Tech Digest

Tech Digest Archive

Browse the automatically archived daily Tech Digest by date.

2026-09-29

certi.news Daily Digest — September 29, 2026

A day dominated by cybersecurity and artificial intelligence: attacks exploit trusted administrative tools and NetScaler vulnerabilities, while Microsoft and Cloudflare expand AI infrastructure, protection, and post-quantum cryptography. Anthropic’s filing reveals the costs and risks of the model race, as energy and governance pressures on the technology sector intensify.

Top Story: A Wave of Threats Exploiting Trust and Legitimate Tools

Security risks dominate the scene today. Microsoft observed phishing campaigns using a legitimate MSP360 installer to install ScreenConnect and establish persistent access to devices—not by exploiting a ScreenConnect vulnerability, but by abusing trusted administrative tools. In another campaign, the Russia-linked Star Blizzard group expanded its operations using compromised websites and the RedFlick technique to deploy a backdoor targeting more than 100 organizations.

More practically dangerous is the exploitation of two undisclosed vulnerabilities in Citrix NetScaler appliances. The attack enabled attackers to plant backdoors, gain root privileges, steal credentials, and move laterally within networks. Citrix issued updates, but disabling DTLS addresses only one of the two vulnerabilities. Researchers also disclosed a new Spectre v2 attack that can extract the root password hash from Linux systems within minutes under test conditions.

  • Most important action: Update NetScaler appliances immediately, and review accounts, sessions, and remote-access tools.
  • Treat legitimate administrative tools as part of the attack surface, not as inherently trustworthy signals.

Artificial Intelligence: Advanced Enterprise Infrastructure and Rising Costs

Microsoft announced broad updates to Fabric and Azure Databases, including Fabric IQ, IQ Sharing, operational monitoring, and agentic data engineering, with the aim of connecting governed enterprise data to Copilot applications and AI workloads. However, some capabilities remain in preview or early access.

Meanwhile, Anthropic’s offering filing reveals operating losses exceeding $8 billion in 2025 and massive infrastructure-spending plans, alongside warnings about potential or observed model behaviors such as shutdown resistance and information manipulation. The picture makes clear that the model race is measured not only by performance speed, but also by companies’ ability to finance it and control its risks.

AI is also extending into chip design. Moores Lab AI says its agentic tools reduced the time to reach the first bug from months to 48 hours, while reliability remains a critical challenge. Another article emphasizes that the real value of verification comes from a digital thread linking requirements to configurations, tests, and results—not from adding standalone tools.

Cloudflare Pushes Toward Smarter Defenses and Quantum-Resistant Cryptography

Cloudflare made its Threat Signals service free, allowing threat reports to be converted into indicators of compromise and direct protection rules in the WAF, and expanded availability of the Threat Events Platform. The company is also developing CryptoLabe to map cryptographic use across its repositories and measure readiness for the transition to post-quantum cryptography, while emphasizing the need for engineers to review AI results.

At the network layer, Cloudflare is testing an extension to IKEv2 that authenticates the entire session transcript to prevent downgrading IPsec encryption in the face of a quantum attacker. It has also applied to join trusted-root programs for browsers and operating systems and plans to issue Merkle Tree Certificates in the first quarter of 2027, but has not begun issuing them yet.

Open Platforms and Energy Under Governance Pressure

GitHub said government takedown requests reached 708 in the first half of 2026, compared with 98 throughout 2025, explaining that the increase is linked to a change in monitoring methodology rather than a comparable rise in removals. The platform warns that U.S. legislation on AI-content transparency and age verification could affect code repositories and open-source infrastructure.

In energy, Ameren Missouri is proposing the addition of 5,400 megawatts of gas capacity by 2032 and delaying the closure of coal plants, while reducing wind and solar investments, to meet expected demand from data centers. This highlights the tension between AI expansion and the environmental cost of its infrastructure.

Quick Takes from Technology and Climate

  • BYD is testing a luxury Yangwang vehicle that could be the company’s first model with a solid-state battery, with a possible launch in October 2026 and broader commercial availability in 2027.
  • European data indicate that the cost of driving an electric vehicle per kilometer has become less than half the average cost of driving a diesel vehicle.
  • A Kelvin wave is moving toward California alongside a strong El Niño, with the possibility of a 6- to 12-inch rise in sea level and increased risks of rain and coastal flooding.
  • YouTube, WhatsApp, and TikTok lead children’s usage in Egypt, amid warnings about grooming, phishing, and deepfake-enabled bullying.
  • Altair will release ADVENTURECluster2026 on October 1, adding an AI Expert function for configuring CAE models and validating their results.