AI Security Digest
Aggregated ecosystem risk analysis
Vendor Watchlist
Tracking 0 critical integrations
Threat Stream Feed
Real-time security logs and system alerts
GCP - UPDATE: Google Cloud Storage customers are experiencing elevated latencies and error rates when performing upload or write operations.
Incident began at 2026-10-08 05:19 (all times are US/Pacific).Summary Google Cloud Storage customers are experiencing elevated latencies and error rates when performing upload or write operations Description We are continuing to mitigate the issue with Google Cloud Storage in the us-central1 region that began on Thursday, 2026-10-08 05:19 PDT. The initial mitigations applied by our engineering team continue to show observable improvements in error rates. Our engineering team is actively monitor...
GCP - UPDATE: Google Cloud Storage customers are experiencing elevated latencies and error rates when performing upload or write operations.
Incident began at 2026-10-08 05:19 (all times are US/Pacific).Summary Google Cloud Storage customers are experiencing elevated latencies and error rates when performing upload or write operations Description We are continuing to mitigate the issue with Google Cloud Storage in the us-central1 region that began on Thursday, 2026-10-08 05:19 PDT. The initial mitigations applied by our engineering team continue to show observable improvements in error rates. Our engineering team is actively monitor...
GCP - UPDATE: Google Cloud Storage customers are experiencing elevated latencies and error rates when performing upload or write operations.
Incident began at 2026-10-08 05:19 (all times are US/Pacific).Summary Google Cloud Storage customers are experiencing elevated latencies and error rates when performing upload or write operations Description We are experiencing an issue with Google Cloud Storage beginning on Thursday, 2026-10-08 05:19 PDT. Initial mitigations applied by our engineering team leading to observable improvements in error rates in our internal monitoring beginning 10:57 PDT. Work remains underway to roll out further...
GCP - UPDATE: Google Cloud Storage customers are experiencing elevated latencies and error rates when performing upload or write operations.
Incident began at 2026-10-08 05:19 (all times are US/Pacific).Summary Google Cloud Storage customers are experiencing elevated latencies and error rates when performing upload or write operations Description We are experiencing an issue with Google Cloud Storage beginning on Thursday, 2026-10-08 05:19 PDT. Initial mitigations applied by our engineering team leading to observable improvements in error rates in our internal monitoring. Work remains underway to roll out further mitigations. We wil...
GCP - UPDATE: Google Cloud Storage customers are experiencing elevated latencies and error rates when performing upload or write operations.
Incident began at 2026-10-08 05:19 (all times are US/Pacific).Summary Google Cloud Storage customers are experiencing elevated latencies and error rates when performing upload or write operations Description We are experiencing an issue with Google Cloud Storage beginning on Thursday, 2026-10-08 05:19 PDT. Our engineering team continues to investigate the issue. We will provide an update by Thursday, 2026-10-08 11:50 PDT with current details. Customer Symptoms Customers are experiencing elevat...
Elastic Cloud - Delayed or Unavailable project operation in GCP us-central1
Oct 8, 16:42 UTC Investigating - We are investigating an issue affecting some Elastic Cloud Serverless projects in the GCP us-central1 region. Customers may experience delayed or unavailable project operation.
Mixpanel - Temporary Data Ingestion Delay for US Projects
Oct 8, 09:32 PDT Investigating - We are currently experiencing delays in our data ingestion pipeline, which is affecting real-time data for projects enrolled in the US projects, resulting in delays for a subset of projects. While no data is being lost, our engineering team is actively investigating the matter and working to restore real-time functionality as quickly as possible. We appreciate your patience during this time.If you have any questions, please contact support.
Zoom - Zoom Phone Maintenance - SIN3 Data Center: October 8, 2026
THIS IS A SCHEDULED EVENT Oct 8, 09:00 PDT - Oct 9, 21:30 PDT Sep 15, 16:36 PDT Scheduled - Zoom will perform service maintenance at our SIN3 Data Center starting at 9:00 AM Pacific on October 8, 2026. Zoom Phone users registered to the those sip zones will be automatically registered in the NRT3 sip zone sequentially. During the maintenance window, a brief disconnection may be experienced and notifications may be missed. If you get disconnected, the system will attempt to reconnect you aut...
HubSpot - Some HubSpot tools may be unavailable for some users
Oct 8, 10:52 EDT Identified - Marketing email stats are delayed. The email performance page isn't showing up to date data for some customers in North America. Emails are still being delivered.We have identified an issue and are working on a solution. We will be back with an update within 3 hours.The information on this page reflects our understanding of the incident and impact at the time of the update. Oct 8, 10:45 EDT Investigating - We are investigating an issue impacting some HubSpot to...
Netlify - Elevated Edge Function Errors
Oct 8, 14:34 UTC Resolved - Between 13:16 and 13:24 UTC some requests to sites that use Edge Functions experienced increased latency and an elevated rate of 502 errors. This incident has been resolved.
ActiveCampaign - Whatsapp message responses delayed
Oct 8, 09:29 CDT Monitoring - The issue has been resolved and response messages are catching up now. Oct 8, 09:19 CDT Identified - The issue has been identified and a fix is being implemented. Oct 8, 09:03 CDT Investigating - We are aware of delays in receiving Whatsapp responses and engineering is actively investigating. Message sending is not impacted.
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks. The activity, per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration. "In this activity, the threat actor leveraged
CircleCI - Elevated wait times for machine jobs
Oct 8, 13:34 UTC Update - Customers using Linux machine jobs are experiencing elevated wait times, averaging about 11 minutes, with the longest waits exceeding 30 minutes on the medium, arm.medium and arm.large resource classes. Our engineers have identified the issue and are working on a fix. We will provide another update by 14:00 UTC. Oct 8, 13:00 UTC Identified - Customers may be experiencing elevated wait times for machine jobs. We are working to resolve this.
Grid Protection Alliance openPDC and openHistorian
View CSAF Summary The following versions of Grid Protection Alliance openPDC and openHistorian are affected: openPDC <2.9.477, <2.9.482 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022) openPDC (Docker image) <2.9.477, <2.9.482 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022, CVE-2026-105278) openHistorian <2.8.580, <2.8.585 (...
Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data
Advisory at a Glance Title Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data Original Publication October 8, 2026 Executive Summary Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and h...
Azure - Active -Azure Data Factory – Pipeline/Activity Failures and Timeouts – UK South
We are aware of an issue affecting Azure Data Factory in UK South, where a subset of customers may experience failures, delays, or timeouts with pipeline and activity runs, integration runtime management, or authoring operations. Our engineers are actively working to determine the cause and impact. As a workaround, customers are advised to cancel and retry affected runs that fail, time out, or remain in progress longer than expected.
Azure - Active -Azure Data Factory – Pipeline/Activity Failures, Delays & Timeouts – UK South
We are aware of an issue affecting Azure Data Factory in UK South, where a subset of customers may experience failures, delays, or timeouts when running pipelines and activities, managing integration runtimes, or performing authoring operations. Our engineers are actively investigating the cause and impact . Workaround: Customers are advised to cancel and retry affected pipeline or activity runs that fail, time out, or remain in progress longer than expected. Further updates will be provided as ...
Box - [Critical] Issues with Multiple Box Services
Oct 8, 02:33 PDT Resolved - After further monitoring, this incident is now considered resolved. Box services have been restored to full functionality. Please contact Box Support at https://support.box.com/ if you continue to experience any issues. Oct 8, 02:27 PDT Investigating - We are investigating an ongoing issue affecting All Files page, API, uploads, downloads, Box Sign and Notes. We will provide more information as soon as it is available.
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
The popular Tensorlake SDK (part of a project with 1,000+ GitHub stars) shipped a poisoned release (v.0.5.144) that was infected with the self-propagating Shai-Hulud worm. The malicious version was published through the project's legitimate GitHub Actions release pipeline, complete with valid SLSA provenance. The attacker poisoned main first, then let the trusted pipeline do the rest. This i...
Pwn2Own Ireland 2026 Day 1: 32 Zero-Days, $388,500, Samsung Galaxy S26 Hacked 3 Times
Full Day One results from Pwn2Own Ireland 2026. The scoreboard: 32 unique zero-days demonstrated. $388,500 in total bounties. Samsung Galaxy S26 compromised three times. AI infrastructure targeted for the first time, including OpenAI Codex, Oracle Autonomous AI Database, and LiteLLM. Longest chain of the day: Philips Hue Bridge Pro, seven zero-days. Notable: Every Galaxy S26 exploit used a four-bu...
Amplitude - BigQuery exports are lagging for US.
Oct 7, 20:33 PDT Identified - We are currently investigating an issue where all BigQuery exports are lagging for US (not EU) due to a downstream issue.
Box - [Medium] Issue with Enterprise Event Reports
Oct 7, 18:48 PDT Investigating - Our team is investigating an issue affecting enterprise event data. Admins may see missing or outdated information in event-based reports and Insights in the Admin Console, as well as in results from the Enterprise Events API. Box AI users may also see inaccurate AI unit usage. We will provide additional information as it becomes available.
Heap - User property data delayed in Heap connect syncs (US customers only)
Oct 7, 17:56 PDT Update - We are continuing to investigate this issue. Oct 7, 16:20 PDT Investigating - We are investigating delays in user property updates appearing in the Heap app for some customers. Our engineering team is working to identify the cause and restore normal processing. Data continues to be collected and no data has been lost.
Rippling - Issues using 1Password passkeys
Oct 7, 20:07 UTC Identified - Users with version 8.12.40.31 of the 1Password browser extension may be unable to complete passkey verification to sign in, or add new Rippling passkeys to their account. 1Password is preparing a fix, and we will share another update when more information is available.
CircleCI - Increased task wait times for Docker Gen2
Oct 7, 18:54 UTC Identified - There is an increased wait time for jobs on Docker Gen2.
GitHub - Incident with Git Operations, Issues, Actions and Pull Requests
Oct 7, 17:27 UTC Monitoring - The degradation has been mitigated. We are monitoring to ensure stability. Oct 7, 17:25 UTC Update - We observed widespread impact across GitHub services from 16:52 UTC to 17:01 UTC, and are investigating the root cause. All systems have recovered. This incident is a reoccurrence of the incident from earlier in the day https://www.githubstatus.com/incidents/djlmxz2zd0j7. Durable mitigation is in progress. We will provide another update in 30 minutes. Oct 7, ...
GhostAction campaign: new spike in malicious workflows
Hundreds of new repositories poisoned with malicious, secret extracting workflows. GitHub held most malicious workflows runs for approval, limiting the impact. Some victims found to also be affected by seemingly unrelated cryptominer attacks, hinting toward a pool of compromised credentials being used by multiple threat actor groups. submitted by /u/mabote [link] [comments]
GitHub - Incident with Git Operations, Pull Requests and Actions
Oct 7, 15:58 UTC Update - We are seeing full recovery across all systems including Git Operations, Pull Requests and Actions. We are continuing to investigate the root cause of the disruption between 15:06 UTC and 15:16 UTC, and will share another update shortly. Oct 7, 15:56 UTC Update - The degradation has been mitigated. We are monitoring to ensure stability. Oct 7, 15:49 UTC Monitoring - The degradation has been mitigated. We are monitoring to ensure stability. Oct 7, 15:49 UTC Up...
Supabase - Maintenance: Statuspage Migration
Status: In progressScheduled maintenance is currently in progress. We will provide updates as necessary.
Supabase - Statuspage Migration
THIS IS A SCHEDULED EVENT Oct 7, 15:00 - 17:00 UTC Sep 30, 22:08 UTC Scheduled - Starting October 7th, we are migrating our status page to a new platform to give you better visibility into Supabase's service status.What's changing:The status page URL will stay the same: https://status.supabase.comIf you are subscribed via email, you will automatically be resubscribed, no action needed.If you are subscribed via any other method (SMS, Slack, webhook, RSS, etc.), you will need to resubscribe on th...
Scans for Atlassian vulnerablity (CVE-2026-21589), (Wed, Oct 7th)
On October 5th, Atlassian published patches&#;x26;#;xc2;&#;x26;#;xa0;for multiple products to fix an "Arbitrary File Access" vulnerability &#;x26;#;x5b;CVE-2026-21589&#;x26;#;x5d;. An attacker can read arbitrary files in the web application&#;x26;#;39;s directory, potentially exposing sensitive information such as configuration files.
CircleCI - Elevated level of infra fails on customer jobs
Oct 7, 14:44 UTC Monitoring - We're seeing signs of recovery. Docker Gen2 wait times are slightly elevated and we're monitoring. Oct 7, 14:27 UTC Investigating - We are investigating a rise in infra fails for customer jobs.
Infostealers are actively hunting AI Agents and developer keys - Warden Infostealer analysis
Log extractions (such as a compromised .claude.json file) show the stealer successfully exfiltrating raw primaryApiKey values and detailed OAuth account data tied to Anthropic/Claude accounts. By grabbing these CLI tokens, attackers are bypassing traditional web logins entirely, gaining direct, programmatic access to premium AI models, organizational workspaces, and potentially sensitive sou...
CircleCI - Delay on starting Machine Job Tasks
Oct 7, 14:06 UTC Resolved - The incident has been resolved. Thank you for your patience Oct 7, 13:52 UTC Monitoring - We are seeing signs of recovery and monitoring the situation. Oct 7, 13:40 UTC Investigating - Customers may be experiencing elevated wait times for Machine Job Tasks, we are investigating the root cause and will update when we know more.
FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat
Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software
Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws
Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional
100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer). The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the
Zoom - Service Degradation Affected Inbound and Outbound Calls for Zoom Contact Center
Oct 6, 20:42 PDT Resolved - This incident has been resolved and the affected services have been restored. Oct 6, 20:30 PDT Monitoring - On 10/07/2026, Between 2:32 UTC to 2:44 UTC, A subset of users may have experienced issues with inbound and outbound calls for Zoom Contact Center.This incident has been resolved and the affected services have been restored.
CircleCI - Emergency Infrastructure Maintenance
Oct 7, 03:00 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Oct 6, 23:17 UTC Scheduled - We will be performing emergency maintenance on October 7, 2026, from 03:00 UTC to 05:00 UTC. While we expect the impact to be minimal during this window, pipelines, workflows, jobs and notifications may briefly experience interruptions, including delays or failures in workflows and jobs starting. We will provide an update when the maintenance begi...
Zoom - Service Degradation Affecting Zoom Calendar
Oct 6, 19:41 PDT Investigating - We are currently investigating a service degradation where new users may be experiencing issues with calendar provisioning.Our team is actively working to identify the impact and root cause. We will provide an update as soon as more information becomes available.We appreciate your patience as we work to resolve this issue.
Zoom - Service Degradation Affecting Zoom Slides Generation in US Region
Oct 6, 19:08 PDT Investigating - We are currently investigating a service degradation affecting a subset of users who are experiencing difficulties with Zoom Slides Generation in US Region.Our team is actively working to identify the impact and root cause. We will provide an update as soon as more information becomes available.We appreciate your patience as we work to resolve this issue.
Netlify - Elevated error rates for AI Gateway
Oct 6, 20:12 UTC Resolved - Between 19:05 and 19:18 UTC, some requests to the AI Gateway returned errors. We've since increased the capacity of the affected service, and error rates returned to normal levels at 19:18 UTC. We apologize for the disruption.
GitHub - Several services are degraded
Oct 6, 19:57 UTC Investigating - We are investigating reports of degraded performance for Pull Requests and Webhooks
Rockstar Games has now been compromised several different ways since 2018, and none of them were a zero-day
Four incidents, four completely different initial access paths: 2022, Lapsus$: MFA fatigue against an employee, then hardcoded creds and API keys sitting in plaintext in Slack and Confluence. Early 2023, GTA Online: P2P netcode on PC reverse-engineered into RCE via malicious packets. The fix was kernel-level BattlEye. April 2026, ShinyHunters: no human identity involved. Long-lived OAuth tokens s...
Sentry - Sentry dashboard down
Oct 6, 18:57 UTC Investigating - We are investigating an issue impacting our dashboard in both US and EU regions
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. The products, which claim to offer campaign optimization, spend audits, and business-account connections, are designed with one goal in
Supabase - Upgrade Issues
Status: ResolvedWe've rolled out a fix for this issue and re-enabled upgrades in the dashboard. We apologize for the inconvenience.
Rippling - RPass Chrome extension login failures
Oct 6, 18:00 UTC Resolved - On October 6, some users were unable to sign in to the RPass Chrome extension. We reverted the change that caused the issue and confirmed sign-in was restored by 3:00 PM PDT.
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) - watchTowr Labs
submitted by /u/dx7r__ [link] [comments]
Optimizely - Data processing delays in EMEA
Oct 6, 17:00 UTC Resolved - We're seeing delays in processing incoming data in the EU region. Campaigns that depend on recent data may be delayed or may not send.A fix is in place and data processing is back to normal. We're watching to make sure it stays stable.
Vercel - Vercel Auth login failures for pages with Deployment Protection enabled
Oct 6, 16:26 UTC Resolved - This incident has been resolved. Oct 6, 16:17 UTC Monitoring - A fix has been implemented and we are monitoring the results. Oct 6, 16:14 UTC Identified - The issue has been identified and a fix is being implemented. Oct 6, 16:10 UTC Investigating - We are investigating an issue causing Vercel Auth login failures for pages with Deployment Protection enabled. We will provide an update as more information becomes available.
CircleCI - Delays in pipelines, workflows, UI data, and notifications
Oct 6, 16:00 UTC Investigating - What's impactedCustomers using CircleCI pipelines and workflows, including UI data display, outbound notifications, and outbound webhooks.What can you expectDelays in pipelines being created and in workflows and jobs starting. Job, workflow, and pipeline data may take up to 15 minutes to appear in the UI. Outbound notifications and webhooks are delayed by up to 1 minute.Next updateWe will provide another update within 30 minutes or as we have more information t...
Zoom - Zoom Chat Update: October 06, 2026 (No Operational Impact)
Oct 6, 09:00 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Sep 22, 20:08 PDT Scheduled - We will be providing an update to Zoom Chat Backend Service. There will be no operational impact. All services will be available during this scheduled update.
Snowflake - INC20000263
Oct 6, 15:57 UTC Resolved - Current status: We've coordinated with our third-party provider who implemented a fix for this issue, and we've monitored the environment to confirm that service was restored. If you experience additional issues or have questions, please open a support case via Snowflake Community or the Support page in Snowsight.Customer experience: Customers hosted in the specified regions may have seen pages that loaded indefinitely. Customers in other regions who connected from ...
Supabase - Upgrade Issues
Oct 6, 15:23 UTC Investigating - We have observed failures in attempted upgrades to 17.11.0.003. We are investigating.
Elastic Cloud - Delayed Serverless Metrics in Azure UAE North region
Oct 6, 14:04 UTC Investigating - Customers with Serverless projects in the Azure UAE North region may see delays in metrics displayed in Cloud UI. The team is investigating the issue and we will post an update in 2 hours or sooner if necessary
Loggly - Degraded Data Collection
Oct 6, 05:17 PDT Update - We are continuing to investigate this issue. Oct 6, 05:16 PDT Investigating - We are currently investigating an issue affecting log ingestion for a subset of customers. Customers using certain ingestion endpoints may experience delayed processing or failed ingestion of new log data. Services not utilizing the affected ingestion path remain operational. We will provide an update within the hour.
Supabase - Intermittent latency in Eastern US
Status: ResolvedA fix for this issue has been implemented and our data shows previous impacted users have recovered.
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies
The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The unauthorized bot activities included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and heavy traffic,
Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security, traced critical vulnerabilities in Anthropic's MCP
Vercel - Elevated Sandbox error rates in Paris (cdg1)
Oct 6, 09:36 UTC Resolved - This incident has been resolved. Oct 6, 09:31 UTC Monitoring - A fix has been implemented and we are monitoring the results. Oct 6, 09:27 UTC Update - We are seeing signs of recovery in Sandbox in Paris, France (cdg1). We will share updates as they become available. Oct 6, 09:12 UTC Identified - We've identified an issue where some customers may experience elevated error rates with Sandbox in Paris, France (cdg1). We are currently investigating this issue. ...
Supabase - Increased errors on management api leading to project operation failures
Status: ResolvedThis issue has been resolved and our error rates have returned back to normal. During this incident users would have observed unauthorized/5xx failures across multiple operations on the project operations and dashboard functions. We have since rolled out a fix and all functionality is restored.
Supabase - Increased errors on management api leading to project operation failures
Oct 6, 08:13 UTC Monitoring - We have identified a rollout causing error increase on management api dependant services, which is causing project operation failures and FGA Authentication errors across multiple functions. We have implementing a fix and observing recovery. Our teams are continuing to monitor for full resolution. Oct 6, 07:55 UTC Update - We are continuing to investigate this issue. Oct 6, 07:53 UTC Investigating - We are investigating an increase in errors on project updat...
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and
GitHub - Disruption with some GitHub services
Oct 5, 23:47 UTC Investigating - We are investigating reports of impacted performance for some GitHub services.
Zoom - Service Degradation Affecting ZoomMate
Oct 5, 14:57 PDT Investigating - We are currently investigating a service degradation with ZoomMate services.Our team is actively working to identify the impact and root cause. We will provide an update as soon as more information becomes available.We appreciate your patience as we work to resolve this issue.
GitHub - Incident with Actions
Oct 5, 19:50 UTC Update - We’re still investigating delays in assigning GitHub-hosted runners, affecting workflow start times across multiple runner configurations. Our teams are working to mitigate the impact; we’ll share another update as we learn more. Oct 5, 19:15 UTC Update - We’re investigating an issue causing delays when assigning GitHub-hosted runners to Actions jobs. Some workflows may take longer to start across runner configurations. Our teams are working to mitigate the issue, ...
Amplitude - Guides and Surveys Service Disruption
Oct 5, 11:56 PDT Resolved - Between 11:40 AM and 11:48 AM PT on October 5, 2026, Amplitude experienced a full outage of the Guides and Surveys service. During this time, users may have been unable to create, publish, or edit Guides and Surveys, or may have seen Guides and Surveys fail to load for end users.The issue has been resolved and Guides and Surveys is fully operational. We are continuing to confirm there was no data loss. No customer action is needed at this time.
Zoom - Zoom Phone Maintenance - NRT3 Data Center: October 5, 2026
Oct 5, 09:00 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Sep 15, 16:32 PDT Scheduled - Zoom will perform service maintenance at our NRT3 Data Center starting at 9:00 AM Pacific on October 5, 2026. Zoom Phone users registered to the those sip zones will be automatically registered in the KIX3 sip zone sequentially. During the maintenance window, a brief disconnection may be experienced and notifications may be missed. If you get di...
Netlify - Error accessing Netlify-hosted sites
Oct 5, 12:44 UTC Investigating - We are investigating reports of errors affecting access to sites on our High-Performance Edge Network. Our engineering team is actively investigating the issue.We will provide additional updates as more information becomes available.
Sumo Logic - Problem with Cloud SIEM Processing in North America 2 (US2)
Oct 5, 10:38 UTC Monitoring - We have implemented a fix for the issue affecting Cloud SIEM Processing. Log security records may take longer than normal to become searchable after processing. Users may not receive data when running queries or viewing dashboards that depend on recently collected data and alerts may not dispatch. Users may also experience delayed insights and signal generation on the affected security records. We are currently monitoring the results. Oct 5, 10:25 UTC Identifi...
DigitalOcean - VPC Networking Availability
Oct 5, 10:38 UTC Identified - Our Engineering team identified a disruption affecting VPC Networking operations that began at approximately 08:48 UTC. During this time, customers may have experienced delays or failures when creating or deleting VPC peerings, VPC Native DOKS clusters, or Private Network Connections (PNCs), as well as when adding cluster members. Creating routes and subnets may also have been affected.Operations are now returning to normal, and our Engineering team is monitoring ...
Zoom - Network Maintenance in SJC Datacenter: October 4, 2026
THIS IS A SCHEDULED EVENT Oct 4, 22:00 PDT - Oct 5, 02:00 PDT Aug 31, 09:06 PDT Scheduled - Zoom will perform service maintenance at SJC Datacenter. During the maintenance window, Users may experience an impact for a brief amount of time for services mentioned.
Zoom - Service Degradation Affecting Zoom Rooms Management and Workspaces Management in SA01.
Oct 4, 17:41 PDT Resolved - This incident has been resolved and the affected services have been restored. Oct 4, 17:00 PDT Monitoring - The issue affecting Zoom Rooms Management and Workspaces Management has been successfully resolved. Our team will continue to monitor the situation closely and keep you informed of any further developments. Oct 4, 16:50 PDT Identified - We have identified the service degradation with Zoom Rooms Management and Workspaces Management. Our team is actively w...
MAL-2026-17472: Anthropic Vulnerability
Malicious code in anthropic-sdk (PyPI)
AWS - Service is operating normally: [RESOLVED] Elevated packet loss
Between 8:48 AM and 11:28 AM PDT, we experienced elevated packet loss within a single Availability Zone (eus2-az1) in the EU-SOUTH-2 Region. This issue resulted in elevated API latencies and error rates for multiple workflows and AWS Services. We were automatically alerted to the issue at 8:54 AM, and immediately began work to identify the root cause while taking multiple parallel paths to mitigate the issue. By 10:00 AM, our mitigation efforts had led to some improvements. By 10:38 AM, we ident...
AWS - Service impact: Elevated packet loss
We are seeing early signs of recovery. We will provide you with another update by 12:00 PM PDT.
AWS - Service impact: Elevated packet loss
We have identified the root cause and are currently focusing our mitigation efforts to drive full recovery. While we don't have an exact estimate for how long our current efforts will take, we do expect to see incremental improvements as our efforts proceed. We will provide you with another update by 11:45 AM PDT, or sooner if new information becomes available.
AWS - Service impact: Elevated packet loss
Our efforts to mitigate the elevated packet loss with a single Availability Zone (eus2-az1) in the EU-SOUTH-2 Region is still underway. We are seeing some signs of improvement as a result of multiple parallel efforts. We continue to work to confirm root cause and fully mitigate the issue. While we currently do not have an estimate for how long our actions will take, we will keep you informed of our progress and provide you with another update by 11:00 AM PDT or sooner as new information becomes ...
AWS - Service impact: Elevated packet loss
We are experiencing elevated packet loss with a single Availability Zone (eus2-az1) in the EU-SOUTH-2 Region. This issue is also resulting in elevated API latencies and error rates for other workflows and AWS Services. Engineers were automatically engaged and are working to identify the root cause and to mitigate the issue. We will provide you with another update by 10:15 AM PDT or sooner as new information becomes available.
AWS - Service impact: Elevated packet loss
We are investigating elevated packet loss in the EU-SOUTH-2 Region.
U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog
submitted by /u/NISMO1968 [link] [comments]
ActiveCampaign - Planned Platform Maintenance
Oct 4, 05:00 CDT Completed - The scheduled maintenance has been completed. Oct 4, 04:00 CDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Sep 29, 11:09 CDT Scheduled - On October 4th, between 4:00 AM and 5:00 AM (Central Time), engineers will be performing maintenance to improve ActiveCampaign infrastructure.During this time, customers may be unable to log in or utilize the platform. Delays in processing of automations, campaign sendin...
Zoom - Service Degradation Affected Inbound and Outbound Calls of Zoom Phone and Contact Center in North America Region
Oct 4, 01:20 PDT Resolved - This incident has been resolved and the affected services have been restored. Oct 4, 01:05 PDT Monitoring - On 10/04/2026, Between 06:36 UTC to 07:30 UTC, A subset of users may have experienced issues with inbound and outbound calls of Zoom Phone and Contact Center in North America region.This incident has been resolved and the affected services have been restored.
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a
HashiCorp - HCP Vault Azure: Cluster Updates and Creation
Status: InvestigatingWe are aware of an issue affecting cluster updates and cluster creation on HCP Vault Dedicated Azure clusters. Our team is actively investigating. We will provide updates as more information becomes available.
Zoom - Service degradation affecting Developer Documentation Website
Oct 3, 09:49 PDT Investigating - We are currently investigating a service degradation affecting users ability to access documentation from Developer Documentation Website.Our team is actively working to identify the impact and root cause. We will provide an update as soon as more information becomes available.We appreciate your patience as we work to resolve this issue.
DigitalOcean - A Network Disruption in BLR1 Region Impacted Multiple Products (Resolved)
Oct 3, 14:51 UTC Resolved - From 11:59 UTC to 13:02 UTC on October 3, 2026, a networking disruption in our BLR1 region affected multiple products, including Monitoring, App Platform, Managed Databases, Functions, Load Balancers, Spaces, and the Cloud Control Panel. During this period, some users experienced degraded connectivity, increased latency, or intermittent errors when accessing resources in the region.Multiple network paths operated by our upstream connectivity providers were unavailab...
LaunchDarkly - Delays in Guarded Rollouts, Progressive Rollouts, Release Pipelines, and Experimentation
Oct 3, 02:06 PDT Resolved - This incident has been resolved. Oct 3, 01:51 PDT Monitoring - The backlog of delayed changes has been fully processed as of 1:45 AM PT on October 3. All changes that were delayed during the incident have been applied. No data was lost. We are continuing to monitor. Oct 3, 00:29 PDT Identified - Some automatic changes in LaunchDarkly are being applied later than expected. This affects stage transitions for guarded and progressive rollouts, release pipeline pha...
Zoom - Zoom Phone Maintenance - US East (IAD9 / IAD10) Data Center: October 2, 2026
THIS IS A SCHEDULED EVENT Oct 2, 17:00 PDT - Oct 4, 21:30 PDT Sep 10, 11:40 PDT Scheduled - Zoom will perform service maintenance at our US East (IAD9 / IAD10)) Data Center starting at 5:00 PM Pacific on October 2nd, 2026. Zoom Phone users registered to the those sip zones will be automatically registered in the other side sip zone sequentially. During the maintenance window, a brief disconnection may be experienced and notifications may be missed. If you get disconnected, the system will att...
Segment - Audience & Journey data delivery delay in EU region
Oct 2, 16:12 PDT Identified - We have identified an issue affecting a small portion of Audience & Journey delivery resulting in data delay.
HubSpot - HubSpot is experiencing issues
Oct 2, 17:58 EDT Update - We estimate that we will restore service in the next hour.We are mitigating impact from a server impairment which we believe is caused by a bad production configuration change. We are reverting the change.We will be back with an update within 30 minutes.The information on this page reflects our understanding of the incident and impact at the time of the update. Oct 2, 17:44 EDT Update - We estimate that we will restore service in the next several hours.We are mitig...
Heap - Salesforce integration: data-in not syncing
Oct 2, 14:57 PDT Update - We are continuing to work on a fix for this issue. Oct 2, 14:49 PDT Identified - Salesforce data isn't syncing into Heap, and new connections or reconnections are failing. We've identified the root cause and are working on a fix. Please don't try to reconnect until we post an update.Thank you for your patience!
Amplitude - Amplitude- Platform Loading Issues
Oct 2, 11:43 PDT Resolved - The issue has been resolved, and the platform is operating normally again.Our Engineering team will continue to monitor the platform closely to ensure everything remains stable.Thank you for your patience and understanding while we worked to resolve this issue. Oct 2, 11:36 PDT Update - We are continuing to investigate this issue. Oct 2, 11:35 PDT Investigating - Beginning at approximately 11:15 AM PT, we are currently investigating an issue affecting the Ampl...
CircleCI - Support tooling maintenance, Friday Oct 2, 2026
Oct 2, 17:45 UTC Completed - The scheduled maintenance has been completed. Oct 2, 17:06 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Oct 2, 17:05 UTC Scheduled - Maintenance is ongoing and we are working through it
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an
CircleCI - Support tooling maintenance, Friday Oct 2, 2026
THIS IS A SCHEDULED EVENT Oct 2, 15:00 - 17:00 UTC Sep 28, 20:53 UTC Scheduled - We'll be performing scheduled maintenance on our support tooling on Friday October 2nd starting 8am PDT to 10am PDT (2 hours). During this window, customers may briefly lose access to viewing ticket history in the support portal. No tickets or data will be lost — you can still reach us and follow up via email or chat as normal, and portal visibility will return once the maintenance concludes. If you have a browser ...
LaunchDarkly - Elevated error rates in the LaunchDarkly application
Oct 2, 07:10 PDT Identified - We're investigating elevated error rates affecting the LaunchDarkly web application and API. Some requests may fail or time out intermittently, including custom role management. We'll share an update as we learn more.