalogued as EUVD-2026-73019, with a CVSS v3.1 score of 5.5 out of 10. The flaw involves missing authentication for a critical function, affecting Windows Server 2025, Windows Server 2016 (Server Core installation), Windows Server 2012 and more than sixteen other configurations. The entry was published on 8 September 2026 and updated on 7 October 2026. Administrators are advised to check whether patches are available for affected builds.
- 29Roundcube Webmail SQL Injection Flaw Actively ExploitedโผRoundcube Webmail SQL Injection Vulnerability CVE-2026-48842 Under Active Exploitation Roundcube Webmail high-severity S
A high-severity SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is under active exploitation. The flaw resides in the virtuser_query plugin and allows unauthenticated attackers to compromise servers running the popular open-source webmail software. Security administrators are being urged to patch affected installations immediately and check systems for signs of compromise.
- 30
The OpenSSH project has released version 10.6 of its widely used secure shell suite, with release notes published on the official OpenSSH website. OpenSSH is a core security tool used on servers and network devices worldwide, so every new release draws attention from system administrators and developers. Early discussion is focused on what changed in this version and whether upgrades are needed.
- 31Microsoft Exchange flaw lets attackers read other users' mailboxesโCVE-2026-96940 is an Exchange Server privilege escalation flaw rated CVSS 8.8. An authenticated attacker can potentially
A newly disclosed vulnerability in Microsoft Exchange Server, tracked as CVE-2026-96940, carries a high severity score of 8.8. Security researchers say an authenticated attacker could bypass authorization checks and read other users' mailboxes and attachments within the same on-premises Exchange organisation. The flaw does not allow pre-authentication remote code execution, but experts are warning administrators to review exposure and patch promptly.
- 32Critical file-access flaw hits self-hosted Atlassian productsโ๐ค CVE-2026-21589: critical arbitrary file-access flaw in self-hosted Atlassian Data Center products (Confluence, Jira, B
Atlassian has disclosed CVE-2026-21589, a critical arbitrary file-access vulnerability affecting self-hosted Data Center versions of Confluence, Jira and Bitbucket. The flaw could let attackers read sensitive files on affected servers. Atlassian is urging administrators to patch immediately. Security commentators are sharing the advisory and warning self-hosted deployments to act quickly.
- 33German IP address flagged as scanner by threat feedโ88.198.1.113 (DE) is flagged as a scanner with 58% confidence, tracked by one threat feed. Worth checking if it shows up
A Germany-based IP address, 88.198.1.113, has been flagged as a network scanner with 58% confidence and appears in one threat intelligence feed. Security watchers are advising administrators to check their server logs for activity from the address, as repeated scanning is often a precursor to targeted attacks.
- 34Step-by-step guide to installing Directus on AlmaLinuxโHow to Install # Directus on # AlmaLinux # VPS Here's a step-by-step guide detailing how to install Directus on AlmaLinu
A new tutorial walks through installing Directus, the open-source headless CMS and data platform, on an AlmaLinux VPS. The guide covers what Directus is โ a tool for managing and interacting with databases through an API-first interface โ and details the setup steps for server administrators. It reflects steady interest in self-hosting flexible CMS alternatives on enterprise-grade Linux distributions.
- 35New guide walks through deploying Nagios Core on Ubuntu VPSโ๐ Deploy # Nagios on # Ubuntu # VPS This guide walks through deploying Nagios Core on an Ubuntu VPS, from system prep to
A step-by-step tutorial for deploying Nagios Core on an Ubuntu virtual private server has been published, covering system preparation, web access setup, plugins, and host and service configuration through to security hardening. The commands target Ubuntu 22.04 LTS, with notes that they work similarly on 20.04 and 24.04, giving administrators a practical open-source server monitoring option.
- 36Pakistani IP address flagged for malware distributionโ223.123.126.197 (PK, CMPak) flagged for ua-wget malware distribution, low confidence. Worth a firewall block if you see
An IP address registered in Pakistan to mobile operator CMPak, 223.123.126.197, has been flagged for distributing malware associated with the ua-wget user agent. The flagging carries a low confidence rating, but security practitioners are advised it may be worth blocking at the firewall level if the address appears in server logs. Administrators are encouraged to review their logs and share threat intelligence on suspicious traffic.
- 37Calnode v0.10.1 Ships with Security Updates and NethServer ModuleโCalnode v0.10.1 Released with Security Updates and One-Click NethServer Module ๐ฐ Original title: Calnode v0.10.1: the re
Calnode has released version 0.10.1, an update that includes security fixes and a new one-click module for deploying the software on NethServer. The release is being described as shaped by feedback from the project's deployers, and it is drawing attention from self-hosting and server administration communities interested in simplified deployment and patched vulnerabilities.
- 38New guide takes sysadmins from Bash basics to production scriptsโBash scripting per sistemisti: dai fondamentali agli script di produzione pronti per cron # tech https:// spcnet.it/bash
A new Italian-language tutorial published on SPCNet walks system administrators through Bash scripting, starting from core fundamentals and building up to production-ready scripts suitable for scheduling with cron. The guide is being shared in tech communities, where users highlight it as a practical resource for automating routine server administration tasks.
- 39German Green politician's infosec idea draws support onlineโRE: https:// gruene.social/@sven/1173781578 04337854 Ui das klingt doch nach einer mega Idee o.O Geren # rt fรผr mehr Fee
Sven, a member of the German Greens posting on gruene.social, has floated an idea in the infosec and sysadmin field that a fellow administrator is publicly endorsing as a strong one. The supporter is calling for more feedback and greater reach for the proposal, using the hashtags admin and infosec. The details of the idea itself are not spelled out in the exchange.
- 40Critical FortiMail Zero-Day Flaw Exploited in Active AttacksโCritical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
Security researchers report that a critical zero-day vulnerability in Fortinet's FortiMail product is being exploited in real-world attacks. The flaw allows unauthenticated attackers to write arbitrary files, potentially enabling remote code execution on affected email security servers. Administrators are urged to apply patches and restrict exposure. Fortinet has faced a series of exploited vulnerabilities in recent months, keeping the company under scrutiny.