FR
live
archive

All articles

AWS taps Qualcomm for custom inference silicon and 1.6 Tbps optics

On September 8, 2026, Amazon Web Services announced a partnership with Qualcomm for custom AI inference silicon and 1.6 Tbps optical interconnect gear, under a commercial commitment that could reach $60 billion through September 2036. A strong signal about the diversification of AWS’s silicon supply chain — and about the real bottleneck of AI clusters: the network.

OpenSSL 4.1 adds DTLS 1.3 and GREASE to the network crypto stack

On September 9, 2026, the first OpenSSL 4.1 alpha enabled DTLS 1.3 — shorter handshakes, forward secrecy and built-in post-quantum crypto — plus GREASE, the mechanism that stops middleboxes from ossifying TLS. For anyone running gateways, IoT fleets or UDP-based services, it is the signal to start planning the migration.

NSA, FBI and CISA accuse six Chinese labs of distilling US AI models

On September 8, 2026, a joint advisory from the NSA, FBI and CISA described “industrial-scale distillation” of American frontier AI models by DeepSeek, Alibaba, Moonshot AI and three other Chinese players, routed through a gray market of proxies called “transfer stations”. For model providers it is a countermeasure playbook; for enterprises it is one more due-diligence question about where their dependencies come from.

IBM ships PatchTST-FM-r2, the top zero-shot time-series forecaster under a permissive license

On September 9, 2026, IBM released Granite Time Series PatchTST-FM-r2, a 385M-parameter model that becomes the best zero-shot forecaster shipped under a permissive license on the GIFT-Eval benchmark, ahead of several larger models. For any team doing demand, load or telemetry forecasting, it is a production-ready zero-shot starting point.

SAP patches OVERPASS and S4GET, two pre-auth flaws that run code on the SAP kernel

On September 9, 2026, SAP shipped fixes for four critical flaws, including CVE-2026-44756 (CVSS 10.0), a memory-corruption bug in Extended Passport processing that yields unauthenticated remote code execution across three protocols at once. Basis teams should patch the SAP kernel first, ahead of any network segmentation effort.

Docker Engine 29.8.0 adds --umask and blocks a 32-bit sandbox-escape path

Docker Engine 29.8.0, released September 3, 2026, introduces a --umask flag to set a container’s file-creation mask and adds AppArmor/SELinux rules that block the 32-bit socketcall(2) path to AF_VSOCK. Upgrade if you share volumes between host and containers or harden your containers.

A Lenovo email-verification flaw opened 5,000 Dropbox accounts without a password

On September 2, 2026, Dropbox disclosed that an attacker accessed roughly 5,000 accounts by abusing a flaw in Lenovo’s email-verification process to register fraudulent Lenovo IDs — never needing the victim’s Dropbox password. Audit every identity-federation link you accept and require re-authentication on SSO sign-ins.

MiniCPM5-2B puts a 2.5B open model above every 4B model in its comparison

OpenBMB shipped MiniCPM5-2B, a dense 2.5-billion-parameter model under Apache-2.0 with a 131,072-token context, posting a 53.9 average that beats every open 4B model it was tested against — and releasing the UltraData training sets behind it. If you run local or on-device AI, this changes the cost-capability tradeoff.

Asahi Linux officially supports M3 Macs, minus GPU, sleep, and HDMI

Asahi Linux merged Apple M3 support into its installer on September 6, 2026: the webcam, microphones, USB 3, hardware video decoding with AV1, Wi-Fi, and Bluetooth work, but the GPU, sleep, and HDMI remain missing. Install in expert mode and wait for the GPU before making it a daily driver.

Aurora MySQL 8.4.8 adds delayed replication to survive an accidental DROP TABLE

Aurora MySQL 8.4.8, available in early September 2026, adds delayed replication: a replica deliberately applies each change with a configurable lag, making it the only copy that does not reproduce an accidental DROP TABLE or DELETE. Configure it by stored procedure and write the recovery runbook before you need it.

File Browser is archived and will receive no more security fixes

File Browser, the self-hosted web file manager with 36,000 GitHub stars, shipped its last release v2.63.23 on July 27, 2026 and archived its repository on September 1, 2026: no more security fixes will follow. Audit your exposed instances and migrate to a maintained alternative.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss