Technology intelligence

Clearer
signals.
Brighter
decisions.

NEXUS TECH WIRE

Technology.
Ideas.
People.
A more connected
tomorrow.

Cyber intelligence

Publisher updates

Security reporting, vulnerability advisories, and defensive research — with direct links to the original evidence.

Conceptual illustration of layered digital defenses and connected infrastructure.
AI-generated illustration Conceptual artwork
Cyber

Wireshark 4.6.9 Released, (Sun, Sep 27th)

The brief

SANS highlights Wireshark 4.6.9, reporting fixes for 19 vulnerabilities and 16 additional bugs. The project's release notes detail crashes, infinite loops and memory problems across protocol dissectors and file parsers, alongside a profile-import issue that could permit code execution. The update adds no new protocols, keeping its emphasis on repairs and existing protocol support.

Source SANS Internet Storm Center

Read full article
Cyber

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

The brief

Mandiant describes renewed exploitation of Oracle PeopleSoft systems that remain vulnerable to CVE-2026-35273. The campaign reached organizations relying on web-application-firewall rules without applying Oracle’s patch, with attackers adapting requests to evade those rules. The report recommends patching or disabling the affected service, investigating application logs and deployed files, and rotating credentials exposed to the PeopleSoft service account.

Source Google Threat Intelligence

Read full article
Cyber

A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)

The brief

SANS researcher Brad Duncan examined a macOS infection delivered through a fake verification prompt and found an information stealer with persistence and separate processor-specific payloads. His follow-up questions an earlier identification as AMOS because several behaviors differ. The diary documents the observed activity while leaving the malware-family attribution unresolved, rather than presenting the initial label as confirmed.

Source SANS Internet Storm Center

Read full article
Cyber

ISC Stormcast For Friday, September 25th, 2026 https://isc.sans.edu/podcastdetail/10110, (Fri, Sep 25th)

The brief

The September 25 Stormcast covers deceptive phishing links, risks from exposed GitLab email credentials and changes observed in MacSync malware. It also discusses SolarWinds Observability fixes for remote-code-execution weaknesses that depend on particular configurations. Johannes Ullrich emphasizes applying the relevant update instead of assuming that today's configuration will remain an adequate defense against later exposure.

Source SANS Internet Storm Center

Read full article
Vulnerabilities

Multiples vulnérabilités dans les produits Elastic (25 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans les produits Elastic. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

Multiples vulnérabilités dans le noyau Linux de Red Hat (25 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans le noyau Linux d'Ubuntu (25 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans le noyau Linux de Debian LTS (25 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un déni de service.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans le noyau Linux de SUSE (25 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et une atteinte à la confidentialité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans les produits IBM (25 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Cyber

DraftKings Is Using AI to Supercharge the Harms of Online Behavioral Advertising

The brief

EFF argues that restricting the sale of personal data would leave important advertising harms unresolved. Citing reporting about DraftKings, it describes how betting histories can inform AI-driven promotions without relying on outside data brokers. The organization uses the example to advocate stronger limits on behavioral advertising, including uses of information collected directly from customers.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Cyber
Conceptual illustration of layered digital defenses and connected infrastructure.
AI-generated illustration Conceptual artwork

Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure

The brief

Mandiant’s new software supply-chain guidance covers developer workstations, repositories and build infrastructure as connected security boundaries. It describes attacks involving trusted tools, stolen development credentials and manipulated CI/CD workflows. Recommended controls include approved IDE extensions, short-lived credentials, protected branches, pinned dependencies and isolated development environments, with human review of AI-generated code and continuous verification across the delivery process.

Source Google Threat Intelligence

Read full article
Vulnerabilities

Multiples vulnérabilités dans LibreNMS (24 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans LibreNMS. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans GitLab (24 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une atteinte à la confidentialité des données et une injection de code indirecte à distance (XSS).

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Vulnérabilité dans Microsoft Office (24 septembre 2026)

The brief

CERT-FR warns that CVE-2026-70125 can allow remote code execution in Microsoft Office. Its affected-product list includes Microsoft 365 Apps for Enterprise and Office LTSC 2021 and 2024, in both 32-bit and 64-bit editions. The September 24 notice directs administrators to Microsoft's security update guide for the vulnerability's product-specific fixes.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans PHP (24 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Zabbix Agent (24 septembre 2026)

The brief

CERT-FR has flagged multiple security issues affecting Zabbix Agent2 releases earlier than 7.0.31. Its September 24 notice references the vendor's ZBX-28059 bulletin for fixes but does not describe the vulnerabilities' impact. The affected-product scope is specifically Agent2; the advisory does not identify a separate Zabbix Server version range.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

Multiples vulnérabilités dans Wireshark (24 septembre 2026)

The brief

CERT-FR identifies remote code execution and denial of service risks in Wireshark's 4.4 and 4.6 release branches. Its September 24 advisory lists versions before 4.4.19 and 4.6.9 respectively as affected. It links the corresponding Wireshark security bulletins and CVE records so operators can match their installed branch with the vendor's corrections.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Papercut (24 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans Papercut. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une injection de code indirecte à distance (XSS).

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Cloud

Intermittent authentication errors for API and R2

The brief

A small proportion of requests to Cloudflare's API and R2 encountered authentication errors in an incident identified on September 22. The company said it reduced the main impact by 19:00 UTC that day while continuing to address remaining effects. A further fix entered monitoring on September 23, and Cloudflare marked the incident resolved at 20:59 UTC that evening.

Source Cloudflare Status

Read full article
Cyber

Cyber Threat Report 2026: Leaders need to prepare now for the impact of AI

The brief

New Zealand's NCSC says frontier AI is accelerating both cyber risks and defensive opportunities. Its 2026 threat report calls on organizational leaders to prepare people, processes and resources for faster-moving attacks. The agency's projection that criminals may gain advanced AI capabilities by early 2027 is an assessment, not a confirmed future outcome.

Source NCSC New ZealandCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Vulnerabilities

Multiples vulnérabilités dans SolarWinds Observability Self-Hosted (23 septembre 2026)

The brief

CERT-FR warns of remote code execution vulnerabilities in SolarWinds Observability Self-Hosted releases before 2026.2.3. The September 23 notice names CVE-2026-28324 and CVE-2026-28325 and links separate SolarWinds advisories for the two flaws. It directs administrators to those vendor bulletins for corrections; its affected-version statement applies specifically to the self-hosted product.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans les produits HPE Aruba Networking (23 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Latest collection

Original briefs are AI-assisted and checked against the linked source. Publisher excerpts are labeled separately; each story keeps its original date and article link.