Anything to fix tonight?
Yes. 5 things to check before bed.
Security news filtered for people running one box or a handful: Proxmox, Docker, NAS, routers, Cloudflare Tunnels, and local LLM stacks. Each item says who it hits and what to do.
- Docker Engine: open API on 2375 and docker.sock in web-facing containers = root on hostClose 2375.
- Ollama / vLLM / LiteLLM: inference API open to the internet with no authStop Ollama listening on every interface.
- Grafana and Prometheus: admin/admin, anonymous access, and unauthenticated metrics/pprof endpointsDelete any port-forward for 3000, 9090, 9093 or 9100 on the router.
- Open WebUI: 150+ advisories in 2026, and an admin login means Python on your serverUpgrade to 0.11.4 or newer.
- MikroTik RouterOS: unauthenticated SSH takeover chain ("MikroTrick") exploited since Sept 2Shut SSH off to the internet.
Everything we track
- ACT TONIGHTDocker Engine: open API on 2375 and docker.sock in web-facing containers = root on host
- ACT TONIGHTOllama / vLLM / LiteLLM: inference API open to the internet with no auth
- ACT TONIGHTGrafana and Prometheus: admin/admin, anonymous access, and unauthenticated metrics/pprof endpoints
- ACT TONIGHTOpen WebUI: 150+ advisories in 2026, and an admin login means Python on your server
- ACT TONIGHTMikroTik RouterOS: unauthenticated SSH takeover chain ("MikroTrick") exploited since Sept 2
- THIS WEEKCloudflare Tunnel: public hostnames with no Access policy, leaked tunnel tokens, and origins still port-forwarded
- THIS WEEKMCP servers: unauthenticated dev proxies, backdoored packages, and tool poisoning in your agent setup
Nothing matches. Clear the search or pick another tag.