tag: Security · 48 items
- Platform/SRE — Skip
- CI/CD — Skip
- Leader — Learn: Conceptual framing on trust and governance for AI agents as org adoption grows; useful for shaping early policy on AI tooling in the platform, but no actionable decision required now.
- Platform/SRE — Plan: CVM node pools on AKS are now GA, enabling sensitive workload isolation at the hardware level; evaluate whether regulated or high-sensitivity workloads in your clusters warrant migrating to CVM node pools this quarter.
- CI/CD — Skip
- Leader — Learn: GA confidential compute on AKS is a new capability relevant to compliance and data-sovereignty positioning, but no immediate strategic decision is required unless the org has active regulated-workload requirements on Azure.
- Signals: GA announcement
- Platform/SRE — Plan: v1.39.1 fixes multiple CVEs in Envoy’s HTTP/3 (UAF, CVE-2026-73512), HTTP/2 (process termination, CVE-2026-73513), and connection-handling paths — real data-plane exposure for any Istio, Contour, or Envoy-based ingress deployment. None are KEV-listed or confirmed exploited, so schedule patching this sprint rather than treating it as an emergency.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a
- Platform/SRE — Plan: Envoy is a common data-plane component in service meshes and ingress layers; this patch addresses a use-after-free in HTTP/3, process-termination bugs in HTTP/2, and multiple URL-normalization bypasses. No KEV listing or known active exploitation, so no hard deadline, but upgrade to v1.38.4 should be scheduled this sprint for any fleet running Envoy.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a
- Platform/SRE — Plan: Nine CVEs addressed including a UAF on HTTP/3, abnormal process termination on HTTP/2 trailers and ext_authz CONNECT requests, and a shared upstream connection-poisoning bug via HTTP upgrade — none are KEV-listed but the severity warrants scheduling an upgrade to v1.37.6 this sprint for any cluster running Envoy as ingress or data-plane proxy.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a
- Platform/SRE — Plan: Backstage is IDP infrastructure platform engineers commonly operate; this patch carries security fixes with no CVE details or KEV/exploitation data in the signals. Schedule upgrade to 1.49.6 within the current patch cycle — no hard deadline anchors Act.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: If you self-host Backstage as your internal developer platform, schedule an upgrade to 1.50.5; the release is flagged as a security fix recommended for all 1.50 users, though no specific CVE or active-exploitation evidence is provided in the signals to anchor an Act verdict.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Plan: CVE-2026-14978 (Unicode normalization in go-slug) can cause files to leak into HCP Terraform/TFE runs despite .terraformignore rules; not KEV-listed and EPSS 0.00, but worth upgrading Terraform to 1.15.9 in the next maintenance window if you upload sensitive files via remote runs.
- CI/CD — Plan: If pipelines run Terraform remote operations against HCP Terraform or Terraform Enterprise, the .terraformignore bypass in CVE-2026-14978 could leak secrets or config files into run uploads; pin Terraform to 1.15.9 in CI pipeline tooling during the next scheduled update.
- Leader — Skip
- Signals: CVE-2026-14978 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Act: OpenTofu 1.11 hit EOL on 2026-08-19 and this is its final patch; the credential-leak via OCI HTTP redirect and the DoS via crafted remote-state URLs are both active security risks in IaC runs. Upgrade to a supported OpenTofu release series (1.12+) now that EOL has passed.
- CI/CD — Act: The credential-leak bug affects
tofu initwhen pulling modules or providers from OCI registries — a standard pipeline step — and could expose registry credentials to a redirect target. Upgrade the OpenTofu version pinned in CI pipelines from 1.11.x to a supported series immediately; 1.11 is already EOL. - Leader — Skip
- Signals: OpenTofu 1.11 is past EOL (2026-08-19, 5d ago)
- Platform/SRE — Plan: Two security fixes affect IaC workflows: credentials intended for an OCI registry origin can leak to HTTP redirect targets, and tofu init can be forced into high CPU/memory usage via crafted URLs from an attacker-controlled state backend or registry. Upgrade OpenTofu to 1.12.6 in your IaC toolchain this sprint; no KEV listing or confirmed active exploitation, but both issues are directly triggerable in adversarial environments.
- CI/CD — Plan: If tofu init runs in your pipelines against external module/provider registries or remote state backends, both the credential-leak and resource-exhaustion issues apply there too. Pin the OpenTofu version in your pipeline tooling to 1.12.6 as part of your next dependency update cycle.
- Leader — Skip
- Platform/SRE — Plan: CVE-2026-17183 is patched in 13.2.0; EPSS is 0.00 and it is not KEV-listed, so there is no emergency, but schedule an upgrade of self-hosted Grafana this quarter to pick up the security fix and the alerting notifications API migration to v1beta1.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-17183 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Plan: CVE-2026-17183 is fixed in this patch for Grafana, which is common observability infrastructure. Not KEV-listed and EPSS is 0.00, so no forced urgency, but schedule an upgrade to 13.0.7 this sprint as standard security hygiene.
- CI/CD — Skip
- Leader — Skip
- Signals: major release (13.0) · CVE-2026-17183 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Plan: Grafana 12.4.9 includes a security fix for CVE-2026-17183 (not KEV-listed, EPSS 0.00 — no active exploitation). Schedule an upgrade to 12.4.9 in your next maintenance window; no emergency action required.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-17183 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Plan: Teams self-hosting GitLab should note that 19.3 reaches EOL 2026-11-19 (~90 days); plan an upgrade to 19.4 or later before that date to stay on a supported version.
- CI/CD — Learn: GitLab 19.3 GA adds bulk false-positive dismissal and agentic SAST remediation for existing vulnerability backlogs — worth evaluating if your pipelines already produce GitLab SAST findings, but no urgent action is required.
- Leader — Skip
- Signals: GitLab 19.3 reaches EOL in 90d (2026-11-19)
- Platform/SRE — Skip
- CI/CD — Learn: New dismissal reason in GitHub Code Scanning lets teams mark alerts as mitigated by external controls (e.g., WAF), reducing noise without falsely closing vulnerabilities — worth noting if you manage GHAS alert triage workflows.
- Leader — Skip
- Platform/SRE — Skip
- CI/CD — Skip
- Leader — Learn: A historical framing of data sovereignty principles that may shape thinking on where workloads run and how cloud-native architectures handle jurisdictional data controls — no decision required, but relevant context for platform strategy.
- Platform/SRE — Learn: Useful new GitHub admin capability for scoping credential revocation by token type during incidents, but no infra dependency or deadline — worth knowing for incident runbooks.
- CI/CD — Plan: Scope incident response playbooks to leverage token-type revocation for PATs, OAuth tokens, and GitHub App tokens; audit current credential hygiene and update runbooks to use this targeted revocation before the next supply-chain incident.
- Leader — Skip
- Platform/SRE — Learn: The incident data on 17,600 attacker actions is a useful framing for why platform-level controls (observation, constraint, blast-radius limiting) matter for agentic workloads, but there is no deployment action or deadline here — useful for teams beginning to run AI agents on shared infrastructure.
- CI/CD — Skip
- Leader — Learn: Relevant context for leaders setting AI adoption standards: the argument that agent governance requires systemic controls, not per-action review, shapes how to frame agentic AI policy, but no licensing, cost, or vendor decision is forced by this piece.
- Platform/SRE — Plan: v3.3.14 patches CLI secret-mask spoofing and fixes secrets leaking in last-applied-configuration annotations; CVE-2026-49978 (DOMPurify) is not KEV-listed and carries EPSS 0.00, so no emergency — schedule the upgrade within the quarter.
- CI/CD — Plan: Argo CD is explicitly in scope as the GitOps delivery layer; the server-side diff secret-mask spoofing fix could expose sensitive data in pipeline contexts — plan the upgrade to v3.3.14 this quarter.
- Leader — Skip
- Signals: Argo CD 3.3 supported · CVE-2026-49978 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Skip
- CI/CD — Learn: If pipelines use GitHub OAuth Apps for automation or registry auth, expiring tokens and refresh support may require updates to credential flows — worth evaluating when authoring new integrations.
- Leader — Skip
- Platform/SRE — Skip
- CI/CD — Skip
- Leader — Learn: Defining least-privilege and containment boundaries for enterprise AI agents is a real governance gap; this Docker framework sketches six security outcomes worth comparing against internal AI adoption standards, even accounting for its vendor-blog origin.
- Platform/SRE — Plan: Role manager can simplify onboarding new AWS services by auto-generating least-privilege starter roles, but teams with strict IaC discipline should evaluate whether console-created roles conflict with Terraform/CDK-managed IAM. Schedule a review of how role manager interacts with existing role governance before enabling org-wide.
- CI/CD — Skip
- Leader — Learn: Role manager lowers the barrier to correct IAM role setup for console-driven workflows, which may reduce misconfiguration risk across teams; worth noting as a governance tool but no immediate strategic decision required.
- Signals: GA announcement
- Platform/SRE — Skip
- CI/CD — Plan: Jenkins 2.576 ships multiple security fixes; review the 2026-08-05 security advisory and plan an upgrade of any self-hosted Jenkins controllers to this weekly build or wait for the next LTS incorporating these patches.
- Leader — Skip
- Platform/SRE — Plan: Grafana 13.1.2 fixes CVE-2026-13438 in software Platform teams commonly operate; schedule the upgrade this sprint. No forced timeline — the CVE is not KEV-listed and no active exploitation is reported.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-13438 — CISA KEV: not listed, EPSS n/a
- Platform/SRE — Plan: Patch includes dependency updates for CVE-2026-56852 and GHSA-hrxh-6v49-42gf (neither KEV-listed nor actively exploited) plus a PromQL SIGBUS crash fix on full disks; schedule an upgrade to 3.13.2 this maintenance cycle.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-56852 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Plan: Upgrade Docker Engine to v29.7.0 to patch CVE-2026-17106 (go-archive archive-traversal fix) and resolve two daemon panic bugs in container network cleanup paths; the CVE is not KEV-listed so no hard deadline, but schedule this within the current sprint.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-17106 — CISA KEV: not listed, EPSS n/a
- Platform/SRE — Skip
- CI/CD — Learn: Describes an integration pattern where Claude flags issues at authoring time and GitLab enforces controls through merge, dependency update, and infra change stages; worth tracking as AI-assisted supply-chain governance matures, but no concrete pipeline change to make today.
- Leader — Learn: Outlines a governance model for agentic coding at scale — pairing Claude security guidance with GitLab policy enforcement — relevant for leaders setting standards around AI-assisted development, but no licensing or cost decision is triggered here.
- Platform/SRE — Learn: If you run Cortex for long-term Prometheus/OTel storage, review the published audit findings to check whether any discovered issues affect your deployment configuration.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Skip
- CI/CD — Plan: GitHub now holds potentially malicious workflow runs for review in public repositories; audit your org’s Actions approval settings and ensure maintainers understand how to review held runs before merging external contributions.
- Leader — Learn: GitHub’s new default protection against credential-stealing workflow attacks reduces supply-chain risk for orgs using public repos; worth noting as a positive vendor-risk signal when assessing GitHub Actions dependency.
- Platform/SRE — Skip
- CI/CD — Plan: Enable or verify Dependabot alerts are active across your repos to benefit from the expanded OpenSSF malicious-package coverage; no deadline, but this materially improves supply-chain detection in your dependency pipeline.
- Leader — Plan: Broader malware signal coverage from OpenSSF integration strengthens your software supply-chain posture — confirm Dependabot alerts are enabled org-wide as a policy standard this quarter.
- Platform/SRE — Skip
- CI/CD — Learn: CodeQL 2.26.1 brings improved framework coverage for Go and better analysis accuracy; worth noting if you run GitHub code scanning in pipelines, but this is a patch-level quality improvement with no breaking changes or deadline.
- Leader — Skip
- Platform/SRE — Skip
- CI/CD — Plan: GitHub now holds unproven workflows pending approval on public repos — review your repository settings and approval workflows to ensure this protection is enabled and fits your release process.
- Leader — Learn: A new GitHub platform-level control targeting supply chain attacks via compromised credentials; worth noting as a defense-in-depth signal for orgs that rely on GitHub Actions for public repositories.
- Platform/SRE — Plan: A security fix for an ECH pre-shared key identity leak in OpenTofu v1.11.x warrants upgrading to v1.11.13; no KEV listing or active exploitation reported, so this is a planned patch rather than an emergency — schedule the upgrade this sprint.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Act: If you operate GitHub Enterprise Server, review the new security requirements for support bundle uploads and ensure your GHES instance is compliant before August 18, 2026, or uploads will be rejected, hampering incident troubleshooting.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Skip
- CI/CD — Skip
- Leader — Learn: A panel of enterprise security leaders sharing governance frameworks for agentic AI is worth a read for leaders thinking through AI policy; no concrete product or standard to act on yet.
- Platform/SRE — Learn: An interesting open-source SIEM/XDR option using eBPF monitoring and high-throughput ingestion; worth evaluating as an observability and security pipeline component, but no EOL pressure or operational urgency.
- CI/CD — Skip
- Leader — Learn: A nascent open-source SIEM/XDR project worth watching as a potential alternative to commercial SIEM vendors, but too early (60 stars, no enrichment signals) to drive a platform strategy decision.
- Platform/SRE — Plan: v1.39.0 patches several CVEs across ext_authz, ext_proc, gRPC stats, and HTTP/2/HTTP/3 DoS vectors, but none are KEV-listed and EPSS is 0.00 — no hard deadline. Plan the upgrade this quarter, and validate the breaking TLS enforcement change and OpenTelemetry sampling behavior shift in staging before rolling to production.
- CI/CD — Skip
- Leader — Skip
- Signals: deprecation mentioned (no explicit date found) · breaking-change flagged · CVE-2026-47204 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-47205 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-47207 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Plan: Five CVEs fixed in Docker Engine including a command injection via git bundle checkout and a directory traversal that can wipe /tmp — no KEV listing or known active exploitation, but the severity warrants scheduling an upgrade to 29.6.2 this sprint.
- CI/CD — Plan: If Docker Engine runs on self-hosted CI runners or build hosts, the git-bundle command injection (CVE-2026-15793) and local-source upload bypass (CVE-2026-15789) are directly relevant to build-time workloads; plan to update runner environments to Docker 29.6.2.
- Leader — Skip
- Signals: CVE-2026-15788 — CISA KEV: not listed, EPSS n/a · CVE-2026-15789 — CISA KEV: not listed, EPSS n/a · CVE-2026-15791 — CISA KEV: not listed, EPSS n/a
- Platform/SRE — Learn: A case study on AI agent risk in production environments; useful for thinking about isolation and least-privilege patterns when AI tooling has infra access, but no operational change required.
- CI/CD — Learn: Relevant to teams integrating coding agents into build/deploy pipelines; the scoped-identity and sandboxed-execution patterns are worth evaluating before granting agents pipeline credentials.
- Leader — Learn: A concrete incident narrative illustrating the risk of ungoverned AI agent access to production systems; useful context for setting policy on AI tooling permissions before broader rollout.
- Platform/SRE — Learn: Useful pattern for air-gapped or registry-mirrored clusters: configure kubelet to use an internal mirror for the pause/infra image instead of registry.k8s.io. No deadline, but worth evaluating if egress control is a concern.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Skip
- CI/CD — Learn: Public-preview slash command that surfaces security findings on in-flight changes within the Copilot app; worth monitoring as it matures, but pre-GA status caps this at Learn with no pipeline action today.
- Leader — Skip
- Platform/SRE — Skip
- CI/CD — Plan: GitHub’s AI-powered security detections now surface on PRs for languages CodeQL doesn’t cover — worth enabling to broaden supply-chain and vulnerability coverage in existing GitHub Actions workflows.
- Leader — Learn: Expanded AI security coverage on PRs broadens GitHub’s appeal as a unified code-security platform, relevant if evaluating whether GitHub Advanced Security covers the org’s language portfolio.
- Platform/SRE — Learn: Post-quantum crypto migration is a long-horizon concern for platform teams managing secrets and TLS; no deadline or concrete action is anchored in this item, so monitor evolving standards and evaluate Vault’s roadmap when NIST PQC finalization timelines solidify.
- CI/CD — Skip
- Leader — Learn: Signals an emerging strategic risk around long-lived cryptographic assets, but no vendor mandate or licensing consequence is present yet — worth adding to the security strategy roadmap as a future planning item.
- Platform/SRE — Plan: Prometheus is core observability infrastructure; upgrade to v3.5.5 to patch CVE-2026-53606 in the UI’s sanitize-html dependency. Exploitation risk is low (EPSS 0.00, not KEV-listed), so this is routine patching rather than an emergency.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-53606 — CISA KEV: not listed, EPSS 0.00
- Platform/SRE — Skip
- CI/CD — Plan: Two deserialization restrictions (COWL/PersistedList and Object fields by default) are meaningful security hardening in the Jenkins controller; review whether your instance is affected and schedule an upgrade within your normal maintenance window.
- Leader — Skip
- Platform/SRE — Learn: Grafana’s PIR confirms no customer production impact and no Grafana Cloud compromise from the TanStack npm attack; useful background on how supply chain attacks can reach observability vendors, but no operational change is required.
- CI/CD — Learn: The report details how a compromised npm package triggered a ransom incident and exposed a missed credential rotation — valuable for evaluating the depth of your own supply chain audit and rotation runbooks, even though Grafana’s customer pipelines were unaffected.
- Leader — Learn: Grafana’s independently audited transparency report (Mandiant confirmed no code tampering or repository poisoning) is useful context for assessing vendor security maturity; no strategic action is required since customer exposure was ruled out.
- Platform/SRE — Skip
- CI/CD — Learn: If your pipelines parse or display GitHub secret scanning output, the renamed detector type labels may affect dashboards or tooling that filters by those names — low urgency, no deadline.
- Leader — Skip
- Platform/SRE — Skip
- CI/CD — Plan: If pipelines run CodeQL scanning on Kotlin 2.4.0 codebases, upgrade to CodeQL 2.26.0 this quarter to maintain scan coverage; the new AI prompt injection queries are worth enabling if building LLM-integrated apps.
- Leader — Skip