2026-09-18
Top stories
- Cisco ISE authentication bypass rated 10.0 is under active exploitation Cisco patched CVE-2026-76460, a CVSS 10.0 ISE and ISE-PIC authentication bypass under active exploitation.
- Plugin4Shell gives zero-click code execution in major coding agents Researchers report Plugin4Shell, a zero-click code execution flaw in major coding agents, with Gemini CLI and Copilot unpatched.
- libheif heap overflow chained through OpenAI SSO to internal repository access Hacktron details a libheif heap overflow chained through OpenAI SSO, with Discourse and Debian patched since 2026-07-28.
- Researcher reports ZCode packages full Git history for upload to Aliyun OSS A researcher reports ZCode packages full Git history for upload to Aliyun OSS, with no user setting that stops it.
AI
ML research
Agentic coding
Security
- Gyazo breach exposes 23.62 million user records and 490 million image metadata records mostly predating 2019 Gyazo says an attacker reached its database on 2026-09-11, exposing 23.62 million user records and password hashes.
- Laser fault injection sets RP2350 debug-enable bits and recovers an OTP secret after a rescue reset Ledger Donjon used laser fault injection to set RP2350 debug-enable bits and restore Secure debug on a locked part.
Outages
- NATS traces the 2026-09-08 UK airspace disruption to a preempted aircraft code request that resumed incorrectly NATS traces the 2026-09-08 UK airspace disruption to a paused aircraft code request that resumed with corrupt state.
- Telstra outage traced to a GPS week rollover and an NTP timing loop An independent review traces Telstra's 2026-07-08 outage to a GPS week rollover on one receiver and an NTP timing loop.
Developer tools
Languages and runtimes
- jemalloc 5.4.0 removes seven tcache tuning options and silently ignores their malloc_conf settings jemalloc 5.4.0 removes seven tcache tuning options and ignores their mallocconf settings without any error.
- Python's steering council froze CPython JIT development pending a standards-track PEP The Python steering council barred new CPython JIT work until a standards-track PEP is accepted, with removal as the default.
- C++26 makes trivial infinite loops well-defined after compilers optimized embedded halt loops away C++26 adopts P2809R3, making a trivially empty while (true) loop defined behaviour that optimizers may no longer delete.
Infrastructure
Engineering posts
- Uber caps retry storms by making services claim ownership of errors Uber cut its maximum retry storm radius from 25 hops to 3 by making each service declare which errors it owns.
- FEX-Emu measures what emulating x86 total store ordering costs on five ARM cores FEX-Emu benchmarks x86 store-ordering emulation on five ARM cores and finds a hardware TSO toggle beats LRCPC.