P.01SonicWall SMA1000's Second Zero-Day Chain: Patch Now
CVE-2026-83548 (SSRF, CVSS 10.0) and CVE-2026-83549 (OS command injection) hit SMA1000 appliances again, seven weeks after the last chain. Affected models and the fix.
Tag
103 articles tagged #Infrastructure.
P.01CVE-2026-83548 (SSRF, CVSS 10.0) and CVE-2026-83549 (OS command injection) hit SMA1000 appliances again, seven weeks after the last chain. Affected models and the fix.
P.02CISA gave federal agencies until Sept 12 to patch a Citrix NetScaler auth bypass and a critical FortiOS RCE tied to a live PivotC2 malware campaign.
P.03A single unauthenticated request can run code inside OmniRoute, the 58k-star AI gateway. Patch status is contested, so verify your build yourself.
P.04A ransomware crew used Cursor's AI coding agent to run reconnaissance and lateral movement by hand across dozens of victims. What that means for defenders.
P.05MikroTik patched three RouterOS bugs after CISA confirmed active exploitation of two: which CVEs to prioritize and how to check your router for compromise.
P.06A phantom join key in JFrog Artifactory's auth service let attackers forge admin tokens days after disclosure. Affected versions, what to check, and the patch.
P.07NVIDIA is acquiring Hugging Face for $12.93B. Here's what actually changes for the Hub, Transformers, and Inference Endpoints, and what to do before the 2027 close.
P.08Two chained PaperCut NG/MF flaws let an attacker with no credentials run code on your print server. PaperCut needed two emergency patches to close it.
P.09Emerald AI raised $150M to make AI data centers shed power on demand. A 96-GPU Nvidia trial cut draw 30% in 30 seconds. What that means for capex plans.
P.10One unauthenticated RCE in PTC Windchill and FlexPLM let Cl0p quietly take data from Shell, Philips, and GE. How CVE-2026-12569 works, and what to check.
P.11Cloudflare logged 13 incidents between August 7 and 14, touching R2, Durable Objects, and Workers KV. What that means for building on one edge provider.
P.12Two writes hit different replicas at once. Which came first? Sometimes neither. How vector clocks tell a real conflict from a false one, without wall time.
P.13Citrix shipped CVE-2026-8452 as a routine DoS fix in June. watchTowr showed it's a pre-auth heap overflow with a path to RCE. CISA's deadline was August 29.
P.14Nvidia posted $96.2B in Q2 FY27 revenue, Data Center up 117% to $89B. What the number means if you're the one budgeting GPU capacity this quarter.
P.15Amazon closes Mechanical Turk and Ground Truth's human workforce on September 30, 2026, after 21 years. The dates that matter, and where teams are moving.
P.16Argo Rollouts replaces a Deployment with a controller that shifts traffic gradually and rolls back on bad metrics. Real manifests, plain Deployment to canary.
P.17A flaw in Gitea's diffpatch API turns a crafted merge conflict into an executable Git hook. CISA added it after miner payloads showed up. What to patch.
P.18Every rolling deploy drops a few requests and the errors look like client noise. The shutdown sequence, the race behind it, and the code that fixes it.
P.19A ripgrep crash on musl looked like an allocator bug, then a threading bug. The real cause was a race in recent Linux kernels. The chain, and the lesson.
P.20Kitesurf is a browser runtime with no UI or tabs, built for AI agents to load pages and extract HTML. It claims 3-7x less CPU than Chromium. When to use it.
P.21Stripe is acquiring the AI gateway OpenRouter for over $7B, roughly 50x annualized revenue. Nothing changes in the API today, but the bet is telling.
P.22A hack at Ceva Logistics exposed customer data for Bol, ING, Ajax, and Steam hardware buyers, none breached directly. What it means for vendor risk.
P.23From Node.js 27 in October 2026, Node drops the odd/even model for one major a year, and every release becomes LTS. What changes, and how to plan for it.
P.24One unauthenticated HTTP request reloads Cisco ASA and FTD devices with remote-access VPN on. CISA's deadline was August 14. What's affected, and the fix.
P.25A heap-buffer bug in Progress Kemp LoadMaster's escape_quotes() lets an unauthenticated attacker run commands on the load balancer. CISA confirmed Aug 7.
AMD acquired Taalas, which hardwires model weights into chip silicon instead of loading from memory. What that trades away, and why it won't replace GPUs.
P.27An SLA is a promise with a penalty. An SLO is the internal target that keeps you inside it. An error budget is what's left. The math, on a real example.
P.28A one-line control-flow change meant to patch CVE-2026-29146 quietly broke Tomcat's cluster encryption. CISA confirmed exploitation on August 4. The fix.
P.29CVE-2026-20079 is a 10.0 CVSS Cisco Secure FMC authentication bypass disclosed before the hardcoded-password bug. Why it matters, and what to patch.
P.30CISA flagged two FortiSandbox command injection bugs as exploited on July 16. Chained with a third, they reach root with no credentials. What to patch.
P.31A static credential baked into on-prem Cisco Secure FMC is being exploited. Who's affected, why a 5.3 CVSS undersells it, and what to check right now.
P.32SambaNova raised $1B at an $11B valuation to build inference-specific chips, not training hardware. What the inference wave means for production AI.
P.33BullMQ for Node, Celery for Python, Sidekiq for Ruby, and Temporal or a cloud queue when you need durability without owning a broker. The reasoning.
P.34CISA added CVE-2025-68686, a FortiOS SSL-VPN symlink persistence bypass, on July 27. It only bites devices compromised earlier and never forensically cleaned.
P.35CISA added CVE-2026-16812, an unauthenticated command injection in Arista VeloCloud Orchestrator scored 10.0, on July 27. Who's affected, and what's patched.
P.36CVE-2026-20262 lets an authenticated attacker write files on Catalyst SD-WAN Manager and escalate to root. It's on CISA's KEV list, deadline already passed.
P.37Ollama closed a $65M Series B on July 9, taking total funding to $88M with nearly 9M developers. What the raise signals for local versus hosted inference.
P.38A CVSS 9.8 unauthenticated flaw in Oracle E-Business Suite Payments has been exploited since late June, with roughly 950 instances still exposed.
P.39Two chained SMA1000 flaws, an unauthenticated CVSS 10.0 SSRF and a post-auth code injection, are under active attack. Affected firmware and the fix.
P.40Together AI raised $800M at an $8.3B valuation with bookings past $1.15B. What the numbers say about running open weights versus closed APIs.
P.41A hacker claimed 35GB from Accenture including RSA and SSH keys and Azure tokens. The code isn't the risk; the credentials next to it are. The audit to run.
P.42Platform engineering has its own hiring cluster now, distinct from DevOps, SRE, and cloud architecture. How to screen for product thinking over ticket-taking.
P.43A forged OIDC token in SimpleHelp RMM lets an unauthenticated attacker create an admin and reach every managed endpoint. CISA added it on June 29.
P.44An unauthenticated SSRF in Cisco Unified CM is being exploited to write files, plant a webshell, and reach root. The chain, and how to patch or work around.
P.45Deno Sandbox spins up isolated Firecracker microVMs in under 200ms for running code you don't trust, AI-agent output included. Here's how it works and a working example.
P.46Cloudflare blocks mixed-use AI crawlers from ad-supported pages by default from September 15, 2026, plus a pay-per-use model. What to configure now.
P.47GPT-5.6 Sol runs on Cerebras wafer-scale hardware at up to 750 tokens per second, roughly 10x typical GPU inference. Who that speed is actually for.
P.48Three 10.0-severity UniFi OS flaws chain into unauthenticated root, and a Mirai botnet is already using them. What's affected, and how to patch today.
P.49Qualcomm's $3.92B all-stock deal for Modular, behind Mojo and MAX, bets on a hardware-agnostic path around NVIDIA's CUDA lock-in. What actually changes.
DevSecOps is distinct from DevOps and from security engineering. What the role covers, what to screen for, and why supply chain security is now the core.
P.51June 2026 Patch Tuesday is the year's largest: 206 CVEs, 37 Critical, three zero-days, and a Splunk RCE already under attack. What to patch first.
SRE is a discipline, not DevOps with a pager. How to define the role, screen for reliability math, and avoid hiring an ops generalist by accident.
Firebase's complexity and Supabase's Postgres assumptions don't fit every project. How PocketBase, Appwrite, and Convex differ, and when each one fits.
Cloud architect is a badly misused title. How to define the role, screen for real judgment, and avoid hiring a certification collection by mistake.
Data engineers build the pipelines, warehouses, and transformation layers. They aren't data scientists, backend developers, or analysts. How to hire for it.
Go runs Kubernetes, Docker, Prometheus, and most cloud tooling. What the language attracts, what it demands, and how to screen for the right profile.
Three tools, three bets on where complexity belongs. How to choose between BullMQ, Inngest, and Temporal based on what your system needs, not what sounds big.
OpenFeature is a CNCF incubating project with broad SDK support. How to use vendor-neutral feature flags, and why the standard beats the tool behind it.
Durable Objects solve edge computing's coordination problem: consistent state across distributed nodes. Here's how they work and when to use them.
Kafka is the default answer for message queuing at scale. But for teams running fewer than a million messages per day, NATS JetStream offers persistence, delivery guarantees, and a dramatically simpler operational footprint.
Setting up metrics with Prometheus and dashboards with Grafana: what to instrument, what to skip, and what a dashboard should show during an incident.
Dev Containers define your entire dev environment in a devcontainer.json file, so new teammates are productive in minutes. Here's how to set them up.
Vulnerability scanning catches known CVEs in your base images and dependencies before they reach production. Here's how to set up Trivy and Snyk, understand their output, and act on what they find.
Multi-stage Docker builds cut image size by 80-90%, speeding up pulls, cold starts, and CI, while shrinking your attack surface and registry bill.
R2's zero-egress pricing looks compelling on paper. Here's when it actually saves money, when S3's ecosystem still wins, and how to migrate if you decide to switch.
Logs say what happened. Error tracking says what broke, for which users, in what context. Setting up Sentry properly, without the alert fatigue.
Every cloud decision locks you in somewhere; the real question is which lock-in costs less. A practical framework for when to abstract and when to accept it.
ClickHouse is a columnar database designed for analytical workloads. It answers queries over billions of rows in seconds that would take minutes in Postgres. Here's what application developers need to know.
Blue-green and canary deployments give you a way to release software without taking down your service or discovering a bug when it's already affecting everyone. Here's how they work and when to use each.
eBPF lets you attach programs to any kernel hook — network packets, system calls, function calls — without patching the kernel or rebooting. Here's what application developers actually need to know.
Tailscale is a mesh VPN giving distributed teams private networking between laptops, servers, and office machines in about 30 seconds, no VPN hardware needed.
Multi-cloud usually costs more in engineering time than the lock-in risk it prevents; most teams do better on one cloud with deliberate exceptions.
OpenTelemetry is the observability standard now. Most tutorials show you how to install the SDK and emit traces. Fewer explain which signals actually matter for web applications and which add noise without helping you debug anything.
Password resets, invoices, and notification emails are infrastructure. Most developers treat them as an afterthought until a client asks why their welcome emails are disappearing. Here is the full picture.
When your AI agent needs to run the code it writes, you can't let it touch your production servers. Here's how the main isolation options work and when to use each.
HPA scales on CPU and memory. But most production workloads don't scale well on those signals. KEDA, VPA, and Goldilocks fill the gaps that HPA leaves open.
The queries that wreck production Postgres share a few root causes. How to find them, read EXPLAIN ANALYZE properly, and fix them without guessing.
Single-provider AI dependencies are a reliability risk. Routing layers like LiteLLM and OpenRouter let you fall back across providers, cap costs, and try smaller models first. Here is the architecture and when it actually matters.
gRPC has been available for years but many teams default to REST without thinking through the tradeoffs. Here's how gRPC works, where it fits, and where it doesn't.
Connection exhaustion is one of the most common production failures for apps that scale. Here's how pooling works, which tool fits which setup, and the configuration decisions that matter.
A practical incident response process for small teams: severity tiers, on-call rotations, better alerting, and blameless postmortems, no SRE org required.
Leaked credentials are the most preventable breach category. When you need a real secrets manager, which one to pick, and what to do if you're still on .env.
Service meshes promise secure, observable microservice communication. But most teams that adopt one do so before they need it. Here is how to decide, and what each option actually costs you.
Message queues and event streams solve different problems. Kafka is not always the right answer. Here's how to think through event-driven patterns and choose the right tool for your production workload.
Running unscanned containers in production is like shipping without tests. Here's how teams scan images, generate SBOMs, and add runtime protection.
Background jobs that crash mid-run lose their state. Temporal makes workflows durable state machines that survive restarts and deploys. In TS and Python.
HashiCorp's 2023 BSL relicensing split Terraform into OpenTofu, while Pulumi took a code-first approach. Here's how to choose between them in 2026.
In March 2024, Redis Ltd. relicensed Redis under a source-available license. Within weeks, the Linux Foundation forked it as Valkey. Two years on, here's how the split played out and what it means for teams choosing an in-memory data store today.
P.89Explore the shift towards serverless edge computing in the post-cloud era, focusing on performance improvements, cost savings, and real-world case studies of enterprises leveraging this technology.
RAM prices jumped roughly 90% in Q1 2026 as AI data centers now consume 70% of global memory supply, and the squeeze isn't expected to ease before 2028.
A cascading config error bypassed canary checks in Cloudflare's Feb 2026 outage, hitting R2 and Workers for 4h37m. Real distributed-systems lessons.
How running AI models at the edge enables real-time intelligence for IoT, autonomous vehicles, and smart manufacturing. A developer guide to edge AI platforms, frameworks, and opportunities in 2026.
The EV charging software market is exploding. Learn how developers can build with OCPP, fleet management APIs, payment integration, and smart grid optimization in this booming $100B+ infrastructure sector.
WASI 0.3 adds native async I/O, stream types, and full socket support to WebAssembly, finally making Wasm viable for production server workloads.
P.95EditorPickA deep dive into the India AI Impact Summit 2026 at Bharat Mandapam — $200B in pledged investments, sovereign AI models, the MANAV framework, and what it all means for builders and founders.
AWS and Google Cloud now offer encrypted cross-cloud interconnect networking. Here is what the partnership includes, and what still locks you in.
Microsoft ($17.5B), Amazon ($35B) & Google ($15B) are investing $67.5B in India's data centres. Here's what this AI infrastructure race means for India's tech future.
GitOps adoption hit 64% in 2025, and the next evolution is integrating real-time cost visibility into every infrastructure pull request. We break down why GitOps plus FinOps is the operational model serious teams are adopting in 2026.
Microsoft, Google, Amazon, and Meta are collectively spending $650 billion on AI infrastructure in 2026. We break down what each company is building, why the numbers keep climbing, and what it means for developers.
Alphabet announced $175-185 billion in 2026 capital expenditure, nearly double 2025 spending. Stock dropped 5% as investors question Big Tech's AI spending sustainability, despite Google Cloud revenue spiking 48%.
Amazon reported quarterly revenue beating estimates but stock dropped 10% after-hours as investors digest the company's $200 billion capital expenditure plan for 2026, driven by aggressive AI infrastructure investment.
P.102Meta Compute, OpenAI's 750MW deal, and a projected $3 trillion investment in AI infrastructure. The biggest story in tech isn't about models—it's about who controls the compute.
Astro powers our site, Vercel deploys it, Airtable runs our CRM, and Satori generates OG images. Here is every tool in our stack and why we picked each one.