Technology intelligence

Clearer
signals.
Brighter
decisions.

NEXUS TECH WIRE

Technology.
Ideas.
People.
A more connected
tomorrow.

Technology intelligence From the original publishers

The technology moves.
See what matters.

Follow the developments shaping technology — with a clear path to the people and evidence behind them.

RHSA-2026:73979: Critical: freerdp security update

From the publisher

An update for freerdp is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

The Cyber Desk

Security, threats & defense
Conceptual illustration of a glass identity medallion with fingerprint-like lines and connected data symbols.
AI-generated illustration Conceptual artwork
Cyber

Ola Bini Ordered to Leave Ecuador Under Obscure Accusations

The brief

EFF reports that Ecuador ordered security researcher and free-software developer Ola Bini’s deportation and imposed a ten-year reentry ban. The advocacy group says officials relied on a secret security report that his defense could not inspect, and that his lawyers sought habeas corpus protection. EFF says Bini was held at Quito’s airport awaiting departure for Sweden and urges authorities to explain the accusations.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article

RHSA-2026:73979: Critical: freerdp security update

From the publisher

An update for freerdp is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

Confidential comments on repository security advisories

The brief

GitHub now lets repository teams discuss vulnerability reports inside security advisories using comments restricted to users who currently have write access. Reporters and invited collaborators lacking that permission cannot read them or receive notifications; losing write access also removes visibility. Comment visibility cannot be changed after posting. GitHub says the feature covers public repositories with private vulnerability reporting enabled across its Free, Pro, Team and Enterprise Cloud plans.

Source GitHub Changelog

Read full article

RHSA-2026:72785: Important: ruby security update

From the publisher

An update for ruby is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

USN-8864-1: Linux kernel vulnerabilities

The brief

Canonical has released kernel fixes for Ubuntu 14.04 and 16.04 LTS, addressing NFS server, IPv6 and Netfilter flaws that could allow system compromise. USN-8864-1 covers several kernel variants; most listed fixes require Ubuntu Pro's Legacy Support add-on, while FIPS packages have separate Pro availability. Ubuntu says a reboot is required after updating, and the changed kernel interface requires rebuilding and reinstalling third-party modules.

Source Ubuntu Security

Read full article
Open the cyber wire

Cyber

From the source
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

RHSA-2026:73979: Critical: freerdp security update

From the publisher

An update for freerdp is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

Ola Bini Ordered to Leave Ecuador Under Obscure Accusations

The brief

EFF reports that Ecuador ordered security researcher and free-software developer Ola Bini’s deportation and imposed a ten-year reentry ban. The advocacy group says officials relied on a secret security report that his defense could not inspect, and that his lawyers sought habeas corpus protection. EFF says Bini was held at Quito’s airport awaiting departure for Sweden and urges authorities to explain the accusations.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article

Confidential comments on repository security advisories

The brief

GitHub now lets repository teams discuss vulnerability reports inside security advisories using comments restricted to users who currently have write access. Reporters and invited collaborators lacking that permission cannot read them or receive notifications; losing write access also removes visibility. Comment visibility cannot be changed after posting. GitHub says the feature covers public repositories with private vulnerability reporting enabled across its Free, Pro, Team and Enterprise Cloud plans.

Source GitHub Changelog

Read full article

RHSA-2026:72785: Important: ruby security update

From the publisher

An update for ruby is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

USN-8864-1: Linux kernel vulnerabilities

The brief

Canonical has released kernel fixes for Ubuntu 14.04 and 16.04 LTS, addressing NFS server, IPv6 and Netfilter flaws that could allow system compromise. USN-8864-1 covers several kernel variants; most listed fixes require Ubuntu Pro's Legacy Support add-on, while FIPS packages have separate Pro availability. Ubuntu says a reboot is required after updating, and the changed kernel interface requires rebuilding and reinstalling third-party modules.

Source Ubuntu Security

Read full article
Explore cyber

AI

From the source
Conceptual illustration of connected computing systems and artificial intelligence.
AI-generated illustration Conceptual artwork

AI Gateway, Web Search API - Introducing Web Search API

From the publisher

Web Search API is now available in beta. Web Search API lets your AI agents and applications search the Internet and ground their responses in live information, instead of guessing URLs or relying on a model's training cutoff. At launch, you can choose between three search providers: Ceramic.ai, Exa, and Linkup. All three support Zero Data Retention for requests made through Cloudflare, and all have committed to Cloudflare's verified bot crawling standards. Web Search API runs through AI Gateway, so search requests appear in your gateway logs and are billed to your AI Gateway credits at each provider's list API price, with no additional markup. You can also bring your own provider API key.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

How Rogo ships agent-written code to production in 5 minutes on Vercel

The brief

Vercel says financial AI company Rogo is rebuilding internal applications on its platform and deploying agent-written code in five minutes. The customer case study reports more than 73,000 deployments in one month and six production AI agents handling work including churn analysis and deal support. Vercel also describes automated production-incident triage and remediation using its AI SDK.

Source Vercel

Read full article

GitHub Copilot can now interact with desktop apps with computer use

The brief

GitHub has opened a public preview of computer use in Copilot CLI and the Copilot app for macOS and Windows. The assistant can work through desktop interfaces, including software without an API or command line. GitHub says users approve app control and can review those permissions; managed organizations can disable the feature. On macOS, additional accessibility and screen-recording permissions are required.

Source GitHub Changelog

Read full article

GitHub Copilot in VS Code, September 2026 releases

The brief

GitHub’s September roundup covers Copilot changes across VS Code versions 1.136 through 1.140. Preview features add recurring agent tasks and assistance with preparing pull requests for merge, while session controls and Dev Container support aim to keep work organized. The update also expands ways to attach GitHub issues and pull requests to chats. Availability varies by feature; several additions remain previews.

Source GitHub Changelog

Read full article

Workers AI - Introducing Clef: Cloudflare's first open-source decision models, now on Workers AI

The brief

Cloudflare has introduced Clef and Clef-flash on Workers AI for applications that need structured decisions instead of generated prose. The models return probabilities for defined answers, supporting tasks such as routing requests or escalating cases to people. Cloudflare says it has released the weights under Apache 2.0 and is seeking design partners for a reinforcement-learning fine-tuning service.

Source Cloudflare DevelopersCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Explore ai

Cloud

From the source
Conceptual illustration of a cloud above connected islands of computing infrastructure.
AI-generated illustration Conceptual artwork

Network Performance Issues in Madrid

The brief

Cloudflare has closed a network-performance incident affecting Madrid after reporting a fix on September 30. Its incident timeline records monitoring from 14:06 UTC that day and a resolved update at 05:42 UTC on October 2. The provider classified the incident as minor; its notice does not identify a root cause or quantify customer impact.

Source Cloudflare Status

Read full article

Cloudflare Workers build delays

The brief

Cloudflare marked its Workers build-delay incident resolved at 21:27 UTC on October 1. The company had opened an investigation at 15:33 UTC on September 30, warning of potential effects on multiple customers, then moved to monitoring after implementing a fix at 17:42 UTC on September 30.

Source Cloudflare Status

Read full article

Accelerating analytics: PayPal’s journey with Managed Service for Apache Spark

The brief

In a Google Cloud customer account, PayPal describes migrating analytics workloads from on-premises Hadoop systems to Managed Service for Apache Spark. The company says the move consolidated fragmented workflows, shortened cluster provisioning and improved integration with Cloud Storage and BigQuery. PayPal reports a 25% improvement in core workload processing times, alongside lower operational overhead; those results reflect its own deployment.

Source Google Cloud

Read full article

Enabling Cloud Storage end-to-end checksums for improved data integrity and durability

The brief

Google says the latest Cloud Storage SDKs now enable end-to-end upload checksumming by default, reducing extra work previously required from application developers. The SDKs calculate and send checksums when applications do not supply them, and support verification during downloads. Range reads through the gRPC API also receive integrity checks. Google recommends updating clients to use these protections against accidental data corruption.

Source Google Cloud

Read full article

Speed Insights deprecates First Input Delay on November 1st

The brief

Vercel will end collection of First Input Delay measurements in Speed Insights on November 1. Its responsiveness scoring already relies on Interaction to Next Paint, which replaced FID as a Core Web Vital. Vercel says customers need no configuration changes: existing FID history remains viewable, and the switch will not alter their Real Experience Score.

Source Vercel

Read full article
Explore cloud

Infrastructure

From the source
Conceptual illustration of a cloud above connected islands of computing infrastructure.
AI-generated illustration Conceptual artwork

Spotlight on SIG Apps

From the publisher

As Kubernetes adoption has grown, the conversation has shifted beyond running containers to managing increasingly complex application lifecycles. Modern platforms support stateless web services, stateful databases, batch processing, AI workloads, and platform services. At the same time, they must remain reliable during upgrades, scaling events, and infrastructure failures. Every Kubernetes user relies on SIG Apps, whether they realize it or not. Deployments, StatefulSets, DaemonSets, Jobs, and CronJobs form the foundation of how applications are deployed, updated, scaled, and operated across the Kubernetes ecosystem. SIG Apps is focused on improving workload resilience, refining application lifecycle management, and addressing the operational challenges that emerge when applications encounter node failures, rollout disruptions, and increasingly complex infrastructure environments.

Source KubernetesCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

Kubernetes v1.37: Tracking When a PersistentVolumeClaim Was Last Used (Beta)

From the publisher

Kubernetes v1.37 promotes the PersistentVolumeClaimUnusedSinceTime feature gate to Beta (enabled by default). With this feature, the PersistentVolumeClaim (PVC) protection controller adds an Unused condition to each PVC, telling you whether any running pod currently references it — no custom tooling or cross-referencing required. For the API definition of PVC conditions, see the PersistentVolumeClaim API reference. Read on to learn how the Unused condition works and how to use it. Why track PVC usage? In large-scale Kubernetes clusters, it is common for users to create PVCs and then delete the associated pods without cleaning up the storage, because Kubernetes does not automatically delete PVCs when their pods are removed (to protect against accidental data loss). Over time, these orphaned PVCs may accumulate, silently consuming storage capacity and driving up cloud costs.

Source KubernetesCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

Kubernetes v1.37: Hardening Container Storage with Bind Mount Options and EmptyDir Permissions

From the publisher

Kubernetes v1.37 brings important storage security features: emptyDir permission modes and bind mount options. They help application programmers and security professionals implement rigorous security policies, for example, prohibiting deletion of files across containers or execution of arbitrary binaries from writable volumes, directly in Kubernetes without any complicated circumvention. Linux storage and permission fundamentals Before diving into the new Kubernetes features, let us briefly review the low-level Linux security mechanisms that make them possible. Bind mount flags When Linux mounts or remounts a directory, Virtual File System (VFS) flags control what actions are permitted on that filesystem: noexec: Do not permit direct execution of any binaries on the mounted filesystem. nosuid: Do not allow set-user-identifier or set-group-identifier bits to take effect.

Source KubernetesCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

Kubernetes v1.37: Pod-Level Resource Managers graduated to Beta

From the publisher

With the release of Kubernetes v1.37, the Pod-Level Resource Managers feature has graduated to Beta status (disabled by default)! First introduced as an Alpha feature in Kubernetes v1.36, this enhancement builds on Pod-Level Resources by equipping Kubelet's Topology Manager, CPU Manager, and Memory Manager to use Pod-level resource declarations (.spec.resources) directly when making hardware placement decisions. Bringing pod-level resources to node managers Before this feature, obtaining exclusive NUMA-aligned CPU cores or memory for latency-critical applications forced cluster operators into an all-or-nothing choice: assign integer resource requests to every container in the Pod, or forfeit exclusive NUMA alignment entirely.

Source KubernetesCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

Kubernetes v1.37: Memory QoS Graduates to Beta

From the publisher

Memory QoS has graduated to Beta in Kubernetes v1.37 and is now enabled by default. On Linux nodes running cgroup v2, the feature uses the memory controller to give the kernel better guidance on how to treat container memory. It was first introduced as Alpha in v1.22, and expanded in v1.36 with tiered memory reservation. This post covers what changed in v1.37, what the Beta promotion means for cluster operators, and how to configure the feature. What changed in v1.37Memory QoS is Beta and enabled by default The MemoryQoS feature gate is now Beta in v1.37. This means every v1.37 kubelet has the feature gate turned on without any configuration change. Turning on the feature by default is safe because the default kubelet configuration does not enable memory throttling or memory reservation.

Source KubernetesCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Explore infrastructure

IT

From the source
Conceptual illustration of code brackets surrounding connected modular computing blocks.
AI-generated illustration Conceptual artwork

GitHub Actions: macOS 14 runner image retirement

The brief

GitHub will remove its macOS 14 Actions runner images on November 2, 2026, covering the standard, large and xlarge labels. Scheduled brownouts beginning October 5 will temporarily fail affected jobs before retirement, and reduced capacity may lengthen queues. GitHub directs workflow maintainers to its listed macOS 15 or macOS 26 arm64 alternatives; the announcement includes the individual UTC interruption windows.

Source GitHub Changelog

Read full article

Accessibility statements highlighted on repository overview

The brief

GitHub now makes repository accessibility statements easier to find from the overview page when maintainers place ACCESSIBILITY.md in the root, .github, or docs directory. Public repositories also let contributors add or propose a statement through Community Standards. The change is available across GitHub.com plans; GitHub says Enterprise Server support will arrive in version 3.24.

Source GitHub Changelog

Read full article

Actions retention now covers checks, runs, and statuses

The brief

Old checks and workflow history now expire alongside Actions logs and artifacts. GitHub says the same retention setting also covers statuses from third-party apps, subject to organization and enterprise limits. Public repositories retain a maximum of 90 days, and extending the setting cannot bring back records already deleted.

Source GitHub Changelog

Read full article

Actions Job Delays

From the publisher

Oct 1, 17:56 UTC Resolved - This incident has been resolved. Thank you for your patience and understanding as we addressed this issue. A detailed root cause analysis will be shared as soon as it is available.

Source GitHub Status

Read full article

Elevated request latency

From the publisher

Oct 1, 13:57 UTC Resolved - This incident has been resolved. Thank you for your patience and understanding as we addressed this issue. A detailed root cause analysis will be shared as soon as it is available.

Source GitHub Status

Read full article
Explore it

Vulnerabilities

From the source
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

RHSA-2026:73979: Critical: freerdp security update

From the publisher

An update for freerdp is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

RHSA-2026:72785: Important: ruby security update

From the publisher

An update for ruby is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

USN-8864-1: Linux kernel vulnerabilities

The brief

Canonical has released kernel fixes for Ubuntu 14.04 and 16.04 LTS, addressing NFS server, IPv6 and Netfilter flaws that could allow system compromise. USN-8864-1 covers several kernel variants; most listed fixes require Ubuntu Pro's Legacy Support add-on, while FIPS packages have separate Pro availability. Ubuntu says a reboot is required after updating, and the changed kernel interface requires rebuilding and reinstalling third-party modules.

Source Ubuntu Security

Read full article

USN-8816-4: Linux kernel (GKE) vulnerabilities

The brief

USN-8816-4, part of Ubuntu's USN-8816 advisory series, supplies fixed GKE kernels for Ubuntu 26.04 LTS. It addresses flaws across networking, filesystems, device drivers and processor architectures that Ubuntu says could compromise systems. The corrected GKE and GKE-64K packages are version 7.0.0-1007.8. A reboot is required, and Ubuntu warns that the kernel interface change requires rebuilding and reinstalling third-party modules.

Source Ubuntu Security

Read full article

Multiples vulnérabilités dans Tenable Nessus (02 octobre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans Tenable Nessus. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Explore vulnerabilities
Latest collection

Original briefs are AI-assisted and checked against the linked source. Publisher excerpts are labeled separately; each story keeps its original date and article link.