proomt

Search

Search posts, papers, and topics

All posts

CNCFEddie Knight and Stacey Potter, Security Slam3 min readrelease notesintro

Security Slam 2026 – Fall edition

Summary

The Security Slam 2026 Fall Edition is a 30-day virtual event from October 5 to November 6, 2026, co-hosted by OpenSSF and CNCF TAG Security. It aims to help open-source projects improve their security posture using OpenSSF tools and is now open to any open-source project, including new metrics for EU's Cyber Resilience Act preparation.

  • 30-day virtual event from Oct 5 to Nov 6, 2026, leading up to KubeCon NA.
  • Eligibility expanded to include any open-source project, not just CNCF projects.
  • Participants use OpenSSF projects to achieve security hygiene milestones.
  • A "Slam Library" of web resources and Slack advisors are available for support.

Open source project maintainers should care to leverage free resources and expert guidance to enhance their project's security and prepare for upcoming regulations like the EU CRA.

3/10

Related reading

  1. Why engineers should come to the SF Ruby Conference in 2026

    The SF Ruby Conference 2026 is a three‑day event for Ruby engineers, offering AI‑heavy and AI‑light tracks, talks from prominent contributors, and a networking format where every attendee gets a 60‑second mic slot. It provides direct access to experts, hiring opportunities, and community activities for anyone building or scaling Rails applications.

    Evil Martiansevilmartians.com6 min
  2. KubeCon + CloudNativeCon North America 2026: Your Week in Salt Lake City

    KubeCon + CloudNativeCon NA 2026 runs Nov 9‑12 in Salt Lake City, offering four days of keynotes, breakout sessions, maintainer tracks, and co‑located events covering Kubernetes, AI, observability, security, and platform engineering. In‑person attendance (All‑Access Pass) is needed for hands‑on ContribFests and CNCF‑hosted events; recordings will be posted later.

    CNCFcncf.io6 min
  3. September 16, 2026 security incident: how we responded to a LiteSpeed zero-day attack

    Hostinger detected a zero‑day exploit in LiteSpeed Web Server on a Brazil server on Sep 16 2026, giving the attacker root access and compromising 399 accounts. The team isolated the server, coordinated with LiteSpeed to patch the vulnerability, rolled out the fix fleet‑wide, and restored affected sites from backups within the same day.

    Hostingerhostinger.com2 minpostmortem
  4. September 2026 newsletter

    ClickHouse's September 2026 newsletter highlights the 26.8 release with features like pipelined SQL and custom HTTP handlers, alongside previews for On-Demand Compute and a PromQL-compatible TimeSeries engine. It also covers new Postgres integration tools and a cost-performance benchmark for cloud data warehouses.

    ClickHouseclickhouse.com7 min
  5. Security updates for Monday

    This article provides a compilation of recent security updates across AlmaLinux, Debian, Fedora, Mageia, Oracle, and SUSE distributions. It lists specific packages like Firefox, Kernel, Chromium, and PostgreSQL that received patches between September 25-28, 2026.

    LWN.netlwn.net3 minrelease