Microsoft warned that CVE-2026-69836, a remote code execution vulnerability in its cloud identity and access management service, has been exploited in the wild. The flaw carries a CVSS score of 10.0, though Microsoft says no customer action is required.
The Rust Project removed malicious releases of arrayref, internment, and append-only-vec after a compromised maintainer account introduced a typosquatted dependency. Its build script downloaded and executed a remote payload during compilation, exposing developers through trusted dependencies.
New usage data indicates OpenAI is narrowing Anthropic's lead with enterprise users as organizations switch between providers when new models arrive. The movement suggests business AI spending remains volatile and model loyalty is still weak.
GitHub published a review of its August 17 service outage, outlining what failed and the work planned to improve resilience. The post gives engineering teams a useful look at the operational and reliability lessons behind a major developer-platform disruption.