
The nginx Patch Is Out, the Exploit Lands in August
CVE-2026-42533 affects nginx builds back to 2011. The fix shipped 15 July and a proof of concept is promised 21 days later. You can check your own exposure.

CVE-2026-42533 affects nginx builds back to 2011. The fix shipped 15 July and a proof of concept is promised 21 days later. You can check your own exposure.

Ofgem is reviewing whether record-keeping during June's Electricity Margin Notices was sufficient. Until it reports, the evidence base for GB grid risk is unsettled.

A remote memory-exhaustion flaw was fixed on 9 June with no CVE and no advisory. Severity-triggered patching could not see it. Schedule-based patching caught it by accident.

ServiceNow shielded hosted instances within 24 hours of the 1 April report. Self-hosted customers got patches on 13 July. Exploitation began on 17 July.

Two WordPress core flaws were patched on 17 July. By Sunday VulnCheck counted more than two dozen public exploits. The patch window was a single evening.

The Commission fined AliExpress EUR 550 million under the DSA. Read the findings and the infringement is about staffing and self-assessment, not only counterfeits.

Current AI holds 400 million dollars in committed funding, seeded by the French government. Its open Alpha Chat took seven weeks to build. Here is what that does to your next AI quote.

EY says an intruder sat in a third-party ITSM platform for two weeks and took client tax documents. The lesson for owners is the ticket queue, not the tax system.

CuspAI confirmed a 450 million dollar Series B and launched the AI Materials Foundry with more than 45 founding partners. The consortium, not the round, is what changes your sourcing position.

SK hynix customers want 60 to 100 percent more AI memory in 2027. The chairman wants prices lower. That combination tells a European operator what to contract now.

Four days after launch, Moonshot AI stopped selling new Kimi K3 subscriptions to protect existing users. Capacity, not capability, decided who got access.

A malicious config.json could run code on any machine loading a public AI model, bypassing trust_remote_code=False. The patch shipped 4 March. The CVE landed 24 May.
Page 3 / 35
One considered note on infrastructure, governance, and measurement, most mornings. No theory.