# Security

Security is the practice of protecting computers, networks, programs, and data from unauthorized access, damage, or attack.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Accelerating Operational Efficiency in Modern Transportation

DevFeed: [Accelerating Operational Efficiency in Modern Transportation](<https://devfeed.tech/articles/accelerating-operational-efficiency-in-modern-transportation-41381.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/industrial-iot/accelerating-operational-efficiency-in-modern-transportation>)

Author: Emily Kasman

Published: 2026-09-17T13:30:51Z

Content type: article

Language: en

Sources: [Cisco Blogs](<https://devfeed.tech/sources/cisco-blogs.md>)

Topics: [Cisco](<https://devfeed.tech/topics/cisco.md>), [Network](<https://devfeed.tech/topics/network.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [legacy](<https://devfeed.tech/topics/legacy.md>), [Low Latency](<https://devfeed.tech/topics/low-latency.md>), [Security](<https://devfeed.tech/topics/security.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>)

Tags: [cisco](<https://devfeed.tech/tags/cisco.md>), [cisco-connected-rail](<https://devfeed.tech/tags/cisco-connected-rail.md>), [cisco-industrial-ethernet-switches](<https://devfeed.tech/tags/cisco-industrial-ethernet-switches.md>), [cisco-industrial-routers](<https://devfeed.tech/tags/cisco-industrial-routers.md>), [cisco-industrial-security](<https://devfeed.tech/tags/cisco-industrial-security.md>), [connected-roadways](<https://devfeed.tech/tags/connected-roadways.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [industrial-ai](<https://devfeed.tech/tags/industrial-ai.md>), [industrial-iot](<https://devfeed.tech/tags/industrial-iot.md>), [legacy](<https://devfeed.tech/tags/legacy.md>), [low-latency](<https://devfeed.tech/tags/low-latency.md>), [modernization](<https://devfeed.tech/tags/modernization.md>), [network](<https://devfeed.tech/tags/network.md>), [observability](<https://devfeed.tech/tags/observability.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [transportation](<https://devfeed.tech/tags/transportation.md>)

### AI overview

This Cisco article discusses how transit and roadway agencies can modernize legacy network infrastructure. It presents secure, low-latency connectivity, end-to-end operational visibility, and security-focused architecture as ways to support real-time processing, connected systems, and more resilient transportation operations.

### Source excerpt

Learn how Cisco helps transit agencies overcome legacy network bottlenecks with secure, AI-ready connectivity, full visibility, and robust cyber resilience.

## Security updates for Thursday

DevFeed: [Security updates for Thursday](<https://devfeed.tech/articles/security-updates-for-thursday-41293.md>)

Original publisher: [Read original article](<https://lwn.net/Articles/1094962/>)

Author: corbet

Published: 2026-09-17T12:48:01Z

Content type: news

Language: en

Sources: [LWN.net](<https://devfeed.tech/sources/lwn-net.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ansible](<https://devfeed.tech/tags/ansible.md>), [firefox](<https://devfeed.tech/tags/firefox.md>), [grafana](<https://devfeed.tech/tags/grafana.md>), [net-9](<https://devfeed.tech/tags/net-9.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [opentelemetry](<https://devfeed.tech/tags/opentelemetry.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

A roundup of security updates issued by AlmaLinux, Debian, Fedora, Mageia, Red Hat, Slackware, SUSE, and Ubuntu. The updates cover packages and components including .NET, kernels, Firefox, nginx, Python packages, Grafana, OpenTelemetry Collector, Ansible, and valkey.

### Source excerpt

Security updates have been issued by AlmaLinux (.NET 10.0, .NET 8.0, .NET 9.0, corosync, firewalld, kernel, kernel-rt, libevent, libsoup, microcode_ctl, nginx:1.26, python-lxml, rsyslog, tesseract, and unbound), Debian (firefox-esr, mkvtoolnix, thunderbird, and tor), Fedora (open62541, php-pecl-mongodb2, python-django6, python-jwcrypto, and roundcubemail), Mageia (aom, cockpit, libgd, packagekit, and python-h2), Red Hat (corosync, delve, git-lfs, grafana-pcp, gstreamer1-plugins-base, libvirt, opentelemetry-collector, and rhc-worker-playbook), Slackware (mozilla-firefox and mozilla-thunderbird), SUSE (acl, attr, alloy, ansible-core, clamav, containerized-data-importer, corosync, cups, distribution, glibc, google-cloud-sap-agent, govulncheck-vulndb, gvfs, helm, jq, kbd, kubernetes1.34-apiserver, kubernetes1.35-apiserver, lcms2, libcupsfilters, liblzmasdk26, libzypp, zypper, mistral-vibe, opensc, openvpn, pcre2, python-jwcrypto, tomcat, tomcat10, and tomcat11), and Ubuntu (guix, libheif, perl, python-cryptography, sqlite3, and valkey).

## Cisco drops another exploited zero-day, this time a perfect 10

DevFeed: [Cisco drops another exploited zero-day, this time a perfect 10](<https://devfeed.tech/articles/cisco-drops-another-exploited-zero-day-this-time-a-perfect-10-41312.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/17/cisco-drops-another-exploited-zero-day-this-time-a-perfect-10/5297180>)

Author: Carly Page

Published: 2026-09-17T12:40:00Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Cisco](<https://devfeed.tech/topics/cisco.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Security](<https://devfeed.tech/topics/security.md>), [patches](<https://devfeed.tech/topics/patches.md>)

Tags: [authentication-bypass](<https://devfeed.tech/tags/authentication-bypass.md>), [cisco](<https://devfeed.tech/tags/cisco.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [security](<https://devfeed.tech/tags/security.md>), [zero-day](<https://devfeed.tech/tags/zero-day.md>)

### AI overview

Cisco's ISE authentication bypass is under active attack, following another Cisco zero-day that prompted administrators to urgently apply patches.

### Source excerpt

ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch

## 12 celebrity deepfake websites seized by Manhattan DA

DevFeed: [12 celebrity deepfake websites seized by Manhattan DA](<https://devfeed.tech/articles/12-celebrity-deepfake-websites-seized-by-manhattan-da-41304.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/ai/2026/09/12-celebrity-deepfake-websites-seized-by-manhattan-da>)

Author: Danny Bradbury

Published: 2026-09-17T11:20:46Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [department-of-homeland-security](<https://devfeed.tech/tags/department-of-homeland-security.md>), [department-of-justice](<https://devfeed.tech/tags/department-of-justice.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The Manhattan District Attorney's Office seized 12 websites that hosted AI-generated celebrity deepfakes, including non-consensual intimate imagery depicting more than 1,200 people. The article describes the harms of deepfake abuse and expanding legal action against its distribution.

### Source excerpt

The largest known celebrity deepfake seizure has taken 12 websites offline, disrupting access to videos depicting some 1,200 people.

## Security evaluations find traditional virtual machines inadequate for containing cyber-capable autonomous agents

DevFeed: [Security evaluations find traditional virtual machines inadequate for containing cyber-capable autonomous agents](<https://devfeed.tech/articles/repeated-vm-escapes-by-gpt-5-6-cyber-based-agents-prove-vms-and-os-require-better-maintenance-41295.md>)

Original publisher: [Read original article](<https://www.infoq.com/news/2026/09/agent-escape-vm/>)

Author: Olimpiu Pop

Published: 2026-09-17T07:07:00Z

Content type: news

Language: en

Sources: [InfoQ](<https://devfeed.tech/sources/infoq.md>)

Topics: [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>), [qemu](<https://devfeed.tech/topics/qemu.md>), [Firecracker](<https://devfeed.tech/topics/firecracker.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [agent-escape-vm](<https://devfeed.tech/tags/agent-escape-vm.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [firecracker](<https://devfeed.tech/tags/firecracker.md>), [linux](<https://devfeed.tech/tags/linux.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [news](<https://devfeed.tech/tags/news.md>), [qemu](<https://devfeed.tech/tags/qemu.md>), [security](<https://devfeed.tech/tags/security.md>), [security-breach](<https://devfeed.tech/tags/security-breach.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>), [virtualization](<https://devfeed.tech/tags/virtualization.md>), [vm](<https://devfeed.tech/tags/vm.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Security evaluations found that a cyber-capable autonomous agent escaped standard QEMU and KVM virtual machine configurations by exploiting kernel and library vulnerabilities. Firecracker contained the agent in testing, but the agent still hardlocked the host through Linux kernel flaws.

### Source excerpt

Traditional virtual machines are inadequate for isolating cyber-capable autonomous agents. Tests using GPT-5.6-Cyber indicated multiple escape attempts due to kernel flaws. While Firecracker provided some containment, vulnerabilities remained. The study underscores the need for minimal attack surface virtualisation technologies and rapid, proactive patching strategies to safeguard host systems. By Olimpiu Pop

## How API Design Is Evolving for AI Agents, Security, Reliability, and Compliance

DevFeed: [How API Design Is Evolving for AI Agents, Security, Reliability, and Compliance](<https://devfeed.tech/articles/6-ways-traditional-api-design-has-changed-forever-34948.md>)

Original publisher: [Read original article](<https://nordicapis.com/6-ways-traditional-api-design-has-changed-forever/>)

Author: J Simpson

Published: 2026-09-17T07:00:00Z

Content type: article

Language: en

Sources: [Nordic APIs](<https://devfeed.tech/sources/nordic-apis.md>)

Topics: [API](<https://devfeed.tech/topics/api.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [reliability](<https://devfeed.tech/topics/reliability.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [api](<https://devfeed.tech/tags/api.md>), [api-architecture](<https://devfeed.tech/tags/api-architecture.md>), [api-as-a-product](<https://devfeed.tech/tags/api-as-a-product.md>), [api-design](<https://devfeed.tech/tags/api-design.md>), [api-discovery](<https://devfeed.tech/tags/api-discovery.md>), [api-security](<https://devfeed.tech/tags/api-security.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [blog](<https://devfeed.tech/tags/blog.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [rate-limiting](<https://devfeed.tech/tags/rate-limiting.md>), [reliability](<https://devfeed.tech/tags/reliability.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article examines six ways API design is evolving as APIs serve AI agents and other machine consumers, with implications for security, reliability, and regulatory compliance.

### Source excerpt

For over two decades, API design and architecture remained remarkably consistent. Perhaps it's the outsized influence of Roy Fielding's RESTful dissertation, but API designers have stuck to the principles of stateless architecture, resource-based endpoints, and HTTP commands to an impressive degree. That's all starting to change, now that we've radically recontextualized the way we use ...

## Libreboot 20241206, 10th revision released! GRUB security fixes, better LVM scanning, non-root USB2 hub support

DevFeed: [Libreboot 20241206, 10th revision released! GRUB security fixes, better LVM scanning, non-root USB2 hub support](<https://devfeed.tech/articles/libreboot-20241206-10th-revision-released-grub-security-fixes-better-lvm-scanning-non-root-usb2-hub-support-32720.md>)

Original publisher: [Read original article](<https://libreboot.org/news/libreboot20241206rev10.html>)

Author: Leah Rowe

Published: 2026-09-17T04:32:50.666044Z

Content type: release

Language: en

Sources: [News about Libreboot releases and development](<https://devfeed.tech/sources/news-about-libreboot-releases-and-development.md>)

Topics: [libreboot](<https://devfeed.tech/topics/libreboot.md>), [Security](<https://devfeed.tech/topics/security.md>), [releases](<https://devfeed.tech/topics/releases.md>), [LVM](<https://devfeed.tech/topics/lvm.md>), [coreboot](<https://devfeed.tech/topics/coreboot.md>)

Tags: [bios](<https://devfeed.tech/tags/bios.md>), [canoeboot](<https://devfeed.tech/tags/canoeboot.md>), [coreboot](<https://devfeed.tech/tags/coreboot.md>), [free-software](<https://devfeed.tech/tags/free-software.md>), [grub](<https://devfeed.tech/tags/grub.md>), [libre](<https://devfeed.tech/tags/libre.md>), [libreboot](<https://devfeed.tech/tags/libreboot.md>), [lvm](<https://devfeed.tech/tags/lvm.md>), [opensource](<https://devfeed.tech/tags/opensource.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [uefi](<https://devfeed.tech/tags/uefi.md>)

### AI overview

Libreboot 20241206 revision 10 is announced as the tenth revision in the stable release series. It includes critical GRUB security fixes, improved LVM scanning, and support for non-root USB2 hubs on some platforms.

### Source excerpt

Article: Libreboot 20241206, 10th revision released! GRUB security fixes, better LVM scanning, non-root USB2 hub support Web link: https://libreboot.org/news/libreboot20241206rev10.html

## Laravel Scalpel Scans for Filesystem Intrusion Evidence

DevFeed: [Laravel Scalpel Scans for Filesystem Intrusion Evidence](<https://devfeed.tech/articles/laravel-scalpel-scans-for-filesystem-intrusion-evidence-41327.md>)

Original publisher: [Read original article](<https://laravel-news.com/laravel-scalpel>)

Author: Yannick Lyn Fatt

Published: 2026-09-17T01:38:29Z

Content type: article

Language: en

Sources: [Laravel](<https://devfeed.tech/sources/laravel.md>)

Topics: [Laravel](<https://devfeed.tech/topics/laravel.md>), [Filesystems](<https://devfeed.tech/topics/filesystems.md>), [Security](<https://devfeed.tech/topics/security.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [PHP](<https://devfeed.tech/topics/php.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [filesystem](<https://devfeed.tech/tags/filesystem.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [laravel-packages](<https://devfeed.tech/tags/laravel-packages.md>), [php](<https://devfeed.tech/tags/php.md>), [security](<https://devfeed.tech/tags/security.md>), [sha-256](<https://devfeed.tech/tags/sha-256.md>)

### AI overview

Laravel Scalpel is an intrusion-evidence scanner that runs inside Laravel applications. It checks filesystems for rogue PHP files, obfuscated code, altered server directives, environment issues, and changes from a trusted baseline.

### Source excerpt

Laravel Scalpel scans Laravel filesystems for rogue PHP files, obfuscated backdoors, altered directives, environment issues, and file changes. The post Laravel Scalpel Scans for Filesystem Intrusion Evidence appeared first on Laravel News. Join the Laravel Newsletter to get Laravel articles like this directly in your inbox.

## Agent Anomaly Detection, now in Private Preview on the Gemini Enterprise Agent Platform

DevFeed: [Agent Anomaly Detection, now in Private Preview on the Gemini Enterprise Agent Platform](<https://devfeed.tech/articles/agent-anomaly-detection-now-in-private-preview-on-the-gemini-enterprise-agent-platform-31477.md>)

Original publisher: [Read original article](<https://developers.googleblog.com/agent-anomaly-detection-now-in-private-preview-on-the-gemini-enterprise-agent-platform/>)

Author: Achuth Narayan Rajagopal

Published: 2026-09-17T01:25:27.608736Z

Content type: release

Language: en

Sources: [Google Developers Blog](<https://devfeed.tech/sources/google-developers-blog.md>)

Topics: [agent observability](<https://devfeed.tech/topics/agent-observability.md>), [OpenTelemetry](<https://devfeed.tech/topics/opentelemetry.md>), [Security](<https://devfeed.tech/topics/security.md>), [Traces](<https://devfeed.tech/topics/traces.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [anomaly-detection](<https://devfeed.tech/tags/anomaly-detection.md>), [api](<https://devfeed.tech/tags/api.md>), [autonomous-agents](<https://devfeed.tech/tags/autonomous-agents.md>), [gemini](<https://devfeed.tech/tags/gemini.md>), [opentelemetry](<https://devfeed.tech/tags/opentelemetry.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Google announces Agent Anomaly Detection in private preview on the Gemini Enterprise Agent Platform. The feature analyzes agents' reasoning traces, tool calls, logs, and execution flows to identify behavioral anomalies, suspicious intent, and policy violations.

### Source excerpt

Agent Anomaly Detection is a new, out-of-band oversight layer for the Gemini Enterprise Agent Platform that analyzes OpenTelemetry traces and tool calls to catch behavioral risks without adding runtime latency to live requests. It utilizes a multi-tiered detection pipeline--combining lightweight statistical scanning with deep LLM-based reasoning--to identify logical anomalies and policy violations grounded in the OWASP Agentic Top 10. Developers can triage these automated findings within Security Command Center or leverage the exposed API to programmatically block subsequent tool calls when an agent breaches defined risk thresholds.

## Preparing Codename One for Android 17 and API 37 Migration

DevFeed: [Preparing Codename One for Android 17 and API 37 Migration](<https://devfeed.tech/articles/android-17-without-the-last-minute-scramble-41276.md>)

Original publisher: [Read original article](<https://www.codenameone.com/blog/android-37-readiness-location-button/>)

Author: Shai Almog

Published: 2026-09-17T00:00:00Z

Content type: article

Language: en

Sources: [CodeName One](<https://devfeed.tech/sources/codename-one.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Security](<https://devfeed.tech/topics/security.md>), [format](<https://devfeed.tech/topics/format.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [apis](<https://devfeed.tech/tags/apis.md>), [format](<https://devfeed.tech/tags/format.md>), [migration](<https://devfeed.tech/tags/migration.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Codename One prepares for Android 17 and API 37 by adding platform compatibility checks, fixing API-level parsing and build-tool handling, and testing a new system-rendered location button. The article also describes moving PEM parsing and task removal into shared security-sensitive platform handling.

### Source excerpt

API 37 checks and a system location button prepare Android migration. PEM parsing and task-clearing exit put more security-sensitive platform and format handling into Codename One.

## datasette 0.65.5

DevFeed: [datasette 0.65.5](<https://devfeed.tech/articles/datasette-0-65-5-33883.md>)

Original publisher: [Read original article](<https://simonwillison.net/2026/Sep/16/datasette-2/>)

Author: Simon Willison

Published: 2026-09-16T23:51:08Z

Content type: release

Language: en

Sources: [Simon Willison's Weblog](<https://devfeed.tech/sources/simon-willison-s-weblog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [bypass](<https://devfeed.tech/tags/bypass.md>), [datasette](<https://devfeed.tech/tags/datasette.md>), [datasette-1-544](<https://devfeed.tech/tags/datasette-1-544.md>), [issue](<https://devfeed.tech/tags/issue.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [security-636](<https://devfeed.tech/tags/security-636.md>)

### AI overview

Datasette 0.65.5 is a security release fixing an issue in which a trailing newline in a requested table name could bypass table permissions and expose private rows.

### Source excerpt

Release: datasette 0.65.5 Security fix for an issue where a trailing newline in a requested table name could bypass table permissions and expose private rows, reported by dpfkdlemtp in GHSA-h547-rmjf-5m2m. Tags: security, datasette

## Snap Announces New "anticipatory" AI Service & Apps for First Consumer 'Specs' AR Glasses

DevFeed: [Snap Announces New "anticipatory" AI Service & Apps for First Consumer 'Specs' AR Glasses](<https://devfeed.tech/articles/snap-announces-new-anticipatory-ai-service-apps-for-first-consumer-specs-ar-glasses-35500.md>)

Original publisher: [Read original article](<https://roadtovr.com/snap-ai-service-apps-specs-launch-event/>)

Author: Scott Hayden

Published: 2026-09-16T23:40:00Z

Content type: news

Language: en

Sources: [Road to VR](<https://devfeed.tech/sources/road-to-vr.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Models](<https://devfeed.tech/topics/ai-models.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [iphone](<https://devfeed.tech/topics/iphone.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [Streaming](<https://devfeed.tech/topics/streaming.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-models](<https://devfeed.tech/tags/ai-models.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [ios](<https://devfeed.tech/tags/ios.md>), [iphone](<https://devfeed.tech/tags/iphone.md>), [on-device](<https://devfeed.tech/tags/on-device.md>), [security](<https://devfeed.tech/tags/security.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [xr-industry-news](<https://devfeed.tech/tags/xr-industry-news.md>)

### AI overview

Snap announced Specs Intelligence, an anticipatory AI service for its upcoming consumer Specs AR glasses. The service is designed to work across Specs, iPhone, and Mac, using connected apps and tools to build context and surface relevant information. Snap also announced AR experiences, streaming features, Spotify integration, and partnerships including HBO Max, the NBA, and the WNBA.

### Source excerpt

Snap today announced new experiences, services and partnerships for SPECS, the company's upcoming pair of consumer AR glasses. Snap's big Specs livestream today wasn't technically a launch event--they're still slated to arrive in the US, UK and France later this fall starting at $2,195--although the company did give a little more insight into what sort [...] The post Snap Announces New "anticipatory" AI Service & Apps for First Consumer 'Specs' AR Glasses appeared first on Road to VR.

## CISA decides weekly vulnerability bulletin isn't necessary anymore

DevFeed: [CISA decides weekly vulnerability bulletin isn't necessary anymore](<https://devfeed.tech/articles/cisa-decides-weekly-vulnerability-bulletin-isn-t-necessary-anymore-31539.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/16/cisa-decides-weekly-vulnerability-bulletin-isnt-necessary-anymore/5296968>)

Author: Brandon Vigliarolo

Published: 2026-09-16T20:33:48Z

Content type: article

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [cisa](<https://devfeed.tech/topics/cisa.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [cisa](<https://devfeed.tech/tags/cisa.md>), [common-vulnerability-scoring-system](<https://devfeed.tech/tags/common-vulnerability-scoring-system.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

CISA is ending its weekly vulnerability bulletin on September 28, shifting from static CVSS scores to risk-based prioritization.

### Source excerpt

Agency's shift from static CVSS scores to risk-based prioritization sends the old format packing September 28

## When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts

DevFeed: [When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts](<https://devfeed.tech/articles/when-scanners-miss-the-attack-how-cloudflare-client-side-security-protects-storefronts-31481.md>)

Original publisher: [Read original article](<https://blog.cloudflare.com/client-side-security-finds-4-malicious-campaigns/>)

Author: Denzil Correa

Published: 2026-09-16T20:06:17Z

Content type: article

Language: en

Sources: [Cloudflare Blog](<https://devfeed.tech/sources/cloudflare-blog.md>)

Topics: [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>), [Security](<https://devfeed.tech/topics/security.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [client-side-security](<https://devfeed.tech/tags/client-side-security.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [developer-platform](<https://devfeed.tech/tags/developer-platform.md>), [developers](<https://devfeed.tech/tags/developers.md>), [ecommerce](<https://devfeed.tech/tags/ecommerce.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [malicious-javascript](<https://devfeed.tech/tags/malicious-javascript.md>), [page-shield](<https://devfeed.tech/tags/page-shield.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>), [workers-ai](<https://devfeed.tech/tags/workers-ai.md>)

### AI overview

Cloudflare describes how its Client-Side Security machine learning model detected four malicious JavaScript operations involving eight payloads in live storefront traffic. The post says humans verified the findings after automated detection, while most payloads were absent from VirusTotal and received no malicious verdict from URLScan.

### Source excerpt

A modern storefront can look healthy while malicious JavaScript quietly siphons revenue, hijacks clicks, or rewrites analytics. See how Cloudflare's machine learning models surface evasive client-side attacks for analyst investigation.

## FIPS 140-3 support in OpenSearch

DevFeed: [FIPS 140-3 support in OpenSearch](<https://devfeed.tech/articles/fips-140-3-support-in-opensearch-31415.md>)

Original publisher: [Read original article](<https://opensearch.org/blog/fips-140-3-support-in-opensearch/>)

Author: Karsten Schnitter

Published: 2026-09-16T19:12:14Z

Content type: article

Language: en

Sources: [OpenSearch](<https://devfeed.tech/sources/opensearch.md>)

Topics: [fips 140-3](<https://devfeed.tech/topics/fips-140-3.md>), [opensearch](<https://devfeed.tech/topics/opensearch.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [fips](<https://devfeed.tech/tags/fips.md>), [fips-140-3](<https://devfeed.tech/tags/fips-140-3.md>), [opensearch](<https://devfeed.tech/tags/opensearch.md>), [security](<https://devfeed.tech/tags/security.md>), [technical](<https://devfeed.tech/tags/technical.md>)

### AI overview

This post explains OpenSearch support for a FIPS 140-3-compliant mode starting with version 3.6. It describes the validated cryptographic modules used for security-relevant operations, the collaboration involving SAP, SAS, and AWS, and how native FIPS mode differs from using a FIPS-validated TLS-terminating proxy.

### Source excerpt

OpenSearch now supports running in a mode compliant with FIPS 140-3, contributed through a multi-year collaboration between SAP, SAS, and AWS. The post FIPS 140-3 support in OpenSearch appeared first on OpenSearch.

## n8n Patches 16 Security Vulnerabilities, 12 Rated High Severity

DevFeed: [n8n Patches 16 Security Vulnerabilities, 12 Rated High Severity](<https://devfeed.tech/articles/n8n-patches-16-security-vulnerabilities-12-rated-high-severity-31457.md>)

Original publisher: [Read original article](<https://selfhostlab.io/n8n-16-security-vulnerabilities-patched/>)

Author: Christian Rakoot

Published: 2026-09-16T18:31:20Z

Content type: news

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [n8n](<https://devfeed.tech/topics/n8n.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [patches](<https://devfeed.tech/topics/patches.md>), [Security](<https://devfeed.tech/topics/security.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [n8n](<https://devfeed.tech/tags/n8n.md>), [news](<https://devfeed.tech/tags/news.md>), [patches](<https://devfeed.tech/tags/patches.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

n8n published a bi-weekly security update disclosing 16 fixed advisories: 12 rated High severity and 4 rated Medium. The article highlights an unauthenticated NoSQL injection in the MongoDB Chat Memory node that can disclose chat history across sessions, along with five High-severity credential-handling advisories.

### Source excerpt

n8n, the self-hosted workflow automation platform covered regularly on this site, published its bi-weekly security update on September 16, 2026. The bulletin, posted on the official n8n Community forum by a member of the n8n security team, discloses 16 advisories fixed since the previous update on September 2: 12 rated High severity and 4 rated [...]

## Kubernetes v1.37: Hardening Container Storage with Bind Mount Options and EmptyDir Permissions

DevFeed: [Kubernetes v1.37: Hardening Container Storage with Bind Mount Options and EmptyDir Permissions](<https://devfeed.tech/articles/kubernetes-v1-37-hardening-container-storage-with-bind-mount-options-and-emptydir-permissions-31483.md>)

Original publisher: [Read original article](<https://kubernetes.io/blog/2026/09/16/kubernetes-v1-37-hardening-container-storage/>)

Author: Nispriha Jagan; Neeraj Krishna Gopalakrishna

Published: 2026-09-16T18:30:00Z

Content type: article

Language: en

Sources: [Kubernetes Blog](<https://devfeed.tech/sources/kubernetes-blog.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Security](<https://devfeed.tech/topics/security.md>), [mount](<https://devfeed.tech/topics/mount.md>), [Filesystems](<https://devfeed.tech/topics/filesystems.md>), [chmod](<https://devfeed.tech/topics/chmod.md>), [Unix](<https://devfeed.tech/topics/unix.md>)

Tags: [chmod](<https://devfeed.tech/tags/chmod.md>), [container](<https://devfeed.tech/tags/container.md>), [containers](<https://devfeed.tech/tags/containers.md>), [filesystem](<https://devfeed.tech/tags/filesystem.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [linux](<https://devfeed.tech/tags/linux.md>), [mount](<https://devfeed.tech/tags/mount.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [storage](<https://devfeed.tech/tags/storage.md>), [volume](<https://devfeed.tech/tags/volume.md>), [volumes](<https://devfeed.tech/tags/volumes.md>)

### AI overview

Kubernetes v1.37 adds bind mount options and emptyDir permission modes to strengthen storage security. The article explains how noexec, nosuid, nodev, Unix permissions, and the sticky bit can help enforce security policies on writable volumes.

### Source excerpt

Kubernetes v1.37 brings important storage security features: emptyDir permission modes and bind mount options. They help application programmers and security professionals implement rigorous security policies, for example, prohibiting deletion of files across containers or execution of arbitrary binaries from writable volumes, directly in Kubernetes without any complicated circumvention. Linux storage and permission fundamentals Before diving into the new Kubernetes features, let us briefly review the low-level Linux security mechanisms that make them possible. Bind mount flags When Linux mounts or remounts a directory, Virtual File System (VFS) flags control what actions are permitted on that filesystem: noexec: Do not permit direct execution of any binaries on the mounted filesystem. nosuid: Do not allow set-user-identifier or set-group-identifier bits to take effect. nodev: Do not interpret character or block special devices on the file system. Directory permissions and the sticky bit Standard Unix permissions regulate access across three scopes: Owner, Group, and Others (e.g., 0755 or 0777). Beyond standard read, write, and execute bits, Linux supports the sticky bit (as in mode 01777). When applied to a directory, the sticky bit ensures that a file inside that directory can only be deleted or renamed by the file's owner or root. This is essential for shared writable directories like /tmp. Motivation for the improvements Why does Kubernetes need bind mount options and emptyDir permissions? The primary goal of these features is to increase the security of Kubernetes workloads by allowing security-related bind mount options on volume mounts. By default, volumes are bind-mounted into containers by the container runtime and kubelet without noexec, nosuid, or nodev flags. This default can undermine security. For example, with noexec missing, a compromised process can use any writable volume (emptyDir, PersistentVolume, etc.) to download, chmod +x, and execute arbitra

## Native Splunk brings real-time insights to Cisco Nexus One

DevFeed: [Native Splunk brings real-time insights to Cisco Nexus One](<https://devfeed.tech/articles/native-splunk-brings-real-time-insights-to-cisco-nexus-one-31399.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/datacenter/native-splunk-brings-real-time-insights-to-cisco-nexus-one>)

Author: David Keith

Published: 2026-09-16T15:00:59Z

Content type: release

Language: en

Sources: [Cisco Blogs](<https://devfeed.tech/sources/cisco-blogs.md>)

Topics: [Nexus Dashboard](<https://devfeed.tech/topics/nexus-dashboard.md>), [observability](<https://devfeed.tech/topics/observability.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [datacenter](<https://devfeed.tech/topics/datacenter.md>), [Security](<https://devfeed.tech/topics/security.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [audit](<https://devfeed.tech/topics/audit.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [analytics](<https://devfeed.tech/tags/analytics.md>), [audit](<https://devfeed.tech/tags/audit.md>), [cisco](<https://devfeed.tech/tags/cisco.md>), [cisco-nexus-dashboard](<https://devfeed.tech/tags/cisco-nexus-dashboard.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [data-center](<https://devfeed.tech/tags/data-center.md>), [data-center-networking](<https://devfeed.tech/tags/data-center-networking.md>), [network](<https://devfeed.tech/tags/network.md>), [nexus-one](<https://devfeed.tech/tags/nexus-one.md>), [observability](<https://devfeed.tech/tags/observability.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [splunk](<https://devfeed.tech/tags/splunk.md>), [troubleshooting](<https://devfeed.tech/tags/troubleshooting.md>)

### AI overview

Cisco describes native Splunk embedded in Cisco Nexus Dashboard as an on-premises analytics and observability capability for data center and AI workloads. It processes telemetry locally, correlates network, security, configuration, and audit data, and provides dashboards, searches, and alerts for troubleshooting, data sovereignty, compliance, and cost efficiency.

### Source excerpt

Discover how native Splunk embedded in Cisco Nexus Dashboard delivers real-time analytics, faster troubleshooting, and on-premises data sovereignty for modern data center and AI workloads.

## Cisco integrates Axis devices, bringing unified management across IT environments

DevFeed: [Cisco integrates Axis devices, bringing unified management across IT environments](<https://devfeed.tech/articles/cisco-integrates-axis-devices-bringing-unified-management-across-it-environments-31400.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/networking/cisco-integrates-axis-devices-bringing-unified-management-across-it-environments>)

Author: Jonathan Cohn

Published: 2026-09-16T15:00:57Z

Content type: release

Language: en

Sources: [Cisco Blogs](<https://devfeed.tech/sources/cisco-blogs.md>)

Topics: [Cisco](<https://devfeed.tech/topics/cisco.md>), [Cisco Meraki](<https://devfeed.tech/topics/cisco-meraki.md>), [Security](<https://devfeed.tech/topics/security.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [Network](<https://devfeed.tech/topics/network.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Internet of things](<https://devfeed.tech/topics/iot.md>)

Tags: [analytics](<https://devfeed.tech/tags/analytics.md>), [cisco](<https://devfeed.tech/tags/cisco.md>), [cisco-cloud-control](<https://devfeed.tech/tags/cisco-cloud-control.md>), [cisco-meraki](<https://devfeed.tech/tags/cisco-meraki.md>), [cisco-networking](<https://devfeed.tech/tags/cisco-networking.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [communications](<https://devfeed.tech/tags/communications.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [internet-of-things](<https://devfeed.tech/tags/internet-of-things.md>), [networking](<https://devfeed.tech/tags/networking.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Cisco announces an integration with Axis Communications that brings network and physical security management into its cloud-managed ecosystem. The article describes Cisco Meraki dashboard management, shared visibility, and potential operational benefits for IT and physical security teams.

### Source excerpt

Cisco and Axis Communications are committed to bridging the gap between IT and physical security infrastructure, as we believe that close collaboration between these teams leads to a stronger, more comprehensive security strategy.

## Arduino announces a live build of a privacy-focused smart doorbell on the Arduino UNO Q

DevFeed: [Arduino announces a live build of a privacy-focused smart doorbell on the Arduino UNO Q](<https://devfeed.tech/articles/build-your-own-smart-doorbell-and-protect-your-privacy-in-one-hour-with-massimo-banzi-31424.md>)

Original publisher: [Read original article](<https://blog.arduino.cc/2026/09/16/build-your-own-smart-doorbell-and-protect-your-privacy-in-one-hour-with-massimo-banzi/>)

Author: Arduino Team

Published: 2026-09-16T14:06:15Z

Content type: article

Language: en

Sources: [Arduino Blog](<https://devfeed.tech/sources/arduino-blog.md>)

Topics: [Arduino](<https://devfeed.tech/topics/arduino.md>), [Computer vision](<https://devfeed.tech/topics/computer-vision.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [arduino](<https://devfeed.tech/tags/arduino.md>), [computer-vision](<https://devfeed.tech/tags/computer-vision.md>), [model](<https://devfeed.tech/tags/model.md>), [notify](<https://devfeed.tech/tags/notify.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [security](<https://devfeed.tech/tags/security.md>), [smart-doorbell](<https://devfeed.tech/tags/smart-doorbell.md>), [uno-q](<https://devfeed.tech/tags/uno-q.md>)

### AI overview

Arduino announces a live build showing how to create a smart doorbell using a computer vision model that runs locally on an Arduino UNO Q board. The event is scheduled for September 22 at 3 PM CET / 9 AM ET and will include questions for the Arduino team.

### Source excerpt

Go on your favorite online shopping platform, and you'll find any number of smart doorbell options. Click to purchase, have it delivered, install it, download some app. But where's the fun in that? And also, don't you wonder how that thing works? That thing that watches you and your loved ones go in and out, [...] The post Build your own smart doorbell and protect your privacy - in one hour, with Massimo Banzi appeared first on Arduino Blog.

## Security updates for Wednesday

DevFeed: [Security updates for Wednesday](<https://devfeed.tech/articles/security-updates-for-wednesday-31515.md>)

Original publisher: [Read original article](<https://lwn.net/Articles/1094720/>)

Author: corbet

Published: 2026-09-16T13:40:53Z

Content type: news

Language: en

Sources: [LWN.net](<https://devfeed.tech/sources/lwn-net.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [nginx](<https://devfeed.tech/topics/nginx.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [Python](<https://devfeed.tech/topics/python.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>)

Tags: [debian](<https://devfeed.tech/tags/debian.md>), [linux](<https://devfeed.tech/tags/linux.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

Security updates were issued by AlmaLinux, Debian, Fedora, Oracle, Red Hat, SUSE, and Ubuntu for packages including kernels, nginx, OpenSSL, Python, Perl, Git, Docker, OpenSSH, and other software.

### Source excerpt

Security updates have been issued by AlmaLinux (kernel, kernel-rt, libkcapi, nginx, nginx:1.24, openssl, osbuild-composer, perl, perl:5.32, python-tornado, rsync, and rust), Debian (cjose and nginx), Fedora (environment-modules, erlang, GitPython, knot, perl-Authen-SASL, python-configargparse, ruby, rubygems, and sblim-sfcb), Oracle (firefox, git-lfs, gstreamer1-plugins-base, kernel, libkcapi, nginx, nginx:1.26, openssl, osbuild-composer, perl, perl-YAML-Syck, postgresql18, python-tornado, and rust), Red Hat (fence-agents, git-lfs, microcode_ctl, osbuild-composer, podman, python-pyasn1, and resource-agents), SUSE (389-ds, ant, bson-devel, chirp-20260911, docker, gimp, google-cloud-sap-agent, hauler, kernel, kimi-code, libpcap, python-GitPython, python310, syncthing, yast2-samba-client, and zstd-jni), and Ubuntu (aom, imagemagick, kitty, openssh, phpseclib, policykit-1, python-sql, python-webob, shibboleth-sp, simplesamlphp, snapcast, srt, and suricata-update).

## AMD Sends Out Linux Patches For Enabling SEV-TIO TDISP With PCIe 6.0

DevFeed: [AMD Sends Out Linux Patches For Enabling SEV-TIO TDISP With PCIe 6.0](<https://devfeed.tech/articles/amd-sends-out-linux-patches-for-enabling-sev-tio-tdisp-with-pcie-6-0-31406.md>)

Original publisher: [Read original article](<https://www.phoronix.com/news/AMD-SEV-TIO-TDISP-Linux-Patches>)

Author: Michael Larabel

Published: 2026-09-16T13:02:52Z

Content type: news

Language: en

Sources: [Phoronix](<https://devfeed.tech/sources/phoronix.md>)

Topics: [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>), [pcie](<https://devfeed.tech/topics/pcie.md>), [trusted-execution-environment](<https://devfeed.tech/topics/trusted-execution-environment.md>), [Confidential Computing](<https://devfeed.tech/topics/confidential-computing.md>), [virtualization](<https://devfeed.tech/topics/virtualization.md>), [Security](<https://devfeed.tech/topics/security.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [MERN](<https://devfeed.tech/topics/mern.md>)

Tags: [amd](<https://devfeed.tech/tags/amd.md>), [arm](<https://devfeed.tech/tags/arm.md>), [attestation](<https://devfeed.tech/tags/attestation.md>), [confidential-computing](<https://devfeed.tech/tags/confidential-computing.md>), [cpu](<https://devfeed.tech/tags/cpu.md>), [desktop-linux](<https://devfeed.tech/tags/desktop-linux.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [intel](<https://devfeed.tech/tags/intel.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [linux-benchmarking](<https://devfeed.tech/tags/linux-benchmarking.md>), [linux-hardware-benchmarks](<https://devfeed.tech/tags/linux-hardware-benchmarks.md>), [linux-hardware-reviews](<https://devfeed.tech/tags/linux-hardware-reviews.md>), [linux-how-to](<https://devfeed.tech/tags/linux-how-to.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [linux-performance](<https://devfeed.tech/tags/linux-performance.md>), [linux-server-benchmarks](<https://devfeed.tech/tags/linux-server-benchmarks.md>), [open-source-graphics](<https://devfeed.tech/tags/open-source-graphics.md>), [pcie](<https://devfeed.tech/tags/pcie.md>), [phoronix](<https://devfeed.tech/tags/phoronix.md>), [phoronix-test-suite](<https://devfeed.tech/tags/phoronix-test-suite.md>), [processors](<https://devfeed.tech/tags/processors.md>), [risc-v](<https://devfeed.tech/tags/risc-v.md>), [security](<https://devfeed.tech/tags/security.md>), [ubuntu-benchmarks](<https://devfeed.tech/tags/ubuntu-benchmarks.md>), [ubuntu-hardware](<https://devfeed.tech/tags/ubuntu-hardware.md>)

### AI overview

AMD submitted 17 Linux kernel patches to enable SEV-TIO TDISP for PCIe 6.0 and newer. The work is intended to secure direct I/O device assignment for confidential-computing environments, including AMD Secure Encrypted Virtualization guest VMs, and includes a common TEE Security Manager developed with Intel, Arm, and RISC-V.

### Source excerpt

The newest Linux kernel patches out of AMD for enhancing the upstream support with the new AMD EPYC 9006 "Venice" processors is for enabling SEV-TIO TDISP that is supported with PCI Express 6.0 and beyond...

## Constraining AI agents with Red Hat AI: Containment, identity, and governance

DevFeed: [Constraining AI agents with Red Hat AI: Containment, identity, and governance](<https://devfeed.tech/articles/constraining-ai-agents-with-red-hat-ai-containment-identity-and-governance-31402.md>)

Original publisher: [Read original article](<https://developers.redhat.com/articles/2026/09/16/constraining-ai-agents-with-red-hat-ai-containment-identity-and-governance>)

Author: Grace Ableidinger

Published: 2026-09-16T13:01:59Z

Content type: tutorial

Language: en

Sources: [Red Hat](<https://devfeed.tech/sources/red-hat.md>), [Red Hat Developer](<https://devfeed.tech/sources/red-hat-developer.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [containers](<https://devfeed.tech/tags/containers.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [security](<https://devfeed.tech/tags/security.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

This tutorial explains how to secure AI agents running on Red Hat OpenShift using containment, verifiable identity, and governance. It covers namespace isolation, quotas, sandboxing, workload identity, and admission control, with OpenClaw used in the demo.

### Source excerpt

When an agent process runs on your laptop, it typically inherits anything your user has access to. Often this includes the full network stack, the file system, and the credentials sitting in memory. When integrating with GitHub, Slack, or a cloud provider, you could be one faulty permission or well-crafted prompt injection away from a security incident. The post Constraining AI agents with Red Hat AI: Containment, identity, and governance appeared first on Red Hat Developer.

## Cloud Sovereignty, Provider Risk, and Migration Options for EU Companies

DevFeed: [Cloud Sovereignty, Provider Risk, and Migration Options for EU Companies](<https://devfeed.tech/articles/beyond-the-hyperscalers-what-actually-protects-you-31468.md>)

Original publisher: [Read original article](<https://www.pulumi.com/blog/beyond-the-hyperscalers-what-actually-protects-you/>)

Author: Adam Gordon Bell

Published: 2026-09-16T13:00:00Z

Content type: opinion

Language: en

Sources: [Pulumi](<https://devfeed.tech/sources/pulumi.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [migration](<https://devfeed.tech/topics/migration.md>), [pulumi](<https://devfeed.tech/topics/pulumi.md>), [Security](<https://devfeed.tech/topics/security.md>), [scaleway](<https://devfeed.tech/topics/scaleway.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [customers](<https://devfeed.tech/tags/customers.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [migration](<https://devfeed.tech/tags/migration.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [pulumi](<https://devfeed.tech/tags/pulumi.md>), [scaleway](<https://devfeed.tech/tags/scaleway.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This recorded discussion examines cloud sovereignty, legal and cost concerns for EU companies using major US cloud providers, and the practical tradeoffs of moving to European providers. Three guests discuss provider exposure, encryption and account shutdown risks, migration costs, and whether Pulumi and agentic infrastructure can make future moves easier.

### Source excerpt

Recorded September 3, 2026. Quotes are lightly edited for clarity. Maybe this sounds familiar. You run infrastructure at a company that isn't American. Your workloads are on AWS, Azure, or Google Cloud, probably more than one, because that is what everyone picked. Until recently nobody asked you where the data lives or who can reach it. Now you're getting questions. Legal wants to know what NIS2 means for where your systems run. Someone on the leadership team read that the US government locked the cloud accounts of judges at the International Criminal Court and wants to know if that could happen to you. Finance wants to know why the bill went up again. A customer's security review asked, in writing, which country your data sits in. So now you have questions of your own: If a US court or agency wants my data, can they get it from my provider without involving me? Does putting everything in an EU region change that? The big providers now sell "sovereign cloud" in Europe. Is that different, or a rename? If I encrypt everything and hold the keys myself, am I covered? Could my account be switched off one day? What would I do? Are Hetzner, OVH, and Scaleway usable for real workloads? How much cheaper are they once you count the migration? What should I be building on now so I can leave later if I need to? A migration like this used to be a multi-year project. Does Pulumi and agentic infrastructure change that? Is any of this worth the disruption, or should I leave what works alone? I put those questions to three people who have each dealt with this for real. One of them helps EU companies work out their exposure and builds the tooling to leave. Another has spent fifteen years sizing what cloud actually costs, and thinks most people should stay put. The third moved his company off AWS and onto a European provider. They don't agree on how big the risk is. The full hour is below. Don't just default to the hyperscalers Waldemar Kindler co-founded Think Ahead Technologies, whe

[Next page](<https://devfeed.tech/topics/security.md?cursor=WyIyMDI2LTA5LTE2VDEzOjAwOjAwKzAwOjAwIiwgIjhkYWFmMDMxLTY2MmYtNGQzZC04MWMwLWFiMjg1NzZjMjYzYyJd>)