Technology intelligence

Clearer
signals.
Brighter
decisions.

NEXUS TECH WIRE

Technology.
Ideas.
People.
A more connected
tomorrow.

The latest wire

Publisher updates

A useful brief, clear publisher credit, and a direct link to every full article.

Cloud
Conceptual illustration of a cloud above connected islands of computing infrastructure.
AI-generated illustration Conceptual artwork

OrioleDB is now in Public Beta with paid plans and paid features

The brief

Supabase has opened OrioleDB projects to paid plans as part of its public beta, adding features including read replicas, scheduled backups and compute resizing. Projects use the same billing as standard Postgres, but point-in-time recovery remains unavailable. The engine must be selected when creating a project. Supabase still limits the beta to testing, does not recommend production use and provides no SLA.

Source Supabase

Read full article
Vulnerabilities

Vulnérabilité dans Cisco Catalyst SD-WAN (01 octobre 2026)

From the publisher

Une vulnérabilité a été découverte dans Cisco Catalyst SD-WAN. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité. Cisco indique que la vulnérabilité CVE-2026-76504 est activement exploitée.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Mozilla Thunderbird (01 octobre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans Mozilla Thunderbird. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Cloud

Artifacts, Workers - Artifacts is now in open beta

From the publisher

Artifacts, Cloudflare's versioned file system that speaks Git, is now in open beta. Artifacts is built for scale, so you can create a repository per project, user, session, or task. With Artifacts, you can: Deploy repositories to Workers — Connect an Artifacts repository through Workers Builds. Pushes to the production branch deploy the updated Worker, while other branches create or update Worker Previews. Programmatically manage repositories — Use an Artifacts binding from a Worker to create or fork repos, inspect files and commits, read files by path, and issue repo-scoped Git tokens. React to repository changes — Subscribe to events when a repository is created, imported, forked, deleted, pushed to, cloned, or fetched. Control where repository data is stored — Choose to store and process your data in the US or EU.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

Multiples vulnérabilités dans CPython (01 octobre 2026)

The brief

CERT-FR has issued a CPython advisory covering CVE-2026-19445 and CVE-2026-19553. It identifies remote denial of service and security-policy bypass as the potential impacts and treats installations missing the latest security fixes as affected. The notice points administrators to Python's September 30 security bulletins for the relevant patches, without naming a specific affected-version range.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
AI

Laya decision model now available on AI Gateway, free through October 31

The brief

Vercel added Convai Innovations’ Laya decision model to AI Gateway for tasks such as routing requests, evaluating guardrails and scoring responses. The model returns structured decisions with probabilities. Calls served by Boundless are free through October 31, 2026; after that promotion, the dedicated free model ID stops serving, while the standard ID becomes billable. Applications should account for that difference before deployment.

Source Vercel

Read full article
Cloud
Conceptual illustration of layered digital defenses and connected infrastructure.
AI-generated illustration Conceptual artwork

Workers - Web Crypto adds ML-KEM and ML-DSA support

From the publisher

The Workers Web Crypto API now supports ML-KEM-768, ML-KEM-1024, ML-DSA-44, ML-DSA-65, and ML-DSA-87. ML-KEM establishes shared secrets, while ML-DSA signs and verifies data. The opt-in API also adds key encapsulation and decapsulation methods, getPublicKey(), SubtleCrypto.supports(), and JSON Web Keys (JWKs) with the AKP key type.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Redmine (01 octobre 2026)

The brief

CERT-FR warns that Redmine releases before 6.1.5 in the 6.1 series and before 7.0.2 in the 7 series contain security weaknesses that can expose data or enable cross-site scripting. Its October 1 advisory identifies those two affected branches and directs operators to Redmine's security notices for the corresponding fixes.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
AI

Agents, Workers - The best way to do MCP auth just got better: Workers OAuth Provider goes v1, with a new split API and full support for MCP 2026-07-28

The brief

Version 1 of Cloudflare's Workers OAuth Provider separates the authorization server from the MCP resource server, allowing them to run in different Workers. Tokens can be checked through a Service Binding rather than over the public internet. The release supports the July 2026 MCP authorization specification while retaining compatibility with older clients, including dynamic client registration.

Source Cloudflare DevelopersCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
AI

Microsoft AI models are now available on AI Gateway

The brief

Vercel’s AI Gateway now supports Microsoft’s MAI-Voice-2.1 and lower-latency Flash speech models, plus MAI-Transcribe-2 Streaming for live transcription. Vercel says the speech models support 23 languages and the transcription API returns updates as audio arrives. Partial transcripts may change as more audio is processed. The announcement also states that inference is billed at listed model rates without an additional platform markup.

Source Vercel

Read full article
AI

Vercel Agent now installs private packages from npm and custom registries

The brief

Vercel Agent can now install private dependencies from npm and custom registries using team-shared environment settings. The change supports npm, pnpm and classic Yarn, with separate configuration for npm tokens or additional registries. Vercel says credential values stay outside the agent’s sandbox. Project-scoped variables are not used for this feature, so existing build configuration may need to be adjusted.

Source Vercel

Read full article
Vulnerabilities

RHSA-2026:74088: Important: python3.9 security update

From the publisher

An update for python3.9 is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

RHSA-2026:74133: Moderate: kernel security, bug fix, and enhancement update

From the publisher

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74087: Important: python3.9 security update

From the publisher

An update for python3.9 is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74095: Important: rsync security, bug fix, and enhancement update

From the publisher

An update for rsync is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74085: Important: nodejs:24 security, bug fix, and enhancement update

From the publisher

An update for the nodejs:24 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74132: Moderate: kernel-rt security, bug fix, and enhancement update

From the publisher

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
IT

Opt-in dist-tag permissions for npm trusted publishing

The brief

npm release automation can now move distribution tags using short-lived OIDC credentials instead of retaining a token just for that step. GitHub says the new trusted-publishing permission is opt-in and starts disabled. It can also be granted to staging-only configurations, while existing token-based tag management continues unchanged.

Source GitHub Changelog

Read full article
AI
Conceptual illustration of connected computing systems and artificial intelligence.
AI-generated illustration Conceptual artwork

AI Gateway adds Browserbase Search and Fetch tools

The brief

Vercel now offers Browserbase Search and Fetch through AI Gateway, letting supported models locate current web pages and retrieve their contents. The same tools can be retained when switching model providers that support tool calling. The integration requires AI SDK 7.0.116 or later and uses an AI Gateway key; the announcement directs developers to separate pricing and configuration details.

Source Vercel

Read full article
Vulnerabilities

RHSA-2026:74084: Critical: webkit2gtk3 security update

From the publisher

An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74081: Important: python3.12-lxml security update

From the publisher

An update for python3.12-lxml is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74082: Important: python3.12-lxml security update

From the publisher

An update for python3.12-lxml is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
AI

Gemini 4 Argon: our next era of frontier intelligence

The brief

Google has announced Gemini 4 Argon, with initial access for selected cybersecurity defenders through its Fairwind Program. The company says the model supports longer reasoning workflows, including software engineering and enterprise tasks, with an output limit of one million tokens. Broader availability is planned after additional testing and safeguards work; the reported capabilities and benchmark results are Google’s claims.

Source Google DeepMind

Read full article
Cloud

Edge Requests are now called CDN Requests

The brief

Vercel has renamed its Edge Requests usage metric to CDN Requests across dashboards, notifications and invoices. The company says pricing, limits and measurement are unchanged, and existing metric identifiers remain valid. Billing integrations that match on the ServiceName field need attention because that displayed name changes; Vercel recommends using the stable SkuId field to avoid depending on future naming changes.

Source Vercel

Read full article
Latest collection

Original briefs are AI-assisted and checked against the linked source. Publisher excerpts are labeled separately; each story keeps its original date and article link.