OpenAI just changed what a chatbot is allowed to be. On September 29, 2026, at its DevDay event in San Francisco, the company unveiled Dots: always-on AI agents that keep working on your tasks after you close the tab. Each Dot runs on GPT-6 Astra, OpenAI’s most capable model, gets its own dedicated cloud computer,…
Google Freezes Its Open Source Bug Bounty Program: What Happened and Why AI Reports Are to Blame
Google has temporarily stopped accepting new vulnerability submissions to its Open Source Software Vulnerability Rewards Program, better known as the OSS VRP. The pause took effect on October 1, 2026, after Google said its reviewers were being buried under a flood of automated, AI-generated bug reports, most of which turned out to be invalid. Google…
Free Gemini Gets Flash-Lite Only From October 9: What Changes and Whether AI Plus Is Worth It
What is happening to free Gemini? Starting October 9, 2026, Google is restricting which Gemini models free users can access in the Gemini app. According to an updated Google support page first reported by 9to5Google on October 3, anyone using Gemini without a Google AI subscription will be limited to the 3.5 Flash-Lite model. Access…
Citrix NetScaler SAML Zero-Day (CVE-2026-88779): What Happened and What to Do Right Now
Citrix has rushed out emergency patches for a new actively exploited zero-day in NetScaler ADC and NetScaler Gateway. Tracked as CVE-2026-88779, the flaw is a memory overflow that attackers can trigger remotely to knock SAML authentication infrastructure offline, and the US Cybersecurity and Infrastructure Security Agency (CISA) has already added it to its Known Exploited…
Apple Zero-Day (CVE-2026-86950): What Happened and What to Do Right Now
What happened in short On September 28, 2026, Apple released emergency security updates for iPhones, iPads, and Macs to fix a zero-day vulnerability tracked as CVE-2026-86950. The flaw is an out-of-bounds write in CoreGraphics, the system framework that renders images, PDFs, and text across Apple’s operating systems. A device that processes a maliciously crafted file…
Pantheon Security Incident Explained: What the Attack on Customer Sites Means for You
Direct answer: Pantheon, the web hosting platform used by thousands of WordPress and Drupal sites, disclosed a security incident on October 1, 2026, in which attackers compromised customer websites and used them to go after Pantheon’s own platform infrastructure. Malicious activity began on September 29. As the investigation continued, Pantheon determined that a small number…
Warlock Ransomware Is Back: How One Unpatched SharePoint Server Led to a Nine-Day Network Takeover
Direct answer: A suspected China-linked ransomware group known as Warlock (also tracked as Longlegs, Gold Salem, and Storm-2603) is actively exploiting both old and new Microsoft SharePoint vulnerabilities to break into critical infrastructure organizations. According to research from Symantec’s Threat Hunter Team published on October 1, 2026, the group hit at least four organizations in…
NVIDIA RTX 6080 Explained: Release Date, Price, Specs and Why It Could Launch Before the RTX 6090
NVIDIA may break with years of tradition on its next graphics card generation. A September 22, 2026 report from hardware outlet GameGPU claims the RTX 6080 could become the first RTX 60-series card to reach store shelves, arriving ahead of the flagship RTX 6090 rather than trailing it the way second-tier cards normally do. The…
Citrix NetScaler Zero-Day (CVE-2026-88771, CVE-2026-88772): What Happened and What to Do Right Now
On September 27, 2026, Citrix published emergency security bulletin CTX697096 disclosing eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are critical remote code execution flaws, both rated CVSS 9.5, that attackers had already been exploiting as zero-days before any patch existed. CISA added both to its Known Exploited Vulnerabilities…
Trump AI Safety Accord Explained: What the White House Pact Really Means
In short: On September 29, 2026, President Donald Trump and the leaders of six major AI companies signed a voluntary White House accord on AI safety. Instead of new regulations, the pact asks companies to police themselves through internal controls, independent external audits, and board-level review. Days later, Trump named intelligence chief Jay Clayton as…









