FR
live
archive

All articles

CVE-2026-67401 turns a cPanel mail account into root through EmailTrack

On September 8, 2026, cPanel disclosed a SQL injection in EmailTrack that lets any mail-account holder write arbitrary files and then execute code as root. Every supported version is affected: on shared hosting, each customer account becomes a doorway to the whole server.

GhostLock turns a fifteen-year-old rtmutex use-after-free into root in five seconds

CVE-2026-43499, dubbed GhostLock, is a use-after-free in rtmutex priority-inheritance code that has shipped since kernel 2.6.39 and is reachable by any unprivileged local process. The fix landed in 7.1, but two months after the public PoC, blind spots like RHEL 9 kernel-rt remain: check your version and block PI futexes in the meantime.

Laos loses nearly four days of BGP routing with no attributed cause

Between September 2 and September 6, 2026, Laos saw its BGP control-plane visibility collapse for 3.7 days, with no public cause offered. The outage measures what a lightly multi-homed country costs, and reminds operators to verify route redundancy before the failure, not after.

Ingress-nginx is end of life: migrate to Gateway API before November 2026

On November 12, 2025, Kubernetes announced the retirement of ingress-nginx; upstream maintenance stopped in March 2026 and the last patch bridge, Microsoft’s for AKS, expires in November 2026. Every annotation in your fleet now has to become a Gateway API route — or remain an unpatched vulnerability.

Amazon Kinesis Data Streams now writes Apache Iceberg tables directly

On August 31, 2026, AWS launched streaming tables for Kinesis Data Streams, turning a stream into a queryable Apache Iceberg table with no pipeline to operate. The vendor claims up to 50% delivery savings and 30% query savings — at the cost of delegating compaction.

Qwen3.8-Max ships open weights, but not under Apache 2.0

On August 12, 2026, Alibaba published the weights of Qwen3.8-Max, a 2.4-trillion-parameter MoE model, under a custom license with revenue thresholds rather than Apache 2.0. Before you deploy, read the clauses: the checkpoint is text-only and resale above a threshold becomes paid.

Self-hosted GitHub Actions runners stop receiving jobs on September 25

GitHub has tightened minimum-version enforcement for self-hosted runners: brownouts began September 14, and from September 25, 2026 any runner not updated within 30 days stops receiving jobs. The failure is silent — jobs sit in “Queued” with no error: audit your runners before the next window.

OEMpocalypse roots Android with an app that has zero permissions

On August 31, 2026, researcher Lukas Maar published OEMpocalypse, an exploit chain that elevates any permissionless Android app to root on Samsung Galaxy S23–S26, Xiaomi flagships and Oppo/OnePlus/Realme devices — locked bootloader, Verified Boot still green. Your root detection is blind to it: only hardware-backed keys (KeyStore/StrongBox) still hold.

Papermerge shifts its focus to SaaS, its open-source edition hunting for maintainers

After nine years of open-source development, the Papermerge document management system is splitting in two: a SaaS launching on November 11, 2026, and a self-hosted edition whose author is now “seeking maintainers” while he transitions to the cloud. If your archive runs on Papermerge, plan a migration instead of waiting to see what happens next.

Kubernetes 1.37 adds scheduler preemption for in-place pod resize

On September 10, 2026, Kubernetes 1.37 introduced, behind the InPlacePodVerticalScalingSchedulerPreemption feature gate, scheduler preemption for in-place pod resizes stuck in the Deferred state. Operators can now bin-pack nodes with low-priority workloads without risking blocked scale-ups for critical services.

A Void Linux maintainer orphans 113 packages after an AI-policy dispute

On September 12, 2026, contributor Andrea Brancaleoni orphaned 113 Void Linux packages — including Kubernetes, Docker, Terraform, and Thermald — after being called out for using an LLM in an undisclosed update comment. AI policies are becoming a maintenance-continuity problem as much as a contribution-ethics one.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss