An Apple Silicon smart home server, Roundcube and WordPress under active attack, and a Proxmox power trick
Homelab Highlights for 2026-09-25: self-hosting and homelab notes worth knowing.
[Audio embed placeholder]
News Roundup
Roundcube pre-auth SQL injection flaw actively exploited in the wild
The Canadian Centre for Cyber Security warns that a now-patched Roundcube Webmail vulnerability is being actively exploited. It’s a pre-authentication SQL injection in the virtuser_query plugin, with a CVSS score of 8.1, affecting Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
Why it matters: Pre-auth means no login is required, and self-hosted Roundcube is everywhere in homelabs. The fix is out, so this is an update-now situation if you run webmail.
Source: The Hacker News
Attackers exploit WordPress critical flaw within hours of disclosure
Threat actors began exploiting a critical WordPress vulnerability within hours of public disclosure. The flaw, with a CVSS score of 9.2, allows an unauthenticated attacker to achieve remote code execution by manipulating page-template resolution to include a chosen local PHP file.
Why it matters: Even a small homelab WordPress blog counts. With exploits in the wild that quickly, the patching window is tiny—apply the update and check your logs.
Source: The Hacker News
4 self-hosted services that made my home network more useful, not more complicated
How-To Geek walks through four self-hosted services the author uses every day, with a framing worth heeding: self-hosting can turn from a hobby into a second job if you pick finicky, high-maintenance software.
Why it matters: A useful sanity check when deciding what to deploy next—favor services that add real utility without adding a maintenance burden.
Source: How-To Geek
Tool & Software Highlight: Lighter: a high-performance container engine that turns an Apple Silicon Mac into a home server
Lighter is a headless container engine written in Rust on Apple’s Hypervisor framework, designed to make a Mac Mini a proper Home Assistant and Frigate server. It gives Linux containers direct access to the Apple Neural Engine for object detection (Frigate YOLO inference at roughly 3 to 6 milliseconds) and routes camera decode to the hardware media engine, cutting 4K H.264 decode from about 69% CPU to 16%. It boots in around 700 milliseconds, idles near 600 MiB, and returns unused memory to macOS. Frigate maintainers have upstreamed the Neural Engine detector and Apple Silicon decode presets, and now recommend lighter in Frigate’s hardware docs. It’s a drop-in Docker engine, MIT/Apache licensed, with no telemetry. One gap: no USB passthrough yet, so Zigbee sticks need a network coordinator or serial-over-TCP.
Why it matters: If you have a spare M1 or newer Mac, this removes the usual trade-offs of running Home Assistant and Frigate on macOS, including no need to hunt down a Coral TPU. Benchmarks are from the project’s own repo, but the upstream Frigate integration is a strong signal.
Source: GitHub
Sources
- Lighter - container engine for Apple Silicon home servers - GitHub
- Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure - The Hacker News
- Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild - The Hacker News
- 4 self-hosted services that made my home network more useful, not more complicated - How-To Geek
- Memory layer for AI agents - hands-on test of four memory SDKs - r/AI_Agents
- Disable RAM optimization (KSM) in Proxmox for power saving - r/homelab
Transcript
Host A: Welcome to Homelab Highlights, the show that surfaces practical homelab wins and useful self-hosted tools.
Host A: So there’s this project called lighter that tackles a classic homelab question. [thoughtful] You’ve got a Mac Mini sitting in a closet. It’s quiet, sips power, Apple Silicon is fast. Why can’t that just be the smart home server? The software has always been the blocker. Running Home Assistant as a full VM in UTM or VMware locks away gigabytes of RAM permanently, and it can’t touch the Mac’s media engine or Neural Engine. Docker Desktop idles at multiple gigs. So a developer built lighter from scratch in Rust on Apple’s Hypervisor framework. It’s a headless container engine meant to turn that spare Mac into a proper server.
Host B: And what makes this more than just another container runtime is the integration with Frigate. [with emphasis] The Frigate maintainers actually upstreamed support—an Apple Neural Engine detector and media engine decode presets. According to the project’s announcement, Frigate’s hardware documentation now points at lighter as the preferred way to run on a Mac. Their numbers show Frigate doing YOLO object detection in about three to six milliseconds per inference on the Neural Engine. That means no hunting for a Coral TPU stick, which has gotten ridiculous. The video side is just as big. Camera decode moves onto the dedicated media engine through V4L2. The project’s benchmarks show a 4K H.264 decode dropping from around sixty-nine percent CPU in software to sixteen percent on hardware. 4K HEVC goes from pegging the CPU at a hundred percent down to about thirty.
Host A: The memory behavior is clever too. It cold-boots to container readiness in roughly seven hundred milliseconds, idles around six hundred mebibytes, and hands unused memory pages back to macOS when things calm down. [quick aside] One tradeoff to know upfront: lighter doesn’t do USB passthrough into containers yet. So a USB Zigbee stick won’t just work. The developer suggests either using a network coordinator over Ethernet, or exposing the stick’s serial port over TCP from the Mac itself. And it’s worth noting these benchmarks are from the project’s own repo. But for anyone with a spare M1 or newer Mac collecting dust, this looks genuinely useful. It’s a drop-in Docker engine, so existing docker and Compose commands work. It’s MIT and Apache licensed, no telemetry. Install is a brew install and starting the engine.
Host B: Alright, time for the feed. [lighter] We’ve got a security double feature today. First, The Hacker News reports the Canadian Centre for Cyber Security is warning about active exploitation of a patched Roundcube vulnerability. It’s CVE-2026-48842, a pre-authentication SQL injection with a CVSS score of 8.1. It’s in the virtuser_query plugin, affecting Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The root cause involves a preg_replace backslash issue. Pre-auth means no login needed.
Host A: That’s basically every self-hosted webmail instance. If you’re running Roundcube, check those versions and patch immediately. The fix is out, so this is an update-now situation. [skeptical] Sticking with security, another active exploit hitting WordPress. Also from The Hacker News, attackers started exploiting CVE-2026-87902 within hours of disclosure. It’s a critical flaw, CVSS 9.2, allowing unauthenticated remote code execution. The trick involves manipulating get_page_template to include a chosen local PHP file.
Host B: Even a homelab WordPress blog for the family counts here. Unauthenticated RCE with exploits in the wild hours after disclosure means the window is tiny. Apply the update and maybe glance at the logs. [conversational] To close the feed on a lighter note, How-To Geek has a piece on four self-hosted services the author uses daily. The framing is good—self-hosting can turn from a hobby into a second job if you pick finicky stuff. The through-line is choosing services that make your network more useful without adding a maintenance burden. Worth a look when you’re deciding what to deploy next.
Host A: Tool and software highlight this week is a hands-on test from a developer on the AI Agents subreddit. [curious] They needed a memory layer for an agent, so they tested four different memory SDKs with the same simple experiment. The test design is the good part. Tell the agent you prefer dark mode in session one. In session five, say you’ve switched to light mode. Then in session eight, ask which mode you use. Every single one of the four tools failed. All of them returned both facts, so the underlying model just picked whichever answer matched the query better. The response depended on how you asked. None of them removed the old preference when the new one came in. One stacked the new fact next to the old, another stored both separately with no link, one usually gave the newer answer until you changed the question phrasing, and the last tool required manual editing because it doesn’t handle contradictions at all.
Host B: They also tested entity resolution. Give the name ‘vansh’ in one session, ‘vansh from India’ in another, and the initials ‘VS’ in a third. [thoughtful] One tool made three separate entries. One linked the first two but missed the shorthand. One decided all three were different people. And one didn’t do entity resolution at all. This maps directly to any self-hosted setup with an agent—think a Home Assistant voice assistant or a support bot. Preferences change, people rename things. A memory layer that only ever appends will drift. The practical takeaway from this one person’s testing is that contradiction handling and entity resolution are worth testing explicitly before you commit to a tool. The sample was small, so results could vary. But the test itself is reusable. A preference that flips across sessions, then a direct question later, is a five-minute check anyone can run.
Host B: Community highlight comes from the homelab subreddit. [conversational] One user shared an experiment with Proxmox’s KSM—that’s kernel same-page merging. It scans RAM for identical pages between VMs and merges them to save memory, and it’s on by default. On their HP EliteDesk with an i5, sixty-four gigs of RAM, and a mix of drives, disabling KSM cut idle power draw by about nine to ten watts and dropped CPU temperature five to six degrees. In that setup, the RAM savings weren’t worth the constant scanning, especially with memory to spare.
Host A: Worth noting the comments pushed back with good context. [with a small lift] One person pointed out KSM does nothing by default until RAM usage hits about eighty percent, and it backs off on its own, so most people should probably leave it enabled. Another warned against disabling it if the system has ever used swap. So this is one result on one specific box, not a universal tip. The original poster later explained their specific setup: around eighty-five percent RAM usage, ballooning disabled, most memory going to a TrueNAS VM for ZFS caching, with only a couple of lightweight guests. With few similar VMs, the deduplication work buys nothing.
Host B: Two bonus details from the thread. Someone else chasing low idle power said tuning CPU power-saving states was a bigger lever, claiming about thirty watts saved on their box, though the most aggressive settings made VMs feel sluggish. And when asked about the temperature graphs, the poster said it wasn’t the Proxmox UI—it was Beszel, with its agent picking up sensors automatically. A nice little recommendation chain in one thread.
Host A: That’s Homelab Highlights for Friday. Until next time, happy hosting!