The ZAP51 blog

RSS JSON

Notes from systems, machines, and everything between.

I write about vulnerabilities, infrastructure, software, motorcycles, and the things that become more interesting when examined closely. The subject can change. Curiosity, evidence, and useful detail stay constant.

Original sourcesTechnical depthMachines and motionIndependent perspective

Latest writing

Technology, machines, observations

Open source · self-hosting · 22 Aug 2026

Why I build Mattermost Team Edition for 1,000 users.

The v11 free offering changed, but the operational need did not. Here is why I maintain latest-ESR builds for the community and for my own 500-plus-user server.

User ceiling1,000
Message historyNo product cap
Release trackLatest ESR
Motorcycles · India · 22 Aug 2026

The 2026 Continental GT 650 changes just enough to matter.

A close look at the new equipment, the much more practical Rocker Red, India pricing, and the mechanical package Royal Enfield wisely left alone.

Starting price₹3,58,427
Engine648 cc twin
New equipmentLED · Type-C · cowl
CVE analysis · Linux KVM · 22 Aug 2026

CVE-2026-53359: JanuScape and the KVM boundary

How nested virtualization reaches a KVM x86 shadow MMU use after free, why both Intel and AMD hosts are exposed, and what operators should patch or disable.

CVSS v3.18.8 · High
CVSS v4.08.4 · High
BoundaryGuest to host
AI infrastructure · llm-d · 22 Aug 2026

One inference pool. Three accelerator vendors. Twenty accelerators.

My field notes from building and benchmarking one sovereign inference service across NVIDIA H100 NVL, AMD MI325X, and Intel Gaudi 3 hardware.

Hardware20 accelerators
Network100 Gbps RoCE
Three-vendor result91% more throughput
Operations · Caddy · 22 Aug 2026

Caddy 2.11 changed the Host header for HTTPS upstreams.

Why the safer reverse proxy default can break redirects, virtual hosts, and WebSockets, plus the compatibility fix and the checks to make before using it.

ScopeHTTPS upstreams
IntroducedCaddy v2.11.1
CompatibilityExplicit opt out
CVE analysis · nginx · 22 Aug 2026

CVE-2026-42533, CVE-2026-56434, and CVE-2026-60005

Three nginx memory safety flaws across map processing, SSI proxying, and HTTP slicing. The analysis covers exposure conditions, CVSS v3.1 and v4.0, and a corrected patch path.

CVE-2026-425339.2 · Critical
CVE-2026-564348.3 · High
CVE-2026-600058.8 · High

Technical articles stay close to primary sources. Product pieces separate confirmed changes from opinion, disclose when they are not road tests, and use market-specific pricing with the proper context.