FR
live
archive

All articles

GitHub Copilot orchestrates multiple models at runtime with Project HydraFusion

GitHub launches HydraFusion, a research preview that picks between a single model, a cascade, or an independent critique at runtime to deliver frontier-level quality at the lowest cost. On TerminalBench 2.1 it gains 4.9 points at 67% lower estimated cost than Claude Opus 5, available via /experimental in Copilot CLI.

MikroTik patches routers hijacked over internet-exposed SSH

CERT Polska warns that attackers are taking full administrative control of MikroTik routers whose SSH service is reachable from the internet, without authentication. Update RouterOS and audit the configuration before putting any device back into service.

A capture-replay auth bypass leaves 22,000 Exchange servers exposed

Disclosed on August 11, 2026, CVE-2026-62911 lets an attacker with some access replay a captured authentication to elevate privileges on Microsoft Exchange, and a public PoC is already circulating. Nearly 22,000 servers were still exposed at the end of August; if you are on Exchange 2016 without ESU, the fix is not an option — migration is.

GitHub Actions adds a vulnerability-alerts token and reusable workflow identity

On September 3, 2026, GitHub shipped three GitHub Actions updates: a vulnerability-alerts permission for GITHUB_TOKEN, the job context for reusable workflows, and a runner deprecation API. Swap your broad scopes for the vulnerability-alerts permission and adopt job.workflow_ref in your reusable workflows.

OpenAI ships GPT-6 Astra in a restricted form, its first cyber-critical model

On September 3, 2026, OpenAI unveiled GPT-6 Astra, the first model it classifies as ‘critical’ for cybersecurity under its Preparedness Framework, then released a public version the next day that refuses offensive requests. For defenders, the full capabilities sit behind the Daybreak Blue program, not the public API.

Tailcat ships Tailscale’s WireGuard data plane with no control plane at all

On August 31, 2026, Brad Fitzpatrick released tailcat, an open-source Go package and CLI that exposes Tailscale’s data plane — WireGuard, NAT traversal, and DERP — with no account, no IP addresses, and no control plane. Use it to connect two isolated machines, or hand an AI agent a disposable connection, with no root access.

Type at least two characters.

navigate open esc dismiss