Latest writing Blogs Field notes, practical guides and technical analysis on AI, cybersecurity, hardware, software and self-hosting. 20 SEPT 2026 OpenAI Codex Sandbox Escapes: Update Desktop and CLI for Heapjack and Overpatch Researchers disclosed two fixed OpenAI Codex sandbox escapes affecting Desktop and CLI. Update Codex Desktop to build 26.818.21641 or later and Codex CLI to 0.149.0 or later. CYBERSECURITY20 SEPT 2026 BIND 9.20.29 and 9.21.26 Fix 14 Security Flaws: DNS Operators Should Update ISC has patched 14 BIND 9 vulnerabilities in versions 9.20.29 and 9.21.26, including seven high-severity remote denial-of-service flaws and a DNSSEC cache-poisoning issue. CYBERSECURITY20 SEPT 2026 RustFS 1.0 Reaches GA: Apache-2.0 S3 Object Storage for Self-Hosted Infrastructure RustFS 1.0 is generally available as an Apache-2.0, Rust-based distributed object store with S3 compatibility, packaged Linux releases, container deployment and production-focused storage features. OPEN SOURCE20 SEPT 2026 CXMT Says Fifth-Generation DRAM Platform Is in Mass Production, Shows 24Gb LPDDR5X CXMT says its fifth-generation DRAM technology platform has entered mass production, using quadruple patterning to reach 11.95nm feature spacing and support denser memory products. The company also introduced new 24Gb LPDDR5X dies. HARDWARE20 SEPT 2026 WCFM Marketplace CVE-2026-18442: Update Past the Checkout SQL Injection WCFM Marketplace fixed an unauthenticated SQL injection in distance-based checkout shipping. Sites running 3.8.1 or earlier should update to the current release and review whether the vulnerable shipping path was enabled. SECURITY19 SEPT 2026 SPARSEUP Brings Apache-2.0 Sparse Retrieval to ModernBERT Linkup released SPARSEUP for learned sparse retrieval, with a ModernBERT backbone, Apache-2.0 licensing, 56.4 nDCG@10 on BEIR-13 and sub-millisecond Seismic retrieval results. AI19 SEPT 2026 AMD EPYC 9006 Agentic AI Benchmarks: What the Venice Results Actually Measure AMD's new EPYC 9006 white paper reports 1.2x per-core and 2.24x platform SPEC CPU 2026 performance versus NVIDIA Vera, plus agentic-AI, cloud and HPC tests. Here is how to read the results and their methodology limits. HARDWARE19 SEPT 2026 NVIDIA AIPerf Replaces GenAI-Perf for LLM Inference Benchmarking NVIDIA's AIPerf uses a multiprocess load client, production-style traffic patterns, percentile latency metrics and GPU telemetry to benchmark generative-AI inference at scale. AI19 SEPT 2026 OpenAI Forum Exploit Reached Employee Codex and an Internal Repository: Patch the Discourse HEIF RCE Researchers chained a Discourse HEIF image-processing RCE with an OpenAI sign-in flaw to reach employee ChatGPT and Codex accounts. Discourse operators should rebuild onto patched releases. CYBERSECURITY19 SEPT 2026 Gemini Accessed Three Real Companies During a Cybersecurity Test: What Failed Google says Gemini accessed three real companies during a May 2026 cybersecurity evaluation after the test environment exposed the agent to the public internet. The incident highlights concrete containment controls for AI cyber evaluations. ARTIFICIAL INTELLIGENCE19 SEPT 2026 CrowdSec TanStack Supply-Chain Incident: 170 Private Repositories Copied CrowdSec traced the copying of about 170 private GitHub repositories to a credential stolen during the May 2026 TanStack npm compromise. Here is the timeline, impact and response guidance. CYBERSECURITY19 SEPT 2026 CISA Weekly Vulnerability Bulletin Ends September 28: What to Use Instead CISA will discontinue its weekly Vulnerability Bulletin on September 28, 2026. Here is how to replace it with KEV, CISA alerts, CVE.org and vendor advisories. CYBERSECURITY19 SEPT 2026 WordPress 7.1.1 Security Update: 11 Fixes and the Backport Versions to Apply WordPress 7.1.1 fixes 11 security issues alongside Core and Block Editor bugs. Older maintained security branches received same-day backports, including 7.0.5, 6.9.8 and 6.8.9. CYBERSECURITY19 SEPT 2026 Tutor LMS CVE-2026-78175: Update to 4.0.8 to Block Subscriber-Level RCE Tutor LMS versions through 4.0.7 contain a PHP object-injection flaw that can give subscriber-level users remote code execution. Version 4.0.8 fixes the issue. CYBERSECURITY19 SEPT 2026 The Events Calendar CVE-2026-78006 and CVE-2026-78159: Update to 6.17.4.1 Two CVSS 9.8 flaws in The Events Calendar can lead to unauthenticated remote code execution when comments are enabled on event pages. Version 6.17.4.1 fixes both chains. CYBERSECURITY18 SEPT 2026 Gemini 3.8 Live and Extended Thinking: Voice-Agent Models, Benchmarks and Availability Google's Gemini 3.8 Live models add near-real-time visual grounding, 97-language switching, background tool calls and an Extended Thinking tier for multi-step voice agents. ARTIFICIAL INTELLIGENCE18 SEPT 2026 Dnotitia VDPU: Vector-Search ASIC Enters Silicon Testing for AI Retrieval Dnotitia's first VDPU ASIC samples are back from fabrication, with Q4 2026 silicon evaluations planned after FPGA tests reported up to 5.77x CPU-server vector-search throughput. ARTIFICIAL INTELLIGENCE18 SEPT 2026 GitLab.com Rate Limits Change October 19: Prepare Automation and AI Agents GitLab.com introduces subscription-tier rate limits from October 19, 2026 for Free and unauthenticated traffic, with Premium and Ultimate changes following in January 2027. DEVELOPER TOOLS18 SEPT 2026 Plugin4Shell: Claude Code and Codex Patched, Copilot and Gemini CLI Remain Exposed Plugin4Shell bypasses plugin SHA pinning across major AI coding agents. Claude Code 2.1.179 and Codex 0.146.0 contain fixes; Copilot and Gemini CLI need separate mitigation. CYBERSECURITY18 SEPT 2026 Azure AI Foundry CVE-2026-85889: CVSS 10 Flaw Is Already Mitigated Microsoft disclosed CVE-2026-85889, a CVSS 10.0 missing-authentication flaw in Azure AI Foundry. The hosted service has already been mitigated and requires no customer patch. CYBERSECURITY ← Newer Page 2 of 20 Older →