Let's Encrypt's 64-day TLS certificates arrive February 10 — test renewals from October 14
The certificate lifetime change is not a new CA or endpoint. It is a renewal-timing deadline for operators whose cron jobs assume 90-day certificates.
Find published research by company, product, platform or technology.
Showing 301–320 of 362 dossiers
The certificate lifetime change is not a new CA or endpoint. It is a renewal-timing deadline for operators whose cron jobs assume 90-day certificates.
The October Nuxt release lays groundwork for server-engine portability and addresses TypeScript scaling problems in large route graphs without claiming Nitro has already been replaced.
The browser-for-machines project has reached 1.0 with a major web-compatibility jump and new cross-origin protections. It is not a drop-in replacement for every Chrome use case.
The October release is more than a version bump: PHP server operators should patch document-root and header risks, then test worker/thread budgets and stricter proxy defaults before upgrading.
PHP's official extension installer can now install multiple packages in one command and select missing project extensions without prompting. PIE 1.5 also improves attestation verification for its own updates.
JPEG XL is leaving the experimental-browser niche. Chrome 155 now decodes it by default, but Edge, older installed browsers and Safari's partial feature set still require fallbacks.
The October major release simplifies SvelteKit's architecture but breaks familiar config files and legacy imports. Teams should run the codemod and verify adapters and deployments.
The October 6 release is broader than WordPress 7.1.2's single critical RCE fix: it closes seven separate core flaws, including stored XSS through pending comments, second-order SQL injection in WXR exports and unauthenticated disclosure of comments on private posts.
Automated promotions make the advertiser's own website a source for ad assets. Google can find an offer, validate it and surface it without a marketer manually creating the promotion.
The break is narrow but concrete: scripts and CI/CD calling the old route paths can fail, while monitoring code that expected `connections` inline must fetch it separately.
The replacement is not a drop-in path rename: Cloudflare separates domain search, availability checks and registration operations into newer endpoints, so old registrar automation can break after the cutoff.
The sharpest operational trap is CVE-2026-91768: PHP-FPM’s listen.allowed_clients can treat an allowed IPv6 address as an entire /96 prefix. Teams relying on that ACL should patch rather than assuming the configured address restriction is exact.
This was not a Firecracker escape or access to a live victim disk. It was a storage-isolation failure underneath the sandbox: researchers recovered foreign directory structures, database pages and complete SQLite databases from reused blocks, and Cloudflare had to fix allocation plus retire existing disks and cached snapshots.
The useful lesson is broader than one coding assistant: repository indexing can quietly become a data-export boundary. ZCode’s response improves inspectability going forward, but builders using AI coding tools still need to know exactly which indexing, wiki and memory features send source code or Git metadata off-device.
Vet turns dependency updates from an implicit trust decision into an explicit, reviewable one for Laravel, Symfony, WordPress and plain PHP projects, with optional local coding-agent review layered underneath the human trust decision.
The deadline is no longer theoretical: browsers, Git HTTPS backends and API clients that still depend on SHA-1-era TLS algorithms can now lose connectivity to GitHub.com.
Cloudflare’s crawler controls now distinguish between refusing AI training and refusing the crawler itself. The new Disallow AI Training option is designed to keep search discoverability while expressing a training opt-out to operators that meet Cloudflare’s Accountable requirements.
This is not a normal container refresh. InfluxDB 3 is a ground-up architecture change with different query and storage assumptions, and Flux is not supported. Treating `latest` as a harmless moving patch tag can therefore turn an ordinary image pull into an unplanned database migration.
The change turns cache poisoning from mostly a workflow-design warning into an enforceable permission boundary. Teams can let untrusted jobs restore caches without writing them, prevent reusable workflows from escalating cache access and isolate jobs that only need to publish cache entries.
The important signal is the infection path. A trusted maintainer can unknowingly become the supply-chain carrier when malware modifies project and build files before a normal package publish, so publisher identity alone does not prove the artifact matches the maintainer’s intent.