Technology intelligence

Clearer
signals.
Brighter
decisions.

NEXUS TECH WIRE

Technology.
Ideas.
People.
A more connected
tomorrow.

Cyber intelligence

Publisher updates

Security reporting, vulnerability advisories, and defensive research — with direct links to the original evidence.

Conceptual illustration of layered digital defenses and connected infrastructure.
AI-generated illustration Conceptual artwork
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

Multiples vulnérabilités dans Apache Tomcat (23 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans Apache Tomcat. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Mattermost Server (23 septembre 2026)

The brief

CERT-FR has grouped several Mattermost Server flaws that can disrupt service remotely or expose confidential data. The affected branches are 11.7 before 11.7.11, 11.8 before 11.8.6, 11.9 before 11.9.2 and 11.10 before 11.10.2. Its September 23 advisory links Mattermost's security-update notices for the corresponding fixes and identifies three associated CVEs.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Vulnérabilité dans WordPress (23 septembre 2026)

The brief

CERT-FR reports that WordPress versions earlier than 7.1.2 are affected by CVE-2026-87902, a vulnerability it describes as permitting remote code execution. The September 23 notice points to WordPress's 7.1.2 release announcement and the project's GitHub security advisory for correction details. Its affected-version statement concerns WordPress itself, without naming a separate plugin or theme.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Vulnérabilité dans Check Point Security Management Server (23 septembre 2026)

From the publisher

Une vulnérabilité a été découverte dans Check Point Security Management Server. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance et une atteinte à l'intégrité des données. L'éditeur indique que la vulnérabilité CVE-2026-93616 est activement exploitée.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Google Chrome (23 septembre 2026)

The brief

CERT-FR's September 23 Chrome notice lists Windows and Linux builds before 154.0.8037.57 and macOS builds before 154.0.8037.58 as affected by multiple vulnerabilities. It links Google's September 22 stable-channel update and the associated CVE records. The notice leaves the security impact unspecified and refers readers to Google's bulletin for the relevant fixes.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Vulnérabilité dans F5 BIG-IP (23 septembre 2026)

From the publisher

Une vulnérabilité a été découverte dans F5 BIG-IP. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. L'éditeur indique que la vulnérabilité CVE-2026-94127 est activement exploitée. Des indicateurs de compromission sont disponibles dans l'avis de l'éditeur.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

Multiples vulnérabilités dans les produits FoxIT (23 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans les produits FoxIT. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et une atteinte à la confidentialité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

2026-013: Critical Vulnerability in F5 BIG-IP APM

From the publisher

On 22 September 2026, F5 published an advisory addressing a critical vulnerability affecting its BIG-IP APM product. The vendor confirmed active exploitation in the wild. CERT-EU recommends taking appropriate actions as soon as possible.

Source CERT-EUCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

Vulnérabilité dans SolarWinds Access Rights Manager (22 septembre 2026)

The brief

CERT-FR identifies a remote code execution flaw in SolarWinds Access Rights Manager releases before 2026.2.1. The issue is tracked as CVE-2026-28326 and is covered by a SolarWinds security advisory dated September 17. The French agency's September 22 notice directs administrators to that vendor guidance for the required correction details.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Moodle (22 septembre 2026)

The brief

CERT-FR warns of SQL injection and security-policy bypass vulnerabilities in Moodle. Its September 22 advisory covers releases earlier than 4.5.14, plus the 5.0, 5.1 and 5.2 branches before 5.0.10, 5.1.7 and 5.2.3 respectively. It links two Moodle security notices published that day and directs site administrators to them for the corresponding fixes.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Cyber

EU Kids Act Won't Keep the Internet Accountable and Trustworthy

The brief

EFF's analysis of the European Commission's proposed Kids Act questions whether age checks and restricted platform access would adequately protect children. It argues that these measures could also undermine privacy and access to information. The organization calls for stronger safeguards around data collection and meaningful participation by young people as the proposal develops.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Synology DSM (21 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans Synology DSM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Cyber
Conceptual illustration of a glass identity medallion with fingerprint-like lines and connected data symbols.
AI-generated illustration Conceptual artwork

How to Limit What Apple’s New Siri AI Can Access in iOS 27

The brief

EFF has published a guide to limiting which personal information Apple's updated Siri can use in iOS 27. It distinguishes search access, app personalization and on-screen content, explaining that their controls do different jobs. The guide also warns that some AI requests may involve cloud processing and describes options for reducing access or disabling the new features.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Cyber

Secure Messaging and AI Remain In Conflict Despite the Promise of TEEs

The brief

EFF examines the tension between encrypted messaging and AI services that process conversations in the cloud. Its analysis says trusted execution environments can offer safeguards but do not preserve the same privacy boundary as keeping messages on participants' devices. The authors call for clear user choices and caution against automatically sending private conversations to external AI systems.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Cloud

v0 now reads npm credentials from shared environment variables

The brief

v0 can now install private npm or custom-registry packages using shared Vercel environment variables scoped to Development or Preview. Teams can supply NPM_TOKEN for npm's registry or NPM_RC for custom and multiple registries, bringing internal libraries into their builds. Vercel says these credentials are neither shown to the model nor written to the sandbox filesystem; integration status appears in v0 settings.

Source Vercel

Read full article
Cyber

EFF to Lawmakers: Ground AI Cybersecurity Rules in Best Practices

The brief

EFF is urging lawmakers to base AI cybersecurity rules on demonstrated risks and established security practices. Its recommendations include isolating high-risk testing, recording system activity and investigating incidents independently. The organization argues that public incident reports can help improve defenses while cautioning against inflexible requirements that assume today's AI systems and threats will remain unchanged.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Cyber

SME cyber vulnerability jumps as attacks hit medium-sized businesses hardest

The brief

New Zealand's NCSC survey found rising concern about cyber exposure among smaller businesses, with medium-sized respondents reporting particularly high levels of threats or attacks. The findings also show gaps in staff training and incident reporting. These are survey results, not a measurement of every business; the agency urges firms to turn concern into routine protective action.

Source NCSC New ZealandCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Infrastructure

Kubernetes v1.37: Hardening Container Storage with Bind Mount Options and EmptyDir Permissions

From the publisher

Kubernetes v1.37 brings important storage security features: emptyDir permission modes and bind mount options. They help application programmers and security professionals implement rigorous security policies, for example, prohibiting deletion of files across containers or execution of arbitrary binaries from writable volumes, directly in Kubernetes without any complicated circumvention. Linux storage and permission fundamentals Before diving into the new Kubernetes features, let us briefly review the low-level Linux security mechanisms that make them possible. Bind mount flags When Linux mounts or remounts a directory, Virtual File System (VFS) flags control what actions are permitted on that filesystem: noexec: Do not permit direct execution of any binaries on the mounted filesystem. nosuid: Do not allow set-user-identifier or set-group-identifier bits to take effect.

Source KubernetesCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
AI
Conceptual illustration of a glass identity medallion with fingerprint-like lines and connected data symbols.
AI-generated illustration Conceptual artwork

AI SDK harness layer now supports native subscription authentication

The brief

Vercel's AI SDK harness can now use native coding-agent subscriptions when the underlying agent supports them. Explicit provider credentials take priority in direct mode; automatic mode can use a subscription only without Gateway credentials. Gateway mode never reads subscriptions. Vercel says tokens remain managed on the host, with placeholder injection available only where the sandbox supports it.

Source Vercel

Read full article
Cyber

Cold TAKE: Amazon's New Encryption Method Still Doesn't Deliver Real Privacy

The brief

EFF's review of Ring's temporary-key encryption approach acknowledges a privacy improvement while arguing that it still falls short of end-to-end encryption. The authors describe how cloud processing and features that restore access can preserve exposure beyond the initial storage window. They call for independent auditing and stronger default protection for the contents of users' recordings.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Vulnerabilities

2026-012: Critical Vulnerabilities in Check Point Products

From the publisher

On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall deployments configured to use Remote Access VPN or Site-to-Site VPN. Both vulnerabilities carry a CVSS score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary code on affected appliances. CERT-EU strongly recommends applying the available hotfixes as soon as possible, prioritising internet-facing and perimeter appliances.

Source CERT-EUCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

Vulnérabilité dans Metabase (10 septembre 2026)

From the publisher

Le 06 août 2026, Metabase a publié un avis de sécurité concernant une vulnérabilité critique permettant à un attaquant non authentifié de provoquer une injection SQL (SQLi) dans la base de donnée de l'application Metabase.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Cyber

Cops Play Hide and Seek About Using Spy Tech to Avoid Scrutiny and Bad PR

The brief

EFF highlights reporting that some police agencies use vague descriptions when documenting searches involving surveillance tools such as automated license plate readers. The organization argues that this can obstruct public oversight and scrutiny of evidence in court. Its article calls for clearer disclosure of surveillance practices and connects the issue to earlier disputes over investigative technologies.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Cyber

Digital Sovereignty: What It Is, What It Could Be

The brief

EFF examines the competing meanings of digital sovereignty, from government control of infrastructure to individuals' ability to choose and maintain their own tools. The authors argue that reducing dependence on dominant vendors requires more than moving data between countries. Their discussion emphasizes open systems, interoperability and local technical capacity as foundations for meaningful user control.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Latest collection

Original briefs are AI-assisted and checked against the linked source. Publisher excerpts are labeled separately; each story keeps its original date and article link.