Technology intelligence

Clearer
signals.
Brighter
decisions.

NEXUS TECH WIRE

Technology.
Ideas.
People.
A more connected
tomorrow.

Technology intelligence From the original publishers

The technology moves.
See what matters.

Follow the developments shaping technology — with a clear path to the people and evidence behind them.

RHSA-2026:74974: Important: kernel security update

From the publisher

An update for kernel is now available for NVIDIA for RHEL 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

The Cyber Desk

Security, threats & defense
Conceptual illustration of layered digital defenses and connected infrastructure.
AI-generated illustration Conceptual artwork
Cyber

Cyber Brief 26-10 - September 2026

The brief

CERT-EU's September threat review highlights stolen AI-service access and hijacked cloud workloads. Its roundup cites Google's reporting on LLM-jacking and Microsoft's account of passkey-themed phishing against Microsoft 365 users. It also covers spyware targeting civil society and alleged unauthorized AI-agent activity. The monthly report separates law-enforcement, espionage, cybercrime and AI developments across Europe and globally, drawing on attributed public reporting.

Source CERT-EUCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article

RHSA-2026:74974: Important: kernel security update

From the publisher

An update for kernel is now available for NVIDIA for RHEL 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

RHSA-2026:73979: Critical: freerdp security update

From the publisher

An update for freerdp is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

Ola Bini Ordered to Leave Ecuador Under Obscure Accusations

The brief

EFF reports that Ecuador ordered security researcher and free-software developer Ola Bini’s deportation and imposed a ten-year reentry ban. The advocacy group says officials relied on a secret security report that his defense could not inspect, and that his lawyers sought habeas corpus protection. EFF says Bini was held at Quito’s airport awaiting departure for Sweden and urges authorities to explain the accusations.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article

New fields for SecurityAdvisory GraphQL API

The brief

GitHub has expanded its advisory GraphQL interface with CVE identifiers, affected source-code links, GitHub review dates, NVD publication dates and links to associated repository advisories. New severity and withdrawal filters let integrations narrow results before downloading them. GitHub says the additions reduce the need to switch to REST for advisory data; they are read-only changes that preserve existing queries.

Source GitHub Changelog

Read full article
Open the cyber wire

Cyber

From the source
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

RHSA-2026:74974: Important: kernel security update

From the publisher

An update for kernel is now available for NVIDIA for RHEL 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

Cyber Brief 26-10 - September 2026

The brief

CERT-EU's September threat review highlights stolen AI-service access and hijacked cloud workloads. Its roundup cites Google's reporting on LLM-jacking and Microsoft's account of passkey-themed phishing against Microsoft 365 users. It also covers spyware targeting civil society and alleged unauthorized AI-agent activity. The monthly report separates law-enforcement, espionage, cybercrime and AI developments across Europe and globally, drawing on attributed public reporting.

Source CERT-EUCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article

RHSA-2026:73979: Critical: freerdp security update

From the publisher

An update for freerdp is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

Ola Bini Ordered to Leave Ecuador Under Obscure Accusations

The brief

EFF reports that Ecuador ordered security researcher and free-software developer Ola Bini’s deportation and imposed a ten-year reentry ban. The advocacy group says officials relied on a secret security report that his defense could not inspect, and that his lawyers sought habeas corpus protection. EFF says Bini was held at Quito’s airport awaiting departure for Sweden and urges authorities to explain the accusations.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article

New fields for SecurityAdvisory GraphQL API

The brief

GitHub has expanded its advisory GraphQL interface with CVE identifiers, affected source-code links, GitHub review dates, NVD publication dates and links to associated repository advisories. New severity and withdrawal filters let integrations narrow results before downloading them. GitHub says the additions reduce the need to switch to REST for advisory data; they are read-only changes that preserve existing queries.

Source GitHub Changelog

Read full article
Explore cyber

AI

From the source
Conceptual illustration of connected computing systems and artificial intelligence.
AI-generated illustration Conceptual artwork

The latest AI news we announced in September 2026

The brief

Google's September AI roundup pairs new Gemini models with wider app integrations. The company says Gemini 4 Argon has a million-token context window and is rolling out first to trusted cyber defenders through Fairwind, with broader access planned after feedback on safeguards. Other announcements include Gemini on Windows, more Connected Apps, and WeatherNext 3 forecasts integrated into Search, Gemini, Maps and Cloud.

Source Google AI

Read full article

AI Gateway, Web Search API - Introducing Web Search API

From the publisher

Web Search API is now available in beta. Web Search API lets your AI agents and applications search the Internet and ground their responses in live information, instead of guessing URLs or relying on a model's training cutoff. At launch, you can choose between three search providers: Ceramic.ai, Exa, and Linkup. All three support Zero Data Retention for requests made through Cloudflare, and all have committed to Cloudflare's verified bot crawling standards. Web Search API runs through AI Gateway, so search requests appear in your gateway logs and are billed to your AI Gateway credits at each provider's list API price, with no additional markup. You can also bring your own provider API key.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

How to implement long-term AI agent memory in AlloyDB and Memorystore for Valkey

The brief

Google Cloud describes an AI-agent memory design that keeps recent conversations in Memorystore for Valkey and durable facts, preferences and events in AlloyDB. The tutorial combines hybrid retrieval with database-managed embeddings, tenant isolation and memory cleanup. Google reports token and latency reductions from an internal simulated developer workload, while cautioning that savings vary with prompt structure, query frequency and data volume.

Source Google Cloud

Read full article

How Rogo ships agent-written code to production in 5 minutes on Vercel

The brief

Vercel says financial AI company Rogo is rebuilding internal applications on its platform and deploying agent-written code in five minutes. The customer case study reports more than 73,000 deployments in one month and six production AI agents handling work including churn analysis and deal support. Vercel also describes automated production-incident triage and remediation using its AI SDK.

Source Vercel

Read full article

Agents, Workers - Run the Pi Durable harness on Cloudflare with the Agents SDK

From the publisher

The Agents SDK now provides first-class support for building agents using the Pi harness. You can build long-running agents using the combination of Pi 1.0 ↗︎, Pi Durable ↗︎, and the new PiHarness class that the Cloudflare Agents SDK provides, ensuring your agent's work is durably persisted, even if interrupted mid-turn. Built with Earendil ↗︎, this integration is our first step toward first-class support for third-party agent harnesses on Cloudflare. Copy promptPrompt copied! Beta PiHarness is in beta. Pi Durable ↗︎ is a new, experimental package, and the PiHarness API will likely change as Pi Durable matures. PiHarness is a new "Lifecycle capability" provided by the Cloudflare Agents SDK. Pi Durable provides the agent harness and the Lifecycle is responsible for keeping the agent running in the Durable Object.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Explore ai

Cloud

From the source
Conceptual illustration of a cloud above connected islands of computing infrastructure.
AI-generated illustration Conceptual artwork

What’s new with Google Cloud

The brief

In its September 28-October 2 roundup, Google Cloud highlights storage-management guidance, an Apigee X blueprint that routes AI requests by complexity, and a new agent-evaluation session. Google describes pairing standardized traces with model-based judges and deterministic checks to detect quality regressions. The roundup also points to storage operations using Storage Intelligence Advisor and Batch Operations, and advertises an Agentic Data Cloud event for November 4.

Source Google Cloud

Read full article

Announcing Spanner queues: Transactional messaging for agentic workloads and beyond

The brief

Google Cloud has made Spanner queues generally available, letting applications commit database changes and queued tasks together in one transaction. Messages support delayed delivery, SQL consumption and transactional acknowledgments for agent handoffs and other asynchronous workflows. Google specifies at-least-once delivery and at-most-once acknowledgment. External calls still need safeguards such as the idempotency key used in Google's example.

Source Google Cloud

Read full article

Jev for Python engineers

The brief

Vercel says its latest AI SDK for Python adds an experimental evaluate() API for Jev, a model that returns structured classification decisions and confidence estimates. The accompanying tutorial explores distinguishing Python from English and constructing code through syntax-tree choices. Its examples still misclassify some inputs and produce mostly incorrect code, so the article urges developers to test whether Jev is accurate enough for their specific tasks.

Source Vercel

Read full article

Network Performance Issues in Madrid

The brief

Cloudflare has closed a network-performance incident affecting Madrid after reporting a fix on September 30. Its incident timeline records monitoring from 14:06 UTC that day and a resolved update at 05:42 UTC on October 2. The provider classified the incident as minor; its notice does not identify a root cause or quantify customer impact.

Source Cloudflare Status

Read full article

Cloudflare Workers build delays

The brief

Cloudflare marked its Workers build-delay incident resolved at 21:27 UTC on October 1. The company had opened an investigation at 15:33 UTC on September 30, warning of potential effects on multiple customers, then moved to monitoring after implementing a fix at 17:42 UTC on September 30.

Source Cloudflare Status

Read full article
Explore cloud

Infrastructure

From the source
Conceptual illustration of a cloud above connected islands of computing infrastructure.
AI-generated illustration Conceptual artwork

Spotlight on SIG Apps

From the publisher

As Kubernetes adoption has grown, the conversation has shifted beyond running containers to managing increasingly complex application lifecycles. Modern platforms support stateless web services, stateful databases, batch processing, AI workloads, and platform services. At the same time, they must remain reliable during upgrades, scaling events, and infrastructure failures. Every Kubernetes user relies on SIG Apps, whether they realize it or not. Deployments, StatefulSets, DaemonSets, Jobs, and CronJobs form the foundation of how applications are deployed, updated, scaled, and operated across the Kubernetes ecosystem. SIG Apps is focused on improving workload resilience, refining application lifecycle management, and addressing the operational challenges that emerge when applications encounter node failures, rollout disruptions, and increasingly complex infrastructure environments.

Source KubernetesCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

Kubernetes v1.37: Tracking When a PersistentVolumeClaim Was Last Used (Beta)

From the publisher

Kubernetes v1.37 promotes the PersistentVolumeClaimUnusedSinceTime feature gate to Beta (enabled by default). With this feature, the PersistentVolumeClaim (PVC) protection controller adds an Unused condition to each PVC, telling you whether any running pod currently references it — no custom tooling or cross-referencing required. For the API definition of PVC conditions, see the PersistentVolumeClaim API reference. Read on to learn how the Unused condition works and how to use it. Why track PVC usage? In large-scale Kubernetes clusters, it is common for users to create PVCs and then delete the associated pods without cleaning up the storage, because Kubernetes does not automatically delete PVCs when their pods are removed (to protect against accidental data loss). Over time, these orphaned PVCs may accumulate, silently consuming storage capacity and driving up cloud costs.

Source KubernetesCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

Kubernetes v1.37: Hardening Container Storage with Bind Mount Options and EmptyDir Permissions

From the publisher

Kubernetes v1.37 brings important storage security features: emptyDir permission modes and bind mount options. They help application programmers and security professionals implement rigorous security policies, for example, prohibiting deletion of files across containers or execution of arbitrary binaries from writable volumes, directly in Kubernetes without any complicated circumvention. Linux storage and permission fundamentals Before diving into the new Kubernetes features, let us briefly review the low-level Linux security mechanisms that make them possible. Bind mount flags When Linux mounts or remounts a directory, Virtual File System (VFS) flags control what actions are permitted on that filesystem: noexec: Do not permit direct execution of any binaries on the mounted filesystem. nosuid: Do not allow set-user-identifier or set-group-identifier bits to take effect.

Source KubernetesCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

Kubernetes v1.37: Pod-Level Resource Managers graduated to Beta

From the publisher

With the release of Kubernetes v1.37, the Pod-Level Resource Managers feature has graduated to Beta status (disabled by default)! First introduced as an Alpha feature in Kubernetes v1.36, this enhancement builds on Pod-Level Resources by equipping Kubelet's Topology Manager, CPU Manager, and Memory Manager to use Pod-level resource declarations (.spec.resources) directly when making hardware placement decisions. Bringing pod-level resources to node managers Before this feature, obtaining exclusive NUMA-aligned CPU cores or memory for latency-critical applications forced cluster operators into an all-or-nothing choice: assign integer resource requests to every container in the Pod, or forfeit exclusive NUMA alignment entirely.

Source KubernetesCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

Kubernetes v1.37: Memory QoS Graduates to Beta

From the publisher

Memory QoS has graduated to Beta in Kubernetes v1.37 and is now enabled by default. On Linux nodes running cgroup v2, the feature uses the memory controller to give the kernel better guidance on how to treat container memory. It was first introduced as Alpha in v1.22, and expanded in v1.36 with tiered memory reservation. This post covers what changed in v1.37, what the Beta promotion means for cluster operators, and how to configure the feature. What changed in v1.37Memory QoS is Beta and enabled by default The MemoryQoS feature gate is now Beta in v1.37. This means every v1.37 kubelet has the feature gate turned on without any configuration change. Turning on the feature by default is safe because the default kubelet configuration does not enable memory throttling or memory reservation.

Source KubernetesCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Explore infrastructure

IT

From the source
Conceptual illustration of layered digital defenses and connected infrastructure.
AI-generated illustration Conceptual artwork

New fields for SecurityAdvisory GraphQL API

The brief

GitHub has expanded its advisory GraphQL interface with CVE identifiers, affected source-code links, GitHub review dates, NVD publication dates and links to associated repository advisories. New severity and withdrawal filters let integrations narrow results before downloading them. GitHub says the additions reduce the need to switch to REST for advisory data; they are read-only changes that preserve existing queries.

Source GitHub Changelog

Read full article

GitHub Actions: macOS 14 runner image retirement

The brief

GitHub will remove its macOS 14 Actions runner images on November 2, 2026, covering the standard, large and xlarge labels. Scheduled brownouts beginning October 5 will temporarily fail affected jobs before retirement, and reduced capacity may lengthen queues. GitHub directs workflow maintainers to its listed macOS 15 or macOS 26 arm64 alternatives; the announcement includes the individual UTC interruption windows.

Source GitHub Changelog

Read full article

Accessibility statements highlighted on repository overview

The brief

GitHub now makes repository accessibility statements easier to find from the overview page when maintainers place ACCESSIBILITY.md in the root, .github, or docs directory. Public repositories also let contributors add or propose a statement through Community Standards. The change is available across GitHub.com plans; GitHub says Enterprise Server support will arrive in version 3.24.

Source GitHub Changelog

Read full article

Actions Job Delays

From the publisher

Oct 1, 17:56 UTC Resolved - This incident has been resolved. Thank you for your patience and understanding as we addressed this issue. A detailed root cause analysis will be shared as soon as it is available.

Source GitHub Status

Read full article

Elevated request latency

From the publisher

Oct 1, 13:57 UTC Resolved - This incident has been resolved. Thank you for your patience and understanding as we addressed this issue. A detailed root cause analysis will be shared as soon as it is available.

Source GitHub Status

Read full article
Explore it

Vulnerabilities

From the source
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

RHSA-2026:74974: Important: kernel security update

From the publisher

An update for kernel is now available for NVIDIA for RHEL 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

RHSA-2026:73979: Critical: freerdp security update

From the publisher

An update for freerdp is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article

USN-8864-1: Linux kernel vulnerabilities

The brief

Canonical has released kernel fixes for Ubuntu 14.04 and 16.04 LTS, addressing NFS server, IPv6 and Netfilter flaws that could allow system compromise. USN-8864-1 covers several kernel variants; most listed fixes require Ubuntu Pro's Legacy Support add-on, while FIPS packages have separate Pro availability. Ubuntu says a reboot is required after updating, and the changed kernel interface requires rebuilding and reinstalling third-party modules.

Source Ubuntu Security

Read full article

USN-8816-4: Linux kernel (GKE) vulnerabilities

The brief

USN-8816-4, part of Ubuntu's USN-8816 advisory series, supplies fixed GKE kernels for Ubuntu 26.04 LTS. It addresses flaws across networking, filesystems, device drivers and processor architectures that Ubuntu says could compromise systems. The corrected GKE and GKE-64K packages are version 7.0.0-1007.8. A reboot is required, and Ubuntu warns that the kernel interface change requires rebuilding and reinstalling third-party modules.

Source Ubuntu Security

Read full article

Multiples vulnérabilités dans Tenable Nessus (02 octobre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans Tenable Nessus. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Explore vulnerabilities
Latest collection

Original briefs are AI-assisted and checked against the linked source. Publisher excerpts are labeled separately; each story keeps its original date and article link.