All newsletters
2026-09-08
2 min read
AIFrameworksSecurityOpen Source

GPT-6-Astra Unveiled & N-central Critical Flaw Patched & MikroTik RouterOS Exploits Active

OpenAI launches GPT-6-Astra, its most advanced model yet; N-able patches critical RCE in N-central platform; MikroTik router flaws under active exploitation.

AI & ML


  • OpenAI announces GPT-6-Astra, described as "the most intelligent and aligned model in the world." The new model is now available to developers through the OpenAI platform. Read more
  • Codex for ChatGPT desktop on Linux enters preview, expanding access to the coding assistant across platforms. Read more
  • OpenAI, WAN-IFRA, and AIRPPU partner to strengthen Ukrainian independent media with the Newsroom AI Masterclass Series and AI Catalyst program, helping publishers adopt AI for sustainability and resilience during conflict. Read more

Frameworks & Libraries


  • Next.js adds built-in AI agent support with automatic AGENTS.md generation in create-next-app. AI coding agents (Claude Code, Codex, Cursor, GitHub Copilot) now automatically read the file for version-specific guidance, with no extra setup required for new projects. Read more

Security


  • N-able patches critical N-central RCE (CVE-2026-86218, CVSS 10.0) allowing unauthenticated remote code execution. Emergency hotfix released September 7; also patched authentication bypass flaws CVE-2026-86206 and CVE-2026-86207. Huntress flagged potential zero-day exploitation. Read more
  • MikroTik RouterOS flaws exploited in the wild via "MikroTrick" attack chain: CVE-2026-67276 (SSH authentication bypass via RSA key validation flaw) and CVE-2026-86060 (SSH privilege escalation through crafted usernames). Fixes available in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21. CVE-2026-67277 also patched, affecting bandwidth-test service memory leaks and DoS. Read more
  • Dell SCG critical flaw (CVE-2026-61410, CVSS 9.4) in versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) allows unauthenticated remote code execution through missing authorization checks. Read more

Open Source


  • DeepSeek Harness (dsh), an open-source agent framework, launches with an everything-is-a-plugin architecture powered by Cordis, enabling spatiotemporal composability for AI agents. Currently in developer preview. Read more
  • LoopX released as a long-horizon agent control plane for durable, governed work across Codex, Claude Code, and other harnesses. Now available on PyPI with Apache 2.0 licensing from v0.4.8 onward (earlier versions MIT). Read more
  • Caveman token-optimization Claude skill reduces token usage by 65% via simplified prompting. Available under MIT (skills) and BSL-1.1 (engine, with Apache-2.0 conversion on 2030-06-21 or four years post-release). Read more

Enjoyed this issue?

Get this in your inbox

Join 1,000+ developers getting daily tech updates.

Subscribe free
Start a project

Have something in mind? Skip the forms, just write to us.

Available for new projectsWe reply within 24 hours. No decks, no lock-in.