FR
live
archive

All articles

Kubernetes 1.37 introduces five Node Lifecycle Conditions to signal drain and maintenance

On September 9, 2026, Kubernetes 1.37 reserved five well-known node conditions — DrainInProgress, Drained, MaintenancePlanned, MaintenanceInProgress, and GracefulNodeShutdownInProgress — giving teams a shared way to say why a node is unavailable. Start publishing them in your maintenance automation now, without waiting for core controllers to consume them.

Google commits €13 billion in Finland to build Europe’s AI infrastructure

On September 9, 2026, Google announced €13 billion across 2027-2028 in four Finnish sites — Hamina, Kajaani, Muhos, and Vaala — its largest European investment, backed by nuclear and wind energy contracts. It is a signal about how Europe’s sovereign cloud capacity is concentrating around the Nordics.

Home Assistant 2026.9 opens the Modbus bus and tightens its security surface

On September 2, 2026, Home Assistant 2026.9 modernizes Modbus so an industrial device can be picked from the UI without writing any YAML, and hardens the instance by passing through the real source IP of Cloud connections so IP banning actually works. Upgrade if you run Modbus gear or expose your instance.

Amazon Quick reaches general availability on the desktop to rein in shadow AI

On September 9, 2026, AWS made the Amazon Quick desktop app generally available on macOS and Windows and added a mobile activity feed that consolidates email, calendar, CRM, and messaging. For an organization already on AWS, it is a lever to bring generative AI back under governance: CloudTrail audit, HIPAA, FedRAMP, SOC 2 and ISO 27001 compliance, without moving data out of your environment.

PivotC2 RAT exploits CVE-2025-25249, a Fortinet heap overflow patched since January

Patched in January 2026, the CVE-2025-25249 heap overflow in the FortiOS cw_acd daemon has resurfaced exploited in the wild: CISA added it to the KEV catalog on September 9, 2026, after SOCRadar observed the PivotC2 RAT deployed on 178 devices. Network teams must upgrade exposed FortiOS trains before September 12, then strip out unnecessary fabric access.

OpenTofu crosses the tipping point as the default engine for new IaC workspaces

On Scalr’s platform, OpenTofu now runs 63% of Terraform-compatible runs and powers 72% of newly created workspaces — not a snapshot of the global market, but of where new work is heading. Version 1.12 adds dynamic prevent_destroy and full provider checksums. For teams provisioning infrastructure, new projects should default to OpenTofu.

Kubernetes 1.37 graduates gang scheduling to beta and adds CompositePodGroup

Kubernetes 1.37 (Garhwal) graduates the Workload and PodGroup APIs, gang scheduling and workload-aware preemption to beta, and introduces the CompositePodGroup API for scheduling hierarchical groups of Pods aimed at AI/ML and distributed computing. Teams running batch workloads can start evaluating this native foundation.

ShieldCrash bypasses Microsoft Defender’s ShieldBreak fix to read files as SYSTEM

On September 9, 2026, researcher Chaotic Eclipse published ShieldCrash, a proof of concept that bypasses CVE-2026-69414 (ShieldBreak), the privilege-escalation flaw Microsoft claimed to have patched in Defender’s antimalware engine. Check your Malware Protection Engine version and treat the EDR itself as attack surface to monitor.

systemd 262-rc2 adds an AI canary to catch unreviewed LLM code

On September 8, 2026, systemd 262-rc2 shipped an AI canary in its AGENTS.md file: a trap instruction that forces AI coding agents to mark the patches they produce, and whose manual removal proves a human actually reviewed the code. A simple, copyable mechanism for any project receiving AI-generated contributions.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss