Technology intelligence

Clearer
signals.
Brighter
decisions.

NEXUS TECH WIRE

Technology.
Ideas.
People.
A more connected
tomorrow.

Cyber intelligence

Publisher updates

Security reporting, vulnerability advisories, and defensive research — with direct links to the original evidence.

Conceptual illustration of layered digital defenses and connected infrastructure.
AI-generated illustration Conceptual artwork
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server

From the publisher

On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server[6]. Both are remotely exploitable without authentication. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds[6].

Source CERT-EUCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cyber

Cyber Brief 26-09 - August 2026

The brief

CERT-EU's August review connects reporting on phishing, supply-chain compromise and attacks on trusted infrastructure. Examples include Microsoft 365 finance lures and remote-access footholds used to reach valuable systems. It is a retrospective synthesis of attributed open-source reporting, with links to the underlying accounts and their qualifications, rather than a new incident alert.

Source CERT-EUCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
AI

Proactive cyber defense for governments and enterprises

The brief

Google introduced Fairwind on September 2 as a restricted program for government agencies, selected Cloud customers and cybersecurity partners. It combines Gemini 3.8 Flash Cyber with CodeMender to identify vulnerabilities and produce validated fixes, according to Google. Initial access prioritizes public-sector systems, critical infrastructure and core technology platforms. Participants must restrict tool access to internal security teams and apply safeguards including multi-factor authentication.

Source Google AI

Read full article
Vulnerabilities

Multiples vulnérabilités dans SonicWall Secure Mobile Access (02 septembre 2026)

From the publisher

Le 01 septembre 2026, SonicWall a publié un avis de sécurité concernant deux vulnérabilités affectant les Secure Mobile Access (SMA) 1000. La vulnérabilité critique CVE-2026-83548 permet une falsification de requêtes côté serveur (SSRF) de la part d'un attaquant non authentifié.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Cyber

Meta's $17 Billion Settlement is a Bad Deal for Teens and All Social Media Users

The brief

EFF criticizes Meta's settlement with state attorneys general, arguing that its age-assurance requirements and restrictions on younger users could create new privacy and expression problems. The organization also questions the agreement's approach to retaining information and parental oversight. Its analysis contends that protecting teenagers should reduce unnecessary data collection rather than expand it across the platform.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Cyber

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

The brief

Google Threat Intelligence and Mandiant describe BREEZE COMET, a financially motivated group targeting Brazilian payment infrastructure, retailers and financial services. Their investigations link compromised accounts and custom malware to fraudulent transfers. The report recommends stronger credential protection, network segmentation and controls on remote management tools. Infrastructure observed elsewhere in Latin America and Africa suggests possible expansion, rather than establishing successful thefts there.

Source Google Threat Intelligence

Read full article
Cyber
Conceptual illustration of a glass identity medallion with fingerprint-like lines and connected data symbols.
AI-generated illustration Conceptual artwork

Doxxing Safety Part II: Incident Response

The brief

EFF's incident-response guide outlines practical steps for people facing doxxing, including documenting events, tightening account access and organizing help from trusted contacts. It recommends assigning responsibilities so one person does not have to manage every alert and decision. The guide treats recovery as an ongoing process that includes personal well-being as well as technical security.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Cyber

Doxxing Safety Pt I: Prevention and Footprint Management

The brief

EFF's prevention guide encourages people to examine their public digital footprint before a doxxing incident occurs. It explains how public records, old accounts and breached information can combine to expose more than expected. The guidance focuses on reducing unnecessary disclosure, reviewing likely risks and involving trusted helpers without letting the assessment become overwhelming.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Cyber

Privacy on the Map (Part 2): Progress, Pitfalls, and the Fight for Enforceable Location Data Protections

The brief

EFF reviews state efforts to protect location data and argues that gaps still leave people exposed to tracking and sensitive inferences. Its recommendations include broader limits on collection, enforceable privacy rights and safeguards against manipulative consent screens. The organization says protections should cover people's movements generally, rather than depend solely on whether they visit a designated sensitive place.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Cyber

EFF and Allies on Brazil's Elections: Privacy Protections are Crucial to Electoral Integrity

The brief

EFF, Access Now and Data Privacy Brasil have issued recommendations linking privacy safeguards to the integrity of Brazil's elections. They argue that political profiling and AI-generated material can amplify manipulative targeting. The proposals call for coordination among regulators, civil society and platforms, along with stronger oversight of personal-data use and limits on political microtargeting during defined periods.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Cyber

Back to the Future: Why Agentic AI Needs a Strong Identity Foundation

The brief

Giving AI agents a person's credentials can recreate familiar identity-management problems at machine speed. NIST's analysis highlights shared credentials, long-lived tokens and excessive permissions, and points to existing authorization standards as a starting point. It also warns that repeated human approval requests can create consent fatigue rather than dependable oversight.

Source NIST

Read full article
Cyber

Disruptive cyber activity highlights risk from internet-exposed systems and edge devices

The brief

The UK's National Cyber Security Centre reports increased targeting of operational technology across sectors worldwide, including the UK, with some limited real-world disruption. It urges organizations to verify internet exposure, protect access to industrial systems, maintain supported boundary devices and test recovery arrangements. The alert also stresses that ordinary businesses face related risks from exposed systems and edge equipment.

Source UK National Cyber Security CentreOpen Government Licence v3.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. Contains public sector information licensed under the Open Government Licence v3.0.

Read full article
Cyber
Conceptual illustration of a glass identity medallion with fingerprint-like lines and connected data symbols.
AI-generated illustration Conceptual artwork

A List of ICE Subpoenas to Tech Companies

The brief

EFF has assembled a list of immigration-enforcement requests for user information from technology companies, drawing on public reporting, court cases and transparency disclosures. It records differing outcomes, including withdrawals, objections and data disclosures. The organization stresses that the list is incomplete because many requests become visible only when companies report them or affected users challenge them.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Cyber

EFF Statement on Meta Settlement

The brief

EFF's statement on Meta's settlement argues that expanding age assurance would require more information from users while limiting younger people's access to online expression and communities. The organization also warns that retained data could face security risks or government requests. These are EFF's objections to the agreement, rather than an independent determination of its eventual effects.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
AI

Agents, Workers - Choose OAuth scopes for Wrangler and the Cloudflare API MCP server

From the publisher

Wrangler and the Cloudflare API MCP server now use optional OAuth scopes. During authorization, you can choose which optional scopes to grant instead of approving every scope requested by each client. The consent dialog now includes the option to edit the permissions you grant to Wrangler or the Cloudflare API MCP server: You can then choose which specific permissions to grant: Required scopes remain selected. Choosing fewer optional scopes limits each tool's access to the permissions needed for your workflow. If a command or tool call needs a scope that you declined, reauthorize the client and grant that scope. For more information, refer to wrangler login and Edit optional permissions.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cyber

EFF and Civil Society Groups Call on Nottinghamshire Police to Halt Live Face Recognition

The brief

EFF and several civil society groups have asked Nottinghamshire Police to stop a proposed expansion of live facial recognition. Their letter raises concerns about scanning people in public, possible use involving children and the effects on participation in everyday activities. The groups argue that the force has not adequately addressed proportionality, public support or safeguards.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Cyber

Intermediary Liability in Brazil: The Intricate Path Ahead

The brief

EFF examines Brazil's changing rules for platforms' responsibility over user posts, including removal notices and duties concerning serious unlawful content. Its analysis welcomes requirements to explain decisions and provide appeals, while warning that broad obligations can encourage excessive removal or surveillance. The organization calls for transparency from both platforms and government agencies as the framework is implemented.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Cyber

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

The brief

Google Threat Intelligence reports three suspected Russian espionage clusters targeting people in government, defense, academia and think tanks through deceptive use of legitimate sign-in features. Personal accounts are frequent targets, limiting employers' visibility. Google recommends verifying unexpected invitations independently and reviewing linked devices. It assesses a Russian connection with high confidence, while links between two clusters and ICE RELIC remain a moderate-confidence assessment.

Source Google Threat Intelligence

Read full article
Cyber
Conceptual illustration of a glass identity medallion with fingerprint-like lines and connected data symbols.
AI-generated illustration Conceptual artwork

Some Tech Companies Have Privately Pushed Back on ICE Subpoenas. They Should All Do More.

The brief

EFF describes instances in which Meta and Reddit challenged immigration-enforcement demands for account information behind the scenes. It argues that private objections are useful but insufficient, especially when users must arrange their own legal challenges. The organization calls on technology companies to provide clearer public commitments and, where appropriate, contest improper demands in court themselves.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Vulnerabilities

2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway

From the publisher

On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). CERT-EU recommends updating affected devices as soon as possible.

Source CERT-EUCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cyber

NIST Releases Tips & Tactics for Building Automation & Control System Cybersecurity

The brief

NIST has released a quick-start security infographic for operators of building automation and control systems. These systems manage functions such as HVAC, lighting and access control, and their connections to corporate networks or cloud services increase exposure. The resource targets teams with limited capacity and links to broader operational-technology guidance.

Source NIST

Read full article
Cyber

Staying Ahead of Adversarial AI Through Agentic Source Code Review

The brief

Mandiant has described its internal Agentic Vulnerability Discovery Harness, which combines AI agents with expert review to identify and validate software flaws. The company says ten months of use have produced 12 assigned CVEs and helped accelerate incident-response code reviews. Its published architecture keeps human verification in the process; reported speed and accuracy gains are Mandiant's own observations, not independent benchmarks.

Source Google Threat Intelligence

Read full article
Cyber

Stronger Cybersecurity Programs Start with People: NIST Wants Your Input on the Path Forward for Human-Centered Cybersecurity

The brief

NIST is asking how security programs can better fit the people who use them. A new concept paper argues that training alone cannot fix confusing tools, disruptive processes or exhausted staff. The agency proposes practical human-centered guidance that treats users as defenders and problem-solvers, with their abilities and limitations shaping security decisions.

Source NIST

Read full article
Cyber

Too Little, Too Late: Flock Admits Their Technology Needs Reforms

The brief

EFF reviews changes Flock Safety has announced for its license plate reader system, including shorter default retention, filtering of access by offense and expanded auditing. The organization acknowledges potential improvements but questions their durability and effectiveness. It argues that binding legal limits and oversight are needed instead of relying solely on policies chosen by surveillance vendors.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Latest collection

Original briefs are AI-assisted and checked against the linked source. Publisher excerpts are labeled separately; each story keeps its original date and article link.