Cybersecurity

Cloudflare Access can now protect a Worker directly

Cloudflare Access authenticating requests before Worker execution

Cloudflare has moved Access policy from individual hostnames to the Worker itself, closing gaps across custom domains, routes, workers.dev, and previews. more


Firewall Architecture for a HomeLab: Simplicity as a Security Feature

MikroTik input and forward chains ending with a default drop rule

Build a readable MikroTik firewall for a homelab: safe mode, interface lists, default deny with logging, and input and forward chains. more


Hardening a HomeLab with Both Public and Private IPs

Homelab split into WAN, DMZ and LAN zones with VPN access to management

Harden a homelab that exposes public services, using a locked-down management plane, VPN access, DMZ segmentation and origin protection. more


New Service: Incident Response for Magento 2 and VPS

Incident response timeline: detect, contain, clean and harden after a webshell

What a persistent webshell on a Magento 2 VPS looked like, how it was removed in two days, and what to check on your own server. more