Skip to content

Writing about Security

Everything from the journal that came out of security work — what broke, what we found, and what actually fixed it.

In this section

8 posts

  1. 29 Jul 2026 Zero Trust on a budget with Cloudflare and CyberPanel Lock CyberPanel and wp-admin behind Cloudflare Access on the free tier. The exact setup we deploy, and the two places free stops.
  2. 20 Jul 2026 When Let’s Encrypt renewal fails: a debug checklist A Let’s Encrypt certificate is good for 90 days, renews itself at 60, and you are supposed to forget it exists. So when the renewal fails,…
  3. 16 Jul 2026 Imunify360 vs ModSecurity: which WAF do you need? People ask us to compare Imunify360 and ModSecurity as if they are two products fighting for the same slot. They are not. Imunify360 ships with a…
  4. 16 Jul 2026 Five Cloudflare rules I add to every site in 2026 Every site we onboard gets the same short list of Cloudflare rules before anything else. Not fifty. Five. They cover the problems that actually cause tickets:…
  5. 30 Jun 2026 Linux server hardening checklist (2026 edition) There are a hundred Linux hardening checklists online and most of them are the same forty bullet points in a different order. We have read them.…
  6. 29 Jun 2026 Five signs your VPS needs an audit Five signs a server you already run is in trouble, the kind you can spot without being a sysadmin, each with the one command to confirm…
  7. 29 Jun 2026 Cloudflare for ecommerce: rules every store should have The custom Cloudflare WAF rules we set up on an online store to stop card testing, credential stuffing, and price scrapers, with the exact expressions and…
  8. 29 May 2026 Why your WordPress site keeps getting hacked You cleaned the malware last month. Reset the passwords, deleted the spammy posts, maybe paid someone $80 on Fiverr to scan the files. The site was…