Technology intelligence

Clearer
signals.
Brighter
decisions.

NEXUS TECH WIRE

Technology.
Ideas.
People.
A more connected
tomorrow.

The latest wire

Publisher updates

A useful brief, clear publisher credit, and a direct link to every full article.

Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

Multiples vulnérabilités dans Zabbix Agent (24 septembre 2026)

The brief

CERT-FR has flagged multiple security issues affecting Zabbix Agent2 releases earlier than 7.0.31. Its September 24 notice references the vendor's ZBX-28059 bulletin for fixes but does not describe the vulnerabilities' impact. The affected-product scope is specifically Agent2; the advisory does not identify a separate Zabbix Server version range.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Wireshark (24 septembre 2026)

The brief

CERT-FR identifies remote code execution and denial of service risks in Wireshark's 4.4 and 4.6 release branches. Its September 24 advisory lists versions before 4.4.19 and 4.6.9 respectively as affected. It links the corresponding Wireshark security bulletins and CVE records so operators can match their installed branch with the vendor's corrections.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Papercut (24 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans Papercut. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une injection de code indirecte à distance (XSS).

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Cloud

Intermittent authentication errors for API and R2

The brief

A small proportion of requests to Cloudflare's API and R2 encountered authentication errors in an incident identified on September 22. The company said it reduced the main impact by 19:00 UTC that day while continuing to address remaining effects. A further fix entered monitoring on September 23, and Cloudflare marked the incident resolved at 20:59 UTC that evening.

Source Cloudflare Status

Read full article
Cyber

Cyber Threat Report 2026: Leaders need to prepare now for the impact of AI

The brief

New Zealand's NCSC says frontier AI is accelerating both cyber risks and defensive opportunities. Its 2026 threat report calls on organizational leaders to prepare people, processes and resources for faster-moving attacks. The agency's projection that criminals may gain advanced AI capabilities by early 2027 is an assessment, not a confirmed future outcome.

Source NCSC New ZealandCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Cloud

Elevated Errors with any / all in http_response_cache_settings

The brief

Cloudflare resolved an API configuration problem on September 23 involving the any and all expressions in http_response_cache_settings. Creating or changing configurations with those expressions could produce unexpected errors, while existing active configurations and live traffic were unaffected. The company identified the issue at 15:54 UTC, said it was deploying a fix and recorded resolution at 18:08 UTC.

Source Cloudflare Status

Read full article
AI
Conceptual illustration of connected computing systems and artificial intelligence.
AI-generated illustration Conceptual artwork

Google Beam expands with new regions, partners, and customers

The brief

Google is expanding Beam video-conferencing hardware to six countries through HP and its channel partners, with support for Google Meet and Zoom. A partnership with Industrious adds bookable installations at selected U.S. workspaces starting in October. Google also reports better connection and fewer follow-up meetings in an eight-week internal study; those findings are company research, not a guarantee for every workplace.

Source Google AI

Read full article
Cloud

Unlimited Vercel Blob stores on every plan

The brief

Vercel has removed plan-specific limits on the number of Blob stores, allowing separate stores for environments, customers or temporary workloads. Creating a store now counts as a Blob Advanced Operation, while deleting one is free. Storage, other operations and data transfer remain metered, so the change expands how teams organize data and credentials without making the underlying service usage unlimited.

Source Vercel

Read full article
AI

Advancing Private AI Compute with secure, server-side memory

The brief

Google outlined a planned persistent-memory layer for Private AI Compute to retain assistant context across devices. Its design combines encrypted cloud storage, keys held on users’ devices and isolated computing environments that temporarily process the data. The company also published updated technical material and server-verification information, positioning the architecture as a way to add continuity without giving Google access to stored personal context.

Source Google DeepMind

Read full article
AI

Gemini 3.8 text-to-speech says hello

The brief

Google introduced Gemini 3.8 Flash TTS for detailed voice direction and Flash-Lite TTS for higher-volume speech generation. Both are rolling out through the Gemini API and AI Studio, while enterprise API access is described as coming later. Voice replication requires a matching consent recording and has regional restrictions; Google says generated audio carries SynthID watermarks. Voice remixing remains a forthcoming feature.

Source Google DeepMind

Read full article
Cloud

Increased Errors for Durable Objects

The brief

Cloudflare marked a September 23 Durable Objects error incident resolved at 10:00 UTC. The company had begun investigating at 08:09 UTC after reporting increased errors that could affect a subset of customers. It identified the issue at 08:35 UTC and monitored a fix from 09:20 UTC.

Source Cloudflare Status

Read full article
Cloud

Issues with 1.1.1.1 for Families

The brief

Cloudflare resolved a September 23 problem affecting DNS-over-HTTPS requests to its 1.1.1.1 for Families service, including the 1.1.1.2 and 1.1.1.3 endpoints. Its authoritative DNS service was unaffected. The company reported the issue at 00:42 UTC, identified it at 00:55 UTC and began monitoring a fix at 01:21 UTC before marking the incident resolved at 01:26 UTC.

Source Cloudflare Status

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

Multiples vulnérabilités dans SolarWinds Observability Self-Hosted (23 septembre 2026)

The brief

CERT-FR warns of remote code execution vulnerabilities in SolarWinds Observability Self-Hosted releases before 2026.2.3. The September 23 notice names CVE-2026-28324 and CVE-2026-28325 and links separate SolarWinds advisories for the two flaws. It directs administrators to those vendor bulletins for corrections; its affected-version statement applies specifically to the self-hosted product.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans les produits HPE Aruba Networking (23 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Apache Tomcat (23 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans Apache Tomcat. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Mattermost Server (23 septembre 2026)

The brief

CERT-FR has grouped several Mattermost Server flaws that can disrupt service remotely or expose confidential data. The affected branches are 11.7 before 11.7.11, 11.8 before 11.8.6, 11.9 before 11.9.2 and 11.10 before 11.10.2. Its September 23 advisory links Mattermost's security-update notices for the corresponding fixes and identifies three associated CVEs.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Vulnérabilité dans WordPress (23 septembre 2026)

The brief

CERT-FR reports that WordPress versions earlier than 7.1.2 are affected by CVE-2026-87902, a vulnerability it describes as permitting remote code execution. The September 23 notice points to WordPress's 7.1.2 release announcement and the project's GitHub security advisory for correction details. Its affected-version statement concerns WordPress itself, without naming a separate plugin or theme.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Vulnérabilité dans Check Point Security Management Server (23 septembre 2026)

From the publisher

Une vulnérabilité a été découverte dans Check Point Security Management Server. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance et une atteinte à l'intégrité des données. L'éditeur indique que la vulnérabilité CVE-2026-93616 est activement exploitée.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

Multiples vulnérabilités dans Google Chrome (23 septembre 2026)

The brief

CERT-FR's September 23 Chrome notice lists Windows and Linux builds before 154.0.8037.57 and macOS builds before 154.0.8037.58 as affected by multiple vulnerabilities. It links Google's September 22 stable-channel update and the associated CVE records. The notice leaves the security impact unspecified and refers readers to Google's bulletin for the relevant fixes.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Vulnérabilité dans F5 BIG-IP (23 septembre 2026)

From the publisher

Une vulnérabilité a été découverte dans F5 BIG-IP. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. L'éditeur indique que la vulnérabilité CVE-2026-94127 est activement exploitée. Des indicateurs de compromission sont disponibles dans l'avis de l'éditeur.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Cloud

Drives for Vercel Sandbox are now in public beta

The brief

Vercel Sandbox Drives are in public beta across Hobby, Pro and Enterprise, adding persistent directories that survive individual sandbox runs. A drive accepts one read-write mount at a time; other sandboxes can use read-only snapshots that do not pick up later changes. Drives and their sandboxes must remain in the same region, and storage, reads and writes are metered.

Source Vercel

Read full article
AI

Gemini 3.8 text-to-speech models now available on AI Gateway

The brief

Vercel added Google’s Gemini 3.8 Flash TTS and Flash-Lite TTS to AI Gateway. Both generate speech in more than 100 languages and support long narration and dialogue between two speakers. Vercel positions Flash-Lite for high-volume generation and Flash for more expressive character voices. The documented AI SDK integration requires version 7 or later.

Source Vercel

Read full article
Vulnerabilities

Multiples vulnérabilités dans les produits FoxIT (23 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans les produits FoxIT. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et une atteinte à la confidentialité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Cloud

Network Performance Issues in Taipei

The brief

Cloudflare reported a network-performance disruption affecting traffic through its Taipei facility on September 22, 2026. The provider placed the affected period at approximately 19:30–19:35 UTC. The incident notice appeared at 21:41 UTC that day and marked the event resolved, after the reported five-minute disruption had ended.

Source Cloudflare Status

Read full article
Latest collection

Original briefs are AI-assisted and checked against the linked source. Publisher excerpts are labeled separately; each story keeps its original date and article link.