Signal
The full archive of enterprise technology signals: launches, funding, partnerships, advisories, and market moves across cloud, networking, cybersecurity, and AI.
The full archive of enterprise technology signals: launches, funding, partnerships, advisories, and market moves across cloud, networking, cybersecurity, and AI.
4,379 articles about Signal
Decision Insights Signals • April 20, 2026
Aptean previewed AppCentral AI agents for Business Central on-premises, with 10 agents and up to 20 intelligent workflows.
Decision Insights Coverage • April 20, 2026
Netskope Threat Labs reports a ClickFix campaign delivering an AppleScript macOS infostealer that harvests Keychain data and browser session cookies via forced password prompts.
Decision Insights Threat Desk • April 20, 2026
Overview A remote code execution vulnerability has been discovered in the SGLang project, specifically in the reranking endpoint (/v1/rerank). A CVE has been assigned to track the vulnerability; CVE-2026-5760. An attacker can create a malicious model for SGLang to achieve RCE. Successful exploitation could allow arbitrary code execution in the context of the SGLang service, potentially leading to host compromise, lateral movement, data exfiltration, or denial-of-service (DoS) attacks. No response was obtained from the project maintainers during coordination. Description SGLang is an open-source framework for serving large language models (LLMs) and multimodal AI models, supporting models such as Qwen, DeepSeek, Mistral, and Skywork, and is compatible with OpenAI APIs. A vulnerability, tracked as CVE-2026-5760, has been discovered within the reranking endpoints. Using a cross-encoder model, the reranking endpoint reranks documents based on their relevance to a query. An attacker exploits this vulnerability by creating a malicious GPT Generated Unified Format (GGUF) model file with a crafted tokenizer.chat_template parameter that contains a Jinja2 server-side template injection (SSTI) payload with a trigger phrase to activate the vulnerable code path. A tokenizer.chat_template is a metadata field that defines how text is structured before being processed. The victim then downloads and loads the model in SGLang, and when a request hits the /v1/rerank endpoint, the malicious template is rendered, executing the attacker's arbitrary Python code on the server. This sequence of events enables the attacker to achieve remote code execution (RCE) on the SGLang server. The vulnerability arises from the use of jinja2.Environment() without sandboxing in the getjinjaenv() function. This function sets up the environment for rendering Jinja2 templates, but since it lacks proper sandboxing, it fails to restrict the execution of arbitrary Python code. Consequently, when the reranking endpoint is accessed and a malicious model file containing a crafted tokenizer.chattemplate is loaded, the model can execute arbitrary commands on the server. Impact An attacker can create a malicious model for SGLang to achieve RCE. Successful exploitation could allow arbitrary code execution in the context of the SGLang service, potentially leading to host compromise, lateral movement, data exfiltration, or denial-of-service (DoS) attacks. Deployments that expose the affected interface to untrusted networks are at the highest risk of exploitation. Solution To mitigate this vulnerability, it is recommended to use ImmutableSandboxedEnvironment instead of jinja2.Environment() to render the chat templates. This will prevent the execution of arbitrary Python code on the server. No response or patch was obtained during the coordination process. Acknowledgements Thanks to the reporter, Stuart Beck. This document was written by Christopher Cullen.
Decision Insights Signals • April 20, 2026
Atos announced an integration of Google Threat Intelligence into its 17 security operations centers and threat research capabilities. The company positions the move as threat-led, AI-assisted intelligence for detection and response, including expanded monitoring features for digital risk protection across its managed security services.
Decision Insights Signals • April 20, 2026
Arctic Wolf released Decipio, a gated community beta tool to detect credential-stealing attempts using LLMNR and NBT-NS abuse.
Decision Insights Signals • April 20, 2026
Redis announced Redis Feature Form, a managed enterprise feature store platform for defining, orchestrating, versioning, and serving ML features across training and inference. The release adds multi-tenant workspaces, fine-grained job control, atomic DAG updates, enhanced RBAC/security, simplified deployment, and a redesigned dashboard.
Decision Insights Signals • April 20, 2026
Kyndryl received Leader recognition in 2026 ISG Provider Lens Mainframes for consulting, MFaaS and application modernization.
Decision Insights Signals • April 20, 2026
Aptean previewed AppCentral and AI Agents for Business Central on-premises customers at Directions North America.
Decision Insights Signals • April 20, 2026
Cato Networks launched the Cato Enterprise Browser to extend Universal ZTNA with secure browser-based access under one UZTNA policy.
Decision Insights Signals • April 20, 2026
Identiv expanded ID-Safe with HF and NFC tags for authentication, tamper detection, and traceability, including tamper-evident and destructible-antenna designs.
Decision Insights Signals • April 20, 2026
Schneider Electric and Deloitte collaborated on AI-enabled digital transformation for industrial operations, combining OT and Deloitte services at Hannover Messe 2026.
Decision Insights Signals • April 19, 2026
SK hynix began mass production of 192GB SOCAMM2, an LPDDR5X low-power DRAM server memory module built on its 1cnm process. The company claims over double bandwidth and over 75% improved power efficiency versus RDIMM, and positions the module for NVIDIA Vera Rubin–based next-generation AI servers.