Loading current advisories
dataThe public JSON feed is read-only. ZSEC clients create local TODOs from it and continue to apply only OS security updates through apt or dnf.
Open-source Linux security automation
ZSEC keeps Linux servers patched against active threats while keeping the blast radius small: security packages, SSH lockout guardrails, fail2ban direction, local exposure checks, and read-only advisory TODOs.
System posture
OperationalSecurity briefing pack
The ZSEC brief explains the promise, risk problem, safety boundary, operating flow, ecosystem fit, and review path. It is written for server owners, hosting teams, and technical stakeholders who want disciplined updates without a remote command channel.
Install
ZSEC is a standalone open-source project. FreeWebPanel can install it, but ZSEC does not depend on panel code.
curl -fsSL https://raw.githubusercontent.com/ResearchForumOnline/ZSEC/main/install.sh | sudo bash
sudo zsec status
Normalized CISA KEV and security-news signals for ZSEC review TODOs. The feed is data, not a command channel.
The public JSON feed is read-only. ZSEC clients create local TODOs from it and continue to apply only OS security updates through apt or dnf.
Automation model
Watch
Use the overview video for the serious explanation and the short for quick security-awareness sharing.
Safe automation
Boundaries
No. The public feed is read-only data. ZSEC clients create local advisory notes and apply only OS security updates through normal package managers.
No. Backups, monitoring, firewall policy, SSH key hygiene, and incident response remain required.
No. ZSEC is not an AI agent and does not need provider keys to do its security-update job.
Featured ecosystem video
Watch the full walkthrough of the TalkToAI ecosystem: ZeroThink, OpenZero, local-first AI infrastructure, research direction, and the practical stack being built for builders, businesses, universities, and serious operators.