47-Day Certificates Are Coming: What SC-081 Means for Your Renewal Process
The CA/Browser Forum approved ballot SC-081, cutting TLS certificate lifetimes from 398 days to 47 by 2029. How to get your renewals ready.
Let's Encrypt Is Ending Expiry Emails and OCSP: What to Replace Before June
Let's Encrypt will stop sending expiration emails and is winding down OCSP in 2025. What that removes from your safety net, and what to put in its place.
TCP Port Monitoring — Watching the Services That Aren't Websites
HTTP checks miss mail servers, SSH and custom services. What a TCP port check proves, what it doesn't, and when a heartbeat is the better tool.
2024: The Year in Outages, and What It Taught Us
CrowdStrike, polyfill.io and a year of cloud and carrier failures: what 2024's big outages share, and what small teams should carry into 2025.
Chrome Stops Trusting New Entrust Certificates: Check Your Chain This Week
Entrust TLS certificates issued after October 31 are no longer trusted by Chrome. How to find Entrust certificates on your estate and switch CAs cleanly.
Monitoring E-Commerce Before Peak Season — A Pre-Black-Friday Checklist
Black Friday readiness for e-commerce: monitor the money path, sweep certificates before code freeze, baseline response times and set up on-call now.
Health Check Endpoints Done Right — Designing /health So It's Worth Monitoring
Shallow vs deep checks, /live vs /ready, real status codes and load-balancer cascade failures: how to design health check endpoints worth monitoring.
The CrowdStrike Outage — Lessons From the Biggest IT Failure Ever
A bad CrowdStrike channel file blue-screened ~8.5 million Windows machines on July 19. What may be the largest IT outage ever teaches teams of every size.
The polyfill.io Supply-Chain Attack — Every Script Tag Is a Trust Decision
The polyfill.io CDN is injecting malicious code into 100,000+ sites. What happened, why SRI didn't save anyone, and how to defend against the next one.
Monitoring WordPress Sites — What Breaks, and How to Catch It
WordPress runs over 40% of the web and fails in WordPress-specific ways. Keyword checks, wp-cron heartbeats, defacement detection and xmlrpc abuse.
The xz Backdoor: A Multi-Year Con Caught by Half a Second of Latency
A backdoor in xz-utils 5.6.0 and 5.6.1 targeted sshd on Linux. What we know three days in, how to check your systems, and why a slow login mattered.
Maintenance Windows Done Right — Planned Downtime Without the Panic
Planned maintenance shouldn't look like an outage. Picking windows, pausing monitors, 503 + Retry-After, SLA carve-outs and a comms template that works.
Browse by topic
Monitor your site — free
Uptime, SSL, DNS, security-header grades and SPF/DKIM/DMARC — one dashboard, one bill. The free tier includes the security layer and allows commercial use.