Technology intelligence

Clearer
signals.
Brighter
decisions.

NEXUS TECH WIRE

Technology.
Ideas.
People.
A more connected
tomorrow.

Cyber intelligence

Publisher updates

Security reporting, vulnerability advisories, and defensive research — with direct links to the original evidence.

Conceptual illustration of layered digital defenses and connected infrastructure.
AI-generated illustration Conceptual artwork
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

RHSA-2026:74471: Critical: freerdp security update

From the publisher

An update for freerdp is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74470: Important: freerdp security update

From the publisher

An update for freerdp is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74464: Moderate: ghostscript security update

From the publisher

An update for ghostscript is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:70585: Important: OpenShift Container Platform 4.17.58 packages and security update

From the publisher

Red Hat OpenShift Container Platform release 4.17.58 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.17. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:70586: Important: OpenShift Container Platform 4.17.58 bug fix and security update

From the publisher

Red Hat OpenShift Container Platform release 4.17.58 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.17. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

USN-8862-1: libXpm vulnerability

The brief

Ubuntu has issued a libXpm fix for images containing zero-dimension values. Its advisory says a local attacker could use a crafted XPM image to exhaust resources and deny service. Updated packages are listed for Ubuntu 22.04, 24.04 and 26.04 LTS; the notice does not establish that the issue has been exploited in the wild.

Source Ubuntu Security

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

USN-8861-1: OpenSSL vulnerabilities

The brief

Ubuntu has released an OpenSSL update for Ubuntu 26.04 LTS addressing two QUIC weaknesses that could allow a remote attacker to exhaust CPU or memory resources. The notice identifies CVE-2026-42772 and CVE-2026-54873 and lists the corrected package version. Canonical instructs affected users to apply the standard system update and reboot to complete the changes.

Source Ubuntu Security

Read full article
Cyber

Securing Water and Wastewater Operational Technology Environments

The brief

NIST describes three reference approaches for protecting remote access to water and wastewater control systems: conventional on-premises access, a cloud-managed option, and encrypted communication between systems. Its guidance combines technical controls with access policies and monitoring. The agency emphasizes that remote-access protection belongs within wider risk management and depends on knowing which operational assets need protection.

Source NIST

Read full article
Vulnerabilities

RHSA-2026:74442: Important: libpcap security update

From the publisher

An update for libpcap is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

USN-8860-1: OpenStack Designate vulnerability

The brief

Canonical has patched an OpenStack Designate validation flaw that could let an authenticated user redirect DNS traffic or disrupt service in certain overlapping-zone configurations. The Ubuntu notice links the issue to CVE-2026-71193 and lists fixes across several releases. Administrators must update the applicable packages and restart Designate for the changes to take effect.

Source Ubuntu Security

Read full article
Vulnerabilities

RHSA-2026:74444: Important: qt security update

From the publisher

An update for qt is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74174: Important: kernel security, bug fix, and enhancement update

From the publisher

An update for kernel is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

USN-8857-1: KCoreAddons vulnerability

The brief

A shell-quoting flaw in KCoreAddons could let hostile input become commands in applications that rely on the affected function. Ubuntu's advisory identifies KShell::quoteArgs and provides an updated package for 26.04 LTS. The described risk depends on an application passing attacker-controlled input through that method, rather than proving every installed application is exploitable.

Source Ubuntu Security

Read full article
Vulnerabilities

RHSA-2026:74370: Important: gvfs security update

From the publisher

An update for gvfs is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cyber

The future of browser-based security: Leveraging browser data for proactive defense

The brief

Google Cloud argues that browser activity should play a larger role in enterprise security as employees adopt AI tools. It describes Chrome Enterprise Premium capabilities for monitoring risky browsing, extensions and generative AI usage, alongside retaining evidence of data-loss policy violations. Google says feeding those signals into security operations platforms can support faster investigation and response.

Source Google Cloud

Read full article
Cyber

ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)

The brief

SANS handler Xavier Mertens examined an invoice-themed phishing email that linked to a legitimate ScreenConnect installer configured for an attacker-controlled test account. His analysis found a valid ConnectWise signature and no tampering with the signed executable. The case shows how criminals can misuse ordinary remote-access software without developing a new malware program.

Source SANS Internet Storm Center

Read full article
Cyber

ISC Stormcast For Thursday, October 1st, 2026 https://isc.sans.edu/podcastdetail/10118, (Thu, Oct 1st)

The brief

The October 1 Stormcast reviews an exploited authentication-bypass flaw in Cisco's SD-WAN Manager and updates addressing WatchGuard access-point vulnerabilities. Johannes Ullrich also discusses a reported exploit chain affecting Vault and OpenBao. The episode closes with Cloudflare's work on post-quantum certificates, explaining why larger cryptographic objects create practical challenges for certificate infrastructure.

Source SANS Internet Storm Center

Read full article
Vulnerabilities

Vulnérabilité dans Cisco Catalyst SD-WAN (01 octobre 2026)

From the publisher

Une vulnérabilité a été découverte dans Cisco Catalyst SD-WAN. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité. Cisco indique que la vulnérabilité CVE-2026-76504 est activement exploitée.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

Multiples vulnérabilités dans Mozilla Thunderbird (01 octobre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans Mozilla Thunderbird. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans CPython (01 octobre 2026)

The brief

CERT-FR has issued a CPython advisory covering CVE-2026-19445 and CVE-2026-19553. It identifies remote denial of service and security-policy bypass as the potential impacts and treats installations missing the latest security fixes as affected. The notice points administrators to Python's September 30 security bulletins for the relevant patches, without naming a specific affected-version range.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Cloud

Workers - Web Crypto adds ML-KEM and ML-DSA support

From the publisher

The Workers Web Crypto API now supports ML-KEM-768, ML-KEM-1024, ML-DSA-44, ML-DSA-65, and ML-DSA-87. ML-KEM establishes shared secrets, while ML-DSA signs and verifies data. The opt-in API also adds key encapsulation and decapsulation methods, getPublicKey(), SubtleCrypto.supports(), and JSON Web Keys (JWKs) with the AKP key type.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Redmine (01 octobre 2026)

The brief

CERT-FR warns that Redmine releases before 6.1.5 in the 6.1 series and before 7.0.2 in the 7 series contain security weaknesses that can expose data or enable cross-site scripting. Its October 1 advisory identifies those two affected branches and directs operators to Redmine's security notices for the corresponding fixes.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
AI

Agents, Workers - The best way to do MCP auth just got better: Workers OAuth Provider goes v1, with a new split API and full support for MCP 2026-07-28

The brief

Version 1 of Cloudflare's Workers OAuth Provider separates the authorization server from the MCP resource server, allowing them to run in different Workers. Tokens can be checked through a Service Binding rather than over the public internet. The release supports the July 2026 MCP authorization specification while retaining compatibility with older clients, including dynamic client registration.

Source Cloudflare DevelopersCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74088: Important: python3.9 security update

From the publisher

An update for python3.9 is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Latest collection

Original briefs are AI-assisted and checked against the linked source. Publisher excerpts are labeled separately; each story keeps its original date and article link.