Cloudanix Zero.

A sample digest

This is what a platform team running the stack below would have received this week. The content is mock data; the shape, the caps and the “because” lines are what the real digest carries.

The stack

AWSAmazon EKSUbuntu 22.04 LTSPythonPostgreSQL 15CursorGitHub ActionsTerraform

Subject

5 security · 3 deprecations · 1 release for your stack — Zero, week 40

Window 25 Sept 2026 – 2 Oct 2026

Security

  • A path traversal in containerd's image unpack lets a crafted layer write outside the rootfs. Every managed Kubernetes distribution ships an affected runtime on nodes older than this week's AMIs.

    Do: Roll nodes to an image carrying containerd 1.7.24 or 2.0.3. Managed node groups: bump the AMI release.

    Because you follow AWS, Amazon EKSGitHub Advisory DatabaseCVE-2026-31337
  • Clusters created between two API releases got an access entry granting cluster-admin to the creating principal's role, not the user. Existing clusters are unaffected until you add a new access entry.

    Do: Audit access entries on clusters created since 2026-08-20 and scope them down.

    Because you follow AWS, Amazon EKSAWS Security Bulletins
  • A repository's .cursor/mcp.json was started without a trust prompt, so cloning a malicious repo could run a command. Fixed in 1.6.2 with a per-workspace approval.

    Do: Update Cursor and review MCP servers listed in any repo you cloned recently.

    Because you follow CursorCursor ChangelogCVE-2026-30412
  • Affects Ubuntu 22.04 and 24.04 servers negotiating RSA key exchange. Services that already disable TLS 1.2 RSA ciphersuites are not exposed.

    Do: apt upgrade libssl3 and restart services that link it; check nginx ciphersuite config.

    Because you follow Ubuntu 22.04 LTSUbuntu Security NoticesCVE-2026-27301
  • A search_path issue during CREATE EXTENSION let a low-privilege role run code as the installing superuser. RDS and Cloud SQL maintenance windows carry the fix this month.

    Do: Apply the minor release; on managed services, do not defer the maintenance window.

    Because you follow PostgreSQL 15, AWSPostgreSQL AnnounceCVE-2026-28870

Deprecations

  • EKS extended support for 1.31 costs 6× the standard rate from the same date. GKE auto-upgrades clusters in the regular channel.

    Do: Plan the 1.32 → 1.33 hop; two minors at once needs an API deprecation check. · by 28 Oct 2025

    Because you follow AWS, Amazon EKSendoflife.date
  • No further security fixes after this date. Lambda's python3.9 runtime is on a deprecation path with the same deadline; new function creation stops first.

    Do: Move to 3.12 or 3.13. Check Lambda runtimes and container base images. · by 31 Oct 2025

    Because you follow Python, AWSPython Insider
  • Last minor release in November. RDS moves 13 to extended support with an hourly surcharge; Cloud SQL forces an upgrade after a grace period.

    Do: Upgrade to 16 or 17. Test logical replication first if you use it. · by 13 Nov 2025

    Because you follow PostgreSQL 15, AWSendoflife.date

Releases

You follow: AWS · Amazon EKS · Ubuntu 22.04 LTS · Python · PostgreSQL 15 · Cursor · GitHub Actions · Terraform Change what you follow

This list is a guess from a few clicks. Connect your environment and Cloudanix builds it for you — exact services, versions and images. Connect your environment

Unsubscribe · Cloudanix, 450 N Mathilda Ave, Sunnyvale CA 94085

Build one for my stack

About a minute. No account.