<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Announcement on Cozystack</title><link>https://deploy-preview-637--cozystack.netlify.app/article_types/announcement/</link><description>Recent content in Announcement on Cozystack</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 03 Aug 2026 13:23:05 +0500</lastBuildDate><atom:link href="https://deploy-preview-637--cozystack.netlify.app/article_types/announcement/index.xml" rel="self" type="application/rss+xml"/><item><title>Are You Using Cozystack Independently?</title><link>https://deploy-preview-637--cozystack.netlify.app/blog/2026/07/using-cozystack-independently/</link><pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate><guid>https://deploy-preview-637--cozystack.netlify.app/blog/2026/07/using-cozystack-independently/</guid><description>&lt;p&gt;&lt;img src="https://deploy-preview-637--cozystack.netlify.app/blog/2026/07/using-cozystack-independently/using-cozystack-independently.png" alt="Using Cozystack independently? We are looking for independent adopters for the CNCF Incubation review."&gt;&lt;/p&gt;
&lt;p&gt;As part of the CNCF Incubation review, the Technical Oversight Committee (TOC) is speaking with Cozystack adopters about their real-world experience.&lt;/p&gt;
&lt;p&gt;We are especially looking for teams and individual adopters using Cozystack &lt;strong&gt;outside a commercial engagement with Ænix&lt;/strong&gt;. If that is you, we would love to hear how you run it, what works, and what does not.&lt;/p&gt;</description></item><item><title>Security Advisory — CVE-2026-53359 ("Januscape"): KVM Guest-to-Host Escape</title><link>https://deploy-preview-637--cozystack.netlify.app/blog/2026/07/security-advisory-cve-2026-53359-januscape-kvm-guest-to-host-escape/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://deploy-preview-637--cozystack.netlify.app/blog/2026/07/security-advisory-cve-2026-53359-januscape-kvm-guest-to-host-escape/</guid><description>&lt;figure&gt;&lt;img src="https://deploy-preview-637--cozystack.netlify.app/blog/2026/07/security-advisory-cve-2026-53359-januscape-kvm-guest-to-host-escape/cve-2026-53359-banner.png"
			alt="Security advisory banner — CVE-2026-53359 Januscape KVM guest-to-host escape" width="720"&gt;
&lt;/figure&gt;

&lt;p&gt;&lt;strong&gt;Severity:&lt;/strong&gt; High for clusters running virtualization. &lt;strong&gt;Status:&lt;/strong&gt; No fixed Talos release yet — mitigation required now.&lt;/p&gt;
&lt;h2 id="what-happened"&gt;What happened&lt;/h2&gt;
&lt;p&gt;On 2026-07-06 a Linux kernel vulnerability, &lt;strong&gt;CVE-2026-53359&lt;/strong&gt; (&amp;ldquo;Januscape&amp;rdquo;), was publicly disclosed together with a working exploit. It is a use-after-free in the KVM/x86 shadow MMU that lets a &lt;strong&gt;guest VM break out to its host&lt;/strong&gt; (the cluster node) or crash the node&amp;rsquo;s kernel. It affects both Intel and AMD CPUs and has been latent in the kernel since 2010.&lt;/p&gt;</description></item><item><title>Introducing /cozystack:wizard — a Guided Cozystack Installer</title><link>https://deploy-preview-637--cozystack.netlify.app/blog/2026/05/introducing-cozystack-wizard/</link><pubDate>Tue, 19 May 2026 00:00:00 +0000</pubDate><guid>https://deploy-preview-637--cozystack.netlify.app/blog/2026/05/introducing-cozystack-wizard/</guid><description>&lt;p&gt;&lt;img src="https://deploy-preview-637--cozystack.netlify.app/blog/2026/05/introducing-cozystack-wizard/cozystack-wizard.png" alt="Cozystack wizard"&gt;&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;ve shipped &lt;strong&gt;&lt;code&gt;/cozystack:wizard&lt;/code&gt;&lt;/strong&gt; — a guided Cozystack installer.&lt;/p&gt;
&lt;p&gt;Tell it &lt;code&gt;Talos&lt;/code&gt;, &lt;code&gt;Ubuntu&lt;/code&gt;, or &lt;code&gt;Existing&lt;/code&gt;, and it orchestrates the whole chain end-to-end. It handles cert-SAN traps on NAT&amp;rsquo;d clouds (OCI, GCP, AWS), ZFS provisioning on Talos, LINSTOR registration races, and a dozen other traps that bit us during real-install testing.&lt;/p&gt;
&lt;p&gt;Boot-to-Talos works too: if nodes already came up on base Talos, the wizard upgrades them to the Cozystack-tuned image. The end-to-end path is validated on a 3-node OCI Talos cluster.&lt;/p&gt;</description></item></channel></rss>