Technology intelligence

Clearer
signals.
Brighter
decisions.

NEXUS TECH WIRE

Technology.
Ideas.
People.
A more connected
tomorrow.

Cyber intelligence

Publisher updates

Security reporting, vulnerability advisories, and defensive research — with direct links to the original evidence.

Conceptual illustration of layered digital defenses and connected infrastructure.
AI-generated illustration Conceptual artwork
AI
Conceptual illustration of a glass identity medallion with fingerprint-like lines and connected data symbols.
AI-generated illustration Conceptual artwork

Agents, Workers - The best way to do MCP auth just got better: Workers OAuth Provider goes v1, with a new split API and full support for MCP 2026-07-28

The brief

Version 1 of Cloudflare's Workers OAuth Provider separates the authorization server from the MCP resource server, allowing them to run in different Workers. Tokens can be checked through a Service Binding rather than over the public internet. The release supports the July 2026 MCP authorization specification while retaining compatibility with older clients, including dynamic client registration.

Source Cloudflare DevelopersCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74088: Important: python3.9 security update

From the publisher

An update for python3.9 is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74133: Moderate: kernel security, bug fix, and enhancement update

From the publisher

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74087: Important: python3.9 security update

From the publisher

An update for python3.9 is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74095: Important: rsync security, bug fix, and enhancement update

From the publisher

An update for rsync is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74085: Important: nodejs:24 security, bug fix, and enhancement update

From the publisher

An update for the nodejs:24 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

RHSA-2026:74132: Moderate: kernel-rt security, bug fix, and enhancement update

From the publisher

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
IT

Opt-in dist-tag permissions for npm trusted publishing

The brief

npm release automation can now move distribution tags using short-lived OIDC credentials instead of retaining a token just for that step. GitHub says the new trusted-publishing permission is opt-in and starts disabled. It can also be granted to staging-only configurations, while existing token-based tag management continues unchanged.

Source GitHub Changelog

Read full article
Vulnerabilities

RHSA-2026:74084: Critical: webkit2gtk3 security update

From the publisher

An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74081: Important: python3.12-lxml security update

From the publisher

An update for python3.12-lxml is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74082: Important: python3.12-lxml security update

From the publisher

An update for python3.12-lxml is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74089: Moderate: RHEL AI 3.0 RPM runtime CVE fix - ffmpeg

The brief

Red Hat has published a Moderate-rated update for FFmpeg RPM components in RHEL AI 3.0, covering eight listed CVEs across four processor architectures. The advisory says these RPMs are internal build artifacts supported only as part of the Red Hat AI application platform. It directs administrators to apply earlier relevant errata before installing the update and following the linked installation guidance.

Source Red HatCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

RHSA-2026:73998: Important: gvfs security update

From the publisher

An update for gvfs is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74001: Important: expat security update

From the publisher

An update for expat is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:73955: Moderate: openssh security update

From the publisher

An update for openssh is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cyber

GitHub Advanced Security trials for GitHub Team

The brief

GitHub Team organizations can now try GitHub Advanced Security through a self-service trial. The offer covers Code Security and Secret Protection, with entry points in the organization overview, licensing settings and completed risk assessment. GitHub's announcement describes the trial access but does not specify its duration or pricing after the trial.

Source GitHub Changelog

Read full article
Vulnerabilities

USN-8858-1: Authen::SASL vulnerability

The brief

Ubuntu has published an update for the Authen::SASL Perl authentication library. The detailed advisory says inadequate validation of login attempts could allow unauthorized access and lists fixed packages across several Ubuntu LTS releases. Some older-release fixes require Ubuntu Pro or Legacy Support; the release-specific package table identifies the applicable update.

Source Ubuntu Security

Read full article
Vulnerabilities

USN-8859-1: ImageMagick vulnerabilities

The brief

Ubuntu's ImageMagick update addresses multiple image-processing flaws that could crash software or, for one issue, expose sensitive information. The affected releases differ by CVE, so the advisory's individual entries matter. Its package table also distinguishes fixes delivered through Ubuntu Pro's ESM Apps coverage from updates available through other channels.

Source Ubuntu Security

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

RHSA-2026:73997: Important: gvfs security update

From the publisher

An update for gvfs is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

USN-8855-1: GStreamer Bad Plugins vulnerability

The brief

A crafted WAV file could trigger a crash or potentially execute code through GStreamer Bad Plugins, according to Ubuntu. The defect concerns validation of multi-channel audio block sizes. Fixed packages are listed by Ubuntu release, with some supplied through extended security coverage; the advisory does not report confirmed active exploitation.

Source Ubuntu Security

Read full article
Cloud

Cloud CISO Perspectives: How cybersecurity startups can win CISOs

The brief

Google Cloud’s security advisers argue that cybersecurity startups should build around CISOs’ operational problems before pitching AI features. Their guidance emphasizes customer discovery, evidence for product claims, resistance to prompt injection and data poisoning, and awareness of sector-specific obligations such as data residency. The article offers practitioner advice from Google’s startup program, rather than announcing a new security product or reporting an incident.

Source Google Cloud

Read full article
Vulnerabilities

USN-8856-1: Kdenlive, MLT vulnerability

The brief

Ubuntu has patched a Kdenlive project-file issue affecting 26.04 LTS. The advisory says dangerous proxy parameters could pass through to MLT consumer properties and allow attacker-controlled projects to execute commands. It lists updates for Kdenlive and the MLT packages, tying the risk to opening a malicious project rather than ordinary video playback.

Source Ubuntu Security

Read full article
Vulnerabilities

USN-8845-1: GVfs vulnerabilities

The brief

Ubuntu's GVfs update addresses two different risks: malicious SFTP data could cause memory corruption, while a local file-ownership flaw could enable root privilege escalation on specified recent LTS releases. The affected versions differ between the issues. Ubuntu says users need to restart their session after applying the relevant package updates.

Source Ubuntu Security

Read full article
Vulnerabilities

RHSA-2026:73971: Important: thunderbird security update

From the publisher

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Latest collection

Original briefs are AI-assisted and checked against the linked source. Publisher excerpts are labeled separately; each story keeps its original date and article link.