Technology intelligence

Clearer
signals.
Brighter
decisions.

NEXUS TECH WIRE

Technology.
Ideas.
People.
A more connected
tomorrow.

The latest wire

Publisher updates

A useful brief, clear publisher credit, and a direct link to every full article.

Cloud
Conceptual illustration of a cloud above connected islands of computing infrastructure.
AI-generated illustration Conceptual artwork

Vercel Marketplace database browser now supports Redis

The brief

Vercel's Marketplace database browser now supports both Redis and Upstash for Redis integrations. Team owners can execute commands, inspect values and browse keys from the dashboard, including filtering by type or pattern and checking expiration metadata. The command tab also supports transactions. Access to these new browser and CLI tabs is currently restricted to members with the Owner role.

Source Vercel

Read full article
Vulnerabilities

Multiples vulnérabilités dans les produits IBM (25 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Cloud

Workers - See every release and gradual deployment on Workers Metrics charts

From the publisher

Workers Metrics charts now show every release in the selected time range, including the full progression of gradual deployments. This makes it easier to correlate changes in memory, CPU time, errors, or latency with the code that was serving traffic. A gradual deployment appears as a single rollout across the chart, with shading that increases as more traffic moves to the new version. Hover over a rollout to see the previous and new versions, the rollout duration, and the traffic percentage configured at each step. Use these annotations to: Find when a regression started — See which traffic percentage was configured when errors, latency, CPU time, or wall time changed. Compare rollout stages — Check whether a metric changed as more traffic moved to the new version.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cloud

PostgreSQL 15.19 / 17.11 minor release — action may be required for ltree, pgcrypto, btree_gist, and custom operators

The brief

Supabase's rollout of PostgreSQL 15.19 and 17.11 brings security fixes alongside compatibility changes that may require database maintenance. The notice identifies affected ltree and btree_gist indexes, legacy pgcrypto PGP ciphers, and custom operators using nonstandard selectivity estimators. It provides detection queries and migration steps; impact depends on those features being used. Dashboard upgrades and new-project versions became available September 28, according to the rollout schedule.

Source Supabase

Read full article
Cloud

Logs usage-based pricing

The brief

Supabase is introducing usage-based log pricing, with ingestion measured by data volume and query allowances linked to ingestion. The soft launch includes a grace period through early 2027 before limits are enforced, giving teams time to inspect and reduce logging. Supabase describes quieter platform defaults and configurable Postgres logging as ways to manage volume; upcoming Studio warnings are informational during that period.

Source Supabase

Read full article
Cloud

Browser isolation session data sync issues

The brief

Cloudflare Browser Isolation users could encounter a browser-storage error and need to sign back into web applications during a September 24 session-sync incident. The company said browsing remained available despite the synchronization problem. It began monitoring a fix at 17:28 UTC and marked the incident resolved at 22:37 UTC.

Source Cloudflare Status

Read full article
IT

Disruption with billing information updates

The brief

GitHub says about 1,700 users encountered errors or delays while adding or changing billing addresses during a resolved September 22-24, 2026 incident. An operating system upgrade exposed an HTTP client adapter incompatibility that stalled address-validation requests. Switching the HTTP client mitigated the problem at 20:24 UTC on September 24. GitHub also reported new alerts and plans to extend the fix to other integrations.

Source GitHub Status

Read full article
Cyber

DraftKings Is Using AI to Supercharge the Harms of Online Behavioral Advertising

The brief

EFF argues that restricting the sale of personal data would leave important advertising harms unresolved. Citing reporting about DraftKings, it describes how betting histories can inform AI-driven promotions without relying on outside data brokers. The organization uses the example to advocate stronger limits on behavioral advertising, including uses of information collected directly from customers.

Source Electronic Frontier FoundationCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Cloud

Cloudflare Access updates delayed

The brief

Updates to Cloudflare Access applications and policies were delayed during a September 24 incident, but the company said authentication and enforcement of policies continued normally. Engineering reported the configuration problem at 15:20 UTC and began monitoring a fix at 15:31 UTC. Cloudflare closed the incident at 18:25 UTC; the reported effect concerned changes taking effect rather than a failure of existing access controls.

Source Cloudflare Status

Read full article
AI

Introducing Gemini 3.8 Live with Live Avatar

The brief

Google has added Live Avatar to Gemini 3.8 Live in Gemini Enterprise, pairing conversational audio with generated video. The feature can continue dialogue while tools run in the background and, according to Google, supports synchronized speech and expressions across 97 languages. Preset avatars are available, while custom avatar creation requires enterprise allowlisting; generated audio and video carry SynthID watermarks.

Source Google DeepMind

Read full article
Cyber
Conceptual illustration of layered digital defenses and connected infrastructure.
AI-generated illustration Conceptual artwork

Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure

The brief

Mandiant’s new software supply-chain guidance covers developer workstations, repositories and build infrastructure as connected security boundaries. It describes attacks involving trusted tools, stolen development credentials and manipulated CI/CD workflows. Recommended controls include approved IDE extensions, short-lived credentials, protected branches, pinned dependencies and isolated development environments, with human review of AI-generated code and continuous verification across the delivery process.

Source Google Threat Intelligence

Read full article
Cloud

Customers using BYOIP can have issues updating their BGP prefixes, including advertising or withdrawing prefixes.

The brief

Cloudflare said customers bringing their own IP addresses temporarily could not change BGP prefixes, including starting or withdrawing advertisements. Its September 24 resolution notice also acknowledged possible delays to address-map changes. The company opened the investigation at 10:22 UTC and marked it resolved at 10:25 UTC, without giving a separate start time for customer impact.

Source Cloudflare Status

Read full article
Cloud

The Vercel Bug Bounty Program is now publicly available

The brief

Vercel has combined its private and open-source bug bounty programs into one public program on HackerOne. The company says the unified route covers its platform and open-source projects, with exact testing scope and rules listed on HackerOne. Existing submissions to the former open-source program remain under review and do not need to be filed again.

Source Vercel

Read full article
IT

Incident across several services

The brief

GitHub's resolved September 23-24, 2026 incident disrupted app installation, organization creation and membership changes, while Projects showed delayed labels and stale search results. GitHub traced the failures to database maintenance and replica recovery problems in Azure Central US. API errors were mitigated at 10:58 UTC on September 23; clearing the Projects backlog took until 04:55 UTC the next day. GitHub says it is strengthening maintenance and recovery safeguards.

Source GitHub Status

Read full article
Cloud

How Klaviyo shipped 356 internal apps in two weeks on Vercel

The brief

A Vercel customer case study says Klaviyo employees deployed 356 internal apps during a two-week citizen-developer program. Its K:Forge pipeline creates repositories, deploys applications and applies shared access controls, including Okta sign-in and private connections to company databases. The account describes platform engineers completing and reviewing more complex builds, so the reported adoption figures do not imply every application was delivered without engineering involvement.

Source Vercel

Read full article
Vulnerabilities

Multiples vulnérabilités dans LibreNMS (24 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans LibreNMS. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

Multiples vulnérabilités dans GitLab (24 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une atteinte à la confidentialité des données et une injection de code indirecte à distance (XSS).

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
AI

Vercel Connect now supports TanStack AI

The brief

Vercel Connect now supports TanStack AI agents calling OAuth-protected MCP servers. A new transport adapter obtains authentication through Connect before each request, handling token freshness without applications storing or rotating those credentials. If a user has not granted access, client creation raises a consent challenge before the model runs, allowing the application to redirect the user to the authorization flow.

Source Vercel

Read full article
Vulnerabilities

Vulnérabilité dans Microsoft Office (24 septembre 2026)

The brief

CERT-FR warns that CVE-2026-70125 can allow remote code execution in Microsoft Office. Its affected-product list includes Microsoft 365 Apps for Enterprise and Office LTSC 2021 and 2024, in both 32-bit and 64-bit editions. The September 24 notice directs administrators to Microsoft's security update guide for the vulnerability's product-specific fixes.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans PHP (24 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Cloud

Workflows, Workers - Declare Workflows in the `exports` configuration

From the publisher

You can now declare the Workflows a Worker defines in the exports field of your Wrangler configuration file. Previously, a Worker could only define a Workflow through a workflows binding, even when the Worker never called the Workflow itself. Key each entry by the name of the class that extends WorkflowEntrypoint: { "exports": { "MyWorkflow": { "type": "workflow", "name": "my-workflow", "limits": { "steps": 25000, }, "schedules": ["0 * * * *"], }, }, } [exports.MyWorkflow] type = "workflow" name = "my-workflow" schedules = [ "0 * * * *" ] [exports.MyWorkflow.limits] steps = 25_000 A workflow export accepts the same settings as a workflows binding: limits, schedules, and default_retention. When you run wrangler deploy, Wrangler creates or updates the Workflow with these settings. You can declare a Workflow as both a binding and an export.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Zabbix Agent (24 septembre 2026)

The brief

CERT-FR has flagged multiple security issues affecting Zabbix Agent2 releases earlier than 7.0.31. Its September 24 notice references the vendor's ZBX-28059 bulletin for fixes but does not describe the vulnerabilities' impact. The affected-product scope is specifically Agent2; the advisory does not identify a separate Zabbix Server version range.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Latest collection

Original briefs are AI-assisted and checked against the linked source. Publisher excerpts are labeled separately; each story keeps its original date and article link.