FR
live
archive

All articles

CISA publishes a guide to trap attackers who are already inside

On September 16, 2026, CISA released its first guide to cyber decoys — fake systems, accounts, and data that detect an attacker already present and using legitimate tools. Start with self-hosted honeytokens before considering a commercial platform.

Linux 7.2.5 catches the Blackwell driver up and hardens ksmbd

Stable kernels 7.2.5 and 6.18.51, released September 11, 2026, fix video output for Blackwell GPUs in nouveau and close a memory leak and a use-after-free in ksmbd. Update first if you expose SMB shares or run a Blackwell card.

GNU Coreutils 9.12 speeds up cut and uniq and fixes a recursive traversal race

GNU Coreutils 9.12, released on September 14, 2026, delivers measurable wins — cut up to 4× faster, uniq up to 2.5× — and fixes a race that made -R commands fail against files deleted in parallel. A maintenance release that reminds us the GNU toolkit remains, against its Rust rewrite, the default foundation of every distribution.

Memory QoS graduates to beta and ships enabled by default in Kubernetes 1.37

Kubernetes Memory QoS, which guides the Linux kernel on container memory handling through cgroup v2, graduates to beta and turns on by default in version 1.37. The more important change lies elsewhere: the implicit throttling factor disappears, making the upgrade a no-surprise event for existing clusters.

OpenRouter guarantees US residency for requests to Chinese models

Open-weight models accounted for 60% of OpenRouter’s US token consumption in August, most of them Chinese. The marketplace has now made US in-region routing generally available, guaranteeing that requests are decrypted, processed, and served entirely on American soil — or rejected.

Perplexity launches its local agent on Windows, gated behind 24 GB of VRAM

Perplexity has brought Portable Computer, the local edition of its Computer agent, to Windows after Linux and macOS — but only for NVIDIA RTX cards with at least 24 GB of VRAM. Simple tasks run on-device, the model hands off to the cloud when it needs more reasoning, and sensitive files can stay on the machine.

Chrome 153 fixes CVE-2026-87491, the seventh exploited V8 zero-day of 2026

On September 8, 2026, Google ships Chrome 153, fixing 230 vulnerabilities including CVE-2026-87491, an out-of-bounds write in V8 already exploited in the wild. Update to 153.0.8010.36 or later before the CISA deadline of September 23, and check every Chromium browser in your fleet, Edge, Brave and Opera included.

HPE Aruba patches two unauthenticated code-execution flaws in AOS-CX

On September 1, 2026, advisory HPESBNW05134 fixes more than twenty vulnerabilities in ArubaOS-CX, including two independent bugs — CVE-2026-73749 (CVSS 9.8) and CVE-2026-73782 — that each give unauthenticated code execution on a switch. Isolate the management plane and apply the fixed branch before a public exploit turns these flaws into a mass campaign.

Four labs ship frontier models in one week and trigger model fatigue

In early September 2026, Anthropic, Meta, Google and OpenAI each ship a frontier model in the same week, and CNBC names the phenomenon model fatigue. A model’s real cost now depends on cache and context as much as benchmarks: stop comparing scores, compare the price of your workload.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss