IT Today
A daily digest of important IT news: platforms, software development, cloud, cybersecurity, open source, markets, and infrastructure. No noise — only what changes work for professionals and businesses.
Latest publications
Microsoft Teams is moving its web client to teams.cloud.microsoft: the network checks IT teams need now
Microsoft’s September Teams web redirect is a small URL change with a large operational edge. Firewalls, proxies, browser policies, embedded apps, CSP rules and runbooks can all turn a harmless redirect into a help-desk incident.
Cloudflare CASB automatic remediation turns SaaS posture findings into production change
Cloudflare CASB can now revoke risky Microsoft 365 and Google Workspace sharing and send webhooks automatically. The useful question is not whether to turn it on, but how to keep the automation from becoming an unreviewed write path into SaaS data.
AWS fixes read-only bypasses in database MCP servers: what operators need to check
Two AWS security bulletins published on September 9 expose a recurring design problem in database-connected MCP tools: a text filter is not an authorization boundary. Here is who is affected, what the disclosures actually say, and how to contain the risk.
Android developer verification: what changes on 30 September 2026
The first enforcement wave covers named app stores in four countries, while Google Play has a separate package-registration deadline. Here is what release, security and business teams need to verify now.
Google’s policy week shows browsers and app stores are IT infrastructure
Manifest V2 removal, uBlock Origin’s Chrome Web Store exit, AnkiDroid’s donation-link fight and Aurora Store friction all point to one risk: client-platform control.
ChatGPT Work turns AI from chat into an enterprise control plane
OpenAI’s new Work layer is less about better answers than delegated action across files, browser sessions and workplace apps. That makes governance the real story.
Cursor losing OpenAI models is a supply-chain warning for AI coding
OpenAI’s planned cutoff shows why teams should treat model access inside AI IDEs as an operational dependency, not an invisible feature.
AWS buying DuckLabs moves DuckDB’s center of gravity
DuckDB stays MIT and under a foundation, but AWS acquiring DuckLabs changes the practical governance questions around one of data engineering’s favorite tools.
Android car head units have become an IoT supply-chain risk
Kaspersky’s new head-unit malware case shows why cheap connected dashboard screens need the same scrutiny as routers, kiosks and TV boxes.
GitHub’s August outage turned developer convenience into a business continuity question
The August 17 incident did not only interrupt a website. It exposed how repositories, reviews, Actions, APIs, identity, issues and Copilot now sit in the same delivery blast radius.
The Android source-code fight is about trust, not just Git tags
GrapheneOS says Google replaced direct Git tags for some Android and Pixel sources with request-driven archives. Even if the legal question remains open, the engineering issue is clear: source access is useful only when it is timely, verifiable and automatable.
Cloudflare Web Analytics backlash: when CDN defaults become production changes
A Cloudflare RUM debate shows why teams should audit edge-provider defaults as carefully as application releases.