All newsletters
2026-08-14
4 min read
AIAI ToolsFrameworksLanguagesBrowserDevOpsDatabasesCMSSecurityOpen SourceDev Tools

Gemini 3.7 Flash Launches & SvelteKit 3 RC Ships & PostgreSQL 18.6 Released & CVE-2026-55040 SharePoint Exploit

Google releases Gemini 3.7 Flash with customizable thinking configs, SvelteKit 3 RC ships with simplified TypeScript config, PostgreSQL releases maintenance updates across multiple versions, and attackers exploit critical SharePoint authentication bypass.

AI & ML

  • Google launches Gemini 3.7 Flash, the next iteration of Gemini 3 with algorithmic improvements to core reasoning and customizable thinking configurations to control quality, cost, and latency trade-offs. Supports 1M token context window and 64K token output. Read more

AI Coding Tools

  • JetBrains Junie CLI now supports plan mode for read-only codebase analysis before code changes, debug mode integrated with JetBrains IDEs for runtime inspection, and brings your own key (BYOK) support for OpenAI, Anthropic, Google, xAI, and OpenRouter models. Read more

Frameworks & Libraries

  • SvelteKit 3 Release Candidate simplifies TypeScript configuration by extending $app/tsconfig instead of the generated ./.svelte-kit/tsconfig.json, moves configuration to vite.config.ts, replaces $lib with #lib subpath imports, and gives service workers a facelift. Read more

Languages & Runtimes

  • Microsoft.Extensions.AI 10.9.0 ships RoutingChatClient, FailoverChatClient, and OrderedFailoverChatClient for intelligent model routing and failover, enabling developers to select between strong and cost-effective models per request in LLM pipelines. Read more

Browser & Web Platform

  • Chrome Email Verification updates include case-insensitive email comparison fixes and HTTP Message Signature support for issuance requests in Chrome 153, helping sites verify email addresses directly in the browser. Read more
  • Safari Technology Preview 250 now available for macOS Golden Gate and Tahoe with accessibility improvements including VoiceOver fixes for stray newlines and line navigation. Read more

DevOps & Cloud

  • CVE-2026-18428OpenSearch SQL Plugin async query validation bypass fixed in OpenSearch SQL plugin versions 3.7 and 2.19.6; users can bypass SQL grammar deny list via direct query endpoint. Amazon OpenSearch Service customers should update to latest service software. Read more
  • Amazon Connect flow modules now support up to five levels of nesting and universal cross-flow compatibility (inbound, outbound, queue, whisper, transfer), enabling maintainable, reusable contact center workflows at scale. Read more
  • Amazon S3 now includes specific IAM and AWS Organizations policy ARN in HTTP 403 Access Denied error messages for same-account and same-organization requests, helping developers quickly identify the exact policy blocking access. Read more
  • OpenAI Daybreak Red (GPT-5.6 Cyber) and Daybreak Blue (GPT-5.6 Sol) now available on Amazon Bedrock in US East (N. Virginia) for eligible customers requiring enrollment and account team coordination. Read more

Databases & Data

  • PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 released with security fixes including ltree overflow fixes, pgcrypto double-free prevention, array overrun fixes in pg_surgery, and NaN handling in btree_gist. Recommend reindexing affected indexes after update. Read more
  • MongoDB 8.0.29 and 8.3.8 released with fixes for jsonSchema validation, NaN handling in statistical operators, $vectorSearch improvements, and transaction management. Recommended for all users. Read more
  • MongoDB for the Agentic Era launches Atlas Managed MCP Server, Atlas App Connections using OAuth 2.1 for per-user delegation, and Vercel v0 integration enabling developers to provision Atlas clusters directly from Vercel with auto-injected connection details. Read more

CMS & Site Builders

  • Wix Headless platform adds free CMS with no content cap and no per-collection fees, universal cross-frontend compatibility, and built-in business backend (eCommerce, bookings, payments). Free tier includes CMS access with Wix-managed CDN and SSL. Read more

Security

  • CVE-2026-55040Microsoft SharePoint critical authentication bypass (CVSS 9.1) allows impersonation of users, enabling file disclosure and data modification. Patched in July 2026 Patch Tuesday; attackers actively exploiting via public PoC. Read more
  • CVE-2026-59310VMware vCenter Syslog Server critical directory traversal vulnerability (CVSS 9.9) exploited for reverse SSH tool deployment enabling persistence across 361 IPs in 47 countries. Affects vCenter 8.0.x, 7.0.x, and 6.7.x; patch available. Read more
  • CVE-2026-28148 — Unauthenticated bypass in Headless Single Sign On ≤1.6 (CVSS 9.8 critical) allows full system compromise. Read more
  • CVE-2026-28008 — Unauthenticated broken authentication in OAuth Single Sign On – SSO (OAuth Client) ≤7.0.0 (CVSS 9.8 critical). Read more

Open Source

  • OfficeCLI — Open-source Office suite purpose-built for AI agents to read, edit, and automate Word, Excel, and PowerPoint files. Single native binary, no Office installation required, Apache 2.0 licensed. HTML rendering engine enables AI agents to reproduce documents with high fidelity. Read more
  • Headroom — Compress tool outputs, logs, files, and RAG chunks before LLM ingestion, reducing tokens by 20% for coding agents and 60-95% for JSON responses while preserving answer quality. Available as library, proxy, or MCP server. Read more
  • ECC — MIT-licensed agent harness supporting 67 agents, 284 skills, and continuous learning across Claude Code, Cursor, OpenCode, and other IDEs. AgentShield security scanning, 1282 tests, 30+ community PRs merged. Read more

Dev Tools & IDEs

  • JetBrains Junie CLI — Agentic coding tool available on Linux, macOS, Windows with slash commands for plan mode, debug mode, and shell execution. Supports local code review and works with connected JetBrains IDEs (2026.1+) for bidirectional integration. Read more

Enjoyed this issue?

Get this in your inbox

Join 1,000+ developers getting daily tech updates.

Subscribe free
Start a project

Have something in mind? Skip the forms, just write to us.

Available for new projectsWe reply within 24 hours. No decks, no lock-in.