AI Security Digest
Aggregated ecosystem risk analysis
Vendor Watchlist
Tracking 0 critical integrations
Threat Stream Feed
Real-time security logs and system alerts
Cloudflare - LAX (Los Angeles) on 2026-09-10
Sep 10, 07:00 UTCIn Progress - Scheduled maintenance is currently in progress. We will provide updates as necessary.Sep 10, 06:00 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Sep 8, 18:50 UTCScheduled - We will be performing scheduled maintenance in LAX (Los Angeles) datacenter on 2026-09-10 between 07:00 and 15:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in ...
Cloudflare - PHX (Phoenix) on 2026-09-10
Sep 10, 06:30 UTCIn Progress - Scheduled maintenance is currently in progress. We will provide updates as necessary.Sep 10, 05:30 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Sep 9, 10:00 UTCScheduled - We will be performing scheduled maintenance in PHX (Phoenix) datacenter on 2026-09-10 between 06:30 and 14:30 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the ...
Cloudflare - DFW (Dallas) on 2026-09-10
Sep 10, 05:00 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Sep 9, 16:20 UTCScheduled - We will be performing scheduled maintenance in DFW (Dallas) datacenter on 2026-09-10 between 06:00 and 11:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting this...
Amplitude - We are actively investigating an issue with our realtime ingestion pipelines.
Sep 9, 20:21 PDT Monitoring - A fix has been implemented and we are monitoring the results. Sep 9, 20:07 PDT Investigating - We are actively investigating an issue with our realtime ingestion pipelines. No data is lost.
Cloudflare - DUB (Dublin) on 2026-09-10
Sep 10, 01:00 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Aug 27, 13:20 UTCScheduled - We will be performing scheduled maintenance in DUB (Dublin) datacenter on 2026-09-10 between 02:00 and 05:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting this...
Elastic Cloud - Organisation Owner role access to Elastic Cloud Hosted Kibana
Sep 10, 01:30 UTC Identified - We have identified and are in the process of fixing+mitigating a bug in our permissions management UI that is prevents users with the Organisation Owner role and Cloud Console, Elasticsearch, and Kibana access from accessing Kibana in Hosted Deployments.
Slack - Incident: Trouble loading Workspace-level Apps & Workflows settings page is returning blank pages
We've engaged our engineering team to assist in the investigation. We’re continuing to work on understanding the issue. We’ll provide an update in 30 minutes or sooner if more information becomes available.
Cloudflare - MAA (Chennai) on 2026-09-10
Sep 10, 00:00 UTCIn Progress - Scheduled maintenance is currently in progress. We will provide updates as necessary.Sep 9, 23:01 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Sep 8, 03:10 UTCScheduled - We will be performing scheduled maintenance in MAA (Chennai) datacenter on 2026-09-10 between 00:00 and 04:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the ...
Cloudflare - DUB (Dublin) on 2026-09-09
Sep 9, 22:00 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Aug 27, 13:20 UTCScheduled - We will be performing scheduled maintenance in DUB (Dublin) datacenter between 2026-09-09 23:00 and 2026-09-10 02:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expect...
Optimizely - Upgrade of Product Information Management (PIM), 9-10 September 2026
THIS IS A SCHEDULED EVENT Sep 9, 22:00 UTC - Sep 10, 04:00 UTC Aug 14, 09:39 UTC Scheduled - The Product Information Management (PIM) service will undergo a product upgrade, starting on September 9th at 22:00 (UTC) and ending at 04:00 (UTC) on September 10th (6 hour window, actual downtime is expected to be 30-60 minutes). For an estimated 30-60 minutes during the service window, the PIM application will be stopped and PIM tenants will not be able to log in and perform normal activities. This...
Cloudflare - AMS (Amsterdam) on 2026-09-09
Sep 9, 21:00 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Sep 1, 08:10 UTCScheduled - We will be performing scheduled maintenance in AMS (Amsterdam) datacenter between 2026-09-09 22:00 and 2026-09-11 04:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are exp...
Snowflake - INC20000211
Sep 9, 21:53 UTC Investigating - Current status: We're investigating an issue with Snowflake Data Cloud. We'll provide an update within 30 minutes.Customer experience: Customers hosted in the specified regions may be unable to access or use multiple core Snowflake services and features. Affected users may be unable to sign in, execute queries, or manage data.Incident start time: 21:27 UTC September 09, 2026
Dropbox - Some customers are unable to access certain website routes and features.
Sep 9, 21:36 UTC Investigating - a number of pages and features are not working for some customers. We’re working to fix the problem as quickly as we can. We’ll share another update shortly.
1Password - Device Trust Service Disruption
Sep 9, 16:53 EDT Monitoring - We have identified the triggering change and have rolled it back. We are monitoring to confirm that this has completely resolved the issue. Sep 9, 16:43 EDT Investigating - We are currently investigating reports of an incident affecting Device Trust. Some customers may experience delays in device posture checks or authentication failures. We will provide an update as soon as we have more information.
Elastic Cloud - Elastic Agent enrollment/check-in failures on 9.5.3 (and 9.4.6) with Fleet remote Elasticsearch output
Sep 9, 20:44 UTC Identified - We've identified a bug in Fleet Server 9.5.3 (also present in 9.4.6) that can cause Elastic Agents to crash-loop and go offline when Fleet pushes a configuration update, including enrollment, a policy change, or a routine revision bump. This only affects policies that use Fleet's remote Elasticsearch output feature.Recommendation: If you use Fleet's remote Elasticsearch output, do not upgrade to 9.5.3 or 9.4.6 until a fixed version is available. If you're already ...
Cybersecurity statistics of the week (August 31st - September 6th)
Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here. All the reports and research below were published between August 31st - September 6th. You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/ Application Security Mythos Readiness ...
Cloudflare - Workers Cron Triggers degraded
Sep 9, 19:18 UTCIdentified - The issue has been identified and a fix is being implemented.Sep 9, 19:17 UTCInvestigating - Workers Cron Triggers may not execute or may be delayed in executing. Updates to Workers Cron Triggers may take some time to take effect.
Monday.com - Investigating issues with Vibe app
Sep 9, 18:39 UTC Resolved - This incident has been resolved. Sep 9, 18:36 UTC Monitoring - A fix has been implemented and we are monitoring the results. Sep 9, 18:32 UTC Identified - The issue has been identified and a fix is being implemented. Sep 9, 18:21 UTC Investigating - We are currently experiencing issues related to vibe applications. Our dedicated team is working to resolve this as quickly as possible
Cloudflare - Increased HTTP Errors
Sep 9, 15:30 UTCResolved - Between 16:40 and 16:54 UTC, Cloudflare experienced an elevated rate of HTTP errors affecting traffic passing through Philadelphia (PHL). The issue has been fully identified and resolved, and impact to the PHL location is completely mitigated. All systems are operating normally.
Cloudflare - Cloudflare Workers AI increased errors
Sep 9, 14:25 UTCInvestigating - Cloudflare is aware of, and investigating, increased Workers AI errors when attempting to use GLM 5.3. Updates to follow.
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability CVE-202...
DigitalOcean - Power Degradation impacting GPU Performance in ATL1
Sep 9, 10:47 UTC Investigating - We are investigating a power issue affecting part of our ATL1 datacenter. Redundant power systems are keeping servers online, and we have not observed any server outages.However, available power capacity is reduced, which may cause degraded performance for some GPU workloads, particularly during periods of high utilization.Our datacenter and infrastructure teams are working to restore full power redundancy. We will provide an update as more information becomes ...
Fortinet Privileged Access Agent: Any Site Could Control Your Proxy and Watch Your Tab
TL;DR. The FortiPAM Chrome extension (1M+ users), used for Privileged Access Management, allowed any site to set the browser's proxy for the session, alongside allowing any site to create a new tab and send screen recordings of it to an attacker's server. That makes for trivial phishing attacks which only require the user to view something sensitive in the attacker-opened tab. CVSS 9.1 | CVE-2026-...
Cloudflare - LUN (Lusaka) on 2026-09-09
Sep 9, 08:00 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Sep 8, 10:41 UTCScheduled - We will be performing scheduled maintenance in LUN (Lusaka) datacenter on 2026-09-09 between 09:00 and 16:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting this...
Supabase - Brief connection disruptions in us-east-1 (N. Virginia)
Sep 9, 08:47 UTC Resolved - Between 05:50–06:05 UTC some customer using Supavisor in us-east-1 may have experienced brief dropped connections or connection disruptions. This issue was caused by an unexpected restart of Supavisor instances in the affected cluster.We apologize for any disruption caused.
Cloudflare - YYC (Calgary) on 2026-09-09
Sep 9, 06:30 UTCIn Progress - Scheduled maintenance is currently in progress. We will provide updates as necessary.Sep 9, 05:30 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Sep 8, 11:31 UTCScheduled - We will be performing scheduled maintenance in YYC (Calgary) datacenter on 2026-09-09 between 06:30 and 12:30 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the ...
Cloudflare - DFW (Dallas) on 2026-09-09
Sep 9, 06:00 UTCIn Progress - Scheduled maintenance is currently in progress. We will provide updates as necessary.Sep 9, 05:00 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Sep 8, 15:40 UTCScheduled - We will be performing scheduled maintenance in DFW (Dallas) datacenter on 2026-09-09 between 06:00 and 11:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the a...
Cloudflare - IAD (Ashburn) on 2026-09-09
Sep 9, 04:00 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Sep 8, 14:40 UTCScheduled - We will be performing scheduled maintenance in IAD (Ashburn) datacenter on 2026-09-09 between 05:00 and 11:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting thi...
Zoom - Service Degradation Affecting Zoom Services
Sep 8, 18:09 PDT Monitoring - The service degradation affecting Zoom Phone, Contact Center, Meetings has been successfully resolved. Our team will continue to monitor the situation closely and keep you informed of any further developments.
Cloudflare - MAA (Chennai) on 2026-09-09
Sep 9, 00:00 UTCIn Progress - Scheduled maintenance is currently in progress. We will provide updates as necessary.Sep 8, 23:00 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Sep 7, 14:00 UTCScheduled - We will be performing scheduled maintenance in MAA (Chennai) datacenter on 2026-09-09 between 00:00 and 04:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the ...
[CISA KEV] CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Product: Multiple Products by Fortinet Description: Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Cloudflare - AMS (Amsterdam) on 2026-09-08
Sep 8, 21:00 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Aug 31, 04:00 UTCScheduled - We will be performing scheduled maintenance in AMS (Amsterdam) datacenter between 2026-09-08 22:00 and 2026-09-09 08:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are exp...
Cloudflare - Intermittent issues accessing the Dashboard on FireFox and Safari
Sep 8, 19:39 UTCInvestigating - Cloudflare is investigating intermittent issues accessing the Cloudflare Dashboard from Firefox and Safari browsers.
Cloudflare - PHL (Philadelphia) on 2026-09-08
Sep 8, 18:50 UTCScheduled - We will be performing scheduled maintenance in PHL (Philadelphia) datacenter between 2026-09-08 19:00 and 2026-09-09 17:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting this traffic to fail over elsewhere during this maintenance window as...
Netlify - Elevated Errors and Latency in IAD Region
Sep 8, 18:28 UTC Resolved - We experienced increased errors and latency in the IAD region on our regular network between 15:50 and 17:45 UTC. This issue has been resolved.
Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files
An operator running a Redis cryptomining botnet left their entire working directory exposed on a server. Instead of the usual single payload, the whole toolkit was there: exploit code, raw campaign logs, a bundled Python runtime, even two exported Windows registry hives. That let us read their own campaign logs instead of guessing: 3,562 distinct Redis servers compromised, out of 12,966 tar...
Cloudflare - Errors in Unified Billing for some requests OpenAI models
Sep 8, 18:00 UTCResolved - Customers using Unified Billing may have seen a low number of requests to OpenAI models result in errors from 18:01 to 18:34UTC on 8th of September 2026
🚨 Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files
Researchers indexed an open directory on 188.245.99.156 (Hetzner) that held an operator's full Redis cryptomining toolkit, not just a payload. 147 files in total: Python exploit source, JSON campaign logs, a bundled portable Python 3.11 runtime, and two exported Windows registry hives. Because the raw campaign logs were sitting there, the numbers come from the operator's own per-host records, not ...
AIs as Modern Genies
This essay was written with Barath Raghavan, and originally appeared in Lawfare. In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the isolated box the devel...
HubSpot - Some HubSpot tools may be unavailable for some users
Sep 8, 12:33 EDT Monitoring - We've addressed the issue that caused our CRM to be partially unavailable in North America since 11:46 AM EDT (UTC -04:00). We're monitoring performance closely to ensure all tools recover properly. Sep 8, 12:21 EDT Investigating - We are investigating an issue impacting some HubSpot tools. We will provide an update when we have more information.
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment
HubSpot - Some HubSpot tools may be unavailable for some users
Sep 8, 11:57 EDT Investigating - We are investigating an issue impacting some HubSpot tools. We will provide an update when we have more information.
Squarespace - Acuity Scheduling / Client Scheduling Page showing "SORRY" error
Sep 8, 11:28 EDT Resolved - Some customers are seeing a "SORRY" page when accessing their Client Scheduling Page.
Cloudflare - FUK (Fukuoka) on 2026-09-08
Sep 8, 14:00 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Sep 4, 20:31 UTCScheduled - We will be performing scheduled maintenance in FUK (Fukuoka) datacenter on 2026-09-08 between 15:00 and 18:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting thi...
Cloudflare - CBR (Canberra) on 2026-09-08
Sep 8, 14:00 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Sep 4, 20:21 UTCScheduled - We will be performing scheduled maintenance in CBR (Canberra) datacenter on 2026-09-08 between 15:00 and 18:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting th...
China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI rese...
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerabili...
Stealing AI Reasoning Traces
Interesting research: “Stealing Reasoning Traces from Proprietary LLM APIs“: Abstract: Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect intellectual property and limit information leakage. Rather than storing these traces server-side, providers return them to the client as blocks of encrypted text, which the client passes back...
Cloudflare - PHX (Phoenix) on 2026-09-08
Sep 6, 20:10 UTCScheduled - We will be performing scheduled maintenance in PHX (Phoenix) datacenter on 2026-09-08 between 10:00 and 13:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting this traffic to fail over elsewhere during this maintenance window as network inte...
Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
submitted by /u/sunychoudhary [link] [comments]
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical
Cloudflare - TXL (Berlin) on 2026-09-08
Sep 8, 07:50 UTCScheduled - We will be performing scheduled maintenance in TXL (Berlin) datacenter on 2026-09-08 between 08:00 and 17:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting this traffic to fail over elsewhere during this maintenance window as network inter...
Cloudflare - DFW (Dallas) on 2026-09-08
Sep 8, 07:00 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Sep 7, 16:10 UTCScheduled - We will be performing scheduled maintenance in DFW (Dallas) datacenter on 2026-09-08 between 08:00 and 11:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting this...
Optimizely - CMP Analytics Data Not Displaying
Sep 8, 07:34 UTC Identified - Customers using the CMP Analytics module may notice that analytics data for the past 4+ days is not visible in their dashboards. This is a display issue only — all data has been safely recorded and will be backfilled once the fix is deployed.
Cloudflare - PHL (Philadelphia) on 2026-09-08
Sep 8, 06:00 UTCIn Progress - Scheduled maintenance is currently in progress. We will provide updates as necessary.Sep 8, 05:01 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Sep 8, 05:01 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Sep 7, 23:40 UTCScheduled - We will be performing scheduled maintenance in PHL (Philadelphia) datacenter on 2026-09-08 between 06:00 and 12:00 UTC. Traffic might be re-routed from this location, hence there is a possibility ...
I removed Qwen3-4B's refusal guardrails (no fine-tuning, runs in Ollama)
During my research into model alignment, I noticed how frequently safety guardrails cause false positive refusals on legitimate cybersecurity tasks. To address this, I applied directional abliteration to Qwen3-4B. By locating the specific internal activation pattern responsible for refusal and removing it directly from the model weights, I neutralised the refusal response entirely. [model : https:...
Cloudflare - Cache Reserve Issue in Paris
Sep 8, 03:25 UTCInvestigating - Cloudflare is investigating an issue with Cache Reserve errors in Paris (CDG). Customers may see an elevated request volume to origin servers in the forementioned region. We are working to analyse and mitigate this problem. More updates to follow shortly.
Cloudflare - Cloudflare Account Member Invite Issue
Sep 8, 00:35 UTCInvestigating - Cloudflare customers may experience an issue when invited to a new account. An error message is displayed, "Invaild redirect_url". A workaround can be used: * Invited members create an account directly from the dashboard (not using the email link) * Admin resends invitation * Invited member clicks new link and signs into their Cloudflare account * Accepts invitation to join without issue We are continuing to investigate this issue.
[CISA KEV] CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Product: Commerce and Magento by Adobe Description: Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code. Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Xero - AU: Customers are experiencing errors when using Activity Statement Prefill
Sep 7, 23:46 UTC Identified - We’re aware that some customers are experiencing errors when using Activity Statement Prefill. We’re working with the ATO to identify the cause and will provide an update when we have more information.
Cloudflare - AMS (Amsterdam) on 2026-09-07
Sep 7, 22:00 UTCIn Progress - Scheduled maintenance is currently in progress. We will provide updates as necessary.Sep 7, 21:00 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Aug 31, 04:00 UTCScheduled - We will be performing scheduled maintenance in AMS (Amsterdam) datacenter between 2026-09-07 22:00 and 2026-09-08 08:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-use...
Sumo Logic - Problem with Cloud SIEM Processing in Europe 1 (EU)
Sep 7, 20:56 UTC Resolved - We are no longer seeing issues with Cloud SIEM Processing and normal operation has been restored at this time. Sep 7, 20:51 UTC Monitoring - We have implemented a fix for the issue affecting Cloud SIEM Processing. The symptoms are: latency in processing and displaying security data. We are currently monitoring the results. Sep 7, 20:42 UTC Identified - We have identified the source of the issue affecting Cloud SIEM Processing. The symptoms are: latency in pro...
Cloudflare - Issues rendering route configuration table in Networking > Routes UI
Sep 7, 15:52 UTCInvestigating - We are continuing to investigate this issue.Sep 7, 15:32 UTCInvestigating - Cloudflare is investigating an issue within the Dashboard UI (Networking > Routes) where the route configuration table is failing to display destination IP addresses/hostnames, connector names, and route descriptions correctly. Actual packet routing, network connectivity across the Cloudflare edge, and API-based route management remain fully operational and unaffected. Our engineering ...
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff
Xero - UK: MTD ITSA - Some customers receiving errors
Sep 7, 15:46 UTC Identified - We have identified the cause of the issue causing some UK customers trying to submit filings via MTD ITSA are receiving error messages. Our team are working on a fix for this issue. Sep 7, 15:30 UTC Investigating - We are aware some UK customers trying to submit filings via MTD ITSA are receiving error messages. Our team is investigating this with urgency.
Wix - We are investigating a potential issue with elements not appearing of Wix Harmony Live Sites
Sep 7, 15:26 UTC Investigating - We are aware that some users are experiencing issues with elements missing on Wix Harmony Live Sites and are currently investigating it.
Cloudflare - Browser Isolation Session Initialization Failures
Sep 7, 14:59 UTCIdentified - The issue has been identified and a fix is being implemented.Sep 7, 14:25 UTCInvestigating - We are investigating reports of customers encountering a white screen when attempting to access websites behind Browser Isolation. This is caused by Browser Isolation session initialization failing to complete. Our engineering team is actively working to identify and resolve the root cause.
MAL-2026-16036: Redis Labs Vulnerability
Malicious code in redis-type-intel (npm)
MAL-2026-16035: Redis Labs Vulnerability
Malicious code in oscar-redis (npm)
Cloudflare - Performance degradation affecting TURN service
Sep 7, 13:52 UTCResolved - A fix was deployed for this issue and the impact is over for any new connections on Realtime TURN service. Existing connection will continue to use TCP until the customers clients end and restart their connections.Sep 7, 13:04 UTCMonitoring - A fix has been implemented and we are monitoring the results.Sep 7, 13:02 UTCInvestigating - We are investigating reports of performance degradation affecting our TURN service since August 22nd. Currently, a significant portio...
Your Cloud Security Checklist Doesn't Work the Way You Think It Does
If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like. How risk differs across cloud providers
Cloudflare - Increased Workflow Instance Creation Errors
Sep 7, 05:12 UTCInvestigating - Cloudflare is aware of, and investigating an issue which potentially impacts multiple customers. Further detail will be provided as more information becomes available.
Cloudflare - IAD (Ashburn) on 2026-09-07
Sep 7, 04:00 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Sep 3, 16:30 UTCScheduled - We will be performing scheduled maintenance in IAD (Ashburn) datacenter on 2026-09-07 between 05:00 and 11:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting thi...
Xero - AU: Xero Tax - Customer won't be able to file tax returns due to an outage with ATO services.
Sep 7, 01:49 UTC Identified - We are aware of an issue where customers cannot file tax returns or STP Fillings to ATO due to an outage with their services. Customers will be able to create tax returns but cannot file these during this time. We are monitoring ATO for updates and we'll update you as soon as we can.
Cloudflare - AMS (Amsterdam) on 2026-09-06
Sep 6, 21:00 UTCScheduled - Maintenance will begin as scheduled in 60 minutes.Aug 31, 04:00 UTCScheduled - We will be performing scheduled maintenance in AMS (Amsterdam) datacenter between 2026-09-06 22:00 and 2026-09-07 08:00 UTC. Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are exp...
Cloudflare - Purchased domains from registrar not appearing in Cloudflare Dashboard
Sep 6, 17:06 UTCInvestigating - We are investigating reports of delays in the provisioning of newly purchased domains. Our engineering team is currently working to resolve these delays affecting domain registration.
Cloudflare - Service Connectivity Issues in Canberra
Sep 6, 16:36 UTCInvestigating - Customers may experience intermittent connectivity issues when accessing services through our Canberra (CBR01) data center. Our team is actively working to restore normal service.
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and
Zoom - Service Degradation Affecting Zoom AI Companion in US Region
Sep 5, 20:57 PDT Investigating - We are currently investigating a service degradation affecting Zoom AI Companion in US Region.Our team is actively working to identify the impact and root cause. We will provide an update as soon as more information becomes available.We appreciate your patience as we work to resolve this issue.
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
Monday.com - Planned mainatance
Sep 5, 08:52 UTC Update - We are continuing to investigate this issue. Sep 5, 08:40 UTC Update - We are currently investigating and working on the platform to gain access back to it. Sep 5, 08:32 UTC Update - We are continuing to investigate this issue. Sep 5, 08:31 UTC Investigating - We are currently investigating reports of connectivity issues across the platform. Our team is working to resolve this promptly.
Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs
Box - Box Sign Scheduled Maintenance
THIS IS A SCHEDULED EVENT Sep 4, 23:00 PDT - Sep 5, 01:00 PDT Aug 25, 01:11 PDT Scheduled - Starting on Friday, September 4th, 2026 Box will be performing maintenance on Box Sign. The maintenance will begin at 11 PM PDT and is expected to complete by 1 AM PDT.Box Sign may be briefly unavailable. Existing Box Sign data will not be affected.After the maintenance concludes, users will be able to resume activity with Box Sign normally. We will also closely monitor the status of Box Sign throughou...
Zoom - Zoom Support Maintenance: September 4, 2026
THIS IS A SCHEDULED EVENT Sep 4, 20:00 - 22:00 PDT Aug 21, 14:39 PDT Scheduled - We will be performing maintenance on Zoom Support Ticketing and Knowledge Base. Users may experience degraded performance and up to 30 minutes of downtime for Zoom Support’s Knowledge Base and Ticketing during the maintenance window.
GitHub - Degradation in repos contents API
Sep 4, 22:23 UTC Resolved - This incident has been resolved. Thank you for your patience and understanding as we addressed this issue. A detailed root cause analysis will be shared as soon as it is available. Sep 4, 22:02 UTC Investigating - We are investigating reports of impacted performance for some GitHub services.
GHSA-rh53-xvx2-j327: Kubernetes Vulnerability
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
Cloudflare - Elevated number of R2 503 errors in Eastern North America region
Sep 4, 21:27 UTCIdentified - The cause of this issue has been identified and a fix is being implemented.Sep 4, 21:10 UTCInvestigating - Cloudflare is investigating issues with R2 buckets in Eastern North America.
GitHub - Disruption with Copilot Code Review
Sep 4, 20:57 UTC Update - Some users may be experiencing failures when using Copilot code review. We have identified the root cause and are working on a mitigation. Sep 4, 20:39 UTC Investigating - We are investigating reports of impacted performance for some GitHub services.
Cloudflare - Zero Trust Dashboard - Posture Check Visibility Issue
Sep 4, 19:55 UTCIdentified - Cloudflare is aware of, and implementing a fix for individual device posture checks not showing on the Devices Page. Device posture checks in the meantime can be inspected through the Logs -> Posture Logs. This is purely a dashboard visibility issue— firewall policies are not impacted.
Vercel - Elevated latency in VCR, Blob, and Sandbox API
Sep 4, 19:55 UTC Update - The fix is currently being rolled out. We'll provide another update once the rollout is complete and we're beginning to see signs of recovery. Sep 4, 19:33 UTC Update - We are continuing to work on a fix for this issue. Sep 4, 19:33 UTC Identified - The issue has been identified and a fix is being implemented. Sep 4, 19:11 UTC Investigating - We've identified an issue where some customers may experience increased latency for API requests to VCR, Blob, and San...
RLSA-2026:63119: Grafana Labs Vulnerability
Important: grafana-pcp security update
Zoom - Service Degradation Affecting Email in Zoom Contact Center Services in North America
Sep 4, 10:55 PDT Resolved - This incident has been resolved. Sep 4, 10:46 PDT Monitoring - On 09/04/2026, Between 15:15 UTC to 16:10 UTC, A subset of users may have experienced issues with Email in Zoom Contact Center. This incident has been resolved and the affected services have been restored.
HashiCorp - Errors creating new VCS workspaces with Bitbucket cloud provider
Status: InvestigatingWe are aware of and investigating reports of errors when creating new VCS workspaces using the Bitbucket cloud provider. We are working to identify and resolve the issue and will post updates with more information when it is available.Affected components HCP Terraform (Degraded performance)
Akamai - Certificate Provisioning System (CPS) Issues and Network Connectivity Issues in Atlanta Region
Sep 4, 16:06 UTC Resolved - We became aware of an issue with a network component related to connectivity in the Atlanta, GA region which impacted the Certificate Provisioning System as well as potential impact to other Edge traffic through the region. The issue lasted between 12:21 UTC and 14:19 UTC on September 4, 2026. We can confirm that the issue is now resolved, and the service has resumed normal operation. Customers and partners can view additional details about the incident by logging i...
Zoom - Common Platform Voice Network Maintenance in London (UK1 & UK2): September 4, 2026 (No Operational Impact)
THIS IS A SCHEDULED EVENT Sep 4, 09:00 - 13:00 PDT Aug 25, 11:01 PDT Scheduled - We will perform scheduled maintenance to upgrade infrastructure software during this time. We do not anticipate any service impact as traffic will be automatically rerouted to the alternate location throughout the maintenance period. Customers and partners with redundant trunks to both London UK1 and London UK2 Common Platform Infrastructure will see 1 peer offline at a time while traffic continue to route through...
CircleCI - macOS Job Delays
Sep 4, 15:43 UTC Identified - We've identified the networking issue with our Mac infrastructure provider, and are working with them to resolve the issue. We're starting to see some recovery, but we expect customers may still see some queueing. We'll update again shortly. Sep 4, 15:16 UTC Investigating - We have detected network issues affecting our Mac infrastructure. We're investigating and will provide updates shortly. Customers may experience queuing during this time.
Self-hosted Coder: check whether you pulled a registry module on Aug 31. no CVE, so nothing will flag it for you
On Aug 31, rogue origins were added to the Cloudflare pool in front of registry.coder.com. For roughly 14 hours, 07:35–21:45 UTC, the real registry domain served Terraform modules carrying an extra data "external" "telemetry" block that shelled out to dlp-docker.sh and posted your environment to www[.]coder-infra[.]com. Why nothing caught it There's no bad version to pin away from, because the poi...
Cloudflare - Cache Purging Errors
Sep 4, 14:51 UTCInvestigating - Cloudflare cache purging called via the Dashboard or API is returning errors, with the message "unable to purge. internal error". We are working to resolve this issue as soon as possible. More updates to follow.