Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.

Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents
The AI giant disclosed six examples of concerning model activity and published a new framework for investigating and disclosing such incidents.

Salesforce wants to charge for AI outcomes, but first it needs to figure out how
Nothing demonstrates how deeply Fortune 500 companies depend on Salesforce quite like a global outage lasting more than seven hours. The interruption struck during the second day of last week's Dreamforce conference, where the $40 billion-a-year SaaS vendor was pitching AIforce and a growing collection of AI products. The question now is how the company will charge for them. AI

Firefox 156 arrives with a forest of forks in its wake
Mozilla and MZLA have delivered the latest releases in their new fortnightly cycle, but users who dislike the faster pace have alternatives. Firefox 156 is trickling out to users. The release notes only mention two new features: for Mac users, there's now an option in Settings to automatically launch the app at login. This vulture has received criticism for saying this in some

Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
The new program expands Vectra AI's partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes.

EY Survey Finds Autonomous AI Implementation Outpaces Oversight
A new survey of senior AI execs shows that while organizations are rapidly deploying AI and autonomous systems, their process and controls are not keeping pace.

Cisco Zero-Day Highlights API Endpoint Authentication Issues
The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.

MFA Won't Save You From OAuth Consent Abuse
MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation.

Admins, you've been warned: The clock is ticking on Edge's IE Mode
Microsoft has reminded administrators that Internet Explorer mode in Edge is guaranteed support only through 2029, so it is time to get those legacy migrations moving. Internet Explorer mode lets enterprises continue using legacy websites within Edge rather than relying on the retired Internet Explorer browser. It uses the Trident MSHTML engine from Internet Explorer 11 and per

KDE turns 30 and someone's brought an AI-native desktop proposal
KDE's annual conference takes place this weekend at Graz University of Technology in Austria, with an AI-native desktop proposal likely to divide attendees. The KDE project is celebrating its 30th anniversary this year, giving delegates at the Akademy conference in Graz another reason to raise a glass. The conference begins on Saturday, September 19, and registration remains op

Microsoft fixes the fix that broke Excel paste – partly
Microsoft has issued a partial fix for the Excel bug that causes paste operations to fail. The hotfix applies only to Excel 2016, and Microsoft warns that pasting may still fail in workbooks containing conditional formatting. Earlier in September, Microsoft released a security update for Excel to address remote code execution and information disclosure vulnerabilities. It later

AI Agent Breaches Spanish Organization, Modifies Personal Data
AI-driven cyberattacks used to be exotic. Soon, it'll be odd if threat actors aren't using agents to do all of their bidding.

CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
The move is consistent with the agency's advice on the need for organizations to prioritize the vulnerabilities that actually matter.

China's FamousSparrow APT Spies on US Politics in Latin America
Amid the US and China's fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight.
![[Virtual Event] Cybersecurity Outlook 2027](/media/blog-covers/1798.jpg)
[Virtual Event] Cybersecurity Outlook 2027

Omarchy gains $18.5M in backing, fresh converts – and fierce critics
In more than 30 years in the Linux business, we've never seen a distro win so much backing so fast – or make so many enemies. As we write, it's less than three weeks since we wrote about David Heinemeier Hansson's Omarchy Arch-based Linux. Much of Omarchy's success is due to the visibility of Hansson – better known as DHH – the man behind both the distro and the Ruby on Rails w

AI Security Spending Jumps as Fear Outpaces Proof of Value
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?

Fighting Your Dragons Through Tough Tech Times
Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns.

BragJack Attack Can Turn a Browser's Agentic AI Against It
A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.

Fedora 45 beta drags the Linux console into the 21st century
Fedora Linux 45 beta has arrived with Linux kernel 7.2, a release-candidate build of GNOME 51, and extensive changes beneath the desktop. The biggest surprise is that Linux's legacy in-kernel console – the text-mode interface normally hidden beneath the GUI – has been replaced with a software-controlled alternative. The replacement is kmscon, a userspace terminal emulator that
