Technology intelligence

Clearer
signals.
Brighter
decisions.

NEXUS TECH WIRE

Technology.
Ideas.
People.
A more connected
tomorrow.

Cyber intelligence

Publisher updates

Security reporting, vulnerability advisories, and defensive research — with direct links to the original evidence.

Conceptual illustration of layered digital defenses and connected infrastructure.
AI-generated illustration Conceptual artwork
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

RHSA-2026:71672: Important: Red Hat build of MicroShift 4.22.16 security update

From the publisher

Red Hat build of MicroShift release 4.22.16 is now available with updates to packages and images that include a security update. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:73187: Important: kernel security, bug fix, and enhancement update

From the publisher

An update for kernel is now available for Red Hat Enterprise Linux for NVIDIA. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:71443: Important: OpenShift Container Platform 4.21.35 packages and security update

From the publisher

Red Hat OpenShift Container Platform release 4.21.35 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.21. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:71442: Important: OpenShift Container Platform 4.20.40 bug fix and security update

From the publisher

Red Hat OpenShift Container Platform release 4.20.40 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.20. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:73129: Important: cjose security update

From the publisher

An update for cjose is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:73040: Important: gstreamer1-plugins-good security update

From the publisher

An update for gstreamer1-plugins-good is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

RHSA-2026:73018: Important: cjose security update

From the publisher

An update for cjose is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:73017: Important: cjose security update

From the publisher

An update for cjose is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:73027: Important: freerdp security update

From the publisher

An update for freerdp is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:73026: Important: freerdp security update

From the publisher

An update for freerdp is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cyber

ISC Stormcast For Tuesday, September 29th, 2026 https://isc.sans.edu/podcastdetail/10114, (Tue, Sep 29th)

The brief

The September 29 Stormcast covers Apple's emergency fixes for older operating-system releases and a separately patched macOS privilege-escalation issue. It also reviews Microsoft's analysis of the modular NeedyMantis implant and research into file-notification side channels. Johannes Ullrich highlights why defenders should distinguish legitimate libraries from malware that reuses them when investigating a compromised system.

Source SANS Internet Storm Center

Read full article
Vulnerabilities

Vulnérabilité dans les produits Apple (29 septembre 2026)

From the publisher

Une vulnérabilité a été découverte dans les produits Apple. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Apple indique que la vulnérabilité CVE-2026-86950 est activement exploitée.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

RHSA-2026:72888: Moderate: java-21-ibm-semeru-certified-jdk security update

From the publisher

An update for java-21-ibm-semeru-certified-jdk is now available for Red Hat Enterprise Linux 10.0 Extended Update Support and Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cyber

Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)

The brief

SANS reports that Apple issued emergency fixes for CVE-2026-86950 on iOS 26, macOS 26 and macOS 15 after reports of targeted exploitation. Its diary distinguishes these security updates from the functional updates released for version 27 systems. The article credits Meta's product security team and points readers to Apple's release information for the affected platforms.

Source SANS Internet Storm Center

Read full article
Vulnerabilities

RHSA-2026:72623: Important: kernel security, bug fix, and enhancement update

From the publisher

An update for kernel is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cyber

EFF to San Francisco Police: Drones are Powerful Surveillance Tools That Require a Robust Policy

The brief

EFF is urging San Francisco's Police Commission to strengthen proposed rules for police drones as their use expands. The organization argues that vague deployment criteria could enable broad surveillance and that the revised policy still lacks adequate safeguards. Its article says the commission is scheduled to consider the proposal on October 14.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Cyber

Cyber security insights shared at Cyber Summit Korea 2026

The brief

New Zealand's NCSC brought its threat assessment to Cyber Summit Korea, where experts and officials discussed emerging technology, cooperation and cybersecurity policy. Catriona Robinson's address covered changes in New Zealand's security environment and the opportunities and risks of AI. The agency links to the full speech for the underlying assessment and detail.

Source NCSC New ZealandCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Cyber

Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway

The brief

UK NCSC says CVE-2026-88771 and CVE-2026-88772 are being actively exploited in customer-managed Citrix NetScaler ADC and Gateway systems. They are two of eight vulnerabilities covered by Citrix's bulletin. The agency urges affected operators to investigate for compromise, isolate and replace systems where possible, and install current updates. It says the impact on UK organisations is still being assessed.

Source UK National Cyber Security CentreOpen Government Licence v3.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. Contains public sector information licensed under the Open Government Licence v3.0.

Read full article
Cyber
Conceptual illustration of layered digital defenses and connected infrastructure.
AI-generated illustration Conceptual artwork

ISC Stormcast For Monday, September 28th, 2026 https://isc.sans.edu/podcastdetail/10112, (Mon, Sep 28th)

The brief

The September 28 Stormcast reviews urgent NetScaler security updates and reports of renewed attacks on Oracle PeopleSoft. It also revisits uncertainty about the malware family behind a macOS ClickFix campaign. For a separate Kiteworks incident, Johannes Ullrich notes limited public detail and directs affected customers to the vendor for clarification rather than treating reported shutdown instructions as universal guidance.

Source SANS Internet Storm Center

Read full article
Vulnerabilities

Multiples vulnérabilités dans Citrix NetScaler ADC et Gateway (28 septembre 2026)

From the publisher

[Mise à jour du 30 septembre 2026] Dans un billet de blogue du 29 septembre 2026 (cf. section Documentation), Mandiant et Google Threat Intelligence Group (GTIG) fournissent des indicateurs de compromission ainsi que des règles de détection au format YARA.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Citrix NetScaler ADC et Gateway (28 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans Citrix NetScaler ADC et Gateway. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Cloud

Search domains without authentication

The brief

Vercel now allows domain discovery and checks of availability and pricing without an account session or access token. The CLI supports keyword searches, while the Domains Registrar API accepts up to 200 exact domain names per request and returns registration and renewal prices when available. Buying a domain or managing an existing one still requires authentication.

Source Vercel

Read full article
Vulnerabilities

Multiples vulnérabilités dans MongoDB (28 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans MongoDB. Elles permettent à un attaquant de provoquer une atteinte à l'intégrité des données, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway

From the publisher

On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE) vulnerabilities. Citrix has confirmed active exploitation of these 2 critical vulnerabilities in the wild. CERT-EU recommends updating affected software and running a compromise assessment on those exposed on the internet.

Source CERT-EUCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Latest collection

Original briefs are AI-assisted and checked against the linked source. Publisher excerpts are labeled separately; each story keeps its original date and article link.