Kiteworks customers need precise weekend shutdown instructions, while exploited SharePoint and router flaws put old patches back on the urgent list. Agent platforms are making it easier to delegate work, but preview access, spending limits and proof that a task actually finished still belong in the rollout decision.
What matters most today
Kiteworks’ precautionary window changed in public reporting. Customer-specific hours and restart instructions matter more than repeating an earlier duration.
SharePoint and MikroTik’s new KEV entries warrant immediate attention to exposed systems. Patch status and evidence of earlier compromise are separate questions.
n8n and Microsoft are widening what agents can do. Trial a bounded task with approval and spending limits before making it a team dependency.
Codex is back up. Check interrupted work before resuming it; the service status does not tell you which edits or tasks completed.
Linux model export and encrypted presentation import can remove manual steps. Validate the resulting model or document where people will actually use it.
Action / Watch List
-
Act
If you self-manage Kiteworks, follow the current customer notice’s exact shutdown window and ask support about any unclear restart timing; Kiteworks handles its hosted systems.
-
Patch
If you run on-premises SharePoint, update to at least 16.0.5565.1001 (2016), 16.0.10417.20198 (2019) or 16.0.19725.20522 (Subscription Edition); covered federal teams also face 2026-09-28 KEV requirements, including forensic triage.
-
Patch
If your RouterOS SSH service is reachable from untrusted networks, restrict access and install your branch’s fixed release: 7.24.2, 7.23.4 or 6.49.21, or a later fixed release.
-
Patch
If a deployed Rust application includes domain below 0.12.3, update the dependency to 0.12.3 or later and rebuild the application to address the DNS-handling flaws.
-
Test
If you use n8n’s Agents preview, connect one test workflow and confirm a sensitive tool call waits for human approval before deciding whether to publish it.
-
Plan
If you develop a Claude extension for public distribution, use the new portal to review validation feedback and resolve required changes before scheduling its launch.
-
Test
If you ship YOLO models to Apple devices, export a representative model with Ultralytics v8.4.163 on Linux and compare its on-device results before moving the build step.
-
Plan
If your tenant is adopting Copilot Code or Autopilot, confirm preview access and set a credit budget and stop condition before admitting pilot users.
-
Test
If your Workspace domain is enrolled in the CSE Office Interop beta, import a non-sensitive test deck and check layout, editing and collaborator access before approving migration.
-
Test
If you operate multiple DataSync tasks, compare a recent batch’s dashboard totals and failed executions with the expected transfers before adopting it for daily checks.
-
Monitor
If the resolved Codex outage interrupted a task, inspect saved changes before retrying its unfinished step and escalate any continuing failure with its error and timestamp.
-
Monitor
If you plan federal IT staffing, ask HR for your agency’s revised shutdown plan and revisit coverage assumptions when the implementation notice arrives.
AI / Agents / Developer Workflow
n8n Agents adds reusable workers alongside existing workflows
Brief: n8n introduced Agents in preview, with sessions, memory, approvals and published versions built in. Agents can call workflows as tools, and workflows can call an agent through the Message an Agent node; the existing AI Agent node remains supported.
Operational Impact: Automation teams can trial a conversational task without rebuilding their reliable workflows. Start with a test channel and a narrowly scoped workflow, then check that sensitive tool calls pause for approval. Cloud users need the latest stable version; self-hosting needs extra setup, and Enterprise availability is still coming.
Strategic Context: The useful shift is separating an agent’s choice of next step from the fixed process that performs it. Billing deserves attention too: each agent turn consumes one execution from the shared workflow quota. A shorter setup path still needs a realistic workload trial.
Claude opens a plugin submission portal with review and usage analytics
Brief: Anthropic opened a directory submission portal for developers on paid Claude plans. Developers can submit a remote MCP connector or a GitHub-hosted plugin bundle, follow validation and safety-review feedback, and choose when to publish after approval.
Operational Impact: Integration developers now have a defined route from a working extension to a public listing. Use the portal’s feedback to resolve packaging issues before planning a launch; approval is a dependency, not a date you control. Existing directory skills, connectors and plugins require no immediate changes.
Strategic Context: Install and discovery analytics make ongoing extension maintenance more measurable. They do not demonstrate that an integration improves a customer’s workflow. The practical product question is whether a plugin completes a useful task reliably enough to justify supporting it across versions and Claude surfaces.
Ultralytics lets Linux build Apple Core AI model exports
Brief: Ultralytics v8.4.163 adds Apple Core AI .aimodel export on x86_64 Linux. The exported models target iOS 27 and macOS 27, while inference still requires Apple hardware; Core ML remains a separate export option.
Operational Impact: Teams shipping vision models to Apple devices can test moving the export step into existing Linux build infrastructure. Compare a representative exported model on the intended Apple device before changing the release pipeline. The update also restores temporarily patched PyTorch functions after failed ONNX exports and reduces unnecessary Docker image contents.
Strategic Context: Preparing an artifact and validating its runtime behavior are different jobs. Linux export can reduce dependence on Mac build capacity without eliminating Apple test devices. Treat any infrastructure saving as something to measure in your own pipeline, not a claim that deployment has become platform-independent.
IT Ops / Security / Infrastructure
Kiteworks asks customers to follow a precautionary shutdown window
Brief: Kiteworks advises a nine-hour precautionary shutdown this weekend after receiving threat intelligence from federal authorities. It says it has no indication of compromise and that release 9.5.1 addresses all known vulnerabilities; exact shutdown hours were sent directly to customers.
Operational Impact: Self-managed customers, including those hosted on AWS or Azure, should follow their current customer notice and contact support if timing or restart instructions are unclear. Kiteworks says it will handle shutdowns for systems it hosts. Coordinate transfer-dependent work with affected teams rather than assuming the service will be available.
Strategic Context: This is a precautionary service interruption, not confirmation of a breach or a published new zero-day. Earlier accounts used a shorter window; the current vendor statement and customer-specific instructions should drive the decision. A current software version does not cancel this separate operational advisory.
SharePoint exploitation puts unpatched server farms back on the urgent list
Brief: The Cyber Centre confirms active exploitation of SharePoint Server CVE-2026-65660. CISA added it to KEV on 2026-09-25 with a 2026-09-28 federal due date and a forensic-triage requirement. The flaw permits authenticated code execution; vulnerable configurations can face additional risk from exploit chaining.
Operational Impact: On-premises administrators should apply the fix for their SharePoint edition, restrict unnecessary internet exposure and examine server and authentication logs for compromise. The advisory lists fixed builds 16.0.5565.1001 for 2016, 16.0.10417.20198 for 2019 and 16.0.19725.20522 for Subscription Edition. It also urges migration from the now unsupported 2016 and 2019 editions.
Strategic Context: The fresh trigger is confirmed exploitation and the new KEV entry, not a newly released patch. A successful update closes a vulnerability but does not settle whether it was used earlier. Federal teams must also follow the applicable CISA response requirements.
Rust domain 0.12.3 fixes DNS parsing and resource-exhaustion flaws
Brief: RUSTSEC-2026-0310 identifies panics, soundness problems and CPU or memory exhaustion across the Rust domain crate. Version 0.12.3 fixes the reported issues, including malicious DNS messages that can trigger panics in transport and DNSSEC components.
Operational Impact: Rust service owners should check direct and transitive dependencies for domain versions below 0.12.3 and rebuild affected applications with a fixed release. Prioritize components handling untrusted DNS traffic or zone data. Exercise normal resolution and error handling in staging so the dependency change does not introduce an availability regression.
Strategic Context: A small library can carry the availability risk of the service around it. Updating the build environment alone is insufficient if deployed binaries still contain the old dependency. The advisory establishes defects and a patched version; it does not establish a widespread exploitation campaign.
Platforms / Devices / Buying Signals
Microsoft’s Copilot expansion brings new runtime and spending decisions
Brief: Microsoft announced Copilot Home, Code and Autopilot, alongside a preview of Copilot Managed Runtime. Home and Code are entering Frontier rollout, while Autopilot expands to private preview at month-end; these are not all generally available today.
Operational Impact: Microsoft 365 administrators should tie pilots to the capabilities actually enabled in their tenant. Cowork, Code and Autopilot use usage-based billing, so define who can consume credits and what spend ends a pilot. Test one bounded task before expanding access to data or internally hosted apps.
Strategic Context: Copilot is becoming both a work interface and an application-hosting environment. That expands the ownership question from which users have licenses to who supports the software they create. Preview availability, administrative controls and the cost of completed work matter more than a demonstration’s speed.
Google Slides beta imports PowerPoint into client-side encryption
Brief: Google’s CSE Office Interop beta now supports importing PowerPoint files as client-side encrypted Slides. Content is encrypted on the client before import and conversion; the feature is available to domains already accepted into the beta and to new participants upon acceptance.
Operational Impact: Workspace teams considering encrypted presentation workflows can test a representative, non-sensitive PowerPoint deck before widening use. Check layout, editability and the intended collaborators’ access, rather than relying on the vendor’s fidelity claim. Participation requires an eligible edition or add-on, and the feature is on for users in registered domains.
Strategic Context: Interoperability is often where a security plan becomes a manual workaround. This beta creates a route worth evaluating, but enrollment and licensing still limit availability. It is a current migration test opportunity, not a reason to assume every PowerPoint workflow can immediately move to encrypted Slides.
User-Facing Apps / Platform Friction
Codex outage is resolved; interrupted tasks still need a completion check
Brief: OpenAI marked its 2026-09-25 Codex outage resolved after mitigation. The incident listed Codex Web, Codex API, CLI and the VS Code extension as affected; the current status page reports full operation.
Operational Impact: If a coding task failed during the incident, inspect its saved changes and recorded outcome before retrying the unfinished step. Escalate continuing failures with the error and timestamp instead of assuming yesterday’s incident remains active. The incident mentioned API-key login as a temporary workaround, not a required permanent account change.
Strategic Context: Service recovery and completed work are separate facts. A green status page cannot establish that a particular interrupted build, review or edit finished. The published incident does not explain the underlying cause or justify changing model subscriptions, credentials or development environments preemptively.
Infrastructure / Self-Hosting
AWS DataSync adds an account-wide transfer dashboard
Brief: AWS DataSync now has a console dashboard for task executions across an account. It combines execution status, transfer rates, duration, totals and failure drill-down, with filters for tasks, execution IDs, modes and start times.
Operational Impact: Teams running concurrent migrations or recurring transfers can use it to identify failed runs without opening each execution separately. Try it against a recent transfer batch and compare its totals with the work expected for that batch. AWS says the dashboard costs no extra and is available in supported commercial and GovCloud regions.
Strategic Context: This is a useful reduction in operator navigation, especially when many transfers finish at different times. It does not turn transfer telemetry into a recovery test or replace alerts that must reach someone outside the console. Keep those distinctions clear before retiring existing monitoring.
Careers / Workforce
Federal shutdown settlement changes workforce contingency planning
Brief: A settlement announced in AFGE v. OMB requires notice that shutdown-related firing guidance was rescinded and changes to covered agencies’ contingency plans. The signed agreement provides a 30-day notice process for specified future changes and limits that planning provision to plans operative through 2026-12-31.
Operational Impact: Federal IT managers and technical staff should obtain the updated agency plan through HR or counsel before changing staffing assumptions. Check how it affects support coverage and work permitted during a funding lapse. The settlement is not a blanket protection against every personnel action or a guarantee of continued funding.
Strategic Context: Workforce rules affect service continuity as directly as technical dependencies. The source announcement comes from counsel for the unions; the linked signed agreement was also inspected. Distinguish its specific planning obligations from broad claims about job security, and watch for agency implementation rather than assuming it is already complete.
Coverage notes
Exact scan window: 2026-09-25 09:00:06 MDT through 2026-09-26 10:27:48 MDT (America/Denver). The last completed retained digest cutoff was 2026-09-25 09:00:06 MDT; this is not a first-run fallback. Dates without publication times are included at day precision and are not claimed to have appeared after an exact hour.
Selection: 11 full cards, each assigned exactly one private primary balance lane: 3 security action, 3 AI/developer/automation, 3 platform/enterprise and 2 user-facing/workforce. No full card repeats a story from the 2026-09-25 edition. Google Slides is a 2026-09-24 live beta rollout; SharePoint is retained for active exploitation and the fresh 2026-09-25 KEV action, not to fill a category.
MikroTik action context: CISA added CVE-2026-67279 on 2026-09-25 with a 2026-09-28 federal due date. Its older vendor advisory lists fixed RouterOS releases 7.24.2, 7.23.4 and 6.49.21. After updating, inspect unfamiliar users, scripts and configuration; the absence of a Flagged marker does not rule out compromise. The older advisory is supporting remediation context rather than a full story card. Sources: https://mikrotik.com/supportsec/september-2026-vulnerability/ and https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Sources were official announcements, release notes, incident records, security advisories and the signed workforce settlement. Direct articles were inspected. CISA web pages failed in the research browser, but the official JSON feed was retrieved directly; Google’s encrypted Slides article was likewise verified through a direct HTTP fetch after browser access failed. MSRC and ServiceNow support pages exposed little readable content, so they were not the sole evidence for any card.
The miss-check covered zero-days and KEV, Microsoft identity and collaboration, model and coding-agent announcements, cloud outages, pricing, platform regressions, workforce, policy, hardware and self-hosting. No strong fresh hardware buying or independent self-hosted infrastructure story displaced the selected items. Routine browser builds, older model launches and uncorroborated subscription rumors were excluded. This is not a claim that every service is incident-free.
The optional local Radar assignment sheet was unavailable. Security advisories and official release notes were directly checked. No card relies on rumor; vendor capability claims and limited previews are identified as such.