Branch Target Reuse bypasses existing Spectre-v2 defences in JIT engines
Researchers disclosed Branch Target Reuse, a speculative execute-after-free technique affecting JIT engines in the Linux kernel, Firefox's SpiderMonkey and Oracle GraalVM across Intel, AMD and Arm processors. They demonstrated Linux-kernel memory disclosure despite existing mitigations; Linux fixes are associated with CVE-2026-64507 and CVE-2026-64508.
Why it matters to you
Systems running multi-tenant workloads, browser automation or untrusted code deserve first attention. Track vendor guidance rather than disabling JIT globally, patch supported Linux kernels and runtimes, reduce unnecessary BPF access, and separate high-value secrets from hosts that execute untrusted workloads.
Visa open-sources part of its AI-powered cyber-defence system
Visa released part of its AI-powered defence system as open-source software after recent agent vulnerabilities highlighted the limits of human-paced response. The payments company expects future attacks to adapt continuously without direct human control and argues that defenders will need automation capable of operating at comparable speed.
Why it matters to you
Automated defence can shorten detection and containment, but it must not become an unsupervised privileged agent. Apply scoped credentials, dry-run modes, human approval for destructive actions, immutable decision logs and tested rollback before allowing an AI security tool to isolate hosts or change network policy.
EU governments favour risk-based timelines for replacing high-risk telecom equipment
EU governments removed a proposed fixed 36-month deadline for mobile operators to replace equipment from suppliers deemed high risk. The draft approach would instead consider risk, product lifecycle, replacement cycles, interoperability and alternative supply; industry estimates put potential replacement costs as high as €40 billion.
Why it matters to you
A supplier exit is a multi-year network migration, not a procurement switch. Maintain vendor and firmware inventories, map dependencies across radio, core and management systems, test interoperable alternatives, preserve configuration portability and plan capacity so security replacement work does not stall fibre, 5G or 6G upgrades.
AT&T secures more than $3 billion of fibre and cable from Corning
AT&T signed a multi-year procurement agreement worth more than $3 billion as it expands toward 60 million fibre locations by the end of the decade. The operator says an average fibre household now consumes more than one terabyte per month—five times its 2016 level—while AI, cloud services and connected devices increase backbone demand.
Why it matters to you
Access-network demand eventually becomes an aggregation and backbone problem. Capacity plans should model concurrent throughput, upstream growth, optical budgets, route diversity and restoration inventory—not only advertised access speed—and should reserve headroom for bursty SaaS and AI traffic.
Leading AI companies commit to independent safety audits
OpenAI, Anthropic, Meta, Google and Nvidia joined a voluntary US agreement to develop internal controls and work with independent auditors. The accord says AI tools should be assessed for whether they operate as intended and prevented from hacking or accessing technical systems in unintended ways.
Why it matters to you
Even voluntary commitments can shape enterprise procurement. Keep model and tool inventories, document evaluation coverage, preserve action logs and incident evidence, and be ready to show an auditor exactly how an AI feature is authorised, monitored, disabled and separated from production credentials.