thiago.Search
HomeProfileArticlesNewsEventsSearch

Market news

Cybersecurity, cloud, identity, DevSecOps and AI security.

AI-assisted curation. External-source summaries and independent editorial context.

News RSS

RSS ↗

GitHub completes rollout of stateless App tokens

On October 2, GitHub completed the move to stateless `ghs_APPID_JWT` installation tokens. Scope, permissions and one-hour expiration are unchanged, but tokens grow from about 40 to roughly 520 characters; the temporary test header retires November 30.

Why it matters

Editorial implication: treat tokens as opaque strings and test databases, vaults, proxies and headers for truncation. Update redaction and DLP rules too: validators tied to the legacy format may expose the new secret in logs.

Read original source ↗

GitHub adds confidential comments to security advisories

From October 2, maintainers can post comments visible only to people with repository write access. Reporters and invited collaborators without that access neither see nor receive notifications; views are audit-logged. Confidential status cannot be changed after posting.

Why it matters

Editorial implication: keep investigation and coordination with the advisory without exposing sensitive details to the reporter, but classify content before posting. Confidentiality inherits current repository permissions, so review write access and preserve evidence needed for incident response.

Read original source ↗

Gemini Enterprise queries federated data through MCP

In preview announced October 2, connectors for AlloyDB, BigQuery, Cloud SQL and Spanner can query data in place through MCP using each user's permissions, without prior ingestion. Google documents data residency, CMEK and VPC Service Controls support; enabled write actions can modify the source.

Why it matters

Editorial implication: the user's authorization is the effective boundary, not merely the connector. Separate read and write, restrict sources with Organization Policy, apply VPC Service Controls and review what conversations and results retain before enabling conversational analysis over sensitive data.

Read original source ↗

npm allows dist-tag management with short-lived OIDC

On September 30, GitHub announced that npm trusted-publishing configurations can optionally receive permission to change dist-tags such as `latest`, `next` and `beta` with short-lived OIDC credentials. The permission is off by default for both new and existing configurations.

Why it matters

Editorial implication: remove persistent tokens used only for tags, but enable the new permission solely for workflows that promote or roll back versions. Protect the environment, branch and OIDC identity because moving `latest` can redirect installations without publishing a new package.

Read original source ↗

API Gateway can protect MCP discovery with an API key

From September 30, API Gateway accepts an API key, as well as JWT, to authenticate `tools/list` on MCP servers. Discovery remains unauthenticated by default; when enabled, clients send the key in the `x-api-key` header.

Why it matters

Editorial implication: protect the tool inventory, but do not mistake authenticated discovery for execution authorization. `tools/call` inherits the underlying operation policy, so validate identity, scope, quotas and destructive operations separately, and avoid accidentally exposing every eligible tool.

Read original source ↗

Apigee hybrid 1.17.1 fixes SSRF and expands operator RBAC

Released September 30, Apigee hybrid 1.17.1 fixes an SSRF issue in `SemanticCacheLookup`, hardens the `JavaCallout` sandbox and blocks calls to internal Kubernetes hostnames. It also grants the operator namespaced permission to manage `Endpoints`, even when external Cassandra is not used.

Why it matters

Editorial implication: prioritize the patch and diff the Role before and after upgrade. The fixes reduce known internal-access paths, while the ability to create and change `Endpoints` increases the impact of operator compromise; monitor those actions and keep the grant namespace-scoped.

Read original source ↗

Dependabot adds repository-level runner configuration

On September 29, GitHub let administrators of private and internal repositories choose the runner type, label and group for Dependabot version and security updates. Labeled runners can reach private registries or specialized environments; security configurations do not yet enforce these settings.

Why it matters

Editorial implication: treat the runner as part of the software-supply-chain trust boundary. Restrict egress and credentials, segment groups by criticality and verify each repository because applying a security configuration does not guarantee the intended runner.

Read original source ↗

GitHub syncs external business context into repositories

In public preview from September 29, external custom properties can sync ownership, criticality, lifecycle and compliance data from a CMDB, internal portal or another system. Values are read-only in GitHub and can drive filtering and ruleset targeting.

Why it matters

Editorial implication: make the external system an explicit source of truth and tightly scope the integration permission, while monitoring lag, missing values and sync failures. Rulesets driven by stale metadata can enforce controls on the wrong scope.

Read original source ↗

GCP API Gateway can now stream LLM traffic

In preview from September 29, API Gateway supports incremental responses, SSE, WebSockets and bidirectional gRPC. Streaming mode is fixed at gateway creation and cannot be changed; Model Router gateways enable it automatically.

Why it matters

Editorial implication: long-lived connections change timeout, cost and observability boundaries. Verify the effective mode, authenticate the consumer as well as the backend, apply quotas and test interruption, partial content and logging instead of assuming controls designed for buffered responses cover the stream.

Read original source ↗

Google discloses three Application Integration vulnerabilities

On September 28, Google published bulletins GCP-2026-064, 065 and 066: incorrect authorization and deserialization were rated critical, while an Email Task confused-deputy issue was rated high. The vendor says fixes were applied in June and no customer action is required.

Why it matters

Editorial implication: even without a customer patch, review who can author tasks and integrations, preserve logs from before remediation and verify whether privileged identities were used unexpectedly. A service fix is not evidence that exploitation did not occur.

Read original source ↗

Cloud Asset Inventory now inventories agent identity providers

Since September 28, Cloud Asset Inventory exposes `agentidentity.googleapis.com/AuthProvider` resources through export, history, feed, query and resource/IAM-policy search APIs.

Why it matters

Editorial implication: add agent identity providers to continuous inventory and link each resource to an owner, policy, scope and change date. The new visibility does not replace authorization controls or prove that every agent credential is covered.

Read original source ↗

Cloud SQL removes export permission from viewer roles

On September 28, Google removed `cloudsql.instances.export` from Cloud SQL Viewer, Basic Reader and Basic Viewer for MySQL, PostgreSQL and SQL Server. Workflows that still need export must use Cloud SQL Editor or a custom role with the explicit permission.

Why it matters

Editorial implication: find jobs, service accounts and recovery routines that relied on inherited access before broadening roles. Prefer a least-privilege custom role and monitor `instances.export` as data access with exfiltration potential.

Read original source ↗

Copilot introduces a default policy for unconfigured features

Announced September 24, the policy takes effect October 22, 2026 for eligible generally available features. Explicit decisions are preserved; previews remain opt-in.

Why it matters

Editorial implication: inventory unset policies and record the administrative decision before enforcement begins. Include MCP servers and code review in the access assessment.

Read original source ↗

GitHub Enterprise adds credential inventory exports

Since September 21, 2026, Enterprise Cloud offers CSV export and a paginated API for credential inventories. Access requires enterprise ownership or the View enterprise credentials permission.

Why it matters

Editorial implication: correlate metadata with audit logs to investigate access and prioritize revocation. Protect exported inventories; listing credentials does not automatically revoke them.

Read original source ↗

Google exposes API key management through a remote MCP server

In preview, the API Keys API remote MCP server lets AI applications list, inspect, create, restrict, update, delete, undelete and look up keys. One tool can also retrieve the secret API key string, which the documentation classifies as highly sensitive.

Why it matters

Editorial implication: treat this MCP endpoint as a privileged control plane, not ordinary agent context. Separate identities for reading, mutation and secret access; deny secret retrieval by default; require approval for changes; and log arguments and outcomes without persisting the key in logs or model memory.

Read original source ↗

Agentic Autofix now reuses patterns through Copilot Memory

GitHub says that when Copilot Memory is enabled, Agentic Autofix reviews memories for context while resolving security alerts and may store the fix pattern for future use. Those memories can also inform other features such as code review and the cloud agent; both capabilities are in public preview.

Why it matters

Editorial implication: memory expands the trust boundary across fixes and features. Define repository scope, retention and who may write or consume memories; defend against poisoned context; and retain review, testing and rollback for every patch. A pattern that worked once must not become a universal security exception.

Read original source ↗

GitHub adds in-product validation for Copilot managed policies

GitHub added a validator that detects malformed JSON, unsupported configurations, invalid team mappings and other errors that can prevent Copilot managed policies from being enforced. Results identify the affected file and JSON path across managed-settings and team-mapping files.

Why it matters

Editorial implication: the validator reduces silent configuration failures but does not prove that policy is effective on every endpoint. Treat the files as code with review and branch protection; test negative scenarios and actual client behavior; and monitor drift between accepted configuration and observed enforcement.

Read original source ↗

CodeQL 2.27.1 expands data-flow models and language support

GitHub released CodeQL 2.27.1 with Kotlin 2.4.20 support, new data-flow models for C/C++, Go and Rust, and improved recognition of Fastify routes in JavaScript/TypeScript. The release also adjusts security queries for C#, C/C++ and GitHub Actions workflows.

Why it matters

Editorial implication: manage the SAST engine version as a controlled pipeline dependency. Before broad rollout, compare the new baseline, investigate added or removed alerts, and verify whether more accurate models change existing exceptions; a clean result is not proof that no vulnerability exists.

Read original source ↗

GitHub adds proof of presence to high-impact actions

In public preview, GitHub Enterprise Cloud can require interactive reauthentication or MFA before actions such as creating tokens, changing webhooks, modifying security settings or viewing recovery codes. Initial scope is limited to EMU enterprises using Microsoft Entra ID through SAML or OIDC, and the validation remains effective for two hours in the browser session.

Why it matters

Editorial implication: a valid credential and session are no longer sufficient evidence for critical operations. Rollout should map high-impact actions, combine MFA with device and risk policies at the IdP, test emergency accounts, and retain the challenge, decision and action trail for later investigation.

Read original source ↗

Apigee hybrid 1.15.8 hardens tokens, JSON and AI protection

Google released Apigee hybrid 1.15.8 with fixes for JWT refresh-token revocation, HTTP 103 response desynchronization, JavaCallout and SSRF in AI protection policies. The release can also reject duplicate JSON keys and updates components with security fixes.

Why it matters

Editorial implication: this is a new event in the 1.15 train, complementing the earlier 1.16.10 news. Teams should confirm their supported train and test revocation, interim responses, ambiguous JSON and destinations reachable by AI policies before and after patching, without assuming branches are equivalent.

Read original source ↗

GitHub Copilot adds per-project local sandboxing

GitHub released local sandboxing for the Copilot app in public preview. The policy can restrict folders, network access and credentials per project; if the operating system cannot enforce it, the session fails instead of starting without isolation. The feature is off by default and applies to new or restarted sessions.

Why it matters

Editorial implication: enable and test a minimum policy per repository, allowing only the directories, network destinations and credentials that are required. Sandboxing reduces the blast radius of unintended commands, but it does not replace code review, secret protection or approval for sensitive actions.

Read original source ↗

Apigee API hub expands inventory to AWS and Azure

Google Cloud announced public-preview API hub connectors for AWS API Gateway and Azure API Management, with automated discovery, a full sync every six hours and optional near-real-time events. On the same date, links among specifications, operations, deployments and gateway revisions became generally available.

Why it matters

Editorial implication: a central catalog is not an access control. The architecture should apply least privilege to connector credentials, validate orphan-API deletion, assign ownership, and monitor delays or failures in the event path so inventory and reality do not drift silently.

Read original source ↗

Cloud EKM adds migration for external-key access

In preview, Cloud EKM can create new versions using either EXTERNAL or EXTERNAL_VPC protection and change the protection level of existing external versions. Google says the migration retains the key material and can occur without downtime or application reconfiguration.

Why it matters

Editorial implication: treat the vendor's continuity claim as a hypothesis to validate. Before changing access, test connectivity and fail-closed behavior, preserve dual control and audit continuity, measure latency, and document rollback so migration does not weaken governance or recovery.

Read original source ↗

Model Armor updates filters and schedules version retirement

Google Cloud set filter v4 as Latest and promoted v3 to Stable in most regions; v1 and v2 move to Legacy with retirement scheduled for December 17, 2026, subject to the vendor's regional exceptions.

Why it matters

Editorial implication: inventory templates pinned to older versions, test false positives and negatives with v3/v4, and plan migration before retirement rather than treating the Latest alias as risk-free.

Read original source ↗

Apigee hybrid 1.16.10 fixes SAML, OAuth and SSRF issues

Google's September 17 notes record fixes to ValidateSAMLAssertion, link-local SSRF blocking and OAuthV2 policy hardening, along with security updates across Apigee hybrid components.

Why it matters

Editorial implication: confirm the deployed version, prioritize the upgrade according to exposure and support, and rerun SAML assertion, OAuth parameter and script-egress tests after the update.

Read original source ↗

Google Cloud expands session controls

Google announced session policies by group and application, managed through Terraform, gcloud and APIs. Cloud Console administration is in preview.

Why it matters

Architecture decision: assess privileged-access reauthentication and test effects on OAuth integrations.

Read original source ↗

GTIG reports growing agent-enabled attacks

In its second-quarter report, GTIG describes offensive agent automation and attacks targeting credentials and AI assets.

Why it matters

Secure RAG connection: review permissions, protect sources and retain evidence of agent actions.

Read original source ↗