FR
live
archive

All articles

A leaked GitLab work-item email lets anyone open merge requests in your name

On September 24, 2026, Aikido revealed that GitLab’s “Email work item to this project” addresses, generated with a long-lived token and accidentally published in READMEs, let an attacker open merge requests or push code as the token owner. Search your repositories for these addresses and reset the exposed tokens.

A documentation placeholder domain now serves a ClickFix lure to Windows users

On September 24, 2026, Manifold Security revealed that third-party.com, a documentation placeholder used as an example for years, had been registered by a third party and now serves a ClickFix lure to Windows browsers. Audit your repositories and stop letting a non-reserved domain stand in as an example.

ShinyHunters breaches Clop’s leak site through a Grav CMS path traversal flaw

On September 25, 2026, BleepingComputer confirmed that the ShinyHunters gang compromised the Clop ransomware leak site by exploiting CVE-2026-42608, an unauthenticated path traversal in Grav fixed in April but never backported to the 1.7 branch. If you still run Grav 1.7, upgrade to 1.7.53.4 without delay.

AWS ships CloudWatch Omni to observe and evaluate AI agents

On September 22, 2026, Amazon CloudWatch launched Omni, a unified observability experience for applications and AI agents, delivered inside VS Code, Kiro, and a standalone web console. Adopt it to trace, compare, and evaluate your agents before a prompt regression silently degrades production responses.

The self-hosted community unmasks the developer of BookOrbit

On September 18, 2026, the self-hosted community identified the developer of BookOrbit — a self-hosted reading platform with about 4,600 GitHub stars — as the creator of Booklore, a twin project that disappeared after being called out for code quality, contributor mistreatment, and license abuse. Before deploying software you run yourself, verify author continuity, the license, and community history.

Transformers now runs llama.cpp GGUF quants natively

On September 22, 2026, Hugging Face added native GGUF support to Transformers, the llama.cpp quantized format behind Ollama, LM Studio, and Jan. If you run local models on Apple Silicon from Python, adopt `from_pretrained` with a GGUF file and drop the homegrown conversions.

The Linux kernel adds a taint flag to filter out fuzzing-bot bug reports

On September 24, 2026, Greg Kroah-Hartman merged into driver-core-next a new taint flag, TAINT_FORCED_BIND, that marks kernels whose sysfs bind/unbind files have been written. It targets fuzzing bots like syzbot that arbitrarily bind drivers to devices and drown maintainers in pointless bug reports.

Docker hands the CNCF an open format for governing AI agent permissions

On September 24, 2026, Docker published the Sandbox Kit Specification v3 under Apache 2.0 and moved it under CNCF governance: a Kit becomes an ordinary OCI image carrying the agent, its tools and the typed list of what it may reach. Teams running coding agents should adopt the model to turn implicit grants into a versioned, reviewable artifact.

A Fedora discussion proposes swapping LibreOffice for Collabora Office by default

A Fedora Discourse thread, relayed by Phoronix on September 24, 2026, proposes replacing LibreOffice with the downstream Collabora Office on Fedora Workstation, citing an ageing interface. The still-informal debate exposes the real tension in the Linux desktop: governance and funding, more than features.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss