All newsletters
2026-09-02
4 min read
AIAI ToolsAI Coding ToolsFrameworksDevOpsDatabasesSecurityOpen Source

Gemini 3.7 Flash Cuts Costs & GitHub Copilot Now Auto-Approves PRs & Critical JFrog Flaw Exploited in 72 Hours

Google cuts costs with Gemini 3.7 Flash, GitHub Copilot gains PR approval automation, and critical JFrog Artifactory flaw exploited within days of disclosure.

AI & ML

  • Google released Gemini 3.7 Flash, a workhorse model for coding and agents just three weeks after 3.6 Flash, with half the original token cost and improvements across software engineering and web development workflows. The company also unveiled Gemini 3.5 Transcribe, a speech-to-text model delivering precise, context-aware transcription for voice agents and live captioning. Read more
  • Anthropic released Fable 5.1 and Mythos 5.1, with the unrestricted Fable version featuring lower token costs and reduced false-positive safeguards. The company also introduced Enterprise Frontier Safeguards for high-privacy deployments launching in June, enabling clients to run models on their own infrastructure with Zero Data Retention while maintaining abuse monitoring under customer control. Read more

AI Coding Tools

  • GitHub Copilot can now approve pull requests, with approvals available in public preview for Pro, Pro+, Max, Business, and Enterprise plans. Admins control approval behavior at three levels—enterprise, organization, and repository—allowing fine-grained control over which file paths Copilot can approve. Read more

Frameworks & Libraries

  • Storybook 10.5.9 shipped with fixes for pseudo-states rewriting, module-graph optimizations, and dependency updates including a bump to Vitest 4.1.6 addressing CVE-2026-47428. The project also released 10.6.0-alpha.9 with improvements to Angular zone.js detection and Vue component meta handling. Read more
  • Cypress 15.20.1 fixed TypeScript 7 support issues where spec files failed to compile with missing @babel/preset-typescript, and resolved a cy.origin() block intermittent failure affecting test reliability. Read more

DevOps & Cloud

  • Broadcom launched VMware Private AI Cloud at VMware Explore 2026, merging VMware's private cloud platform with enterprise AI infrastructure. VMware Cloud Foundation is now positioned as a unified platform for running production inference workloads, autonomous AI agents, containers, and traditional VMs together, with validated support for AI models from Google, NVIDIA, NEC, Alibaba Cloud, and Z.ai. Read more
  • Amazon Web Services announced a first cloud region in Saudi Arabia launching by December 2026 as part of a $5+ billion investment, with data sovereignty built-in and expansion of partnership with HUMAIN for a dedicated AI zone equipped with AWS and NVIDIA technologies. Read more

Databases & Data

  • ClickHouse published a case study showing Uken Games reduced observability costs by 87% using ClickHouse with OpenTelemetry as the data plane, leveraging the open-source database's vendor-agnostic approach and cost efficiency for logs, metrics, and traces. Read more
  • Pinecone deployed an AI support agent called Nexus that improved resolution rate from 24.6% to 55.1% (+30.5 percentage points), assist rate from 60.5% to 87.8%, and assign rate from 76.5% to 94.2% by leveraging account context to ask only customer-specific questions. Read more

Security

  • CVE-2026-82329 in JFrog Artifactory is being actively exploited just 72 hours after public disclosure on August 28, 2026. The critical authentication bypass (CVSS 9.8) lets unauthenticated attackers mint admin tokens on default-configured instances. Threat intelligence firm WatchTowr confirmed exploitation by September 1, with attackers generating admin tokens, enumerating users, and probing Artifactory environments for further exploitation. Read more
  • CVE-2026-0768 in Langflow (CVSS 9.8), a critical RCE in the code validator of the custom component editor, is being exploited for reconnaissance and credential harvesting, with VulnCheck observing over 15,000 successful attacks against three known-exploited Langflow flaws (CVE-2026-0769, CVE-2025-3248, CVE-2026-5027). Read more
  • CVE-2026-62911 in Microsoft Exchange Server remains exploitable on unpatched systems despite patch availability. Shadowserver now reports vulnerable instances daily, with organizations needing to verify exact build numbers as sub-versions before the August 2026 security update remain at risk, especially with public PoC code in circulation. Read more

Open Source

  • GitHub rolled out new repository-level controls letting maintainers disable pull requests entirely, restrict submissions to existing collaborators, or cap concurrent PRs from outside contributors, responding to a surge in low-quality AI-generated contributions that pushed monthly PR volume to 90 million. The changes went live August 27, 2026. Read more
  • An npm package @7nohe/openapi-react-query-codegen with 150K weekly downloads was compromised in a supply-chain attack with malicious versions (0.5.4, 0.5.5, 1.6.3, 1.6.4, 2.2.1, 2.2.2, 3.0.3, 3.0.4) executing obfuscated JavaScript during preinstall to harvest credentials and environment variables. Read more
  • DeepSeek Harness, an open-source AI agent runtime published August 13 under MIT license, topped 207,000 GitHub stars in just over two weeks, learning to fold in Claude Code and Codex as plugins across seven releases. Read more

Enjoyed this issue?

Get this in your inbox

Join 1,000+ developers getting daily tech updates.

Subscribe free
Start a project

Have something in mind? Skip the forms, just write to us.

Available for new projectsWe reply within 24 hours. No decks, no lock-in.