BriefTechNews

Citrix drops two NetScaler bugs, Slack turns the group chat into an IDE

7 min read · 11 sources

TL;DR
  • Citrix disclosed CVE-2026-19490 (unauthenticated SAML auth bypass) and CVE-2026-19489 (SIP ALG memory overflow), urging immediate NetScaler patching after prior flaws were exploited in the wild.
  • Slack Code puts Claude Code, Devin, GitHub Copilot and Vercel into shared channels, with agents running under the invoking user's permissions.
  • NanoClaw's Slack integration lets one message spin up persistent, self-hosted AI agent teams with per-agent identity, memory and permissions.
  • Gartner projects 2026 AI model and platform spend at $64B, up 63% YoY, as agentic workloads consume 3-5x more tokens per query than earlier models.
  • Google's Workspace Allowlisted Domains API hit general availability on August 20, 2026, letting admins script external sharing allowlists via Cloud Identity.

Citrix is asking admins to drop what they’re doing and patch NetScaler. The vendor disclosed two fresh vulnerabilities on Wednesday, and the more dangerous one lets an unauthenticated attacker walk past authentication entirely on appliances configured as AAA virtual servers or Gateways with SAML. The fix list is short and the build numbers are specific, but the urgency is real: Citrix notes that earlier NetScaler flaws (CVE-2026-3055 and CVE-2026-4368) were weaponised shortly after disclosure, so the security team’s weekend is on the clock.

Prior NetScaler flaws (CVE-2026-3055, CVE-2026-4368) were exploited in the wild shortly after disclosure, so Citrix wants this fix shipped before that pattern repeats.

Citrix ships two NetScaler CVEs, one unauthenticated

CVE-2026-19490 is the headline. It’s an authentication bypass on NetScaler ADC and Gateway appliances when they’re fronting SSL VPN, ICA Proxy, CVPN, or RDP Proxy traffic and have a SAML Action configured. Admins can grep their configs for add authentication samlAction to find exposed boxes. CVE-2026-19489 is a high-severity memory overflow that turns into a denial-of-service when SIP ALG is enabled inside large-scale NAT groups; the tell is add lsn group lines that include sipalg. Fixed builds are 14.1-73.32 or later, 13.1-63.21 or later, the FIPS 14.1-73.32 build, or 13.1-37.277 or later. Citrix says neither flaw has been observed exploited yet, which is the window to close.

Slack Code puts Claude Code, Devin and Copilot in the group chat

Slack wants coding agents to live where the team already talks. The new Slack Code feature brings Claude Code, Devin, GitHub Copilot, and Vercel into shared channels, where prompts, diffs, previews, and review activity are preserved as a searchable record of the work. The permission model is the part to read carefully: agents run with the invoking user’s identity and access, so the audit trail and blast radius are tied to whoever typed the slash command. For teams that already review PRs in Slack, this collapses the loop from “PR opened” to “agent commits fix” into the same scrollback.

NanoClaw turns one Slack message into a self-hosted agent team

Source: venturebeat.com ↗

While Slack is opening its channels to outside agents, NanoClaw is going the other direction: persistent digital coworkers that live in your infrastructure, not Slack’s. A single message can spin up an entire roster of agents, each with its own identity, memory, permissions, tool set, and Slack presence. The agents stay self-hosted on customer infrastructure and coordinate through Slack channels and Canvases, which means the data plane, the model keys, and the audit logs all stay on your side of the wall. The interesting bit is positioning: Slack becomes the workspace where employees manage digital staff, not just where humans chat.

Serval Catalyst roams for IT work to automate

Source: venturebeat.com ↗

Catalyst from Serval hit general availability this week. It’s an admin-facing agent that chews through ticket history, SOPs, and connected systems to spot repetitive IT work, then drafts the automations to handle it. There’s a second tier: background agents that watch for issues across systems and propose fixes before anyone files a ticket. Every automation Catalyst produces is gated by admin permissions and approval, so the failure mode is “it drafts something you don’t run,” not “it shipped at 3am.” For IT teams buried in ticket queues, the pitch is the same one ServiceNow has chased for years, but with an LLM doing the pattern matching.

The cautious AI era arrives for enterprise

Source: ciodive.com ↗

The big infrastructure story underneath the launches is that enterprise AI spend is colliding with reality. Gartner projects $64B in AI model and platform spend in 2026, up 63% year-over-year, and agentic workloads can burn 3 to 5x more tokens per query than earlier chat-style models. That’s the number finance teams noticed when bills started arriving. CIO Dive reports the move from “tokenmaxxing” to gated deployments, driven by consumption-based pricing, federal and global policy shifts, and uneven workforce adoption. An SAP report flagged that current deployments are producing insights and better decisions rather than measurable cost savings, which is the line CFOs ask about. The operational takeaway: model selection, use-case gating, and per-workload token budgets are now first-class engineering concerns, not procurement line items.

In defence of boring infrastructure

Source: weblog.rogueamoeba.com ↗

Rogue Amoeba’s CTO has a post making the case that the opposite of being on the bleeding edge is being resilient. The Mac audio utilities shop runs a stack that is, by their own admission, decades old in places, and the infrastructure codebase is now nearly double the size of the commercial product codebase. One concrete change they call out: migrating legacy CGI scripts to FastCGI after they enriched their software update system with richer release notes, which reduced server strain under load. They also moved primary order databases from MySQL to SQLite for simpler backups. The pitch to engineers is that slow-rolled, stable tech maximises uptime and lets a small team sleep, which is the only real resilience metric that pays the rent.

Delta flight knocked sideways by a rogue Wi-Fi network

Source: darkreading.com ↗

A Delta flight from Las Vegas to Atlanta was disrupted this week when someone allegedly stood up a rogue access point called “Delta WiFi Fast” that pushed passengers to a phishing-style login page. Federal authorities are investigating, no perpetrator has been identified, and the timing lines up awkwardly with Black Hat and DEF CON having just wrapped. The interesting operational question is what “Wi-Fi is a separate untrusted network” means for in-flight systems; the reassuring answer is that the incident appears confined to the passenger network, but the security boundary between that and avionics is the thing every airline CISO is now staring at.

Remote MCP needs OAuth, not local stdio

Source: thegustafson.com ↗

A new post on thegustafson.com argues that the Model Context Protocol’s local-subprocess model doesn’t survive contact with the cloud. The reasoning is straightforward: multi-tenant SaaS, serverless scale-to-zero, and enterprise needs for centralised revocation, auditing, and scopes all push MCP off the laptop. The proposed shape is a standard JSON-RPC-over-HTTP API fronted by OAuth 2.1 with PKCE bearer tokens, with the OAuth dance (steps 1-4) happening once and normal MCP calls (steps 5-6) carrying the bearer after. For engineers shipping or integrating MCP-based tools, the practical takeaway is to treat remote MCP servers as ordinary SaaS APIs with standard auth primitives, not as a special snowflake that gets to skip the identity layer.

Workplace surveillance has its own data broker problem

Source: apnews.com ↗

The Associated Press has a piece on workplace monitoring that engineers building or buying these tools should read. Post-pandemic surveillance has expanded from endpoint management into location, communications, application activity, productivity data, and on some platforms, laptop and smartphone cameras. Coworker’s Wilneida Negrón and others warn that AI and data science let employers assemble dossiers used to discipline or predict worker behaviour. A Vanderbilt, Northeastern, and UC Berkeley investigation found major monitoring programs shared worker personal data with hundreds of data brokers without clear disclosure. For engineering teams, the data-handling and third-party data-broker sharing practices of workforce monitoring products are now a procurement and compliance question, not a people-ops one.

Claude Enterprise: where the tokens actually go

Source: support.claude.com ↗

Anthropic’s Claude Enterprise consumption guide is worth reading if you’re paying the bill. The model is per-seat plus usage-based, pooled across the org, and the different surfaces burn tokens at very different rates. Claude Code and Cowork consume significantly more than Core Chat because of system prompts, file context, tool calls, and multi-turn agentic loops. Claude for M365 (Excel, PowerPoint, Word, Outlook), Claude Design in beta, Claude in Chrome, and Claude Tag in Slack each have their own billing rules; the Slack tag, notably, bills to org usage and bypasses per-user or per-group limits. Admins get spend caps, RBAC, and per-model or per-effort selection, with analytics through the UI, spend export, or the Analytics API. The actionable line: map workloads to surfaces and set org, group, and per-user caps, especially for Cowork-like surfaces where intermediate token use is invisible to the end user.

Google Workspace Allowlisted Domains API hits GA

Source: workspaceupdates.googleblog.com ↗

Google’s Workspace Allowlisted Domains API became generally available on August 20, 2026, with rollout starting the day before on both Rapid and Scheduled Release tracks and up to 15 days for full visibility. It exposes CRUD plus exact-match filtering via the Cloud Identity API, so admins can script trusted-partner domain management instead of clicking through the Admin console. The catch: it needs domain or domain allowlist management privileges, and reseller-managed workflows are not supported, which means MSPs and resellers still get the manual treatment. For teams integrating external-sharing controls, plan the migration off the console and note the reseller gap before you wire this into automation.

Get the brief

Liked this one? The rest of today's stack — AI, crypto, fintech, infra — lands in your inbox tomorrow morning. Five minutes, no hype.

About Me Author

My name is

BriefTechNews

A daily digest of what actually moved in AI, tech, crypto and fintech, assembled and written with AI, and reviewed before it publishes. Read More

You May Also Like