AI Security Digest
Aggregated ecosystem risk analysis
Vendor Watchlist
Tracking 0 critical integrations
Threat Stream Feed
Real-time security logs and system alerts
Box - [Medium] Issue with User Engagement Reports
Sep 30, 11:53 PDT Update - Data recovery is progressing. User Engagement Reports and collaboration-related insights may continue to contain missing or outdated data while processing catches up. We are continuing to monitor recovery. Sep 30, 11:08 PDT Monitoring - We are monitoring an issue affecting User Engagement Reports and collaboration-related insights in the Admin Console. Some data may be missing or out of date. We have taken steps to restore data processing and are validating recovery...
MongoDB Atlas - Delays in Atlas cluster management operations
Sep 30, 18:51 UTC Investigating - We are investigating an issue with Atlas metrics ingestion that may delay cluster management operations, including cluster creation and modification.
Datadog - Delayed Events
Sep 30, 14:51 EDT Resolved - The issue is now resolved. Sep 30, 14:29 EDT Monitoring - We have deployed a mitigation and we are monitoring the results. Sep 30, 14:05 EDT Identified - We have identified the issue and are working on a mitigation strategy. Sep 30, 14:02 EDT Investigating - We are investigating increased latency processing Events generated by RUM, Trace Analytics, Service Checks, CI Visibility, Cloud Network Monitoring, and Error Tracking.As a result of this issue, some users...
Akamai - Akamai Control Center and Configuration Deployment Issues
Sep 30, 15:03 UTC Resolved - We became aware of an issue with Configuration Deployment and Akamai Control Center related to errors when activating delivery configurations in Property Manager and an inability to access Identity Manager in Akamai Control Center to manage users. The issue lasted between 14:13 UTC and 14:34 UTC on September 30, 2026. We can confirm that the issue is now resolved, and the service has resumed normal operation. Customers and partners can view additional details about ...
Asana - Partial API outage
Sep 30, 14:31 UTC Investigating - We are currently investigating this issue.
I taught my laptop to fake cyberattacks — and it's scarily good at it.
Meet log-generator: an open-source tool that spits out realistic SIEM logs so you can test your security stack without waiting for an actual breach to ruin your Friday. Just shipped a bunch of new toys: Attack Chains — replay full multi-stage attacks (recon → exploit → exfil), every step mapped to MITRE ATT&CK. Basically a "choose your own villain" adventure for your detection rules. Benchmark mo...
Optimizely - Optimizely Graph - All region's production clusters experienced failed stored queries
Sep 30, 13:57 UTC Monitoring - We have identified the root cause and applied a mitigation. The service has returned to normal operation and we are actively monitoring to confirm stability.
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released. In most cases, they sat under developers' personal accounts
I Want Better Reporting on AI Genie Behavior
AI systems are regularly completing tasks in ways that their prompters don’t want or intend. Some of them are disturbing, and some of them are dangerous. This is something I’ve been calling “genie behavior,” because I think that really gets at the core of what’s happening. I wish the popular press would report on this better. I don’t like the “going rogue” framing because it deflects the responsib...
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way
Zoom - Service Degradation Affecting Zoom Phone in the EU01 cluster.
Sep 29, 18:20 PDT Resolved - This incident has been resolved. Sep 29, 18:07 PDT Monitoring - On 09/29/2026 - 09/30/2026, Between 21:08 UTC to 00:44 UTC, A subset of users may have experienced issues with Zoom Phone in the EU01 cluster.This incident has been resolved and the affected services have been restored.
Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed
OpenBao engineers at ControlPlane have chained 4 vulnerabilities to show how under certain conditions, an OpenBao or Vault server can be completely compromised from an unauthenticated position. This is only the second RCE ever found in the Vault codebase. The exploit is highly plausible in real-world environments, requiring only an unauthenticated entry path and a defined Raft snapshot policy to t...
Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed
OpenBao engineers at ControlPlane have chained 4 vulnerabilities to show how under certain conditions, an OpenBao or Vault server can be completely compromised from an unauthenticated position. This is only the second RCE ever found in the Vault codebase. The exploit is highly plausible in real-world environments, requiring only an unauthenticated entry path and a defined Raft snapshot polic...
Xero - Degraded Performance: US Payroll (Powered by Gusto)
Sep 29, 20:57 UTC Identified - We're aware that some customers may experience errors when accessing Jobs and Contractors using US Payroll in Xero due to an issue on Gusto's side. Gusto have identified the cause and currently working on a fix.
Akamai - Akamai Control Center and Configuration Deployment Issues
Sep 29, 20:48 UTC Update - We are continuing to investigate the issue. We identified another issue in Identity Management where customers can't access to manage their users in Akamai Control Center. Customers and partners can find more details on the Akamai Community: https://community.akamai.com/customers/s/feed/0D5a700001WM3dyCAD. We will provide an update within the next 60 minutes. Sep 29, 20:28 UTC Investigating - We are investigating an emerging issue with Configuration Deployment relat...
Rippling - Rippling app is down
Sep 29, 19:51 UTC Update - The Rippling app is fully operational again. We are continuing to investigate the root cause of the database overload. Sep 29, 19:28 UTC Update - We observed an overload in utilization of our authentication database. Access to Rippling has started to recover but there may be some degraded performance. Sep 29, 19:20 UTC Investigating - We are investigating issues where the Rippling app is not loading. We will provide an update within the next 10 minutes.
Supabase - Intermittent latency in Eastern US
Sep 29, 16:26 UTC Identified - We have identified an issue with increased latency for clients in the eastern US during spikes caused by bursty traffic. This is most noticeable during EDT working hours around the :00 and :30 hour marks.We are actively working on a fix. We will provide updates as the fix is implemented.
GCP - RESOLVED: Multiple products in us-central1-b are experiencing network service degradation.
Incident began at 2026-09-01 07:44 and ended at 2026-09-01 11:52 (all times are US/Pacific).Addendum to Incident Report This addendum extends the Detailed Description of Impact from the previous message. Though only two clusters in a datacenter in us-central1-b and us-central1-f experienced network isolation, a few regional products with a dependency on the affected datacenter were also affected. Between 07:41 and 11:52 US/Pacific on Tuesday, September 1, 2026, the following products were affec...
Box - [Critical] Issues with All Files Page, Box Notes, API calls, logins and downloads
Sep 29, 08:30 PDT Resolved - From approximately 06.39 AM to 06:44 AM US Pacific time, we observed an issue impacting All Files Page, Box Notes, API calls, logins and downloads. Our systems automatically detected and corrected the underlying issue. There is no current impact and no further updates will be provided here. If you continue to experience any issues, please contact Box Support at https://support.box.com.
Xero - UK: HMRC connected services
Sep 29, 13:33 UTC Investigating - HMRC have let us know they're having an issue with their services. We have confirmed that this is impacting MTD IT and MTD VAT but may be impacting other services too. We will update as we receive more information from HMRC.
Asana - Partial API outage in EU
Sep 29, 12:14 UTC Investigating - We are currently investigating the issue.
Lantronix G520 Series Cellular Gateway
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges. The following versions of Lantronix G520 Series Cellular Gateway are affected: G520 Series 2.6.0.4R6_stable (CVE-2026-84409, CVE-2026-91191) CVSS Vendor Equipment Vulnerabilities v3 7.5 Lantronix Lantronix G520 Series Cellular Gat...
Azure - Observing improvements - Intermittent request failures and increased latency across Azure OpenAI, Azure AI Foundry, and Cognitive Services
Impact Statement: Starting at 10:00 UTC on 29 September 2026, a subset of customers using OpenAI Service, Foundry Agent Service, Foundry Models, and Cognitive Services, in Sweden Central may experience intermittent request failures, increased latency, and HTTP 5XX error codes when submitting requests to affected models and APIs hosted in this region.Current Status:Currently we are monitoring improvements in the overall experience. Initial findings indicate that a backend service which is relied ...
Azure - Intermittent request failures and increased latency across Azure OpenAI, Azure AI Foundry, and Cognitive Services
We are investigating an issue affecting Azure OpenAI Service, Azure AI Foundry Agent Service, Azure AI Foundry Models, and Azure AI Cognitive Services in the Sweden Central region. Impacted customers may experience intermittent request failures, increased latency and HTTP 5XX error codes when making service requests.We are investigating the underlying issue and exploring mitigation options to restore normal service performance. Our analysis remains ongoing, and we are closely monitoring service ...
Azure - Azure OpenAI and Foundry agent Service intermittent request failures and increased latency
We are investigating an issue affecting Azure OpenAI and Foundry agent services in the Sweden Central region. Impacted customers may experience intermittent errors when making service requests.We are investigating the underlying issue and exploring mitigation options to restore normal service performance. Our analysis remains ongoing, and we are closely monitoring service health while continuing our investigation.We will provide additional information as it becomes available.
Policy-enforced egress in AI agent sandboxes: an empirical evaluation of NVIDIA OpenShell v0.1.2 (123 trials, pre-registered, logs public)
Short version: no bypass of a documented control across 35 test IDs. Default policy took a malicious-setup-script canary leak from 10/10 to 0/10 with a local agent. Egress still happened through operator-opened paths: read-write rules, query and header values on GET-only rules, audit-mode rules, and auto-approval, which granted new public hosts in 12/12 trials. The prover flags GraphQL/MCP/WebSoc...
Netlify - Error accessing Netlify-hosted sites
Sep 29, 08:46 UTC Resolved - This incident has been resolved. Sites on the High-Performance Edge have returned to normal operation, and we are no longer seeing elevated error rates.
Zoom - Announcing Updated IP Address Ranges: September 28, 2026 (No Operational Impact)
Sep 28, 23:59 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Aug 28, 09:59 PDT Scheduled - The published IP range for Zoom Meeting and Zoom Phone services has been updated from 192.204.12.0/22 to 192.204.12.0/23. We recommend that network administrators, with Zoom-specific firewall or network rules, update their systems as soon as possible in preparation.Mask change for Zoom Phone and Zoom Meetings service:192.204.12.0/22 changed to 192...
OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions
OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal safety and alignment audits. The development was first reported by The Wall Street Journal. The move "marks a rare case of a major AI developer ditching a new release because of safety concerns," the news publication said.
OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions. "An agent attempting to complete a search-based training task queried a public chatbot service through a gap in our internet-access restrictions:
Zoom - Service Degradation Affecting Zoom Canvas
Sep 28, 15:15 PDT Investigating - We are currently investigating a service degradation with Zoom Canvas.Our team is actively working to identify the impact and root cause. We will provide an update as soon as more information becomes available.We appreciate your patience as we work to resolve this issue.
GitHub - Copilot Code Review is unable to complete reviews
Sep 28, 21:23 UTC Update - Revert of the impacted change is in flight, expect full recovery once the deployment is done. Sep 28, 21:16 UTC Investigating - We are investigating reports of impacted performance for some GitHub services.
Amplitude - We are actively investigating an incident in our data exports
Sep 28, 14:09 PDT Update - We are continuing to investigate this issue. Sep 28, 14:09 PDT Investigating - We are actively investigating an incident in our data exports. Once the issue is resolved, data will continue to be exported. No data is lost.
Xero - US: Payroll (Powered by Gusto) - customers will be unable to access US Payroll in Xero
Sep 28, 20:32 UTC Identified - We're aware that customers are currently unable to access US Payroll in Xero, due to an issue on Gusto's side. Our Product Team is working with Gusto to restore service. This is our top priority and we will update you as soon as we can.
Akamai - Edge Delivery issues in Canada
Sep 28, 18:48 UTC Update - We are continuing to investigate this issue. Customers and partners can find more details on the Akamai Community: https://community.akamai.com/customers/s/feed/0D5a700001W3hnvCABWe will provide an update as we progress. Sep 28, 16:41 UTC Update - We are continuing to investigate this issue. Customers and partners can find more details on the Akamai Community: https://community.akamai.com/customers/s/feed/0D5a700001W3hnvCABWe will provide an update as we progress. ...
Zoom - Zoom Phone Maintenance - EU01 - AMS2 Data Center: September 28, 2026
Sep 28, 09:00 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Sep 10, 13:43 PDT Scheduled - Zoom will perform service maintenance at our EU01-AMS2 Data Center starting at 9:00 AM Pacific on September 28, 2026. Zoom Phone users registered to the those sip zones will be automatically registered in the EU01-FRA2 sip zone sequentially. During the maintenance window, a brief disconnection may be experienced and notifications may be missed. If...
ActiveCampaign - Transactional Email Failures
Sep 28, 10:30 CDT Update - The backlogged messages are rapidly catching up. We expect full resolution within 20 minutes. Sep 28, 10:22 CDT Monitoring - A fix has been implemented and we are monitoring the results. Sep 28, 10:16 CDT Identified - The issue has been identified and the backlogged messages have started to send. Engineering is working to expedite the catch up. Sep 28, 10:05 CDT Investigating - Transactional email is currently failing to send. Engineering is investigating the ro...
Supabase - Log Ingestion Degradation
Sep 28, 14:00 UTC Monitoring - Log ingestion has recovered. We are monitoring for continued stability. Sep 28, 13:52 UTC Identified - The log ingestion issue was the result of a scaling gap. The relevant resources have been scaled and ingestion is recovering. Sep 28, 13:47 UTC Investigating - Log ingestion is experiencing some delays. Ingestion will be retried by clients.
Vercel - Build failures and 500 errors for functions using Edge runtime
Sep 28, 13:44 UTC Monitoring - A small number of customers who built or deployed functions using Edge runtime between 13:01 and 13:11 UTC experienced elevated rates of build failures due to unexpected error. Some builds succeeded but resulted in 500 errors from functions using Edge runtime. Re-deploy functions using Edge runtime to accelerate remediation.
Squarespace - Squarespace loading and editing Issues
Sep 28, 09:50 EDT Monitoring - A fix has been implemented and we are monitoring the results. Sep 28, 09:35 EDT Update - We are continuing to work on a fix for this issue. Sep 28, 09:17 EDT Identified - We are currently investigating issues across Squarespace, specifically regarding access to the Email Campaigns panel as well as applying and accessing certain premium features.
Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI
AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across business systems—often without the same controls applied to human users. According to Okta’s Global CISO Insights 2026 report, only 47% of CISOs are confident they can identify every AI agent in their environment. Even among those who feel
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through
Box - [Medium] Issues with Box Notes
Sep 28, 03:31 PDT Resolved - After further monitoring, this incident is now considered resolved. The Box Note service has been restored to full functionality. If you continue to experience any issues, please contact Box Support at https://support.box.com. Sep 28, 03:04 PDT Investigating - Our team is investigating an issue with Box Notes. Users may see errors or slowness when creating or updating Box Notes. We will provide additional information as it becomes available.
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations
Zoom - Network Maintenance in SJC Datacenter: September 27, 2026
Sep 27, 22:00 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Aug 31, 00:47 PDT Scheduled - Zoom will perform service maintenance at SJC Datacenter. During the maintenance window, Users may experience an impact for a brief amount of time for services mentioned.
Zoom - Scheduled Update to Prompt Track Versions for Zoom Clients: September 27, 2026 (No Operational Impact)
THIS IS A SCHEDULED EVENT Sep 27, 18:00 - 21:00 PDT Sep 17, 16:40 PDT Scheduled - Zoom will be updating the Prompt track versions for Zoom clients on 9/27/2026.Slow channel updates:Windows: 7.1.9macOS: 7.1.9Linux: 7.1.9For more information, such as specific versions, please refer to the Zoom Minimum, Prompted, and Slow/Fast Update Versions support article: https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0061900
Xero - ATO services may be unavailable
Sep 28, 00:28 UTC Resolved - The ATO has resolved their issue impacting customers trying to file tax returns from Xero. Sep 28, 00:18 UTC Monitoring - The ATO has implemented a fix and we are currently monitoring the results. Sep 28, 00:03 UTC Identified - Our team are aware of an issue with the ATO where customers cannot file tax returns or STP filings. We are monitoring the outage and will work to keep you update as the ATO works to resolve the issue.
Xero - Xero Scheduled maintenance - Xero Ask Service, Xero Signing, Document Packs and the Practice Chart of Accounts Library
Sep 27, 07:00 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Sep 24, 20:07 UTC Update - We will be undergoing scheduled maintenance during this time. Sep 24, 11:30 UTC Scheduled - We're carrying out scheduled maintenance on Sunday 27 September 2026 from 7.00pm to 8.00pm NZDT. During this window, the following features may be temporarily unavailable:- Sending or signing documents using Xero Sign- Sending or replying to queries in Ask-...
Snowflake - INC20000239
Sep 27, 02:15 UTC Monitoring - Current status: We identified an issue with our third-party cloud platform that caused impact to Snowflake services. We've coordinated with our third-party cloud platform to implement the fix for this issue, and we'll continue to monitor the environment until we're confident all services are functioning properly.Customer experience: Customers hosted in the specified regions may have been unable to access or use multiple core Snowflake services and features. Affect...
Sumo Logic - Problem with Tracing Collection in North America 2 (US2)
Sep 27, 01:34 UTC Monitoring - We have implemented a fix for the issue affecting Tracing Collection. We are currently monitoring the results. Sep 27, 01:22 UTC Investigating - We are currently investigating reports of problems with Tracing Collection. Trace data sent may fail to ingest or be rejected due to service unavailability. We will provide more information soon.
Figma - Service disruption
Sep 27, 01:18 UTC Monitoring - Figma should now be operational. We are continuing to monitor. Sep 27, 01:04 UTC Investigating - We are currently investigating an issue where Figma Services are degraded or unavailable because of failures with AWS and other dependencies.
Revealing the details of how OpenAI agents hacked Hugging Face
GET-only egress to full code execution: chaining a URL mirror and a screenshot service submitted by /u/NOTHING_gets_by_me [link] [comments]
Xero - Global : Xero apps unavailable on Apple App Store
Sep 26, 23:28 UTC Identified - We're aware that the Apple App Store listings for the Xero apps Xero Accounting, Xero Me, Xero Projects, Xero Verify and Hubdoc apps are not currently accessible. We have taken action to resolve this and are in contact with Apple.Existing installations of these apps are unaffected. We apologise for any inconvenience caused.
Looking for an independent security firm to review a small SaaS security product before wider launch. Recommendations?
Small business, about 20 corporate users currently in a private pilot, live billing not yet enabled. There's no revenue yet to pay one of those big firms thousands of dollars to rubberstamp it, but we have used multiple AI security evaluation tools like Akido in the free tier to cross our t's and dot our i's. The SaaS in question is a security-focused platform designed to monitor the lifecycle of ...
I’ve been building my own Red Team tooling here’s what I’ve learned so far
I’ve been spending a lot of time building security tooling for my own research and authorized testing rather than relying entirely on existing frameworks. A few of the problems I kept running into were surprisingly simple: Recon gets repetitive. You end up running the same discovery, probing, fingerprinting and enumeration workflows over and over. Tooling becomes fragmented. One tool handles recon...
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and
Zero Trust for AI Agents Starts With Fixing Zero Visibility
The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to
Plaid - Service Disruption Impacting Bank of America connections
Status: InvestigatingBank of America is currently experiencing downtime impacting all channels and data recipients. API calls through Plaid are impacted. We will provide an update when Bank of America has resolved the issue.Affected components Dashboard (Partial outage) API - Production (Partial outage)
HashiCorp - Users unable to access releases.hashicorp.con
Status: MonitoringOur Engineering team has implemented a fix to resolve the issue. We are monitoring the situation closely and will post an update as soon as the issue is fully resolved.Affected components Releases Site (Partial outage)
Snowflake - INC20000237
Sep 25, 23:26 UTC Monitoring - Current status: We've implemented the fix for this issue, and we'll continue to monitor the environment until we're confident all services are functioning properly.Customer experience: Customers hosted in the specified regions may have been unable to access or use multiple core Snowflake services and features. Affected users may have been unable to sign in, execute queries, or manage data, and may have been unable to connect to Snowflake via private connectivity, ...
New Relic - Data Irregularities for US region
Sep 25, 19:57 UTC Investigating - We are currently investigating a service interruption where a subset of customers may be experiencing delayed data in queries, charts, and dashboards as well as delayed or missing alert notifications for related data. Affected alerts are currently being suppressed.
Zoom - Service Degradation Affecting Customer Using Polycom Devices Going Offline
Sep 25, 10:45 PDT Investigating - We are currently investigating a service degradation with a subset of users with Polycom devices going offline. Our team is actively working to identify the impact and root cause. We will provide an update as soon as more information becomes available.We appreciate your patience as we work to resolve this issue.
'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
I'm a Salesforce admin, not a cybersecurity expert, so please talk to me like I'm dumb. Salesforce had a similar exploit that was "patched" last year. My question is, is there anything that prevents exfiltration via calling 3rd party URLs in other AI clients, like Claude? In Agentforce, after the first web-to-lead vulnerability was discovered last year, you have to allowlist URLs for your us...
Datadog - Users are unable to acknowledge, escalate, or resolve On-Call Pages
Sep 25, 11:38 EDT Resolved - The issue is now resolved. Sep 25, 11:29 EDT Monitoring - We are monitoring the issue. Sep 25, 11:23 EDT Identified - We have identified the issue with pages and are applying mitigations. Sep 25, 11:17 EDT Update - We are investigating an issue with users unable to acknowledge, escalate, or resolve On-Call Pages. Sep 25, 11:11 EDT Investigating - We are investigating an issue with users unable to acknowledge on call pages
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are listed below - actions-cool/issues-helper actions-cool/maintain-one-comment Visiting either of the repositories now shows the message: "Access to this
Zoom - Zoom Phone India Maintenance (Mumbai) : September 25, 2026
Sep 25, 04:30 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Sep 3, 02:47 PDT Scheduled - Zoom Phone users registered to the India (Mumbai) Data Center will be automatically registered in an alternative datacenter (Hyderabad) starting at 25th September 2026 04:30 AM PDT (5:00 PM IST on 25th September 2026). During the maintenance window, a brief disconnection may be experienced and notifications may be missed. If you get disconnected, ...
On Anthropic’s AI Misuse Report
Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings. A few of the highlights: AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans selected targets, set goals, and reviewed important outputs...
Zoom - An unintended pop-up message appear for users in US region during initial invocation of Zoom AI’s Catch Me Up feature
Sep 25, 02:20 PDT Investigating - We are currently investigating an unintended pop-up message appear for users in US region during initial invocation of Zoom AI’s Catch Me Up feature in Zoom Meetings. At this time, Catch Me Up service itself remains fully functional.Our team is actively working to identify the impact and root cause. We will provide an update as soon as more information becomes available.We appreciate your patience as we work to resolve this issue.
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. The data came from disk space that earlier containers had used and given up, not from any live workload, and an attacker could not choose whose data they got, according to Cloudflare. The company
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,
New Relic - SRE Agent UI Availability Monitor (EU) query result is > 0.0 for 20 minutes on 'SRE Agent UI Unavailable (EU)'
Sep 25, 03:56 UTC Resolved - Between 01:10 UTC and 03:33 UTC on September 25th, some customers in the US, EU, and JP regions may have experienced intermittent UI errors while navigating the New Relic UI. Data ingest and alert notifications were not impacted. We have resolved this issue and impacted services have returned to normal operations.
New Relic - SRE Agent UI Availability Monitor (EU) query result is > 0.0 for 20 minutes on 'SRE Agent UI Unavailable (EU)'
Sep 25, 03:55 UTC Resolved - Between 01:10 UTC and 03:33 UTC on September 25th, some customers in the US, EU, and JP regions may have experienced intermittent UI errors while navigating the New Relic UI. Data ingest and alert notifications were not impacted. We have resolved this issue and impacted services have returned to normal operations.
New Relic - SRE Agent UI Availability Monitor (EU) query result is > 0.0 for 20 minutes on 'SRE Agent UI Unavailable (EU)'
Sep 25, 02:57 UTC Update - We are currently investigating some intermittent UI navigation errors in the EU region. Data ingest and alert notifications are not impacted at this time. Sep 25, 02:34 UTC Investigating - We are investigating an issue with New relic UI for EU region
New Relic - Potential Service Interruption
Sep 25, 02:23 UTC Investigating - We are investigating a potential service interruption that may impact some customers. Please continue to monitor this page for updates.
Argus Monitor Local Denial-of-Service Vulnerability (CVE-2026-79417)
(1) An exposed IOCTL lets unprivileged users disable the x86 MONITOR & MWAIT instructions used by Hyper-V and other kernel components--triggering a HYPERVISOR_ERROR bugcheck. (2) Reaching the IOCTL requires exploiting a TOCTOU bug arguably caused by poor documentation of the SeLocateProcessImageName function. (3) Reimplementation of the driver's security through obscurity IOCTL encryption scheme: ...
Zoom - Scheduled Update to Slow Track Versions for Zoom Clients: September 24, 2026 (No Operational Impact)
THIS IS A SCHEDULED EVENT Sep 24, 18:00 - 21:00 PDT Sep 17, 16:38 PDT Scheduled - Zoom will be updating the Slow track versions for Zoom clients on 9/24/2026.Slow channel updates:Windows: 7.1.9macOS: 7.1.9Linux: 7.1.9For more information, such as specific versions, please refer to the Zoom Minimum, Prompted, and Slow/Fast Update Versions support article: https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0061900
The 2026 State of AI Security Report has three numbers that really stuck with me: 81%, 50.1%, 99.9%
So I read this state of AI security report from orca security yesterday and a couple numbers stuck with me longer than I expected. First, 81% of orgs with AI packages have at least one known vulnerability. Half of those alerts now have a public exploit, which is up from almost nothing two years ago. The one that actually got me was 99.9%. Thats the share of fixable AI vulnerabilities still unpatch...
Amplitude - Export Destinations data delivery issue
Sep 24, 12:58 PDT Identified - The issue has been identified and a fix is being implemented. We will provide another update in 30 minutes. Sep 24, 12:47 PDT Investigating - Since 2026-09-24 09:30 PT (17:30 UTC), Amplitude has been experiencing a delay in Data Export processing due to a lagging data partition. Realtime data processing and Amplitude charts and dashboards are not impacted. No data is being lost, and delayed exports will complete once the underlying issue is resolved. No customer...
Netlify - Error accessing Netlify-hosted sites
Sep 24, 19:25 UTC Resolved - This incident has been resolved. Service has returned to normal operation, and we are no longer seeing elevated error rates. Sep 24, 19:10 UTC Monitoring - We are seeing signs of recovery, and service has returned to normal operation. Sep 24, 19:01 UTC Investigating - We are investigating reports of errors affecting access to Netlify-hosted sites. Our engineering team is actively investigating the issue.We will provide additional updates as more information beco...
GitHub - Disruption with billing information updates
Sep 24, 16:51 UTC Update - We are investigating failures on billing information updates. Customers may be unable to create or update their billing information in the meantime. Sep 24, 16:51 UTC Investigating - We are investigating reports of impacted performance for some GitHub services.
Supabase - Project Lifecycle Issues in eu-west-1
Sep 24, 15:50 UTC Identified - We have isolated the scope of the problem to a specific upstream incident. We are working to address the upstream incident and determine mitigations. Sep 24, 15:36 UTC Investigating - We are investigating project lifecycle operation issues in eu-west-1.
Zoom - Service Degradation Affecting Live Transcription Services.
Sep 24, 08:47 PDT Investigating - We are currently investigating a service degradation affecting Live Transcription Services.Our team is actively working to identify the impact and root cause. We will provide an update as soon as more information becomes available.We appreciate your patience as we work to resolve this issue.
How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
submitted by /u/natcoba [link] [comments]
Heroku - Heroku Feature Degradation
Heroku engineers are investigating.
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. "When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the
HubSpot - The Salesforce integration is unavailable for some customers
Sep 24, 10:08 EDT Identified - We have identified an issue with our Salesforce integration. Some customers may find that their integration has been unexpectedly disconnected and is temporarily unavailable in the App Marketplace.We're actively investigating the cause and working to restore full functionality.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to...
Zoom - Service Degradation Affecting Zoom Phone and Zoom Contact Center Inbound calls in India
Sep 24, 04:19 PDT Investigating - We are currently investigating a service degradation affecting a subset of Airtel subscribers for inbound call connectivity to Zoom India phone numbers for Zoom Phone and Zoom Contact Center. Outbound calls continue to function normally. Our team is actively working to identify the impact and root cause. We will provide an update as soon as more information becomes available.We appreciate your patience as we work to resolve this issue.
Supabase - Permission errors in the Supabase Dashboard
Sep 24, 10:50 UTC Identified - We have identified the issue causing some users to encounter permission-related errors, such as “You need additional permissions,” when performing administrative actions in the Supabase Dashboard.We are working on a fix and will provide another update once it has been implemented. Sep 24, 10:37 UTC Investigating - We are investigating reports of users encountering permission-related errors, such as “You need additional permissions,” when performing administrativ...
OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files
An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said. The portal publishes aggregate figures, such as spending, and is separate from the systems that handle Medicare claims and personal records. The agent reached files on it that were not public, but no personal
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. "The campaign compromised 7 accounts –
Xero - Global: Invoicing/Contacts and Payroll - Brief latency in some areas on Xero
Sep 24, 04:00 UTC Resolved - Our team has resolved an issue impacting our customers globally over the past 3 minutes from 2:17pm-2:19pm AEST where there was some latency using Payroll, Invoicing and Contacts We apologise for any inconvenience this has caused.
Netlify - Elevated CDN Errors
Sep 24, 00:00 UTC Resolved - The issue causing elevated CDN errors has been resolved. DNS resolution has recovered, and affected services are operating normally. Sep 23, 23:50 UTC Monitoring - We have applied a fix for the issue causing elevated CDN errors. Services are recovering, and we are monitoring the platform to confirm full recovery. Sep 23, 23:40 UTC Update - We have identified the cause of the elevated CDN errors and are applying mitigations across affected systems. Recovery is un...
[CISA KEV] CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability
Product: Commerce and Magento by Adobe Description: Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Zoom - Service Degradation Affecting Live Transcription Services.
Sep 23, 16:43 PDT Investigating - We are currently investigating a service degradation with Live Transcription Services.Our team is actively working to identify the impact and root cause. We will provide an update as soon as more information becomes available.We appreciate your patience as we work to resolve this issue.
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) - watchTowr Labs
submitted by /u/dx7r__ [link] [comments]
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) - watchTowr Labs
submitted by /u/dx7r__ [link] [comments]
Heap - Heap Connect Syncs: Possibility Of Stale Data
Sep 23, 15:15 PDT Identified - We are experiencing latency in our upstream data source. Syncs running during this period may have stale data. We will post an update within the hour.
Supabase - Supabase CLI CI workflow failures
Sep 23, 21:58 UTC Investigating - We're seeing rate limiting issues causing Supabase CLI CI workflow failures