Homelab Highlights cover art

Homelab Highlights

A show about homelab infrastructure, self-hosted tools, community discoveries, and the practical operational lessons that matter, released three times a week.

Latest Episodes

· 08:09

GitLab's critical AI Gateway patch and Homarr v2

GitLab has patched a critical command execution flaw in the self-hosted AI Gateway, fixed in versions 19.2.4, 19.3.2, and 19.4.1. Microsoft shipped wslc for running Linux containers in WSL without Docker Desktop. An open-source tool generates subtitles with ElevenLabs speech-to-text and Gemini for about nine cents per 90-minute video. Sucuri details a self-healing WordPress backdoor that rebuilds itself after cleanup. And Homarr v2 arrives with Custom Widgets, a community Workshop, Integration Requests, and optional MCP support.

Listen

· 06:37

RSA panic explained, Zimbra exploited, and a $92 homelab

A viral headline about breaking RSA faster than ever turns out to apply only to blind-signature RSA, not the padded RSA behind standard TLS certificates. Then a roundup of active threats: unauthenticated code execution attacks against Zimbra Collaboration Suite, a high-severity DTLS leak fixed in OpenSSL, Cloudflare's multi-year push toward hybrid post-quantum TLS certificates, and new audio playback options in Plex Web. Plus, a look at Copyparty's WebDAV timestamp quirk on macOS, and a community build where a simple RAM upgrade spiraled into a 22-core, 128 GB ECC TrueNAS machine for roughly ninety-two dollars net.

Listen

· 07:55

Carbonato hijacks Docker daemons, plus a local Roborock win

This week on Homelab Highlights: researchers break down the Carbonato botnet, which compromises exposed Docker daemons and repurposes the open-source Hermes Agent framework for Telegram-based command and control. We cover actively exploited SharePoint and MikroTik RouterOS flaws, a Rust-built Distributed-JBOD storage project for pooling mismatched drives, and a community debate on whether Claude Code earns its place alongside n8n. Our tool highlight is Local Roborock Server, now out of beta with fully offline vacuum control, and our community highlight documents three weeks running a Minisforum N5 Max as a single-box NAS, media, and local AI machine.

Listen

· 08:18

Lighter turns a Mac Mini into a Frigate server, plus Roundcube and WordPress exploits

Homelab Highlights for 2026-09-25: Lighter is a Rust container engine that turns an Apple Silicon Mac into a real Home Assistant and Frigate server with Neural Engine detection and hardware video decode. In the feed, active exploitation of a patched Roundcube pre-auth SQL injection and a WordPress unauthenticated RCE exploited within hours of disclosure, plus four self-hosted services worth running. Tool highlight: a hands-on test of four AI agent memory SDKs that all failed a simple contradiction test. Community highlight: disabling Proxmox KSM cut idle power by nine to ten watts on one homelab box.

Listen

· 06:05

Ubuntu container escape exploit and Spinifex's AWS-on-your-hardware

Homelab Highlights for 2026-09-23: an exploit for an unpatched Ubuntu kernel flaw that enables container escape to host root, the MikroTrick vulnerability chain hitting internet-exposed MikroTik routers, new Plex audio enhancements, a major HA-arr-stack-card update, Filewright for AI-assisted photo organization, a tool dive into Spinifex, the open-source AWS-compatible cloud for your own hardware, and a community story about moving from Claude Code to open-source models.

Listen

· 08:09

Fluado's one-week Big Tech exit and a Gitea patch

Homelab Highlights for September 21, 2026: Fluado's founder details moving 17 US Big Tech dependencies in about a week to Hetzner, Forgejo, self-hosted Supabase, Scaleway, and Mattermost. Gitea users are urged to patch a file-read flaw that can chain into remote code execution, an Aqara FP300 owner updates sensors over Matter and Thread without an Aqara hub, and Youtarr 1.84.0 adds watched-status sync, cleanup rules, and whole-channel downloads. Plus: whether one Deviceside PSU5 can power two TEAC floppy drives, and a platform engineer's overly-documented homelab README.

Listen

· 06:12

nanoCron's Container Scheduling and AI Coding Pace

This episode covers nanoCron, a new container-native cron alternative with JSON config and resource-aware scheduling, and a developer's reflection on Claude Code's impact on cognitive pacing and mental fatigue.

Listen

· 07:39

Crawler Costs, Agent Swarms, and a Web-Based Video Tool

This episode covers the massive resource cost of abusive crawlers on public services, Google DeepMind's research on cheating AI agents, OpenAI's undisclosed wiki incident, and a client-side video compression tool using FFmpeg and WebAssembly.

Listen

· 07:47

Building a Container by Hand, MinIO's End of Life, and Walgit

This episode covers building a Linux container by hand for learning, Docker's Extended Lifecycle Support for the archived MinIO project, the Walgit single-binary Git server, Nextcloud Hub as an alternative to Microsoft 365, and a speculative essay on LLM security risks.

Listen

· 05:39

Self-Hosted Agent Factories and Plex Rollbacks

This episode covers a detailed walkthrough for building a self-hosted, sandboxed AI agent factory, advice on rolling back a problematic Plex container, a look at the Floppy media tracker, and a community story about the unexpected costs of an AI experiment.

Listen

· 05:38

Self-Hosted Agentic Factory, Plex Container Bug, and Floppy Media Tracker

This episode covers a blueprint for a self-hosted, sandboxed AI agentic software factory, a Plex container update bug, Backblaze hard drive reliability data, Spotify's Soloist client, Debian's AI contribution vote, the Floppy media tracker, and a viral AI agent's Cloudflare bill.

Listen

· 06:41

Nextcloud updates, RustDesk on Wayland, and a 50TB data scare

This episode covers Nextcloud Hub maintenance updates, RustDesk's new unattended Wayland access, a cautionary tale of 50TB of data stuck in a defunct cloud, the NoteDiscovery notes app update with plugins, a community toolkit for Dell T110 II ECC reporting, and a quick tip on monitoring Docker container restarts.

Listen

· 11:51

Keyv NPM Attack, NutriTrace v1.1.0, and AI Code Review Risks

This episode covers the active Shai-Hulud NPM supply chain attack targeting Keyv, the NutriTrace v1.1.0 release with in-app updates, Flowise AI's shutdown, Docker's supply chain incident stats, and a study on the risks of using AI for code review.

Listen

· 10:32

OpenAI's Hugging Face hack and Docker's AI sandbox

This episode covers the details of OpenAI's breach of Hugging Face via a JFrog zero-day, Docker's new sandbox for securing AI coding assistants, the self-hosted music tool Aurral, and a practical tip for automating against backend APIs instead of brittle UI scraping.

Listen

· 16:15

Xray-core Tunnels Under Pressure and Mini PC Price Shifts

This episode covers a detailed account of running self-hosted tunnels using Xray-core's Reality protocol under aggressive ISP inspection, a fundamental community discussion on always-on Plex servers, and the changing economics of mini PC hardware for home servers.

Listen

· 06:27

DVinyl 3.0's Rewrite, Docker's Quote Bug, and Nextcloud Patches

This episode covers DVinyl 3.0's complete TypeScript rewrite, a long-standing Docker CLI parsing bug for environment files, Nextcloud's July maintenance updates, a security camera with a leaked GitHub token, and AI-assisted Plex projects from the community.

Listen

· 10:13

Nextcloud's Community Awards and a Dell OptiPlex Windfall

Nextcloud launches its inaugural Community Awards for its 10th anniversary. A homelabber scores free Dell OptiPlex Micro PCs from a corporate refresh. Self-Host Weekly shares new Insider perks and covers Linus Torvalds's stance on AI in Linux kernel development.

Listen