The useful shift is automation at the CDN-to-origin boundary: operators no longer need to manually force post-quantum key exchange, while Cloudflare says its measured HelloRetryRequest rate fell from about 52% to 3.7% across the scanned cohort.
The endpoint names are staying the same, but the trust chain is not. Teams that pin Sentry certificates or still ship very old Android/Java runtimes need to remove or update those assumptions before Sentry publishes its exact February cutover date.
App Engine’s TLS migration is now an active rollout. Applications that still depend on TLS 1.1 or earlier can opt out only through August, while September enforcement may block old clients differently on appspot.com and custom domains.
The checkout ScriptTag shutdown already had an earlier deadline; this is the separate storefront cutoff. Pinning an old Admin API version will not preserve write access after October, and any feature still depending on an injected storefront script stops working in March.
Google has moved the Smart Campaign API creation cutoff to September 23. New create operations will fail, while existing campaigns can still be updated and served; Google points developers toward Performance Max, Search or Demand Gen for new automation.
The sharpest operational trap is CVE-2026-91768: PHP-FPM’s listen.allowed_clients can treat an allowed IPv6 address as an entire /96 prefix. Teams relying on that ACL should patch rather than assuming the configured address restriction is exact.
The deadline is no longer theoretical: browsers, Git HTTPS backends and API clients that still depend on SHA-1-era TLS algorithms can now lose connectivity to GitHub.com.
The Assistants API shutdown date has passed. OpenAI’s deprecation documentation lists August 26, 2026 as the removal date and directs developers to Responses and Conversations for replacement workloads.
The release is more than routine maintenance. OpenSSH is changing cryptographic defaults, sacrificing some compression effectiveness for side-channel safety, and warning that AI-assisted security reports are pushing it toward a faster release cadence.
This is a hard capability removal rather than a routine model migration. Products built on OpenAI’s video-generation API now need another provider or a redesigned video path because the official deprecation table offers no successor endpoint.
This is a hard managed-database migration rather than a soft deprecation. IONOS says automatic migration is impossible, v1 instances are switched off, and applications need new v2 endpoints even though Valkey remains compatible with standard Redis clients.
The change is separate from post-quantum TLS. DNSSEC signatures authenticate DNS records, and ML-DSA-44 makes them dramatically larger — 2,420 bytes per signature — while dual-signing with older algorithms creates a downgrade path unless resolvers enforce the post-quantum chain deliberately.
The change is not about where database rows live; Cloud SQL already has regional instance placement. It changes where API control traffic is processed, reducing dependence on global frontend infrastructure and making data-in-transit boundaries easier to align with sovereignty requirements.
The most broadly relevant issue lets attackers potentially drive TLS retransmission state into unbounded behavior or acknowledge packets that cannot be outstanding. Several additional fixes narrow local or configuration-dependent Windows attack paths.
Supabase’s self-hosted stack now routes through Envoy by default, bringing new API-key support and hardened gateway defaults while breaking some Kong-specific assumptions.
Cloudflare’s new MCP controls turn TLS-inspected Gateway traffic into an inventory and policy surface for remote MCP use, while explicitly leaving local stdio, off-network and uninspected traffic outside visibility.
The May Antigravity agent ID is retired. Managed Agents now require the September preview ID and default to Gemini 3.8 Flash, alongside hooks, token budgets and scheduled sandboxes.
The replacement is not a drop-in path rename: Cloudflare separates domain search, availability checks and registration operations into newer endpoints, so old registrar automation can break after the cutoff.
A new npm granular-token scope lets CI stage package versions without permission to publish them, extending npm’s broader move toward least-privilege publishing after its install-script, trusted-publishing and malware-gate changes.