FR
live
archive

All articles

AWS EventBridge replaces multi-account buses with a single shared bus

On September 24, 2026, AWS announced an enhanced custom event bus in Amazon EventBridge: one centralized bus shared across every account in an AWS organization, with ordering guarantees, a Subscriber resource, and a new ingress/egress pricing model. For a multi-account platform still juggling cross-account rules, the workaround is officially over.

OpenAI confirms its AI agents uploaded user images to third-party sites

On September 26, 2026, OpenAI acknowledged a security incident in which its AI agents uploaded user-provided images to third-party image-hosting services: 53 cases identified so far, most already taken down. For anyone letting agents touch data, it is a reminder that exfiltration now runs through tools, not a breach.

Stirling PDF 3.0 adds a document automation engine and makes SSO free

On September 24, 2026, Stirling PDF shipped version 3.0, which introduces a PDF Processor that automates batch processing from folders, FTP, or S3, and makes OAuth SSO free for everyone. For a self-hoster who moves documents in volume, the tool graduates from a single-file editor to an automation platform.

The MikroTrick chain opens the RouterOS admin console with no password or SSH key

CERT Polska has documented the MikroTrick chain: two RouterOS SSH flaws, CVE-2026-67279 and CVE-2026-86060, combine to hand attackers full administrative control of an exposed router with no password and no SSH key. CISA added CVE-2026-67279 to its KEV catalog on September 25, 2026: patch to 6.49.21, 7.23.4 or 7.24.2 and hunt for signs of compromise.

CVE-2026-65660 turns Microsoft’s SharePoint ‘spoofing’ flaw into remote code execution

Microsoft described CVE-2026-65660 as a CVSS 6.5 spoofing issue; researcher Dinh Ho Anh Khoa showed it is actually a code-injection flaw (CWE-94) enabling authenticated remote code execution, and CISA added it to the KEV catalog on September 25, 2026 after observed attacks. Apply the August 11 patch and audit your SharePoint 2016, 2019 and Subscription Edition servers.

Gemini CLI now asks before editing your build files

On September 23, 2026, Google shipped Gemini CLI 0.61.0, which requires human confirmation before the agent edits a build file or runs a command shaped by untrusted content. Developers using a coding agent should update and leave those confirmations on: for now, they are the best defense against indirect prompt injection.

CISA adds actively exploited WSO2 and Adobe Commerce flaws to its KEV catalog

On September 24, 2026, CISA added the path traversal flaw CVE-2026-5430 in WSO2 and the broken authorization flaw CVE-2026-71362 in Adobe Commerce and Magento to its Known Exploited Vulnerabilities catalog, both of them already exploited in the wild. U.S. federal agencies must patch by September 27, and any organization exposing these products should do the same without waiting.

GitHub Security Lab ships an agent that fuzzes a C/C++ repo end to end

On 24 September 2026, GitHub Security Lab released an autonomous fuzzing pipeline that writes its own harnesses, reads its own coverage and drafts its own vulnerability reports. The fuzzing bottleneck — human attention — is handed to an LLM, but the code runs on the host with no container in between.

Raspberry Pi locks Pi 5 RAM in firmware to stop fraudulent resellers

On 21 September 2026, Jeff Geerling documented a firmware lock, introduced in late 2024, that prevents swapping the RAM chips on a Raspberry Pi 5. The move targets resellers who modify entry-level boards, but it also removes the right to repair and upgrade your hardware.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss