senn-techsenn-tech
IT News
Week 2026-W382026-09-20

IT News Week 38/2026: NISG form from 1 October, the decision model Jev, the TrueNAS fix in the .deb

CRANISGNext.jsJevTrueNASProxmox VERTX Pro 5500

Two layers: the week's news and what it means in our own operation. Everything fetched again on 20 September 2026, two claims from last week now stand right.

Deep dive: The CRA clock running, the NISG form arriving later

Correction: the form exists, just not before 1 October

Last week we wrote that Austria's registration portal does not exist. Outdated. The Company Service Portal has announced since 08 September 2026 that the application "NIS 2 Services" goes online in the USP as the NISG 2026 takes force on 1 October 2026, for registration and incident reports, deadline "initially by 1 January 2027". The same day the site of the new Federal Office for Cybersecurity goes live at the interior ministry, the agendas sit there and at the BMI, not at the RTR, whose old NISG page returns 404. The WKO FAQ names the same window, 1 October to 31 December 2026, plus the fields from § 29 para. 2. Binding remains BGBl. I Nr. 94/2025, two-tier thresholds, 50 employees or EUR 10m turnover and balance sheet total, in a group the association counts, fines from EUR 50,000 for registration breaches to EUR 7m or 1.4 per cent of group turnover.

Four jobs before 1 OctoberDetermine size and sectoremployees, turnover, balance sheetClarify group affiliationallocation to the associationName a contact personreachable 24/7, not just office hoursCheck the USP accesswithout access nothing runs from 1 October
The portal is a date, the preparation is work. The fourth line is the one most often missing on 1 October. Both duties end at the managing director, and who clarifies size, sector and group affiliation before October keeps a three-month buffer. (Quelle: NISG 2026, BGBl. I Nr. 94/2025; USP announcement of 08.09.2026; WKO NIS-FAQ)

The Cyber Resilience Act reporting duties apply since 11 September 2026, early warning within 24 hours, full notification within 72, final report 14 days after a corrective measure is available, over the ENISA platform. No new clarification of who counts as a manufacturer came from the Commission or ENISA this week. The clock starts with knowledge of the exploitation, played through in the CRA reporting manual. Germany is further, the NIS2UmsuCG applies there since 6 December 2025 with around 29,500 entities, the BSI portal stood live on 6 January 2026.

Assessment: Both duties end at the same table, at the managing director.

Two reporting clocks, the same nightlogarithmic axis, hours from awareness24 h72 h14 days1 monthNISG 2026Incident, BMI/CERT.atInitial reportInterim reportFinal reportCRA Art. 71Product, ENISA platformEarly warningFull notificationReport after measuresevere incidentAwareness starts the clock. Both chains run in parallel and do not line up.
Deadlines per statute and authority descriptions, as of September 17, 2026 (source: European Commission, CRA reporting)

Deep dive: The gap without a CVE number, and our own endpoint

The advisory GHSA-2xp9-vwfh-vxw4 of 8 September 2026 describes unauthenticated remote code execution over AVIF files in the image optimization API, root cause libheif, reached through sharp. Affected: >= 10.0.0 below 15.5.24, >= 16.0.0 below 16.3.3. No CVE number on the entry, so scanners working off CVE lists miss it, and AVIF optimization stays disabled only while the fix is missing, a state and not a patch.

From request to code executionAVIF request to /_next/imagewithout authenticationsharp calls libheifimage path, not Next.js logicHeap overflow in libheifpossible code executionFixes 15.5.24 and 16.3.3tidying up does not help before
The entry point is a route that sits in the build, whether or not anyone uses it. Both gaps disappear through structure: an endpoint check in the build pipeline, error isolation in the patch run. (Quelle: GitHub Advisory GHSA-2xp9-vwfh-vxw4, 08.09.2026)

CVE-2026-75604 is older and narrower, NVD 9.0, published 1 September 2026: Windows hosts without Cache Components mask backslashes in route segments inconsistently, one remote request can leave the cache directory and expose build data including the server manifest key. Fixed in 15.5.24 and 16.3.3, afterwards rotate the NEXT_SERVER_ACTIONS_ENCRYPTION_KEY.

The test bench was our own site, measured on the version in the build directory, next 16.2.12, right in the affected span. The endpoint answered instead of refusing, /_next/image returned 200 with image/png for a real asset, although next/image is nowhere in use. The route does not ask about use. This edition appears after a rebuild above 16.3.3, framed in the Next.js post.

Operations, same week: one host ended the nightly patch run with apt exit 100, 19 packages open, 5 of them security updates. The queue behind it was not empty but unprocessed, every host behind that position got neither patches nor CVE comparison, logged as a terse "failed". A second node stayed blind across 13 runs, a changed host key let the CVE watcher abort, correct behaviour that ended as a footnote in the log. Both changed in the patch-run post and the patch management frame.

Assessment: The image optimizer gap was one patch release away, the blind night a formatting problem in the run itself.

Deep dive: Jev, a decision model without chat, on our GPUs

On 15 September 2026 TypeSafe AI presented Jev as the first "System One Model". Neither chat nor reasoning, the model returns no sentences but typed decisions, a Choice of at most 255 options, a score, a noun, each with a probability. Access: a hosted US API with a waitlist, no open weights. The vendor numbers are aggressive, 0.042 USD per million input tokens, output free, 70 to 500 ms, on the front page 193.6 times faster and 444.6 times cheaper. Heavier than those numbers: the evaluation reference is agreement with GPT-6 Astra and Claude Fable 5.1, agreement rather than correctness.

Saving against the reference, factorVendor claim444.6 · 444.6x cheaper, own evalsCounter-measurement best case14 · v1.13.0, 1/14 of the referenceCounter-measurement worst case6 · 1/6, not 1/4450489
Two orders of magnitude lie between advertised and measured. The counter-measurement comes from early access, it is a single finding, but a traceable one. For an operation with its own inference chain the answer is a pilot on own GPUs, not a US contract. (Quelle: TypeSafe AI (own claim) against the Lindfors counter-measurement, 18.09.2026)

The counter-calculation came from Lindfors on 18 September 2026 over 24 Norwegian documents. On the stance decision Jev ties at 20 of 24 with DeepSeek V4.1 Flash without reasoning, only the score task wins clearly, and real costs lay at one sixth to one fourteenth of the reference, not 1/445. Good Start Labs measured 86 to 92 per cent agreement with five other models on 6,003 checks, the models among themselves 88 to 95 per cent, Hacker News at 1,909 points and some 500 comments.

For us the frame decides before the performance: no EU region, no self-hosting, no weights, so Jev is unusable today for personal and NIS2-relevant data, and no LiteLLM provider exists. The contract is rebuildable in-house with the Python adapter on own vLLM endpoints, and the jaggedness page itself lists what fails, no counting, no date sequences, adversarial content can move the answer.

Assessment: Jev is a classifying switch with a probability, measurably cheap for routing and triage.

Deep dive: TrueNAS plugin, the HA fix is in the .deb, not in APT

Two days after our plugin post, v2.1.23-beta4 appeared on 19 September 2026 at 03:11 UTC. We read the postinst of the tag, it now restarts pvedaemon pveproxy pvestatd pve-ha-crm pve-ha-lrm and knows an escape with TRUENAS_PLUGIN_NO_RESTART=1. The issue #100 fix is now inside the package, and iXsystems marks this release itself as prerelease, the three betas before it were not.

The catch is the route the documentation shows. Counted again on 20 September, install.sh holds no pve-ha restart anywhere in main, alpha and beta4, and the signed APT repo still serves 2.1.17+deb1 of 1 July 2026. Whoever installs per the guide through APT has issue #100 unchanged, twelve weeks behind. The docs page still shows api_host, its footer names 26 March 2026 as last change, and the warning stands verbatim, "Do not use in production workloads". Open on 20 September: 46 issues, 87 per cent of posts from one person.

Proxmox logo
The integration runs over the Proxmox interface, the package is delivered by iXsystems. (Quelle: Proxmox Server Solutions GmbH, Wikimedia Commons, Public Domain)
Three install routes, one of them fixedinstall.sh per the docsno pve-ha restart, all branchesSigned APT repo2.1.17+deb1, as of 01.07.2026.deb beta4 of 19.09.postinst restarts pve-ha-crm/lrm
Identical software, three delivery paths, different state, whoever follows the docs takes the oldest. On our inventory it stays a test bench, one TrueNAS owns every Zvol, replication the plugin does not know, shared storage stays LINSTOR/DRBD. What is won is a rule: after every custom storage backend, restart pve-ha-crm and pve-ha-lrm and test before the emergency comes. (Quelle: GitHub: tag v2.1.23-beta4 postinst, install.sh, APT Release of 01.07.2026, all fetched on 20.09.2026)

Digest: More news that matters

Security and operations

  • Three kernel gaps in the KEV, due 21 September: CVE-2025-39964, CVE-2026-53266 and CVE-2025-39682 added as actively exploited on 18 September. Local privilege escalation on a hypervisor host lifts guest isolation, unprivileged user namespaces as entry are standard on container hosts. No Proxmox advisory, the announcements end at 2 September, a Debian kernel topic.

  • Grafana, RCE unpacking plugins, still no fix: CVE-2026-15815, high, published 17 September. Prepared archives chain relative symlinks out of the plugin directory, unpacked before the signature check, and the advisory names no patched version, CERT-Bund. No update call but a lever, GF_INSTALL_PLUGINS empty.

  • Nextcloud, RCE through the preview: high, published 17 September, without a CVE, the path runs over the preview of corrupt files in Imagick. Recommended 32.0.13, 33.0.7 and 34.0.2, equivalents: Imagick out of PHP, enable_previews false.

  • n8n, 15 advisories of 16 September: fixed in 2.39.6, 2.40.1 and 1.123.80. CVE-2026-92587 hits our exact configuration, a git node with a relative URL against a forge, workaround n8n-nodes-base.git in NODES_EXCLUDE, as in the n8n post.

  • Unbound, critical heap overflow, Alpine old: CVE-2026-81642 of 16 September, affected up to and including 1.26.0, fix 1.26.1 the same day. Alpine 3.23 packages 1.25.2-r0, 1.26.1 only in edge. A resolver built at night from alpine:latest delivers that version, regardless of source pinning.

  • Caddy, placeholder injection in rewrite, fixed in 2.11.4: CVE-2026-77281, medium, published 18 September, affected up to 2.11.3. A rewrite URI ending in a literal question mark lets attacker-controlled substitutions run a second placeholder expansion. Broader than our Caddyfile post: secrets in expandable environment variables are the exposed surface.

  • Windows 11, domain devices locked out below Server 2025: from KB5124008 Windows takes Machine Identity Isolation into account, without enforcing it, yet devices with the feature enabled below that domain functional level lose interactive sign-in. The remedy, registry values from 2 to 0, restart, then Test-ComputerSecureChannel -Repair, is on that page.

  • CrowdSec, 170 private repos copied over an old access: the attacker used the still-open GitHub access of someone who left in May, his device compromised through prepared npm packages from TanStack. One endpoint, one forgotten access, with us the Gitea check at offboarding.

Models and inference

Infrastructure and storage

Hardware

  • RTX Pro 5500 Blackwell, 84 GB, no price, no delivery date: the product page is online as of 20 September, reads "Coming Soon" and names the specs preliminary. ComputerBase confirms the 21,760 FP32 units on GB202 and the dual blower cooler, PNY confirms 1,398 GB/s, Geizhals carries the card since 14 September with 0 offers in Germany and Austria. No Austrian street price, no independent token measurements, the card is six days old, recalculated in the comparison post.
Memory bandwidth in GB/sRTX 5090, 32 GB1792 · GDDR7RTX Pro 5500, 84 GB1398 · 78 per cent, 2.6x the VRAM01971
Same core count, different ceiling, 1,398 against 1,792 GB/s are 78 per cent of bandwidth with 84 against 32 GB of VRAM. Capacity is paid for with bandwidth, not with compute, and without a delivery date it stays a calculation. (Quelle: NVIDIA product data, RTX Pro 5500 marked as preliminary)
The next genuinely measured data point on the Blackwell Pro class, by Gamers Nexus on 24 June 2025, thermals, noise and LLM runs on the RTX PRO 6000. Explicitly not the Pro 5500, which was not on the market at that test.
  • RTX 5090, no first-party stock, listings up to 9,500 USD: Tom's Hardware finds no offer from the platforms themselves at Amazon and Newegg, PCGH counts on 15 September an Asus TUF from 6,395 USD at a marketplace seller against 4,299 USD median in June and 5,249 EUR at the cheapest dealer here, ComputerBase lies above 6,000 EUR in the median of newly listed German offers, in Austria 5,849 EUR for a ROG Astral in the Geizhals. Listings, not transactions, marketplace accounts with 81 per cent positive ratings. The GeForce licence still says "No Datacenter Deployment" from December 2017, and the RTX Pro 5500 aims there.

  • Memory prices, the curve points up: 3dcenter laid the September index for German end-customer prices, template the TrendForce line of plus 12 to 15 per cent on conventional DRAM in the fourth quarter.

Compliance and business

Mainstream support for Windows Server 2022 ends 14 October 2026, extended support to 15 October 2031.

Sources for this edition

Primary sources first, then the framing. We called every address ourselves on 20 September 2026.

What we could not substantiate, and therefore do not write as fact: a price, a delivery date and a CUDA core count from NVIDIA itself for the RTX Pro 5500, the page names everything preliminary and the dealer lists in Germany and Austria were empty on 20 September; any independent token measurement on this card; the architecture, the parameter count and the training data of Jev, the 200 times figures have been reproduced by nobody, and what was measured was Norwegian, not German; the Forbes report on the valuation, the page was not reachable for our fetch; the subprocessor list of TypeSafe, it is loaded by script; an NVD score for the Unbound CVE-2026-81642, the entry stood at publication on "Awaiting Analysis"; full texts from TechPowerUp, VideoCardz and pcwelt, which refused us on all three; a statement by NVIDIA on the supply situation of the RTX 5090; and a Proxmox advisory for this week, there is none, the kernel gaps belong to the Debian kernel of the hosts.

From the blog


Compiled on 20 September 2026, as of 07:00 CEST, with own measurement on the site and in operations, all sources in the block above.