FR
live
archive

All articles

Chrome patches its sixth exploited zero-day of 2026, a V8 type confusion

On September 4, 2026, Google shipped an emergency Chrome update fixing CVE-2026-85046, a type confusion in the V8 engine already exploited in the wild and rated 8.8 on the CVSS scale. Update to Chrome 152.0.7977.82 or later and check every Chromium browser in your fleet, including Edge, Brave and Opera.

CloudFront flat-rate plans become manageable through the API and IaC

On September 3, 2026, AWS opened programmatic management of CloudFront flat-rate plans through the new PricingPlanManager API, the CLI, CloudFormation and the CDK. Teams can now codify subscribing, changing tiers and cancelling a no-overage monthly price, with a two-phase approval that prevents unintended billing.

Kubernetes 1.37 scales queue consumers to zero replicas with the HPA

On September 2, 2026, Kubernetes 1.37 enabled horizontal scaling to zero replicas by default (Beta) whenever an object or external metric, such as a queue length, allows it. Queue consumers and batch processors can release reserved CPU and GPU while idle, provided they accept the cold-start latency.

CERN leaves RHEL and moves its 2,200 control computers to Debian 13

A RHEL and CentOS institution for two decades, CERN announced in late August 2026 that it is moving its 2,200 industrial accelerator-control computers to Debian 13 by the end of the year, with the -march=x86-64-v2 flag as the trigger. For any long-lived industrial or embedded fleet, the lesson fits in one line: watch your distribution’s CPU baseline.

Kubernetes 1.34 leaves support and all three clouds charge $438 a month

Moved into maintenance mode on August 27, 2026, Kubernetes 1.34 reaches end of life on October 27, at which point AWS, Azure and Google all bill $0.60 per cluster per hour — $438 a month — to keep patching it. Upgrade before the deadline: the surcharge buys no features, only the survival of an outdated control plane.

AWS opens its first Saudi Arabia region and commits 50 MW of AI with HUMAIN

Announced at LEAP in Riyadh, AWS’s first infrastructure region in Saudi Arabia will go live in December 2026, bringing the global network to 40 regions on a planned investment of over $5.3 billion. For teams serving the Gulf, it is the long-awaited answer to data-residency requirements, doubled with a 50 MW AI Zone planned for 2028.

Gemini 3.8 Flash Cyber finds a critical vulnerability in under two hours

On September 2, 2026 Google shipped Gemini 3.8 Flash and its Cyber variant, a security model that identified a critical foundational vulnerability in under two hours — work that normally takes researchers months. For defenders the real story is not raw capability but access, which is reserved for trusted defenders through the Fairwind Program.

A CVSS 9.8 flaw opens a remote root shell on ten Cisco Nexus 9000 switches

On 2 September 2026 Cisco disclosed CVE-2026-20212, a CVSS 9.8 flaw that leaves TCP ports 43210 and 43211 on ten Nexus 9000 switches reachable for unauthenticated remote code execution as root. Apply an iACL on both ports and the Live Protect lp00031 shield now, then check your release in the Software Checker.

A poisoned .git/config runs code when Claude Code, Codex or Cursor opens a repository

Manifold Security disclosed on 2 September 2026 eight flaws across seven CLI coding agents: a repository delivered as an archive can trigger a local command on open, outside the sandbox and without approval, via Git’s core.fsmonitor setting. Disable core.fsmonitor by default and inspect .git/config before opening a received folder with an agent.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss