Pgpool-II patches seven watchdog and certificate-authentication vulnerabilities
Pgpool-II operators should upgrade to the October 1 security releases and review watchdog network exposure and certificate-authentication configuration.
Find published research by company, product, platform or technology.
Showing 61–80 of 92 dossiers
Pgpool-II operators should upgrade to the October 1 security releases and review watchdog network exposure and certificate-authentication configuration.
Panda CSS 2.0 keeps the familiar styling API but changes the compiler, minimum Node version and how teams can distribute design systems.
Python 3.15 is out: lazy imports, UTF-8 defaults, Tachyon profiling and a stable ABI for free-threaded builds. The experimental JIT is faster in Python's benchmarks but isn't a blanket production speedup.
Google's agent-accessible data toolkit has moved beyond its August launch: GA expands support to Bigtable, BigQuery Graph and Spark, with IDE/CLI integration, IAM enforcement and no separate kit fee. Underlying Google Cloud usage still costs money.
Two pgJDBC vulnerabilities affect different older driver ranges and only specific connection or binary-write configurations. Upgrade and verify the affected paths rather than treating this as a PostgreSQL server vulnerability.
This is a compatibility boundary for old Windows build hosts, not the end of Rust support for 32-bit Windows applications.
PostgreSQL operators gain per-statement and per-transaction estimated-cost limits across versions 14–18, useful for runaway reports and ORMs. The guard is disabled by default and can be bypassed by users allowed to change planner cost parameters.
The release is more than routine maintenance. OpenSSH is changing cryptographic defaults, sacrificing some compression effectiveness for side-channel safety, and warning that AI-assisted security reports are pushing it toward a faster release cadence.
Tailcat remains useful as a small encrypted peer-connectivity primitive, but its first documented malware adoption changes the operational context: Kothamine can use Tailcat to avoid a conventional command-and-control domain that defenders would otherwise block.
The scanner itself is not the new part. The September 16 change removes the CodeQL-default-setup gate that GitHub’s July rollout originally required, making AI-assisted vulnerability detection easier to add to repositories with different code-scanning configurations.
The observe–test–release loop now has explicit economics: Free and Pro include 30,000 captured generations and 25 million system-initiated AI tokens per month; Pro overages start at $1.50 per 1,000 generations and $2 per million LLM Eval/Guard tokens, while ordinary telemetry is billed separately.
Jalapeño is working first-party silicon rather than a roadmap item, and OpenAI now says AI itself materially accelerated the design process. The distinction still matters: tape-out means the design was finalized for manufacturing; it does not mean fleet-scale production qualification or API deployment is complete.
Meta’s Muse Glimmer 30B combines tool use, coding, vision and agentic task completion with official local-runtime artifacts. A 17GB GGUF build targets 24GB-VRAM machines, but Meta also attaches a separate usage policy, so builders should distinguish weight availability from unrestricted use.
WebMCP is no longer a Chrome-only browser experiment: Microsoft Edge now has its own active origin trial, while ChatGPT’s built-in browser and WordPress Playground show agent-client and platform implementation paths.
A previously preparatory compliance field is now an operative delivery gate. Builders automating Toll-Free onboarding need to collect, validate and submit policy URLs as part of registration rather than treating them as optional metadata.
Google appears to have completed a talent-focused Mechanize deal: the startup still exists, but much of the team that builds coding-agent training environments and evaluations has moved into Google’s model-development work.
The Assistants API shutdown date has passed. OpenAI’s deprecation documentation lists August 26, 2026 as the removal date and directs developers to Responses and Conversations for replacement workloads.
Google’s September Search changes now form a broader migration story: legacy campaign-level Broad Match and standalone Automatically Created Assets settings will be converted into AI Max, while language targeting stops affecting Search delivery and related API mutations begin failing.
GitHub OAuth apps can now use eight-hour access tokens with rotating refresh tokens, register up to 10 callback URLs, and explicitly control wildcard callback matching. New apps default to expiring tokens, while existing single-callback apps should review a legacy wildcard setting GitHub has now made visible.
Small sites can now compare a full month of HTTP, security and DNS activity without upgrading Cloudflare plans. The October 2 change applies to adaptive analytics, not every dataset.