AI Security Digest
Aggregated ecosystem risk analysis
Vendor Watchlist
Tracking 0 critical integrations
Threat Stream Feed
Real-time security logs and system alerts
Amplitude - Amplitude- Platform Loading Issues
Oct 2, 11:43 PDT Resolved - The issue has been resolved, and the platform is operating normally again.Our Engineering team will continue to monitor the platform closely to ensure everything remains stable.Thank you for your patience and understanding while we worked to resolve this issue. Oct 2, 11:36 PDT Update - We are continuing to investigate this issue. Oct 2, 11:35 PDT Investigating - Beginning at approximately 11:15 AM PT, we are currently investigating an issue affecting the Ampl...
CircleCI - Support tooling maintenance, Friday Oct 2, 2026
Oct 2, 17:45 UTC Completed - The scheduled maintenance has been completed. Oct 2, 17:06 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Oct 2, 17:05 UTC Scheduled - Maintenance is ongoing and we are working through it
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an
CircleCI - Support tooling maintenance, Friday Oct 2, 2026
THIS IS A SCHEDULED EVENT Oct 2, 15:00 - 17:00 UTC Sep 28, 20:53 UTC Scheduled - We'll be performing scheduled maintenance on our support tooling on Friday October 2nd starting 8am PDT to 10am PDT (2 hours). During this window, customers may briefly lose access to viewing ticket history in the support portal. No tickets or data will be lost — you can still reach us and follow up via email or chat as normal, and portal visibility will return once the maintenance concludes. If you have a browser ...
LaunchDarkly - Elevated error rates in the LaunchDarkly application
Oct 2, 07:10 PDT Identified - We're investigating elevated error rates affecting the LaunchDarkly web application and API. Some requests may fail or time out intermittently, including custom role management. We'll share an update as we learn more.
Akamai - Edge Delivery Issues
Oct 2, 13:53 UTC Update - We are continuing to investigate this issue. Customers and partners can find more details on the Akamai Community: https://community.akamai.com/customers/s/feed/0D5a700001WrkrnCABWe will provide an update as we progress. Oct 2, 13:24 UTC Investigating - We are investigating an emerging issue with Edge Delivery related to Edge DNS report with record change on master DNS server not reflected to Akamai Edge DNS. We are actively investigating the issue and will provide...
Datadog - Delayed RUM sessions
Oct 2, 08:46 EDT Investigating - We are investigating increased latency processing RUM sessions.As a result of this issue, some users may see gaps or delays in RUM graphs as well as empty or partial query results on RUM Sessions, RUM Analytics, and RUM Application pages since Oct 2, 2026, 11:42 AM UTCTo prevent false monitor alerts due to delayed data, monitors affected by the delay will not notify and will automatically resume once current data is available. All other monitors will operate no...
OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying. "Our investigation confirmed that these
Twilio - SMS Delivery Delays from a Subset of Twilio Long Codes to Telenet BidCo NV Belgium
Oct 2, 03:46 PDT Identified - Twilio customers may be experiencing SMS delivery delays from a subset of Twilio Long Codes to Telenet BidCo NV network subscribers in Belgium. Our team has identified the cause, and is working to resolve the issue. We will provide another update in 1 hour or as soon as more information becomes available. Oct 2, 03:35 PDT Update - Twilio customers may be experiencing SMS delivery delays from a subset of Twilio Long Codes to Telenet BidCo NV network subscribers ...
SendGrid - SMS Delivery Delays from a Subset of Twilio Long Codes to Telenet BidCo NV Belgium
Oct 2, 03:46 PDT Identified - Twilio customers may be experiencing SMS delivery delays from a subset of Twilio Long Codes to Telenet BidCo NV network subscribers in Belgium. Our team has identified the cause, and is working to resolve the issue. We will provide another update in 1 hour or as soon as more information becomes available. Oct 2, 03:35 PDT Update - Twilio customers may be experiencing SMS delivery delays from a subset of Twilio Long Codes to Telenet BidCo NV network subscribers ...
Twilio - United States SMS Carrier Maintenance - AT&T
Oct 2, 01:00 PDT Completed - The scheduled maintenance has been completed. Oct 1, 21:00 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Sep 30, 04:41 PDT Scheduled - The AT&T network in the United States is conducting an emergency maintenance from 01 October 2026 at 21:00 PDT until 02 October 2026 at 01:00 PDT. During the maintenance window, there could be intermittent delays delivering SMS to and from AT&T United States handsets whe...
SendGrid - United States SMS Carrier Maintenance - AT&T
Oct 2, 01:00 PDT Completed - The scheduled maintenance has been completed. Oct 1, 21:00 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Sep 30, 04:41 PDT Scheduled - The AT&T network in the United States is conducting an emergency maintenance from 01 October 2026 at 21:00 PDT until 02 October 2026 at 01:00 PDT. During the maintenance window, there could be intermittent delays delivering SMS to and from AT&T United States handsets whe...
SendGrid - Silent Network Authentication (SNA) Failure Increase on AT&T in United States
Oct 1, 23:56 PDT Investigating - Twilio customers may be experiencing verification failures during API transactions for Silent Network Authentication (SNA) on AT&T in the United States. Our team is actively investigating the issue. API transactions may temporarily fail over to secondary methods like SMS OTP. We will provide another update in 1 hour or as soon as more information becomes available.
Twilio - Silent Network Authentication (SNA) Failure Increase on AT&T in United States
Oct 1, 23:56 PDT Investigating - Twilio customers may be experiencing verification failures during API transactions for Silent Network Authentication (SNA) on AT&T in the United States. Our team is actively investigating the issue. API transactions may temporarily fail over to secondary methods like SMS OTP. We will provide another update in 1 hour or as soon as more information becomes available.
Sumo Logic - Problem with Cloud SIEM Processing in North America 2 (US2)
Oct 2, 06:23 UTC Investigating - We are currently investigating reports of problems with Cloud SIEM Processing. Logs may take longer than normal to become searchable after processing. Users may not receive data when running queries or viewing dashboards that depend on recently collected data and alerts may not dispatch. We will provide more information soon.
SendGrid - SMS Delivery Delays from a Subset of Twilio Phone Numbers to Vodafone Netherlands
Oct 1, 22:59 PDT Update - Twilio customers may be experiencing SMS delivery delays from a subset of Twilio Phone Numbers to Vodafone network subscribers in the Netherlands. Our team has identified the cause, and is working to resolve the issue. We will provide another update in 2 hours or as soon as more information becomes available. Oct 1, 21:58 PDT Identified - Twilio customers may be experiencing SMS delivery delays from a subset of Twilio Phone Numbers to Vodafone network subscribers i...
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper
Twilio - SMS Delivery Delays from a Subset of Twilio Phone Numbers to Vodafone Netherlands
Oct 1, 21:58 PDT Identified - Twilio customers may be experiencing SMS delivery delays from a subset of Twilio Phone Numbers to Vodafone network subscribers in the Netherlands. Our team has identified the cause, and is working to resolve the issue. We will provide another update in 1 hour or as soon as more information becomes available. Oct 1, 21:42 PDT Investigating - Twilio customers may be experiencing SMS delivery delays from a subset of Twilio Phone Numbers to Vodafone network subscri...
MongoDB Atlas - MongoDB Charts: Infinite login loop when creating new Charts projects
Oct 2, 00:01 UTC Identified - Since approximately 23:30 UTC on 2026-10-01, users creating new Charts projects by clicking on the "Visualization" tab will repeatedly be prompted to login and will not be able to view the Charts interface. While these Charts projects will be created, we cannot guarantee the timing at this moment.Existing Charts projects are not affected.
Xero - Degraded Performance: US Payroll (Powered by Gusto)
Oct 1, 21:37 UTC Identified - We're aware that some US customers may experience slowness when using US Payroll in Xero due to an issue on Gusto's side. Gusto is currently investigating and working on a fix. We'll provide an update as soon as we can.
TV Box Sentinel v2.0: Open-source network monitoring and heuristic threat detection for compromised Android TV / IoT devices
Hey everyone, I wanted to share an open-source project I’ve been developing: TV Box Sentinel (v2.0). The Problem: A widespread issue with uncertified Android TV boxes (often powered by Allwinner, Rockchip, etc.) is factory-installed malware residing directly in the /system partition, as well as botnet loaders (such as Badbox, Peachpit, Triada, and Guerrilla). Since on-device antiviruses are untrus...
Zoom - Service Degradation Affected Incoming and Outgoing Calls of Zoom Contact Center, Virtual Agents, Mail, Calendar, Meetings, Cloud Meeting Recordings, Webinars and Events
Oct 1, 10:53 PDT Resolved - This incident has been resolved. Oct 1, 09:49 PDT Update - On 10/01/2026, Between 15:33 UTC to 15:37 UTC, a subset of users may have experienced service degradation affected incoming and outgoing calls of Zoom Contact Center, Virtual Agents, Mail, Calendar, Meetings, Cloud Meeting Recordings, Webinars and Events.This incident has been resolved and the affected services have been restored. Oct 1, 09:08 PDT Monitoring - On 10/01/2026, Between 15:33 UTC to 15:37 ...
MongoDB Atlas - Trigger processing may be delayed in AWS ap-southeast-2
Oct 1, 15:41 UTC Investigating - As of approximately 15:00 UTC, some users of MongoDB Atlas Triggers in AWS ap-southeast-2 may experience delayed unordered trigger processing. We are investigating and working to restore normal processing.
GitHub - Actions Job Delays
Oct 1, 14:54 UTC Update - We have identified the cause of increased Actions run start delays on Ubuntu runners and are actively deploying a fix. Customers may continue to experience intermittent delays while the mitigation rolls out and service metrics return to normal. Oct 1, 14:47 UTC Investigating - We are investigating reports of degraded performance for Actions
Sumo Logic - Problem with Cloud SIEM Processing in North America 2 (US2)
Oct 1, 14:04 UTC Resolved - We are no longer seeing issues with Cloud SIEM Processing and normal operation has been restored at this time. Oct 1, 13:55 UTC Identified - We have identified the source of the issue affecting Cloud SIEM Processing. Logs may take longer than normal to become searchable after processing. Users may not receive data when running queries or viewing dashboards that depend on recently collected data and alerts may not dispatch. We are working on a fix for the problem...
GitHub - Elevated request latency
Oct 1, 13:57 UTC Resolved - This incident has been resolved. Thank you for your patience and understanding as we addressed this issue. A detailed root cause analysis will be shared as soon as it is available. Oct 1, 13:51 UTC Monitoring - The degradation has been mitigated. We are monitoring to ensure stability. Oct 1, 13:39 UTC Update - We are investigating recurrent periods of elevated latency affecting web requests. We’ll share updates as more information becomes available. Oct 1, ...
Slack - Incident: Free Plan Customers Are Experiencing Message Failures
We identified that a third-party app is stuck in a loop that has triggered billions of messages. This is causing free plan users to exceed messaging limits. We apologize for the inconvenience and will provide another update as soon as we have more details to share.
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Securit...
Zoom - Service Degradation Affecting user’s integration of Zoom app in 3P Calendar Services
Oct 1, 04:52 PDT Investigating - We are currently investigating a service degradation affecting users ability to add Zoom app in 3P Calendar Services.Our team is actively working to identify the impact and root cause. We will provide an update as soon as more information becomes available.We appreciate your patience as we work to resolve this issue.
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A "core cluster of the activity," going back to the first week of July, has been attributed to individuals associated with Moonshot AI, a Chinese AI company based in Beijing. It did not cite any
Box - [Medium] Issue with File Requests
Oct 1, 03:00 PDT Resolved - From approximately 2:50 AM to 3:30 AM PDT on Oct 01, 2026, we observed an issue impacting File Requests. There is no current impact and no further updates will be provided here. If you continue to experience any issues, please contact Box Support at https://support.box.com.
CircleCI - Delays starting Gen 2 Docker Jobs
Oct 1, 09:47 UTC Identified - We have identified the root cause and we are actively working on a fix. Thank you for your patience. Oct 1, 09:06 UTC Investigating - Customers may experience delays in starting Docker Gen 2 Jobs. We are working to increase the throughput of the system to accomodate this.
Sumo Logic - Problem with Cloud SIEM Processing in North America 2 (US2)
Oct 1, 09:42 UTC Resolved - We are no longer seeing issues with Cloud SIEM Processing and normal operation has been restored at this time. Oct 1, 09:03 UTC Monitoring - We have implemented a fix for the issue affecting Cloud SIEM Processing. Log security records may take longer than normal to become searchable after processing. Users may not receive data when running queries or viewing dashboards that depend on recently collected data and alerts may not dispatch. Users may also experience d...
Wix - RESOLVED: Some Users Are Experiencing Issues With Multiple Services
Oct 1, 05:42 UTC Resolved - This incident has been resolved. Oct 1, 05:23 UTC Monitoring - Monitoring telemetry shows normal performance across all services. We are continuing to observe system metrics closely. Oct 1, 05:17 UTC Update - We are continuing to investigate this issue. Oct 1, 05:17 UTC Investigating - We are currently investigating this issue.
Confluence - Job processing and scheduling is degraded affecting multiple Atlassian products
Oct 1, 03:47 UTC Identified - Our teams have identified the root cause of this incident and is now actively working on mitigating the issue. We will provide further updates within an hour or sooner if we have any significant progress to share. Oct 1, 02:55 UTC Investigating - Job processing and job scheduling is degraded, which is affecting scheduled and asynchronous work across several products, including Jira, Confluence and Bitbucket Cloud.Affected users may see delayed or missing job ex...
Segment - Braze Web Event Delivery is experience event delivery issue
Sep 30, 20:30 PDT Investigating - The issue is reported by one customer. We are investigation this issue.
GitHub - [Retroactive] Actions workflow run failures after deployment gate approvals
Oct 1, 02:00 UTC Resolved - On October 1, around 02:00 UTC, an isolated infrastructure failure caused GitHub Actions to lose execution state for a small number of existing workflow runs. Affected runs may remain stuck, fail deployment approvals, or return errors when cancelled. Service connectivity has recovered, but the lost state cannot be restored by retrying an approval.If you're affected, you can trigger a new run or contact GitHub Support with links to your stuck runs so we can unblock t...
[CISA KEV] CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability
Product: FortiMail by Fortinet Description: Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Azure - Active - Multiple services experiencing connectivity issues in multiple regions
Starting at 20:30 UTC on 30 September 2026, customers using ExpressRoute and VPN Gateway may have experienced degraded or interrupted network connectivity. Customers may also experience failures or delays with some network management operations.Current status: ExpressRoute gateways are showing significant recovery as of 22:35 UTC, and we continue to monitor service health to validate that recovery is sustained. We have paused infrastructure servicing activity associated with the onset of this ev...
Azure - Active - ExpressRoute Gateway - Multiple services experiencing connectivity issues in multiple regions
Starting at 20:30 UTC on 30 September 2026, customers using ExpressRoute and/or Azure VPN Gateway may experience degraded or interrupted connectivity. We are also seeing impact to components responsible for managing network gateways, which may affect some management operations. Our investigation has identified a correlation between the onset of impact and infrastructure ‘operating system’ servicing activity. During this activity, some network gateway instances became unhealthy or temporarily una...
Cybersecurity statistics of the week (September 21st - September 27th)
Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here. All the reports and research below were published between September 21st - September 27th. You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/ Inside the SOC 2026 Creating a Mod...
Box - [Medium] Issue with User Engagement Reports
Sep 30, 11:53 PDT Update - Data recovery is progressing. User Engagement Reports and collaboration-related insights may continue to contain missing or outdated data while processing catches up. We are continuing to monitor recovery. Sep 30, 11:08 PDT Monitoring - We are monitoring an issue affecting User Engagement Reports and collaboration-related insights in the Admin Console. Some data may be missing or out of date. We have taken steps to restore data processing and are validating recovery...
MongoDB Atlas - Delays in Atlas cluster management operations
Sep 30, 18:51 UTC Investigating - We are investigating an issue with Atlas metrics ingestion that may delay cluster management operations, including cluster creation and modification.
Datadog - Delayed Events
Sep 30, 14:51 EDT Resolved - The issue is now resolved. Sep 30, 14:29 EDT Monitoring - We have deployed a mitigation and we are monitoring the results. Sep 30, 14:05 EDT Identified - We have identified the issue and are working on a mitigation strategy. Sep 30, 14:02 EDT Investigating - We are investigating increased latency processing Events generated by RUM, Trace Analytics, Service Checks, CI Visibility, Cloud Network Monitoring, and Error Tracking.As a result of this issue, some users...
Akamai - Akamai Control Center and Configuration Deployment Issues
Sep 30, 15:03 UTC Resolved - We became aware of an issue with Configuration Deployment and Akamai Control Center related to errors when activating delivery configurations in Property Manager and an inability to access Identity Manager in Akamai Control Center to manage users. The issue lasted between 14:13 UTC and 14:34 UTC on September 30, 2026. We can confirm that the issue is now resolved, and the service has resumed normal operation. Customers and partners can view additional details about ...
Asana - Partial API outage
Sep 30, 14:31 UTC Investigating - We are currently investigating this issue.
I taught my laptop to fake cyberattacks — and it's scarily good at it.
Meet log-generator: an open-source tool that spits out realistic SIEM logs so you can test your security stack without waiting for an actual breach to ruin your Friday. Just shipped a bunch of new toys: Attack Chains — replay full multi-stage attacks (recon → exploit → exfil), every step mapped to MITRE ATT&CK. Basically a "choose your own villain" adventure for your detection rules. Benchmark mo...
Optimizely - Optimizely Graph - All region's production clusters experienced failed stored queries
Sep 30, 13:57 UTC Monitoring - We have identified the root cause and applied a mitigation. The service has returned to normal operation and we are actively monitoring to confirm stability.
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released. In most cases, they sat under developers' personal accounts
I Want Better Reporting on AI Genie Behavior
AI systems are regularly completing tasks in ways that their prompters don’t want or intend. Some of them are disturbing, and some of them are dangerous. This is something I’ve been calling “genie behavior,” because I think that really gets at the core of what’s happening. I wish the popular press would report on this better. I don’t like the “going rogue” framing because it deflects the responsib...
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way
Zoom - Service Degradation Affecting Zoom Phone in the EU01 cluster.
Sep 29, 18:20 PDT Resolved - This incident has been resolved. Sep 29, 18:07 PDT Monitoring - On 09/29/2026 - 09/30/2026, Between 21:08 UTC to 00:44 UTC, A subset of users may have experienced issues with Zoom Phone in the EU01 cluster.This incident has been resolved and the affected services have been restored.
Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed
OpenBao engineers at ControlPlane have chained 4 vulnerabilities to show how under certain conditions, an OpenBao or Vault server can be completely compromised from an unauthenticated position. This is only the second RCE ever found in the Vault codebase. The exploit is highly plausible in real-world environments, requiring only an unauthenticated entry path and a defined Raft snapshot policy to t...
Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed
OpenBao engineers at ControlPlane have chained 4 vulnerabilities to show how under certain conditions, an OpenBao or Vault server can be completely compromised from an unauthenticated position. This is only the second RCE ever found in the Vault codebase. The exploit is highly plausible in real-world environments, requiring only an unauthenticated entry path and a defined Raft snapshot polic...
Xero - Degraded Performance: US Payroll (Powered by Gusto)
Sep 29, 20:57 UTC Identified - We're aware that some customers may experience errors when accessing Jobs and Contractors using US Payroll in Xero due to an issue on Gusto's side. Gusto have identified the cause and currently working on a fix.
Akamai - Akamai Control Center and Configuration Deployment Issues
Sep 29, 20:48 UTC Update - We are continuing to investigate the issue. We identified another issue in Identity Management where customers can't access to manage their users in Akamai Control Center. Customers and partners can find more details on the Akamai Community: https://community.akamai.com/customers/s/feed/0D5a700001WM3dyCAD. We will provide an update within the next 60 minutes. Sep 29, 20:28 UTC Investigating - We are investigating an emerging issue with Configuration Deployment relat...
Rippling - Rippling app is down
Sep 29, 19:51 UTC Update - The Rippling app is fully operational again. We are continuing to investigate the root cause of the database overload. Sep 29, 19:28 UTC Update - We observed an overload in utilization of our authentication database. Access to Rippling has started to recover but there may be some degraded performance. Sep 29, 19:20 UTC Investigating - We are investigating issues where the Rippling app is not loading. We will provide an update within the next 10 minutes.
Supabase - Intermittent latency in Eastern US
Sep 29, 16:26 UTC Identified - We have identified an issue with increased latency for clients in the eastern US during spikes caused by bursty traffic. This is most noticeable during EDT working hours around the :00 and :30 hour marks.We are actively working on a fix. We will provide updates as the fix is implemented.
GCP - RESOLVED: Multiple products in us-central1-b are experiencing network service degradation.
Incident began at 2026-09-01 07:44 and ended at 2026-09-01 11:52 (all times are US/Pacific).Addendum to Incident Report This addendum extends the Detailed Description of Impact from the previous message. Though only two clusters in a datacenter in us-central1-b and us-central1-f experienced network isolation, a few regional products with a dependency on the affected datacenter were also affected. Between 07:41 and 11:52 US/Pacific on Tuesday, September 1, 2026, the following products were affec...
Box - [Critical] Issues with All Files Page, Box Notes, API calls, logins and downloads
Sep 29, 08:30 PDT Resolved - From approximately 06.39 AM to 06:44 AM US Pacific time, we observed an issue impacting All Files Page, Box Notes, API calls, logins and downloads. Our systems automatically detected and corrected the underlying issue. There is no current impact and no further updates will be provided here. If you continue to experience any issues, please contact Box Support at https://support.box.com.
Xero - UK: HMRC connected services
Sep 29, 13:33 UTC Investigating - HMRC have let us know they're having an issue with their services. We have confirmed that this is impacting MTD IT and MTD VAT but may be impacting other services too. We will update as we receive more information from HMRC.
Asana - Partial API outage in EU
Sep 29, 12:14 UTC Investigating - We are currently investigating the issue.
Lantronix G520 Series Cellular Gateway
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges. The following versions of Lantronix G520 Series Cellular Gateway are affected: G520 Series 2.6.0.4R6_stable (CVE-2026-84409, CVE-2026-91191) CVSS Vendor Equipment Vulnerabilities v3 7.5 Lantronix Lantronix G520 Series Cellular Gat...
Azure - Observing improvements - Intermittent request failures and increased latency across Azure OpenAI, Azure AI Foundry, and Cognitive Services
Impact Statement: Starting at 10:00 UTC on 29 September 2026, a subset of customers using OpenAI Service, Foundry Agent Service, Foundry Models, and Cognitive Services, in Sweden Central may experience intermittent request failures, increased latency, and HTTP 5XX error codes when submitting requests to affected models and APIs hosted in this region.Current Status:Currently we are monitoring improvements in the overall experience. Initial findings indicate that a backend service which is relied ...
Azure - Azure OpenAI and Foundry agent Service intermittent request failures and increased latency
We are investigating an issue affecting Azure OpenAI and Foundry agent services in the Sweden Central region. Impacted customers may experience intermittent errors when making service requests.We are investigating the underlying issue and exploring mitigation options to restore normal service performance. Our analysis remains ongoing, and we are closely monitoring service health while continuing our investigation.We will provide additional information as it becomes available.
Azure - Intermittent request failures and increased latency across Azure OpenAI, Azure AI Foundry, and Cognitive Services
We are investigating an issue affecting Azure OpenAI Service, Azure AI Foundry Agent Service, Azure AI Foundry Models, and Azure AI Cognitive Services in the Sweden Central region. Impacted customers may experience intermittent request failures, increased latency and HTTP 5XX error codes when making service requests.We are investigating the underlying issue and exploring mitigation options to restore normal service performance. Our analysis remains ongoing, and we are closely monitoring service ...
Policy-enforced egress in AI agent sandboxes: an empirical evaluation of NVIDIA OpenShell v0.1.2 (123 trials, pre-registered, logs public)
Short version: no bypass of a documented control across 35 test IDs. Default policy took a malicious-setup-script canary leak from 10/10 to 0/10 with a local agent. Egress still happened through operator-opened paths: read-write rules, query and header values on GET-only rules, audit-mode rules, and auto-approval, which granted new public hosts in 12/12 trials. The prover flags GraphQL/MCP/WebSoc...
Netlify - Error accessing Netlify-hosted sites
Sep 29, 08:46 UTC Resolved - This incident has been resolved. Sites on the High-Performance Edge have returned to normal operation, and we are no longer seeing elevated error rates.
Zoom - Announcing Updated IP Address Ranges: September 28, 2026 (No Operational Impact)
Sep 28, 23:59 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Aug 28, 09:59 PDT Scheduled - The published IP range for Zoom Meeting and Zoom Phone services has been updated from 192.204.12.0/22 to 192.204.12.0/23. We recommend that network administrators, with Zoom-specific firewall or network rules, update their systems as soon as possible in preparation.Mask change for Zoom Phone and Zoom Meetings service:192.204.12.0/22 changed to 192...
OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions
OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal safety and alignment audits. The development was first reported by The Wall Street Journal. The move "marks a rare case of a major AI developer ditching a new release because of safety concerns," the news publication said.
OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions. "An agent attempting to complete a search-based training task queried a public chatbot service through a gap in our internet-access restrictions:
Zoom - Service Degradation Affecting Zoom Canvas
Sep 28, 15:15 PDT Investigating - We are currently investigating a service degradation with Zoom Canvas.Our team is actively working to identify the impact and root cause. We will provide an update as soon as more information becomes available.We appreciate your patience as we work to resolve this issue.
GitHub - Copilot Code Review is unable to complete reviews
Sep 28, 21:23 UTC Update - Revert of the impacted change is in flight, expect full recovery once the deployment is done. Sep 28, 21:16 UTC Investigating - We are investigating reports of impacted performance for some GitHub services.
Amplitude - We are actively investigating an incident in our data exports
Sep 28, 14:09 PDT Update - We are continuing to investigate this issue. Sep 28, 14:09 PDT Investigating - We are actively investigating an incident in our data exports. Once the issue is resolved, data will continue to be exported. No data is lost.
Xero - US: Payroll (Powered by Gusto) - customers will be unable to access US Payroll in Xero
Sep 28, 20:32 UTC Identified - We're aware that customers are currently unable to access US Payroll in Xero, due to an issue on Gusto's side. Our Product Team is working with Gusto to restore service. This is our top priority and we will update you as soon as we can.
Akamai - Edge Delivery issues in Canada
Sep 28, 18:48 UTC Update - We are continuing to investigate this issue. Customers and partners can find more details on the Akamai Community: https://community.akamai.com/customers/s/feed/0D5a700001W3hnvCABWe will provide an update as we progress. Sep 28, 16:41 UTC Update - We are continuing to investigate this issue. Customers and partners can find more details on the Akamai Community: https://community.akamai.com/customers/s/feed/0D5a700001W3hnvCABWe will provide an update as we progress. ...
Zoom - Zoom Phone Maintenance - EU01 - AMS2 Data Center: September 28, 2026
Sep 28, 09:00 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Sep 10, 13:43 PDT Scheduled - Zoom will perform service maintenance at our EU01-AMS2 Data Center starting at 9:00 AM Pacific on September 28, 2026. Zoom Phone users registered to the those sip zones will be automatically registered in the EU01-FRA2 sip zone sequentially. During the maintenance window, a brief disconnection may be experienced and notifications may be missed. If...
ActiveCampaign - Transactional Email Failures
Sep 28, 10:30 CDT Update - The backlogged messages are rapidly catching up. We expect full resolution within 20 minutes. Sep 28, 10:22 CDT Monitoring - A fix has been implemented and we are monitoring the results. Sep 28, 10:16 CDT Identified - The issue has been identified and the backlogged messages have started to send. Engineering is working to expedite the catch up. Sep 28, 10:05 CDT Investigating - Transactional email is currently failing to send. Engineering is investigating the ro...
Supabase - Log Ingestion Degradation
Sep 28, 14:00 UTC Monitoring - Log ingestion has recovered. We are monitoring for continued stability. Sep 28, 13:52 UTC Identified - The log ingestion issue was the result of a scaling gap. The relevant resources have been scaled and ingestion is recovering. Sep 28, 13:47 UTC Investigating - Log ingestion is experiencing some delays. Ingestion will be retried by clients.
Vercel - Build failures and 500 errors for functions using Edge runtime
Sep 28, 13:44 UTC Monitoring - A small number of customers who built or deployed functions using Edge runtime between 13:01 and 13:11 UTC experienced elevated rates of build failures due to unexpected error. Some builds succeeded but resulted in 500 errors from functions using Edge runtime. Re-deploy functions using Edge runtime to accelerate remediation.
Squarespace - Squarespace loading and editing Issues
Sep 28, 09:50 EDT Monitoring - A fix has been implemented and we are monitoring the results. Sep 28, 09:35 EDT Update - We are continuing to work on a fix for this issue. Sep 28, 09:17 EDT Identified - We are currently investigating issues across Squarespace, specifically regarding access to the Email Campaigns panel as well as applying and accessing certain premium features.
Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI
AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across business systems—often without the same controls applied to human users. According to Okta’s Global CISO Insights 2026 report, only 47% of CISOs are confident they can identify every AI agent in their environment. Even among those who feel
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through
Box - [Medium] Issues with Box Notes
Sep 28, 03:31 PDT Resolved - After further monitoring, this incident is now considered resolved. The Box Note service has been restored to full functionality. If you continue to experience any issues, please contact Box Support at https://support.box.com. Sep 28, 03:04 PDT Investigating - Our team is investigating an issue with Box Notes. Users may see errors or slowness when creating or updating Box Notes. We will provide additional information as it becomes available.
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations
Zoom - Network Maintenance in SJC Datacenter: September 27, 2026
Sep 27, 22:00 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Aug 31, 00:47 PDT Scheduled - Zoom will perform service maintenance at SJC Datacenter. During the maintenance window, Users may experience an impact for a brief amount of time for services mentioned.
Zoom - Scheduled Update to Prompt Track Versions for Zoom Clients: September 27, 2026 (No Operational Impact)
THIS IS A SCHEDULED EVENT Sep 27, 18:00 - 21:00 PDT Sep 17, 16:40 PDT Scheduled - Zoom will be updating the Prompt track versions for Zoom clients on 9/27/2026.Slow channel updates:Windows: 7.1.9macOS: 7.1.9Linux: 7.1.9For more information, such as specific versions, please refer to the Zoom Minimum, Prompted, and Slow/Fast Update Versions support article: https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0061900
Xero - ATO services may be unavailable
Sep 28, 00:28 UTC Resolved - The ATO has resolved their issue impacting customers trying to file tax returns from Xero. Sep 28, 00:18 UTC Monitoring - The ATO has implemented a fix and we are currently monitoring the results. Sep 28, 00:03 UTC Identified - Our team are aware of an issue with the ATO where customers cannot file tax returns or STP filings. We are monitoring the outage and will work to keep you update as the ATO works to resolve the issue.
Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
Update October 2, 2026: CISA has updated this Alert to provide a SIGMA detection rule resource to help identify potentially suspicious activity. CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and C...
Xero - Xero Scheduled maintenance - Xero Ask Service, Xero Signing, Document Packs and the Practice Chart of Accounts Library
Sep 27, 07:00 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Sep 24, 20:07 UTC Update - We will be undergoing scheduled maintenance during this time. Sep 24, 11:30 UTC Scheduled - We're carrying out scheduled maintenance on Sunday 27 September 2026 from 7.00pm to 8.00pm NZDT. During this window, the following features may be temporarily unavailable:- Sending or signing documents using Xero Sign- Sending or replying to queries in Ask-...
Snowflake - INC20000239
Sep 27, 02:15 UTC Monitoring - Current status: We identified an issue with our third-party cloud platform that caused impact to Snowflake services. We've coordinated with our third-party cloud platform to implement the fix for this issue, and we'll continue to monitor the environment until we're confident all services are functioning properly.Customer experience: Customers hosted in the specified regions may have been unable to access or use multiple core Snowflake services and features. Affect...
Sumo Logic - Problem with Tracing Collection in North America 2 (US2)
Sep 27, 01:34 UTC Monitoring - We have implemented a fix for the issue affecting Tracing Collection. We are currently monitoring the results. Sep 27, 01:22 UTC Investigating - We are currently investigating reports of problems with Tracing Collection. Trace data sent may fail to ingest or be rejected due to service unavailability. We will provide more information soon.
Figma - Service disruption
Sep 27, 01:18 UTC Monitoring - Figma should now be operational. We are continuing to monitor. Sep 27, 01:04 UTC Investigating - We are currently investigating an issue where Figma Services are degraded or unavailable because of failures with AWS and other dependencies.
Revealing the details of how OpenAI agents hacked Hugging Face
GET-only egress to full code execution: chaining a URL mirror and a screenshot service submitted by /u/NOTHING_gets_by_me [link] [comments]
Xero - Global : Xero apps unavailable on Apple App Store
Sep 26, 23:28 UTC Identified - We're aware that the Apple App Store listings for the Xero apps Xero Accounting, Xero Me, Xero Projects, Xero Verify and Hubdoc apps are not currently accessible. We have taken action to resolve this and are in contact with Apple.Existing installations of these apps are unaffected. We apologise for any inconvenience caused.
Looking for an independent security firm to review a small SaaS security product before wider launch. Recommendations?
Small business, about 20 corporate users currently in a private pilot, live billing not yet enabled. There's no revenue yet to pay one of those big firms thousands of dollars to rubberstamp it, but we have used multiple AI security evaluation tools like Akido in the free tier to cross our t's and dot our i's. The SaaS in question is a security-focused platform designed to monitor the lifecycle of ...
I’ve been building my own Red Team tooling here’s what I’ve learned so far
I’ve been spending a lot of time building security tooling for my own research and authorized testing rather than relying entirely on existing frameworks. A few of the problems I kept running into were surprisingly simple: Recon gets repetitive. You end up running the same discovery, probing, fingerprinting and enumeration workflows over and over. Tooling becomes fragmented. One tool handles recon...
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and