<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Project Wintermute</title><link>https://wintermutecore.com/tags/security/</link><description>Recent content in Security on Project Wintermute</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 15 Jun 2026 14:00:00 +0000</lastBuildDate><atom:link href="https://wintermutecore.com/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>K3s Activity: CVE-2026-39821 Fix, Component Bumps, and RBAC Stability</title><link>https://wintermutecore.com/posts/k3s-activity-cve-2026-39821-fix-and-rbac-updates/</link><pubDate>Mon, 15 Jun 2026 14:00:00 +0000</pubDate><guid>https://wintermutecore.com/posts/k3s-activity-cve-2026-39821-fix-and-rbac-updates/</guid><description>&lt;p&gt;K3s continues to refine its lightweight Kubernetes distribution with a focus on security patching and operational robustness. Recent activity includes a critical fix for CVE-2026-39821 in the Go networking stack, alongside updates to core components like Traefik and CoreDNS. These changes reflect a steady effort to maintain a secure and stable environment for edge and resource constrained deployments.&lt;/p&gt;</description></item><item><title>OpenTofu v1.11.9 Release - Security Hardening and SSH Fixes</title><link>https://wintermutecore.com/posts/opentofu-v1-11-9-release-security-ssh-fixes/</link><pubDate>Fri, 12 Jun 2026 16:11:30 +0000</pubDate><guid>https://wintermutecore.com/posts/opentofu-v1-11-9-release-security-ssh-fixes/</guid><description>&lt;p&gt;OpenTofu v1.11.9 was released on June 12, 2026, delivering critical security updates for SSH connectivity and state encryption providers. This version patches vulnerabilities that could lead to hangs or high CPU consumption when interacting with compromised servers or specifically crafted encryption keys. As a maintenance release in the v1.11 series, it focuses on stability and security without introducing breaking changes to the core engine or configuration syntax.&lt;/p&gt;</description></item><item><title>Services</title><link>https://wintermutecore.com/services/</link><pubDate>Sun, 13 Feb 2022 11:11:11 -0100</pubDate><guid>https://wintermutecore.com/services/</guid><description>&lt;p&gt;&lt;p style="text-align:center;"&gt;
 &lt;img src="https://wintermutecore.com/services.jpg" alt="Services" /&gt;
&lt;/p&gt;
&lt;/p&gt;
&lt;p&gt;Below is what we actually do day to day. We try to keep the list short and the descriptions honest. If something here matches what you need, get in touch.&lt;/p&gt;

&lt;h2 id="software-engineering" class="anchor-link"&gt;&lt;a href="#software-engineering"&gt;Software engineering&lt;span class="pilcrow"&gt;&amp;nbsp;¶&lt;/span&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;We write backend services in Java, Kotlin, Go, and Groovy. Most of the work falls into a few buckets: REST and gRPC APIs, distributed systems handling high request volumes, and the occasional batch job that has to be reliable more than fast.&lt;/p&gt;</description></item></channel></rss>