Vulnerabilities, advisories and security research · Straight from the source

The Tech Gazette

Cyber Edition
Vol. I No. 2 ★★★ Wednesday, September 23, 2026 ★★★ Closing 11:03 PM BRT

News

Announcements from the labs, companies and platforms themselves.

Today

  1. .NET5:00 PMdevblogs.microsoft.com
    Microsoft is updating its author-signing certificate starting September 23, 2026

    Starting September 23, 2026, Microsoft is updating the author-signing certificate used for NuGet packages. Customers using trusted signer policies or certificate fingerprint verification should add the new certificate as soon as possible. The post Microsoft is updating its author…

    Dev Tools
  2. Next.js3:00 PMnextjs.org
    Upcoming Next.js September Security Release

    Next.js is preparing a scheduled September security release for September 30, 2026.

    Security
  3. GitHub Changelog12:00 PMgithub.blog
    Local sandboxing in the GitHub Copilot app

    Local sandboxing helps reduce the potential impact of unintended commands by limiting access to files, network resources, and credentials on your machine. In the GitHub Copilot app, you configure it… The post Local sandboxing in the GitHub Copilot app appeared first on The…

    Security
  4. OpenAI10:00 AMopenai.com
    OpenAI extends cyber access to Ukraine for civilian defense

    OpenAI is extending access to its Daybreak program to the Government of Ukraine to support the cyber defense of civilian infrastructure.

    Security

Yesterday

  1. PostgreSQL9:00 PMpostgresql.org
    PgBouncer 1.26.0 released - Fixes three CVEs

    PgBouncer 1.26.0 has been released. This release fixes three CVEs: CVE-2026-19888: DoS due to crash, triggerable by unauthenticated clients. Caused by a SCRAM client-final-message without a nonce. CVE-2026-6668: DoS due to infinite loop, triggerable by unauthenticated clients. Ca…

    More on PgBouncer 1.26.0 · PgBouncer

    LaunchSecurity
  2. Cursor9:00 PMcursor.com
    Rollouts and Security Review

    Two bots for the last mile of shipping code: Rollouts watches every change as it deploys, and Security Review reports exploitable bugs on every pull request.

    LaunchDev Tools
  3. GitLab9:00 PMdocs.gitlab.com
    GitLab Critical Patch Release: 19.4.1, 19.3.3, 19.2.7
    LaunchSecurity
  4. Next.js3:00 PMnextjs.org
    Next.js Security Update for a Critical Upstream Issue

    The September 22, 2026 out-of-band security update for Next.js is now available

    LaunchSecurity
  5. Next.js12:00 PMnextjs.org
    Upcoming Next.js Security Update for a Critical Upstream Issue

    Next.js 16.3.6 and 15.5.26 are planned for a critical out-of-band security update on September 22, 2026.

    Security
  6. GitHub Changelog11:11 AMgithub.blog
    Security improvements for SSH

    We’re removing several SSH algorithms, adding a new algorithm, and requiring larger RSA SSH keys to improve security. The changes are as follows: We’re removing the ability to use RSA… The post Security improvements for SSH appeared first on The GitHub Blog.

    Security

Monday, September 21

  1. Netlify9:00 PMnetlify.com
    Security Update: Critical Next.js vulnerability in ImageResponse

    The Next.js team has disclosed a critical severity vulnerability in an upstream dependency that can lead to remote code execution when ImageResponse renders untrusted input. It is patched in 15.5.26 and 16.3.6. Applications that do not pass untrusted input into ImageResponse are…

    Security
  2. Stripe9:00 PMstripe.com
    New trends in global card fraud: How 3D Secure and regional mandates are affecting risk

    We analyzed billions of transactions on Stripe from January 2022 to March 2026 to understand how card fraud patterns differ by region and country, what's driving those differences, and how businesses can respond.

    Security
  3. Google Cloud1:00 PMcloud.google.com
    Strengthen your CI/CD pipeline with new Secure Source Manager capabilities

    A resilient software supply chain is the foundation of modern delivery, and securing your continuous integration and continuous delivery (CI/CD) pipeline is what keeps innovation moving safely. Notable supply chain attacks more than doubled in the first half of 2026 compared to t…

    LaunchSecurity
  4. NVIDIA11:51 AMblogs.nvidia.com
    AI Security Is an Engineering Problem — How to Solve It at Every Layer of the Agent Stack

    AI security is an engineering problem. That means defined security requirements, enforceable controls, named owners and evidence that protections work. As AI becomes more capable, the industry must accelerate security engineering, broaden access to defensive tools and share what…

    Security
  5. Google Cloud release notes4:00 AMdocs.cloud.google.com
    September 21, 2026

    Access Context Manager Feature Access Context Manager supports extended session length for Workforce Identity Federation. This feature is in Preview for Looker (Google Cloud core) customers. For more information, see Configure extended session length for Workforce Identity Federa…

    LaunchPlatforms

Sunday, September 20

  1. Rust9:00 PMblog.rust-lang.org
    GitHub Actions leaking secrets when Miri output is cached

    The Rust Security Response Team was notified that Miri stores all environment variables to target/, allowing secrets to persist in caches. While not necessary a vulnerability in and of itself, when paired with GitHub Actions caching behavior, it is possible for this to expose sec…

    Security

Friday, September 18

  1. What's New with AWS3:34 PMaws.amazon.com
    AWS Continuum now supports credential testing and accessible domain suggestions

    AWS Continuum for penetration testing is a frontier agent that proactively secures applications throughout the development lifecycle by offering on-demand, customized penetration testing with real exploitability testing. Developers and security teams can now test login credential…

    LaunchSecurity
  2. Google Cloud1:00 PMcloud.google.com
    Changing the game: Using agentic AI to secure infrastructure code

    AI is accelerating software development at an unprecedented pace. But as code generation scales, so do the challenges of securing the code, especially emerging AI-based vulnerability exploitations. To meet these challenges, the Google AI and Infrastructure team is transforming ho…

    Security

Thursday, September 17

  1. Stripe9:00 PMstripe.com
    Analyzing rising fraud attempts among travel and leisure businesses on Stripe

    Last year, Stripe data shows fraud attempts against travel and leisure businesses hit a four-year high. We analyzed payment activity from more than 200,000 active travel and leisure businesses on Stripe to understand where fraud is rising, how effectively it’s being blocked, and…

    Security
  2. GitLab9:00 PMabout.gitlab.com
    Securing the software factory at machine speed

    I joined GitLab at a moment when the way teams build and secure software has been changing rapidly. GitLab CEO Bill Staples recently framed that shift in When Code Is Abundant. When code is no longer the bottleneck, trust becomes scarce, and that constraint shows up first in what…

    Security
  3. Android Developers4:00 PMandroid-developers.googleblog.com
    Introducing the AndroidX Security State Libraries: A Unified View of Device Security

    Posted by Maunik Shah, Staff Software Engineer, Alec Garcia, Software Engineer, and Joseph Yong, Technical Program Manager At Android, we are constantly working to provide developers and enterprise partners with the data they need to keep devices protected. Today, we're thrilled…

    LaunchSecurity
  4. HashiCorp1:00 PMhashicorp.com
    Simplify compliance with the native pre-written policy experience in HCP Terraform

    Teams can now browse HashiCorp-managed pre-written policies, add them to a policy set, and apply common compliance guardrails directly in HCP Terraform.

    LaunchDev Tools
  5. Ai25:00 AMallenai.org
    What a crowdsourced game revealed about steering Olmo 3

    A crowdsourced game built on Olmo 3 showed how people can exploit unexpected model behaviors to stress-test prosocial AI evaluations—and how open access to a model’s internals can help researchers understand why those tests break.

    More on Olmo 3 · Olmo

    Research

Security Desk

Vulnerabilities exploited in the wild (CISA), critical advisories in the ecosystems devs build on (GitHub), and the security teams' own reports.

Exploited in the Wild CISA Known Exploited Vulnerabilities

CVEProductVulnerabilityDev impactAdded
CVE-2025-39682Linux KernelLinux Kernel Improper Check for Unusual or Exceptional Conditions VulnerabilityBroadSep 18
CVE-2025-39964Linux KernelLinux Kernel Race Condition VulnerabilitySomeSep 18
CVE-2026-53266Linux KernelLinux Kernel Out-of-Bounds Write VulnerabilitySomeSep 18
CVE-2026-94127F5 BIG-IP APMF5 BIG-IP APM Heap-based Buffer Overflow VulnerabilityNicheSep 22
CVE-2026-93952Arista VeloCloud OrchestratorArista VeloCloud Orchestrator Improper Input Validation VulnerabilityNicheSep 22
CVE-2026-93616Check Point Multiple ProductsCheck Point Multiple Products Path Traversal VulnerabilityNicheSep 22
CVE-2026-85102Check Point Multiple ProductsCheck Point Multiple Products Improper Certificate Validation VulnerabilityNicheSep 22
CVE-2026-7273Zyxel GS1900 Series SwitchesZyxel GS1900 Series Switches Stack-Based Buffer Overflow VulnerabilityNicheSep 21

Critical Advisories GitHub Advisory Database

PackageEcosystemAdvisoryDev impactPublished
github.com/rabbitmq/amqp091-goGoRabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI ParserSomeSep 17
github.com/rabbitmq/amqp091-goGoRabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstrSomeSep 17
github.com/rabbitmq/amqp091-goGoRabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer OverflowSomeSep 17
@vendure/corenpmVendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verificationSomeSep 17
lightrag-hkuPyPIlightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force AttacksSomeSep 22
mcp-atlassianPyPI[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty tokenSomeSep 22
github.com/kcp-dev/kcpGokcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspaceSomeSep 18
mnemosyne-memoryPyPIMnemosyne has JWT signature verification bypass sync server that allows authentication bypassSomeSep 18
io.moquette:moquette-brokerMavenMoquette: Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS cluster, a Will-message authorization bypass, and a cross-session durable-corruption bugSomeSep 23
plone.app.portletsPyPIplone.app.portlets Vulnerable to Remote Code Execution via TALES InjectionSomeSep 23
org.xwiki.rendering:xwiki-rendering-xmlMavenorg.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issueSomeSep 18
homeassistantPyPIHome Assistant: XSS in Statistics Graph CardSomeSep 22
github.com/openbao/openbaoGoOpenBao's Recovery Mode Vulnerable To Token Leakage via Timing AttackNicheSep 22

Reports

  1. OpenSSFSep 16Broad impact
    We’re In: Enterprise Commitment to Sustainable Package Registries

    The OpenSSF Governing Board and major tech enterprises are partnering to support sustainable funding models for public package registries. This commitment aims to secure and scale the global software supply chain while ensuring open source stays free and accessible for individual…

  2. OpenSSFSep 14Broad impact
    Empowering Open Source Security with Scalable Infrastructure

    How can open source projects maintain secure infrastructure without financial strain? OpenSSF Premier Member, Amazon Web Services (AWS) addresses this by providing critical funding and scalable compute resources.

  3. OpenSSFSep 22Broad impact
    What’s in the SOSS? Podcast #73 – S3E25 Securing the Source: Navigating AI Velocity, CRA Compliance, and Dependency Debt with Abby Kearns

    In this episode of What’s in the SOSS, ActiveState CEO Abby Kearns breaks down the rapidly evolving open source security landscape. The conversation explores why reactive post-build scanning fails, the risks of AI-driven code ingestion, and how impending EU CRA mandates will impa…

  4. Ubuntu Security NoticesSep 22Broad impact
    USN-8804-1: OpenSSH vulnerabilities

    Florian Kohnhäuser discovered that OpenSSH incorrectly handled shell metacharacters in certain usernames. An attacker could possibly use this issue to execute arbitrary commands when certain non-default configurations were used, resulting in arbitrary code execution. This issue o…

  5. Unit 42Sep 21Broad impact
    From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies

    We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies. The post From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies appeared first on Uni…

  6. Chrome ReleasesSep 18Broad impact
    Chrome Dev for Android Update

    Hi everyone! We've just released Chrome Dev 156 (156.0.8063.0) for Android. It's now available on Google Play. You can see a partial list of the changes in the Git log. For details on new features, check out the Chromium blog, and for details on web platform updates, check here.…

  7. OpenSSFSep 23Broad impact
    Security Slam 2026 – Fall Edition

    The Open Source Security Foundation (OpenSSF) is partnering with the Cloud Native Computing Foundation (CNCF) Security Technical Advisory Group (TAG Security) to support the 2026 Security Slam at KubeCon + CloudNativeCon America.

  8. Chrome ReleasesSep 17Broad impact
    Stable Channel Update for Desktop

      The Stable channel has been updated to 153.0.8010.52/.53 for Windows and Mac and  153.0.8010.52 to  Linux which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log   Security Fixes and Rewards Note: Access t…

  9. Chrome ReleasesSep 23Broad impact
    Chrome Beta for Android Update

    Hi everyone! We've just released Chrome Beta 155 (155.0.8059.16) for Android. It's now available on Google Play. You can see a partial list of the changes in the Git log. For details on new features, check out the Chromium blog, and for details on web platform updates, check here…

  10. Chrome ReleasesSep 22Broad impact
    Stable Channel Update for Desktop

    The Chrome team is delighted to announce the promotion of Chrome 154 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks. Chrome 154.0.8037.57 (Linux)  154.0.8037.57/.58  Windows/Mac contains a number of fixes and improvements…

  11. Ubuntu Security NoticesSep 23Broad impact
    USN-8809-1: libgit2 vulnerability

    Kazuma Matsumoto and Isabel Mill discovered that libgit2 incorrectly handled certain repository URLs when using the SSH transport. A remote attacker could possibly use this issue to execute arbitrary commands.

  12. Ubuntu Security NoticesSep 22Some impact
    USN-8803-1: Sudo vulnerability

    Guannan Wang, Zhanpeng Liu, and Guancheng Li discovered that Sudo failed to apply intercept policy checks when commands were executed under certain circumstances. A local attacker permitted to run specific commands could possibly use this issue to bypass policy enforcement and lo…

  13. Unit 42Sep 18Some impact
    A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

    Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity appeared first on Unit 42.

  14. Microsoft SecuritySep 17Some impact
    From guidance to action: Security fundamentals that materially reduce risk

    AI has made fundamental changes to the operating environment for cybersecurity. Explore exposure management guidance on recommended controls and take action and stay ahead of cyberthreats. The post From guidance to action: Security fundamentals that materially reduce risk appeare…

  15. OpenSSFSep 15Some impact
    Grow CRA Readiness: Find Your Path Through the European Union Cyber Resilience Act

    Discover how the EU Cyber Resilience Act (CRA) impacts your open source work. OpenSSF’s new community garden user journey helps maintainers, software stewards, and manufacturers navigate legal requirements and find essential tools for CRA readiness.

  16. Trail of BitsAug 26Some impact
    VMs won't contain cyber-capable agents

    As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing. The target was a QEMU/KVM VM on my Linux…

  17. Google Project ZeroSep 8Some impact
    Testing race conditions with memory access tracing and stack-based delay injection

    Many security bugs are race conditions, where multi-threaded execution has to occur with the right interleaving for a negative effect to appear. This creates challenges for several use cases: Confirming bug candidates that have been discovered manually or through static analysis.…

  18. GitHub SecurityAug 27Some impact
    OpenClaw went viral. Meet the maintainers building and securing it.

    OpenClaw is the fastest-growing project in GitHub history. Peter Steinberger and several maintainers share what they learned in the project's first six months. The post OpenClaw went viral. Meet the maintainers building and securing it. appeared first on The GitHub Blog.

  19. Ubuntu Security NoticesSep 23Some impact
    USN-8287-2: XDG Desktop Portal regression

    USN-8287-1 fixed a vulnerability in XDG Desktop Portal. Unfortunately the fix for CVE-2026-40354 was incomplete and introduced a regression when trashing files. This update fixes the problem and provides the corresponding update for Ubuntu 26.04 LTS. We apologize for the inconven…

  20. Ubuntu Security NoticesSep 23Some impact
    USN-8808-1: SQL parse vulnerabilities

    It was discovered that SQL parse contained multiple algorithmic complexity flaws when parsing SQL statements with deeply nested parentheses, comments, or dollar-quoted string literals. An attacker could use this issue to cause SQL parse to consume excessive CPU resources, resulti…

  21. Trail of BitsSep 18Some impact
    Auditing in the age of (good enough) AI

    Security firms have published numerous blog posts describing how they pointed their agent harness at a codebase and found dozens of bugs ( we’re one of them ). However, these posts tend to focus on agentic code review, which is just one aspect of how we use AI in our security rev…

  22. CERT/CCSep 17Some impact
    VU#280377: Dokploy is vulnerable to OS command injection

    Overview Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and restoration processes. The vulnerability stems from unsanitized shell command construction that can allow an attacke…

  23. Microsoft SecuritySep 22Some impact
    Unmasking EvilTokens: Getting to the root of device code phishing

    EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens inf…

  24. Trail of BitsSep 21Some impact
    SAML: A fractal of bad design

    Born out of academia and raised in corporate IT departments, the Security Assertion Markup Language (SAML) authentication protocol continues to be a staple in these organizations. However, it’s time for it to retire. With the rise of software-as-a-service (SaaS) companies i…

  25. Unit 42Sep 17Some impact
    Inside the Modern SOC: Defending the Cross-Environment Pivot

    Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending the Cross-Environment Pivot appeared first on Unit 42.

  26. Cisco TalosSep 22Some impact
    Introducing CAIRN: Frontier tracking for AI-integrated malware

    Talos is releasing CAIRN, a research toolkit for hunting, classifying, and tracking emerging AI-integrated malware.

  27. Trail of BitsSep 15Niche impact
    1Password's AI patching benchmark is misleading

    1Password’s FLAWED report, published on August 6, 2026, gives defenders a misleading picture of AI patching. Its headline says models produced clean fixes only 26% of the time. That figure includes experiments that deliberately instructed agents to apply the wrong fix, along with…

  28. Google Project ZeroSep 21Niche impact
    Windows Exploitation Techniques: Dangling COM Object Registrations

    This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in Windows, CVE-2026-66804, that I and 14 others reported. This issue is an incomplete fix for CVE-2026-50343, a bug dubbed “Dark Elevator” by Calif. The root cause of the bug was a dan…

  29. CERT/CCSep 23Niche impact
    VU#754548: Cinnamon's Kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers

    Overview Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or overwrite another user’s conversation data by supplying the correct ID. This…

  30. Microsoft SecuritySep 23Niche impact
    Reimagining the SOC for the agentic era in Microsoft Defender

    We are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for SIEM and threat protection together. The post Reimagining the SOC for the agentic era in Microsoft Defender appeared first on Microsoft Security Blog.

  31. Microsoft SecuritySep 17Niche impact
    Improving email security outcomes with real-world Microsoft Defender insights

    The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve. The post Improving email security outcomes with real-world Microsoft Defender insigh…

  32. Cisco TalosSep 22Niche impact
    The Closed Quorum: Inside the first reported autonomous AI C2 implant

    CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involveme…

  33. Cisco TalosSep 17Niche impact
    Should you care about an “AI slowdown?”

    In this week's Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.

  34. Cisco TalosSep 17Niche impact
    Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

    Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.

  35. CERT/CCSep 22Niche impact
    VU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypass

    Overview Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). On systems that trust the affected vendor’s certificate or include the application’s Authenticode hash in the UEFI Authorized Sig…

  36. Trail of BitsSep 9Niche impact
    A “proof” of Fermat’s Last Theorem that fits the margin

    Fermat famously claimed to have a “truly marvelous proof” of his Last Theorem, but he never wrote it down, insisting the margin of his page was too narrow to contain it. A few centuries later, Anthropic announced a complete formalization of Fermat’s Last Theorem using 13 mi…

  37. CERT/CCSep 23Niche impact
    VU#273940: Enterprise Access Management EAM does not rotate RSA keys

    Overview Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below. The product provides no supported mechanism to rotate its RSA key pair after deplo…

Technical Guides

Tutorials, case studies and technical deep dives.

  1. CoreWeaveSep 22
    Bringing Enterprise Identity and Key Control to AI on CoreWeave
  2. NVIDIA DeveloperSep 22
    Enabling Private High-Performance Production AI Inference with NVIDIA Confidential Computing
  3. AWS Machine LearningSep 21
    How Benchling secured multi-tenant AI agents with Amazon Bedrock AgentCore
  4. VercelSep 17
    Reproducing, disclosing, and fixing the libheif vulnerability with Hacktron and the maintainers
  5. DatadogSep 17
    Enforce custom rules in Datadog IaC Security scanning
Open at the source ↗