IT News Week 39/2026: MiMo takes the open top spot, Technitium's token oracle, Stalwart ate rules updates in silence
The weekend turned out to be the busy part of the week. MiMo v2.6 landed on Sunday morning and took first place among open models on one index score. Technitium 15.5.1 followed on Saturday with an odd defect: a session token that could be probed from outside. Stalwart 0.16.24 carries the fix for a fault nobody had noticed, because it never reported an error. Rule updates never reached existing installations, and block lists stayed six weeks old while the admin UI kept calling the import a success. Every version state here was read again, on 27 September on most hosts and in the small hours of 28 September on the GPU, identity and backup machines. The RTX 5090 correction from last week is in here too, one step further than we first printed it.
Deep dive: MiMo v2.6 leads the open models, and our cards are too small for it
Xiaomi published MiMo v2.6 on Friday evening and Sunday morning, in three variants: the RL checkpoint on 21 September, and on Sunday at 03:58 and 04:01 UTC two more builds from the same on-policy training line, one tuned for speed and one for agents that call tools.
The number behind the headline: MiMo-V2.6-Pro-RL scores 46 on the Artificial Analysis Index, good enough for first place among open models. GLM-5.3 sits at 45, Kimi K3 at 44. The best proprietary model reaches 58, and V2.5 Pro from April scored 26. Twenty points for the same vendor inside half a year, two points of lead over the rest of the open field. On a leaderboard a two-point lead is one re-run away from being gone, the twenty points are the fact.
What the index does not carry is the size. The Pro-RL checkpoint is a Mixture-of-Experts with 1.02 trillion parameters, 42 billion active per token, 70 layers, 384 experts with 8 active per token, and a context window of 1,048,576 tokens. The weights fill 534 GB across 130 files. Measured on our inference host, four cards give 130,428 MiB of video memory, so we cannot even hold the weights. The Flash build needs 166 GB, ggml-org's own Q2_K build 117 GB. What would actually run here is the small sibling of the family, 9 billion parameters and 5.4 gigabytes as Q4_K_M, a comparison candidate against our Qwen lane. For this size class our path stays an API connection. The figure that concerns us most is the licence: MIT, without usage restrictions, in a class where Apple two days later puts a model built on an open base under a non-commercial licence.
Assessment: we stay away from the 1.02 trillion variant, it does not fit here. The two-point lead over GLM and Kimi is thin and will move on the next re-run, the twenty points the vendor gained on itself in six months say something about how fast open releases move now. Our own three-year estimate for reaching a usable level was too pessimistic. We measured what we can carry, and that is the small one. The 27B in ternary format from PrismML stays the practical candidate for our fleet, with its known limits named in the linked post.
Deep dive: Technitium 15.5 and 15.5.1, ten security fixes and a token oracle
The quietest news week in a long time produced the loudest patch notes. Technitium v15.5.0 arrived on 19 September, four days before our window, which is exactly why it stays on top: it is the largest security package this software has ever shipped. Verified on the release page and in CHANGELOG.md, the two sources agree. The changelog names the class of fixes, all with external reporters, among them Palo Alto Networks and three university labs. Eight days later came v15.5.1 of 26 September, five fixes, two of them security, and the first one reads like a warning addressed to every web UI that works with tokens. An attacker could tell from outside whether an API key prefix was valid or not. Anyone who can separate "right so far" from "wrong here" can work a token forward character by character. On top, a cross-site scripting hole in the Logs view, where entries reached the page unsanitised. The other three are small and sit in daily use: a skipped check on the zone transfer, wrong sorting in API results, and RDATA validation failing under DNS over TLS.
- Multi-hop amplification at a ratio of 4,096:1 over CNAME and delegation hops, one small query, a thousandfold answer load at third parties.
- Cache poisoning over an out-of-bailiwick DNAME, plus a DNSSEC validation bypass through DS records smuggled into referrals. For a resolver that carries our mail delivery, ACME and DANE, this is the base layer under every delivery.
- Off-path CNAME poisoning with redirection to attacker domains, a DoH/3 out-of-memory denial of service, and a persistent denial of service against one target domain that clears only on a restart.
- An authorization bypass through the ptr option of the add, update and delete record APIs: PTR entries in any reverse zone, without entitlement. On top, several stored XSS and a zone-name bypass in Clone Zone.
- Then one removal with no CVE: Auto Prefetch is gone. Whoever relied on it has to replan. For affected setups that is a breaking change, dull as that word sounds.
Measured again on Sunday evening: all three nodes run the image technitium/dns-server:15.4.0, our own containers up four and fifteen hours. That reads as two releases behind, one week after 15.5 and one day after 15.5.1, with three nodes that have no cluster link between them. So three manual passes, with parity produced only through the API. The plan is all three on 15.5.1 in one pass this week, and nothing else in the same window.
Assessment: the only entry this week with mandatory character, and the decision backlog is self-made. Anyone running a resolver under mail, ACME and DANE should not keep a package waiting three weeks that fixes a poisoning bug, a DNSSEC bypass and a token oracle at once. The roll itself is a quarter of an hour per node; the parity check afterwards is the work.
Deep dive: Stalwart, Zammad, n8n, one update train with four wagons
Stalwart 0.16.23 and 0.16.24, the silent message loss and the rules that never arrived
On 27 September, shortly before midnight central European time, v0.16.24 followed, and two entries in it matter to a mail host directly. First: a JMAP client that set the mailboxes of a message to their current value while changing a keyword wrote that message into the store with IMAP identifier 0, and IMAP clients stopped seeing it. Second, and the more unpleasant one: rule updates never reached existing installations. New objects were added, changed DNSBL servers, HTTP lookups and lookup keys were not, and a failed import was still reported as a success. Anyone who has relied on current PhishTank and OpenPhish lists for weeks may still be running the state of six weeks ago. The same release fixes that entries with upper-case letters in them never matched, because the URLs in the message were compared in lower case. Plus a VAPID fix on the aud claim, which until now came out of a hand-written parse of the push URL, and an MTA fix for a node without the outboundMta role that stopped answering DATA after roughly 1024 queued messages.
Version 0.16.23 of 21 September has no security section in its notes, and we say that up front. We read four of the fixes as security-relevant ourselves, that is our assessment while upstream attaches no label to any of them. The most serious one: a DSN that could not be written to the store was discarded, the recipient was marked as notified and the original message was removed from the queue. Bounce gone, mail gone, queue green. Next an OIDC fix, where bearer tokens without an identity claim were always authenticated against the default directory, and a TLSA fix: a failed or bogus DANE lookup no longer stopped the delivery. Breaking changes: none, the notes say replace the binary or docker pull.
Read off the host: our mail host runs stalwartlabs/stalwart:v0.16 with the running binary version 0.16.23, container up for 33 hours, read on 27 September. So 0.16.24 is not in yet. The riskiest update in this issue is already installed here, the small follower from Sunday is not.
Zammad 7.2.0, the two traps
Zammad 7.2.0 appeared on 23 September, the date verified twice through the tag commit and the vendor page. The content is substantial: a tamper-proof admin audit log, a modular spam framework for web forms, AI reply suggestions from solved tickets, self-hosted videos in knowledge base articles. The traps are in BREAKING_CHANGES.md, section 7.2, no speculation:
- The shipped nginx and Apache configs clear
Forwarded,X-Forwarded-SchemeandX-Forwarded-Ssl, onlyX-Forwarded-Protocounts now. The Docker images rebuild their nginx config on every start, so the change takes effect automatically at the next boot. If HTTPS used to arrive only through the proxy, the instance stands on http after the update. Fix:NGINX_SERVER_SCHEME=https. POST /api/v1/links/addanswers 422 instead of 201 when creating a link fails. Any integration that reads 201 as success then runs silently into nothing.- After the update an Elasticsearch reindex is mandatory, otherwise the new audit log stays incomplete.
docker ps shows: on the Zammad host ghcr.io/zammad/zammad:7.0.0-9, Elasticsearch on 9.3.1. From 7.0 to 7.2 is two minor jumps, the reindex on top, and the proxy-header trap hits our Docker chain with full force. The roll is therefore not a click but a plan with a test clone first. The 17 bundled advisories of the versions up to 7.1.2, among them account takeover through SSO auto-link and RCE through the AI agent sanitizer, have been patched since 7.1.3 of 25 August. Anyone still on 6.x or an older 7.x is not patching comfort but a known collection of entry points.
n8n, or: the weekly train is rarely a security update
Twelve releases between 21 and 25 September. On the stable branch those are 2.40.6 of 24 September and 2.40.7 of 25 September, the 2.41.x line is the beta branch with 2.41.3 of 25 September. The 15 advisories of 16 September, twelve of them high, had according to patched_versions already been fixed before our window in 2.40.1, 2.39.6 and 1.123.80 respectively. One default flip still deserves a note: 2.41.1 turns Agents on by default, and the notes name no migration path for switching it off. Anyone running n8n in production with MCP or webhooks should know which surfaces that opens before an update flips it.
Assessment of the section: four systems, four different trap types, one pattern. The updates themselves are small, the side effects sit in configs, headers and defaults. Whoever applies them wins, whoever applies them without a clone is betting.
Keycloak 26.7.4, our instance measured, and one hole still open
Keycloak 26.7.4 came on 16 September with eleven fixes and no CVE advisory among them. More important are two reports from the same branch that were only published this week. The first is CVE-2026-90997, published on 17 September and tracked at Red Hat under Bugzilla 2533141: when Keycloak runs stateless with MySQL or MariaDB, the semantics of the row count read by the database driver and by the application logic disagree, and replay protection can be walked around with that. Anyone who catches a single-use item, a JWT client assertion, a DPoP proof or a TOTP code, simply presents it again at the token endpoint or in the login flow. The entry names no usable version band. The second, with no fix available and CVSS 4.2, is GHSA-5jw9-cc9v-8h8r: the enforcement of the level-of-authentication step is missing when authenticating over an existing session set. Anyone who uses LoA steps or ACR classes for sensitive areas may end up with a session that is too weak. State on Sunday evening: still unpatched, for five days.
Measured, not guessed: this time we could read the host. On the identity machine, quay.io/keycloak/keycloak:26.7.1 with KC_DB=postgres in the environment, from docker inspect in the night before Monday. The precondition of CVE-2026-90997 is therefore not met, our instance does not run stateless on MySQL or MariaDB, it hangs off Postgres. That leaves the LoA advisory without a fix on 26.7.1 as well, and the jump from 26.7.1 to 26.7.4 stays a small maintenance update.
Security: three findings that would have hit us at home
Looking outward would be half the job if we were not standing in one of the affected bands ourselves. We measured three findings from this week against our own environment.
Next.js, our own blog engine. Next.js 16.3.6 of 22 September closes a remote code execution rated critical in next/og, more precisely in Satori, the component that parses the HTML fragments handed to it. The advisory puts the affected range at every version from 16.2.0 below 16.3.6, and our package-lock.json stood on 16.3.5. We render graphics from the frontmatter data of our own articles, with no foreign HTML input, so this was not exploitable here. We patch anyway, to 16.3.6 at this state, because the exposure does not start with us but with whoever feeds ImageResponse content from user input. On the LTS branch there was only hardening in 15.5.26, and 15.x is not affected.
Proxmox Backup Server, the integrity of our backups. PSA-2026-00051-1 of 24 September is the more restless find, because it hits exactly the layer that makes a backup trustworthy. A client with an encryption and signing key configured silently accepted a manifest without a signature. Whoever could write on the PBS server could swap a signed manifest for an unsigned one, and the restore did not check. Confidentiality stays, integrity is gone, and with it the answer to whether this state really came from our encrypted backup. Fixed in proxmox-backup-client from 4.2.6-1, the same for proxmox-backup-file-restore, and on the PVE side in libproxmox-backup-qemu0 from 2.0.3, reported by Shaun Mirani and independently by Project Loupe. Measured on our backup host pbs3: proxmox-backup-server and proxmox-backup-client at 4.2.6-1, from dpkg -l at 01:00 CEST on 28 September, so the server side sits on the fixed state. What we could not measure is libproxmox-backup-qemu0 on the six Proxmox nodes, the API path to the package lists demands rights our token does not have, and answers 403. Those exact packages are what writes from the nodes onto that server, so they stay on the follow-up list.
Container escape over AF_UNIX, and whether we would be reachable. CVE-2026-80521, CVSS 7.8, a race in the garbage collection of AF_UNIX socket inodes, public exploit included, Ubuntu status on Sunday "Vulnerable, work in progress". Standard Docker does not protect against it, the default seccomp profile lets AF_UNIX through. The second part of the story is the reason we measured at all: Carbonato, a botnet that goes through the unprotected Docker API on port 2375. It starts a privileged container, takes the host through it and installs the Hermes agent framework, whose persona file SOUL.md the operators swap for a 39-line prompt that names the agent GH0ST. Every five minutes the infection scans its own networks and Docker bridges for further hosts with an open 2375, counter-commands run over reverse SSH, and what gets collected are API keys, SSH access and tokens. We connected port 2375 against seven of our hosts, from .180.1 over .180.3 to .201.88, and all seven refused. That path is closed here. What stays open is the kernel underneath: our six Proxmox nodes all run Linux 7.0.2-6-pve with pve-manager 9.2.20, all started on 23 or 24 September, uptimes between 356,648 and 371,713 seconds, measured through the cluster API on 27 September. Whether the AF_UNIX fix is in our kernel backports cannot be read from here, the update endpoint of the API answers 403 for our token. That counts against three kernel entries that have been in the KEV since 18 September, all with a due date of 21 September.
Deep dive: Microsoft 365, the data-location switch runs the other way
By 14 December 2026 it is decided for eligible commercial tenants in Germany, France, Norway, Sweden and Switzerland whether customer data stays inside national borders. The switch Store Microsoft 365 customer data in-country is disabled by default, and without a click Microsoft may distribute data anywhere inside the EU data borders. Austria is not on the list of eligible countries, which still touches every company with a declared German location. The message centre notice itself is not readable without tenant access, and there are reader reports of the option being greyed out; the deadline plan stands regardless. It is data-protection neutral, commitments to customers and auditors are not. Whoever finds the switch only after the date has to plan a return migration of up to six months.
Assessment: twenty minutes in the admin centre, that is all it is, and the two minutes on the data-location map are worth knowing for Austrian tenant administrators anyway. The post on it links the sources and the wording of the notice in a mirror.
Correction: the RTX 5090 figures from last week
Our week 38 edition gave the 5090 price situation with a US reference that sounded newer than it was. State today, measured against the primary sources: the PCGH article "not below 5,200 euros" carries the date 10 September in its JSON-LD, minimum 5,249 euros for a Gigabyte Gaming OC at Cyberport and Computeruniverse, and nothing below 5,365 euros on Nvidia's own marketplace. A live tracker (gpuprix.com, Alternate listings, a secondary source) showed on 24 September a low of 5,392 euros, in-stock models from 5,590, a 12-month median of 3,399 and a 12-month low of 1,200 euros. The trend was right, the calendar date belongs with it. From now on we carry the figure only with its measurement time. Re-measuring on Sunday surfaced a second error in our own source: the tracker lists 5,392 euros as the cheapest entry, and that is an Acer Predator Helios 18 laptop at Amazon, not a card, while the cheapest card on the used market stands at 4,499 euros. The medians barely moved, 3,992 euros over three months and 3,402 over twelve. For a price picture built from aggregated sources that means: a single value is not a price statement until someone has checked which product carries it.
Digest: other news
AI and operations
- llama.cpp v0.5.0, 23 September: RPC protocol major v7, no mixing of versions across hosts, CUDA builds fully on 13.4. The post on it is below, with the four break points of vLLM v0.30.0 in the same text.
- vLLM v0.30.0, 22 September, 762 commits: a weight-cache daemon and KV offloading into host RAM. Our production lane already runs that image, docker ps measured on 24 September.
- MiMo v2.6 now leads the open models, the GGUF builds from ggml-org for Flash-RL cover 21 to 166 gigabytes, and the 9-billion variant at 5.4 gigabytes in Q4_K_M is the only one for our cards. Ternary Bonsai 2 holds at 3.34 million downloads.
- Apple LensVLM-9B, 25 September, built on Qwen3.5-9B, 588,936 downloads: Apple trains on an open base and puts the result under a non-commercial licence. For company-owned setups, ours included, that is the most relevant sentence about this model.
- The other labs were quiet. Qwen, DeepSeek, zai, moonshot, mistralai, Microsoft, Google, OpenAI and Ollama added no new model repository between Friday and Sunday evening, checked through the author pages. The week belonged to one vendor and to the maintenance branches.
- Unsloth maintains its own llama.cpp branch with prebuilt rounds instead of self-builds, last builds on 27 September. ENISA presented its 2026 threat report on 22 September.
- PostgreSQL 19 Beta 4: expected for 24 September, not published on Friday, our query on 24 September showed only Beta 3 of 13 August. General availability stays an October topic.
Hardware and prices
- Memory prices, a year of crisis: RAM plus 370, HDD plus 134 and SSD plus 129 per cent against mid-September 2025, new highs. Product prices and the procurement bill are in a post of their own.
- Apple, Mac mini M6 plus 50 per cent: after the older iPhone models, the memory crisis now reaches Apple's desktop price list. PCGH follows up on laptop prices at 100 to 300 euros per quarter.
- iPhone Duo: the folding iPhone from 2,319 euros in Austria, pre-order on 16 October, sales in the DACH region on 23 October, Austria on 30 October. Siri AI is absent in the EU because of the DMA dispute, while the Galaxy Z Fold 8 sits at around 1,329 euros in the street market. Everything in a post of its own.
- The Phison chief contradicts the all-clear, 25 September: Khein-Seng Pua calls DRAM the real bottleneck, money does not buy it at any time, and the shortage is only starting, explicitly against Acer's statement that there is enough memory. XMG and Schenker raised their laptop prices, since 18 September between 100 and 300 euros per device, with their own Geizhals tracking as the reason: DDR5 SO-DIMM costs close to six times the July 2025 level.
- MSI Pro Max Edge AI+, 24 September: a four-litre chassis, Ryzen AI Max+ 395, 128 gigabytes of LPDDR5X as one memory pool, 4,799 euros list. The current price anchor for local inference without a card park, and 128 gigabytes of system RAM for 4,800 euros is the number to set beside our four 5090s.
Security and advisories
- CISA KEV, 21 to 27 September: twelve entries, seven of them on Friday, all with unknown ransomware relation. Among them F5 BIG-IP APM with a zero-click stack overflow on the management interface, two NetScaler entry points from Sunday with a due date of 30 September, the SharePoint entry concerns the online environment and not our servers, and the WordPress entry is a remotely executable file. None of it reappeared on our hosts, no F5, no Citrix, no Check Point, no Zyxel, no Magento, no WordPress, our site runs on Kirby. The severity of the week sits elsewhere, with the kernel entries above.
- CERT-Bund WID, the picks for an Austrian SME: an Office and Outlook vulnerability with remote code execution, a Windows bundle carried as critical, a denial of service in the Elasticsearch lookup plugin and an information disclosure in Gitea, measured here on 1.27.3, all four without an available fix. On Tuesday 13 October it is patch Tuesday again.
- Ubuntu is switching to weekly kernel releases, reported in the CERT.at daily report of 25 September. The reason is a figure from the project itself that is circulating in the coverage: close to 5,700 recorded kernel security defects, last described as no longer workable in Canonical's monthly rhythm. The cadence change reaches us through the PVE nodes, even though those build their own branch.
Network, files and backup
- Samba 4.25.0, 24 September: experimental SMB3 persistent handles, and the mechanism behind them is the actual progress. Samba writes the handle state onto a durable store, and after a server restart the client can reconstruct its open file handles instead of opening them again. The building block is called Transparent Failover and interests every VM and database attachment over SMB. Then the step to AES-only encryption for Kerberos signatures, and anyone with clients using older enctypes on the network will notice that first.
- PgBouncer 1.26.0, 24 September, the first new branch in a year and a half, with STARTTLS upgrade, SASL channel binding, a workload profile for Postgres 18 and a maintenance mode. Relevant since Keycloak, Zammad and the BI back ends run through pools.
- DRBD 9 moves into the kernel, 27 September, through a new patch series preparing the upstreaming; the kernel has carried the 8.4 line for years. For our DRBD and LINSTOR ring this is the slow news of the year, not an update due tomorrow.
- systemd-report collects, as a new unit set, a signed document over Varlink from architecture, versions, load, unit failures and journal lines, and uploads it over HTTPS, signed optionally with a software key, a TPM or a confidential VM. For fleet inventory without a collector of our own, this is the direction in which we have been writing scripts ourselves for two years.
- TrueNAS plugin for Proxmox, merged 24 September: snapshots from TrueNAS can be imported into the guest configuration of VMs and containers. Four new issues since Friday, among them an authentication error shown despite successful audit logs.
Compliance in Austria and the EU
NISG 2026: the network and information security act applies from 1 October 2026, and the registration duty runs from 1 October to 31 December 2026 through the company service portal. Incidents are reportable within 24 hours with a preliminary notice and 72 hours with the full report, up to 50,000 euros in fines, 100,000 for operators of critical facilities, around 4,000 companies in the country. The reporting portal is nis2.cert.at, the supervisory authority is the new Federal Office for Cybersecurity, a subordinate unit of the interior ministry, which starts work the same day. Director Markus Kasinger comes from critical-infrastructure supervision as former CIO of Austrian Power Grid.
- CRA: reporting duties for active exploitation and for vulnerabilities have been running since 11 September 2026 over the ENISA platform, and no Austrian implementation law exists. Notified bodies have to be ready by 11 December 2026, full application starts on 11 December 2027. Products we build ourselves or hand on are directly covered from then.
- EDPB: on 21 September the harmonised calculation method for fines was adopted, three days later the Irish authority imposed 403 million euros on Google. The number is the headline, the method is the reason such figures will be better argued from now on.
- Digital Omnibus: noyb warns about the draft amending Article 88c of the GDPR, which would hand employee data protection entirely to the member states. A draft, not a decision, and the warning comes from an advocacy body, both worth saying.
- Windows 11 24H2 ends on 13 October 2026, Home and Pro then need 25H2 or newer, and whoever does not take the update gets no security patches after that date.
Tools and licences
- open-code-review: the largest intake in the weekly trending, and measured on 28 September at 01:35 CEST the repo stands at 41,915 stars. A deterministic review pipeline with an LLM agent as a single-binary tool, Apache-2.0.
- colibri: an inference engine in plain C, with storage, RAM and VRAM as one hierarchy, the README advertises MoE up to 2.8 trillion parameters on consumer hardware. Not measured, read as a vendor claim.
- LibreChat, our own chat rail in production: plus 949 stars in the week, rarely that much.
- Notifuse: v41 (17 September) put the sixth feature behind a licence switch, and the Business Source 1.1 count runs a fixed four years per release. Whoever plans it in plans that clock in too.
- Papermerge: maintainer search since 5 September, archiving of the repository announced after 30 days. The clock runs out in early October, no new activity was visible on 24 September.
- Open WebUI v0.11.4, 21 September, closes a series of advisories and adds a switch that stops forwarding browser cookies into backend calls, off by default, plus a slim container that occupies 1.35 instead of 12.5 gigabytes. LiteLLM 1.102.1 of 23 September fixes cascade deletion through the API key endpoint and JWT renewal without a valid signature, both points that speak directly to a gateway setup like ours.
- At the head of the weekly trending sits deepseek-harness with 237,648 stars, paperclip with 89,723, both MIT, and colibri with 37,941 under Apache-2.0. Figures through the repository API measured on 28 September at 01:35 CEST, licences from the LICENSE files. For Tencent WeKnora the licence cannot be read unambiguously there, which is worth a question before any production use.
Sources in this issue
Primary sources first, then interpretation. Every address here was callable again on 28 September 2026 at 01:45 CEST, and the host measurements (docker ps, binary versions, package lists) were taken on 27 and 28 September.
- Technitium v15.5.0 release and v15.5.1, with CHANGELOG.md
- Stalwart v0.16.23 release and v0.16.24, with CHANGELOG.md
- Zammad 7.2 release page, tags and BREAKING_CHANGES.md
- n8n releases, Keycloak 26.7.4, GHSA-5jw9-cc9v-8h8r
- heise online on the M365 data location, BornCity follow-up of 24 September
- ComputerBase memory prices September, gpuprix RTX 5090, PCGH laptop prices
- Trending Topics iPhone Duo, Apple Newsroom, Idealo.at and Geizhals.at for the street prices
- GitHub Trending weekly and the repository API for every single star count
- postgresql.org/about for the beta state, Samba 4.25.0, PgBouncer 1.26.0 and Open WebUI v0.11.4, retrieved 27 September 2026
- Red Hat on CVE-2026-90997 with Bugzilla 2533141, the GitHub advisory GHSA-5jw9-cc9v-8h8r and the raw NVD record for the CVSS vectors, retrieved 28 September 2026
- Next.js security update of 22 September 2026 and the npm registry for the publish times of 16.3.5 and 16.3.6
- PBS advisory PSA-2026-00051-1, Ubuntu CVE-2026-80521, BleepingComputer on Carbonato
- Artificial Analysis on MiMo-V2.6-Pro, MiMo-V2.6-Pro-RL, Apple LensVLM-9B
- CISA KEV, the WKO on NIS2 implementation, derstandard on the new Federal Office for Cybersecurity, the European Commission on the Cyber Resilience Act, EDPB on sanctions, Microsoft on the Windows 11 product lifecycle
From the blog
Four posts appeared this week, each with its own measurements and source list:
- Microsoft 365: choosing the data location, the deadline is 14 December
- Local AI is not only getting better, it is getting smaller
- iPhone Duo against Fold 8: the folding iPhone in Austria from 30 October
- Memory prices after a year of crisis: RAM plus 370 per cent
Compiled in the night before Monday, 28 September 2026, as of 01:00 CEST. Version states were measured on 27 September on the named hosts, the GPU, Keycloak and the backup host in the night before 28 September. The states of the Proxmox nodes came through the cluster API, their package lists did not, and those stay open. The RTX 5090 correction above refers to the week 38 edition of 20 September.
senn-tech