pgvector 0.8.7 patches an IVFFlat index-build overflow with potential code execution
A security fix for a widely used PostgreSQL vector extension makes index-build permissions and extension patching part of AI search infrastructure hygiene.
Find published research by company, product, platform or technology.
Showing 21–40 of 148 dossiers
A security fix for a widely used PostgreSQL vector extension makes index-build permissions and extension patching part of AI search infrastructure hygiene.
The certificate lifetime change is not a new CA or endpoint. It is a renewal-timing deadline for operators whose cron jobs assume 90-day certificates.
The bug is a useful warning for AI application plumbing: turning a user-supplied URL into a model attachment also turns the application server into a network client unless the adapter enforces an outbound trust boundary.
This was not a Firecracker escape or access to a live victim disk. It was a storage-isolation failure underneath the sandbox: researchers recovered foreign directory structures, database pages and complete SQLite databases from reused blocks, and Cloudflare had to fix allocation plus retire existing disks and cached snapshots.
The scanner itself is not the new part. The September 16 change removes the CodeQL-default-setup gate that GitHub’s July rollout originally required, making AI-assisted vulnerability detection easier to add to repositories with different code-scanning configurations.
This is a compiler-correctness fix rather than a routine patch. Code built with Rust 1.98.0 can be wrong even when the source is valid, so teams that adopted that stable release should update and rebuild affected artifacts.
WordPress 7.0.4 fixes CVE-2026-65640, a CVSS 8.8 remote code execution flaw affecting installations that process malicious PostScript uploads through Imagick and Ghostscript. Fixes have also been backported to branches as old as 4.7.
GitHub OAuth apps can now use eight-hour access tokens with rotating refresh tokens, register up to 10 callback URLs, and explicitly control wildcard callback matching. New apps default to expiring tokens, while existing single-callback apps should review a legacy wildcard setting GitHub has now made visible.
Shopify is turning off its old cross-merchant catalog REST API on November 2. The replacement is a UCP-compatible MCP server, not a renamed URL: agents must remap tools, payloads and saved-catalog identifiers.
The release is more than routine maintenance. OpenSSH is changing cryptographic defaults, sacrificing some compression effectiveness for side-channel safety, and warning that AI-assisted security reports are pushing it toward a faster release cadence.
Google's distributed SQL database can now run in production beyond Google Cloud, but 'deploy anywhere' doesn't mean free or fully managed. Spanner Omni GA brings security, backup and paid commercial licensing, with important limits on its developer edition.
PostgreSQL operators gain per-statement and per-transaction estimated-cost limits across versions 14–18, useful for runaway reports and ORMs. The guard is disabled by default and can be bypassed by users allowed to change planner cost parameters.
Rashomon's experimental local recorder can expose discrepancies between a coding agent's closing claims and its tool execution. It is an observability aid, not a sandbox or tamper-proof security product.
The practical change is that debugging a Cloudflare-backed application no longer has to stop at the Worker boundary: one trace can follow security, cache, routing, Worker and origin handling, while logs and traces move toward one query and pricing model.
The exploitation signal has strengthened again: CISA added CVE-2026-87902 to KEV on September 25. That turns earlier vendor and security-company telemetry into formal U.S. government confirmation of in-the-wild exploitation.
Muse packages persistent autonomous execution, credentials, payments, app access and memory into a mainstream consumer product. A September macOS hotfix now provides an early real-world lesson: agent containment has to protect not only the cloud runtime but also the local control path into the agent.
The important failure is not another prompt injection. Plugin4Shell breaks the mechanism intended to guarantee that an AI-agent plugin is still the exact code a marketplace reviewed.
The useful lesson is architectural rather than vendor-specific: coding agents inherit execution paths from ordinary developer tooling. If an agent shells out to Git without sanitising repository-local configuration, a hidden `.git/config` can become a host-level command channel that bypasses the controls users think govern the model.
The interesting change is security economics rather than another hosting feature. A control that previously sat behind a $150/month add-on is now free across plans, changing the cost boundary for private dashboards, internal tools and pre-launch production domains.
The important signal is the infection path. A trusted maintainer can unknowingly become the supply-chain carrier when malware modifies project and build files before a normal package publish, so publisher identity alone does not prove the artifact matches the maintainer’s intent.