Technology intelligence

Clearer
signals.
Brighter
decisions.

NEXUS TECH WIRE

Technology.
Ideas.
People.
A more connected
tomorrow.

The latest wire

Publisher updates

A useful brief, clear publisher credit, and a direct link to every full article.

Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

RHSA-2026:74470: Important: freerdp security update

From the publisher

An update for freerdp is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
IT

GitHub async merge API generally available

The brief

Automation no longer has to wait for a complex pull-request merge to finish inside one request. GitHub's generally available async merge API accepts the job and returns an identifier to poll for progress. It supports individual and stacked pull requests, merge queues and direct merges; bypassing rules still requires the appropriate permission.

Source GitHub Changelog

Read full article
IT

Elevated request latency

From the publisher

Oct 1, 13:57 UTC Resolved - This incident has been resolved. Thank you for your patience and understanding as we addressed this issue. A detailed root cause analysis will be shared as soon as it is available.

Source GitHub Status

Read full article
Vulnerabilities

RHSA-2026:74464: Moderate: ghostscript security update

From the publisher

An update for ghostscript is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:70585: Important: OpenShift Container Platform 4.17.58 packages and security update

From the publisher

Red Hat OpenShift Container Platform release 4.17.58 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.17. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
IT

Actions Runner Controller release 0.15.0

The brief

Actions Runner Controller 0.15.0 targets the operational friction of large Kubernetes runner fleets. GitHub describes less disruptive patch upgrades, configurable graceful shutdown and concurrency, and fewer Kubernetes API updates. Runner status moves into metrics, while scale sets can register again if their recorded counterpart has disappeared from the Actions service.

Source GitHub Changelog

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

RHSA-2026:70586: Important: OpenShift Container Platform 4.17.58 bug fix and security update

From the publisher

Red Hat OpenShift Container Platform release 4.17.58 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.17. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cloud

Democratizing Managed Lustre with lower cost and frictionless development

The brief

Google Cloud is positioning Managed Lustre’s Dynamic Tier as shared storage for AI training and high-performance computing, combining a fast cache with a larger capacity pool. The update also targets developer workloads such as repository operations and library loading, aiming to reduce separate storage environments. Published performance comparisons are Google’s tests, with test configurations supplied for evaluation.

Source Google Cloud

Read full article
AI

Workers AI - Introducing Clef: Cloudflare's first open-source decision models, now on Workers AI

The brief

Cloudflare has introduced Clef and Clef-flash on Workers AI for applications that need structured decisions instead of generated prose. The models return probabilities for defined answers, supporting tasks such as routing requests or escalating cases to people. Cloudflare says it has released the weights under Apache 2.0 and is seeking design partners for a reinforcement-learning fine-tuning service.

Source Cloudflare DevelopersCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Vulnerabilities

USN-8862-1: libXpm vulnerability

The brief

Ubuntu has issued a libXpm fix for images containing zero-dimension values. Its advisory says a local attacker could use a crafted XPM image to exhaust resources and deny service. Updated packages are listed for Ubuntu 22.04, 24.04 and 26.04 LTS; the notice does not establish that the issue has been exploited in the wild.

Source Ubuntu Security

Read full article
Cloud

Speed Insights deprecates First Input Delay on November 1st

The brief

Vercel will end collection of First Input Delay measurements in Speed Insights on November 1. Its responsiveness scoring already relies on Interaction to Next Paint, which replaced FID as a Core Web Vital. Vercel says customers need no configuration changes: existing FID history remains viewable, and the switch will not alter their Real Experience Score.

Source Vercel

Read full article
Vulnerabilities

USN-8861-1: OpenSSL vulnerabilities

The brief

Ubuntu has released an OpenSSL update for Ubuntu 26.04 LTS addressing two QUIC weaknesses that could allow a remote attacker to exhaust CPU or memory resources. The notice identifies CVE-2026-42772 and CVE-2026-54873 and lists the corrected package version. Canonical instructs affected users to apply the standard system update and reboot to complete the changes.

Source Ubuntu Security

Read full article
Cyber
Conceptual illustration of layered digital defenses and connected infrastructure.
AI-generated illustration Conceptual artwork

Securing Water and Wastewater Operational Technology Environments

The brief

NIST describes three reference approaches for protecting remote access to water and wastewater control systems: conventional on-premises access, a cloud-managed option, and encrypted communication between systems. Its guidance combines technical controls with access policies and monitoring. The agency emphasizes that remote-access protection belongs within wider risk management and depends on knowing which operational assets need protection.

Source NIST

Read full article
Vulnerabilities

RHSA-2026:74442: Important: libpcap security update

From the publisher

An update for libpcap is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

USN-8860-1: OpenStack Designate vulnerability

The brief

Canonical has patched an OpenStack Designate validation flaw that could let an authenticated user redirect DNS traffic or disrupt service in certain overlapping-zone configurations. The Ubuntu notice links the issue to CVE-2026-71193 and lists fixes across several releases. Administrators must update the applicable packages and restart Designate for the changes to take effect.

Source Ubuntu Security

Read full article
Vulnerabilities

RHSA-2026:74444: Important: qt security update

From the publisher

An update for qt is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74174: Important: kernel security, bug fix, and enhancement update

From the publisher

An update for kernel is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

USN-8857-1: KCoreAddons vulnerability

The brief

A shell-quoting flaw in KCoreAddons could let hostile input become commands in applications that rely on the affected function. Ubuntu's advisory identifies KShell::quoteArgs and provides an updated package for 26.04 LTS. The described risk depends on an application passing attacker-controlled input through that method, rather than proving every installed application is exploitable.

Source Ubuntu Security

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

RHSA-2026:74370: Important: gvfs security update

From the publisher

An update for gvfs is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cyber

The future of browser-based security: Leveraging browser data for proactive defense

The brief

Google Cloud argues that browser activity should play a larger role in enterprise security as employees adopt AI tools. It describes Chrome Enterprise Premium capabilities for monitoring risky browsing, extensions and generative AI usage, alongside retaining evidence of data-loss policy violations. Google says feeding those signals into security operations platforms can support faster investigation and response.

Source Google Cloud

Read full article
Cyber

ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)

The brief

SANS handler Xavier Mertens examined an invoice-themed phishing email that linked to a legitimate ScreenConnect installer configured for an attacker-controlled test account. His analysis found a valid ConnectWise signature and no tampering with the signed executable. The case shows how criminals can misuse ordinary remote-access software without developing a new malware program.

Source SANS Internet Storm Center

Read full article
Cloud

Introducing the Server Side Cloud Swift SDK

The brief

Google has introduced official Cloud API client libraries for server-side Swift, requiring Swift 6.2 or later. The SDK gives Linux and macOS developers asynchronous access to services such as Cloud Storage and IAM, with built-in authentication and pagination support. Google positions it for backends, containers and automation, and warns developers against embedding these server libraries or administrative credentials in Apple client apps.

Source Google Cloud

Read full article
Cyber

ISC Stormcast For Thursday, October 1st, 2026 https://isc.sans.edu/podcastdetail/10118, (Thu, Oct 1st)

The brief

The October 1 Stormcast reviews an exploited authentication-bypass flaw in Cisco's SD-WAN Manager and updates addressing WatchGuard access-point vulnerabilities. Johannes Ullrich also discusses a reported exploit chain affecting Vault and OpenBao. The episode closes with Cloudflare's work on post-quantum certificates, explaining why larger cryptographic objects create practical challenges for certificate infrastructure.

Source SANS Internet Storm Center

Read full article
IT

[Retroactive] Actions workflow run failures after deployment gate approvals

The brief

GitHub's resolved, retroactive incident report says an infrastructure failure around 02:00 UTC on October 1 lost execution state for a small number of Actions runs. Connectivity recovered, but affected runs could remain stuck or fail deployment approvals. GitHub advises starting a new run or contacting support; before rerunning jobs, teams should check completed deployment steps to avoid repeating changes.

Source GitHub Status

Read full article
Latest collection

Original briefs are AI-assisted and checked against the linked source. Publisher excerpts are labeled separately; each story keeps its original date and article link.