Brazilian customers can authorize Pix Automático mandates for Paddle subscriptions without a separate early-access application. The path broadens local-payment access for SaaS, while delayed renewals, fixed mandate amounts and re-authorisation requirements still create implementation caveats.
This was not a Firecracker escape or access to a live victim disk. It was a storage-isolation failure underneath the sandbox: researchers recovered foreign directory structures, database pages and complete SQLite databases from reused blocks, and Cloudflare had to fix allocation plus retire existing disks and cached snapshots.
The 10GB Hobby storage cap has not changed, but the consequence of crossing it has. Vercel has removed the previous 30-day grace period for non-exempt deployments, shrinking the rollback and preview history free-plan builders can assume will remain available.
Click2Shell turns a theme-preview parsing bug into a supply-path problem: an attacker can force official catalog code onto a site without the administrator choosing Install, then potentially reach executable pre-activation theme code.
The observe–test–release loop now has explicit economics: Free and Pro include 30,000 captured generations and 25 million system-initiated AI tokens per month; Pro overages start at $1.50 per 1,000 generations and $2 per million LLM Eval/Guard tokens, while ordinary telemetry is billed separately.
The material issue is not ordinary model distillation. Anthropic’s evidence suggests a customer-facing AI product may have used a rival model as an undisclosed backend while simultaneously harvesting those interactions for training, turning routing architecture into a privacy and trust boundary.
Azure’s old PostgreSQL versions do not switch off on September 1, but they do become a paid legacy choice. Extended Support is automatic, billed by vCore-hour for running servers, and cannot be declined while an unsupported engine version remains in use.
HIPAA support moves Laravel Cloud into a class of regulated workloads that shared application hosting could not safely claim. Private Cloud supplies dedicated tenancy, encryption, SSO/SAML, backups and a BAA path, while application-level access control, audit logging and PHI handling remain the developer’s responsibility.
Cloud Storage project deletion no longer necessarily destroys every soft-deleted bucket immediately. Google’s August 17 change makes bucket retention part of project-recovery behavior, affecting disaster recovery, teardown assumptions and ongoing storage cost.
Amplitude’s new consent gating separates the visible experiment experience from persistence and measurement. Sites can avoid experiment flicker before a consent decision, but denied users’ buffered impressions are discarded and Analytics consent still has to be handled separately.
Google is creating a geographic split in one of Search's most consequential spam controls. Publishers can face a manual action globally, but EEA users will see the affected section ranked on its own merits rather than directly demoted by that action.
The AI Compute Partnership tied Nvidia more directly to the capital structure and utilization risk of emerging cloud providers. Reuters says the initiative is now paused amid concerns about circular demand, control over partners and antitrust exposure, although Nvidia says the broader compute-access model continues to evolve.
Google did not announce a new spam policy with the August update, but early independent measurement shows unusually large ranking displacement across 20 industries. The data is useful for diagnosing timing and scale, not proof that any individual site was demoted for spam.
WordPress 7.0.4 fixes CVE-2026-65640, a CVSS 8.8 remote code execution flaw affecting installations that process malicious PostScript uploads through Imagick and Ghostscript. Fixes have also been backported to branches as old as 4.7.
Stripe’s August FX update moves more global money management inside the payments stack: businesses can convert balances 24/7 without first paying out to an external bank or FX provider, and settlement coverage is expanding across more markets and currencies.
Search Console can now treat supported social and video accounts as properties, exposing Google impressions, clicks, queries and post-level performance for Instagram, TikTok, X and YouTube content.
Meta has made the privacy-versus-price trade explicit in its Model API: developers can choose standard pricing or a contributor model ID with steeply discounted inference in exchange for training-data permission. The choice matters for proprietary code, customer data and AI SaaS workloads.
Retention-locked backups are gaining a project-level consequence: Google Cloud plans to create automatic liens that can block project deletion while protected backups remain. Infra teams need to account for this in teardown automation, IAM and recovery design.
App Engine’s TLS migration is now an active rollout. Applications that still depend on TLS 1.1 or earlier can opt out only through August, while September enforcement may block old clients differently on appspot.com and custom domains.
Agent Identity is moving from a standalone credential boundary into a mainstream serverless runtime. Cloud Run can now assign agent identities and register agents/MCP servers automatically, reducing custom discovery and identity plumbing while keeping the runtime integration itself in Preview.