FR
live
archive

All articles

GitHub Security Lab ships an agent that fuzzes a C/C++ repo end to end

On 24 September 2026, GitHub Security Lab released an autonomous fuzzing pipeline that writes its own harnesses, reads its own coverage and drafts its own vulnerability reports. The fuzzing bottleneck — human attention — is handed to an LLM, but the code runs on the host with no container in between.

Raspberry Pi locks Pi 5 RAM in firmware to stop fraudulent resellers

On 21 September 2026, Jeff Geerling documented a firmware lock, introduced in late 2024, that prevents swapping the RAM chips on a Raspberry Pi 5. The move targets resellers who modify entry-level boards, but it also removes the right to repair and upgrade your hardware.

A leaked GitLab work-item email lets anyone open merge requests in your name

On September 24, 2026, Aikido revealed that GitLab’s “Email work item to this project” addresses, generated with a long-lived token and accidentally published in READMEs, let an attacker open merge requests or push code as the token owner. Search your repositories for these addresses and reset the exposed tokens.

A documentation placeholder domain now serves a ClickFix lure to Windows users

On September 24, 2026, Manifold Security revealed that third-party.com, a documentation placeholder used as an example for years, had been registered by a third party and now serves a ClickFix lure to Windows browsers. Audit your repositories and stop letting a non-reserved domain stand in as an example.

ShinyHunters breaches Clop’s leak site through a Grav CMS path traversal flaw

On September 25, 2026, BleepingComputer confirmed that the ShinyHunters gang compromised the Clop ransomware leak site by exploiting CVE-2026-42608, an unauthenticated path traversal in Grav fixed in April but never backported to the 1.7 branch. If you still run Grav 1.7, upgrade to 1.7.53.4 without delay.

AWS ships CloudWatch Omni to observe and evaluate AI agents

On September 22, 2026, Amazon CloudWatch launched Omni, a unified observability experience for applications and AI agents, delivered inside VS Code, Kiro, and a standalone web console. Adopt it to trace, compare, and evaluate your agents before a prompt regression silently degrades production responses.

The self-hosted community unmasks the developer of BookOrbit

On September 18, 2026, the self-hosted community identified the developer of BookOrbit — a self-hosted reading platform with about 4,600 GitHub stars — as the creator of Booklore, a twin project that disappeared after being called out for code quality, contributor mistreatment, and license abuse. Before deploying software you run yourself, verify author continuity, the license, and community history.

Transformers now runs llama.cpp GGUF quants natively

On September 22, 2026, Hugging Face added native GGUF support to Transformers, the llama.cpp quantized format behind Ollama, LM Studio, and Jan. If you run local models on Apple Silicon from Python, adopt `from_pretrained` with a GGUF file and drop the homegrown conversions.

The Linux kernel adds a taint flag to filter out fuzzing-bot bug reports

On September 24, 2026, Greg Kroah-Hartman merged into driver-core-next a new taint flag, TAINT_FORCED_BIND, that marks kernels whose sysfs bind/unbind files have been written. It targets fuzzing bots like syzbot that arbitrarily bind drivers to devices and drown maintainers in pointless bug reports.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss