Latest writing Blogs Field notes, practical guides and technical analysis on AI, cybersecurity, hardware, software and self-hosting. 16 SEPT 2026 Acronis CVE-2026-87886: Update cPanel and Plesk Backup Plugins CISA added exploited Acronis CVE-2026-87886 to KEV with a September 19 remediation deadline. See affected cPanel and Plesk builds, fixed versions and response priorities. CYBERSECURITY16 SEPT 2026 LiteSpeed Enterprise Privilege Escalation: Update to 6.3.7 or Later cPanel says LiteSpeed Web Server Enterprise before 6.3.7 has a critical privilege-escalation flaw that can let a low-privilege shared-hosting user reach root. See the affected versions, official update command and 6.3.7 security changes. CYBERSECURITY16 SEPT 2026 Cisco Secure Email Gateway CVE-2026-76461: Fixed AsyncOS Versions and Exploitation Checks Cisco says CVE-2026-76461 is actively exploited and can give an unauthenticated attacker root command execution through a crafted email. See fixed AsyncOS releases, affected products and Cisco investigation guidance. CYBERSECURITY16 SEPT 2026 Velociraptor CVE-2026-19583: Permission Bypass Can Enable Endpoint Command Execution Rapid7 rates CVE-2026-19583 at CVSS 9.9. Velociraptor users with investigator-level access can abuse client monitoring to schedule restricted artifacts such as Linux.Sys.BashShell. Version 0.77.2 fixes the flaw. CYBERSECURITY16 SEPT 2026 ArubaOS-CX CVE-2026-73749: Critical Unauthenticated RCE and Fixed Versions HPE Networking rates CVE-2026-73749 at CVSS 9.8. The ArubaOS-CX buffer-overflow flaws can enable unauthenticated remote code execution with elevated privileges. This guide maps affected and fixed AOS-CX releases and the vendor mitigation guidance. CYBERSECURITY16 SEPT 2026 Google Mantis: Open-Source AI Vulnerability Harness, Architecture, Setup and Sandbox Requirements Google open-sourced Mantis to automate vulnerability discovery, triage, reproduction and patching with coding agents. This guide covers its architecture, 85% token-overhead reduction claim, setup flow, sandbox requirements and deployment limits. CYBERSECURITY16 SEPT 2026 OpenHands 1.18 Tightens Automation Permissions and Cloud Agent Controls OpenHands 1.18 builds on the 1.17 automation overhaul with creator-only reactivation, cloud automation editing, execution-identity visibility and stricter harness registry handling. This guide explains the release changes, Agent Canvas architecture and upgrade impact. AI16 SEPT 2026 vphone-cli 1.0.14 Runs Virtual iPhones on Apple Silicon: Requirements, iOS 27 Support and Automation vphone-cli 1.0.14 virtualizes iPhone firmware on Apple Silicon Macs using Apple’s Virtualization.framework and PCC research VM infrastructure. Here are the host requirements, firmware support, security trade-offs, VM workflow and automation features. OPEN SOURCE14 SEPT 2026 Pipecat 1.10 Adds OpenAI 3 Support, Speechmatics Agent STT and DeepSeek Voice-Agent Changes Pipecat 1.10.0 updates the OpenAI, Anthropic, MCP, Speechmatics and DeepSeek integration paths used by real-time voice agents. This guide covers the breaking changes, TLS implications, migration steps and new turn-detection controls. ARTIFICIAL INTELLIGENCE14 SEPT 2026 PAN-OS CVE-2026-0310: Root RCE on PA-Series, VM-Series DoS and Fixed Versions Palo Alto Networks rates CVE-2026-0310 at HIGHEST urgency. The XML-processing flaw can enable unauthenticated root code execution on PA-Series firewalls and denial of service on VM-Series. This guide maps fixed PAN-OS, Prisma Access and Cloud NGFW versions. CYBERSECURITY13 SEPT 2026 Claude Code 2.1.269 Adds Plugin Evals, Agent Map and Workflow Concurrency Controls Claude Code 2.1.269 adds reproducible plugin evaluations, workflow concurrency controls, repository-aware telemetry, Bash edit diffs and a VS Code agent map; 2.1.270 fixes a permission regression introduced in 2.1.269. AI13 SEPT 2026 AMD Ryzen 5 5500F and Ryzen 5 7500: Specs, Pricing and AM4 vs AM5 Value AMD launched the Ryzen 5 5500F for AM4 and Ryzen 5 7500 for AM5 on September 10, 2026. This guide compares their official specifications, reported launch pricing, platform requirements and upgrade value. HARDWARE13 SEPT 2026 Rune IDE Goes Open Source: GPLv3 Codebase, Go Architecture and Agent Design Unstable Build has open-sourced the Rune IDE under GPLv3. This technical guide covers its Go-based GPU-rendered architecture, extension SDK, integrated coding agent, platform requirements, build process and published terminal benchmarks. DEVELOPER TOOLS13 SEPT 2026 Abacus.AI Smaug Models: Agentic Fine-Tunes of Kimi K3, DeepSeek V4 Flash and Qwen3.8 Abacus.AI refreshed its Smaug open-weight model line for agentic workloads with Smaug Agentic on Kimi K3, Smaug Flash on DeepSeek V4 Flash and Smaug Mini on Qwen3.8 27B. This guide covers architecture, context, benchmarks, deployment and licensing details. ARTIFICIAL INTELLIGENCE13 SEPT 2026 Amazon Kiro CVE-2026-89332: Workspace Data Exfiltration, Fixed Version and Credential Rotation AWS disclosed CVE-2026-89332 in Kiro IDE, where crafted repositories could redirect the Kiro Powers registry and expose workspace data. This guide covers affected versions, the attack path, version 0.8.135 remediation and credential-rotation steps. CYBERSECURITY13 SEPT 2026 Amazon SageMaker Adds Prefix-Aware Routing for LLM Inference: Benchmarks and Configuration Amazon SageMaker Inference now supports prefix-aware routing for real-time LLM endpoints. AWS reports up to 77% lower P50 time-to-first-token, KV-cache hit rates above 80%, and up to 16% higher throughput on long-context tests. AI13 SEPT 2026 AWS Pizza Bot 1.0: Local-First Inbox for Long-Running AI Agents AWS released Pizza Bot as an Apache-2.0 local-first application for background AI agents. Version 1.0 supports durable approvals, cron and webhook automation, MCP, Agent Skills, multiple model providers, desktop/web/CLI clients and self-hosted backends. AI13 SEPT 2026 OpenAI Adds API Key Expiration and Maximum-Lifetime Controls: Rotation Guide OpenAI now lets teams set expiration dates on project API keys and enforce maximum key lifetimes at the organization or project level. This guide covers the new controls, service-account API limits and a safe production rotation workflow. AI13 SEPT 2026 Check Point VPN CVE-2026-85102 and CVE-2026-85103: Critical RCE Patch Guide Check Point disclosed two CVSS 9.8 VPN certificate-processing flaws that can enable unauthenticated remote code execution. This guide maps affected releases, fixed Jumbo Hotfix Takes, LivePatch coverage and interim controls. CYBERSECURITY12 SEPT 2026 OpenAI GPT-Rosalind Goes Global: API Pricing, Benchmarks and Trusted Access OpenAI moved GPT-Rosalind out of research preview on September 11, 2026. Eligible organizations can use it globally through ChatGPT, Codex and the API, with API billing at $5 input, $0.50 cached input and $25 output per million tokens from October 5. AI ← Newer Page 4 of 20 Older →