All newsletters
2026-09-25
4 min read
AIAI ToolsFrameworksLanguagesBrowserDevOpsSecurityOpen SourceDev Tools

Claude Discovers CRISPR-Like Enzyme & WordPress CVE-2026-87902 Exploited & Marvell 2nm AI Optical Tech

Claude autonomously discovered a novel gene-editing enzyme in 21 hours, WordPress patches critical RCE flaw being exploited within hours, and Marvell unveils industry-first 2nm optical interconnect for AI data centers.

AI & ML

  • Anthropic announced its Claude AI model autonomously discovered a novel enzyme system with CRISPR-like structural features by combing through genomic databases over 21 hours using ~950 coordinated AI agents, marking AI's move from assisting humans to driving primary scientific discovery. Read more
  • Marvell Technology unveiled the industry's first 2-nanometer optical technology for AI data centers, featuring 400G-per-lane PAM4, 800G ZR/ZR+ pluggable with MACsec, and 1.6T ZR coherent-lite technology to address hyperscaler bandwidth demands without proportional power increases. Read more
  • UiPath and GeekWire announced 21 enterprise organizations won the 2026 AI Breakthrough Awards for agentic AI implementations, collectively reporting 800,000+ hours saved annually and millions in ROI, with wins ranging from 80% reduction in insurance certificate costs to cutting dispute resolution time from 97 hours to under 5. Read more

Frameworks & Libraries

  • Zod 4.6.5, Valibot 1.5.0, and ArkType 2.2.3 all shipped meaningful releases in September 2026 and now implement Standard Schema, a shared interface that eliminates lock-in between validation libraries and lets teams swap validators without rewriting stacks; Zod leads adoption by 15x over Valibot and 160x over ArkType. Read more
  • Cardano Foundation open-sourced Mesmo, a native shared library for Python, Go, Rust, and JavaScript that exposes wallet, cryptographic, transaction, and governance functions without requiring a Java Virtual Machine runtime; Python release is at 0.1.0rc8 pre-release. Read more

Languages & Runtimes

  • Cardano Foundation released Mesmo native language bindings that let Python, Go, Rust, and JavaScript developers access Cardano Client Lib v0.8.0-pre4 functionality offline—including Ed25519 signing, Blake2b hashing, transaction serialization, and hierarchical deterministic wallet operations—without JVM dependency, broadening developer reach beyond Haskell/Plutus ecosystem. Read more

Browser & Web Platform

  • Canvas UI launched 35 WebGL and WebGPU components that apply GPU effects to live DOM elements, with html-in-canvas support requiring Chrome 148+ origin trial token, fallback rendering for unsupported browsers, and optimizations like IntersectionObserver to pause animations off-screen and respect prefers-reduced-motion. Read more

DevOps & Cloud

  • Microsoft Security announced AI agent discovery in Defender portal, local agent inventory visibility, and Zero Trust extension for agent traffic governance; also launched selective SharePoint content archiving in Purview Data Lifecycle Management to drop stale content from Copilot indexing while preserving eDiscovery discoverability. Read more
  • Fastly launched AI Firewall, AI Runtime Control, and new API Security capabilities to manage AI agent activity, detect prompt injection attacks against LLMs, and enforce security policies on AI agent access to enterprise APIs. Read more
  • SentinelOne extended its Wayfinder threat hunting service to AWS, Azure, and Google Cloud, enabling security teams to hunt threats across major cloud platforms from a unified interface. Read more
  • IBM announced Digital Asset Haven now connects to Swift's blockchain-based shared ledger with ISO 20022 messaging support, enabling institutions to move tokenized deposits 24/7 using existing payment message formats; on-premises beta deployment option now available. Read more

Security

  • WordPress patched CVE-2026-87902 (CVSS 9.2), a critical unauthenticated path traversal in the get_page_template() function affecting WordPress 4.7.0 through 7.1.1 that can lead to RCE under certain theme/server conditions; exploitation began within hours of September 22 disclosure; fix shipped in WordPress 7.1.2 with backports to versions back to 4.7.37. Read more
  • SolarWinds patched two critical RCE flaws in Observability Self-Hosted: CVE-2026-28324 (CVSS 9.8, insufficient integrity check) and CVE-2026-28325 (CVSS 8.8, untrusted deserialization), both exploitable without authentication on versions up to 2026.2.2; fix in 2026.2.3. Read more
  • Check Point disclosed CVE-2026-93616 (pre-authentication directory traversal and file-upload RCE) affecting Security Management Server, Multi-Domain Security Management Server, Log Server, and SmartEvent; vulnerable to unauthenticated script upload and execution on management servers; real-world targeting confirmed. Read more
  • Microsoft quietly fixed CVE-2026-85889 (CVSS 10.0) in Azure AI Foundry, a missing authentication flaw allowing unauthenticated privilege escalation over the network; fix deployed server-side on September 18 with no client patch required, affecting 100,000+ enterprise customers. Read more

Open Source

  • Black Forest Labs released FLUX 3 Action, a 7B open-weights World Action Model (WAM) for robot control that reads camera frames, robot state, and text instructions to predict future video frames and next action chunks; ranks #1 on RoboLab-120 leaderboard at 42.92% task success. Read more
  • GitHub Security Lab open-sourced a Taskflow Agent that automates fuzzing lifecycle for C and C++ projects, generating harnesses, chasing coverage, and triaging crashes using LLM decision-making while keeping execution in deterministic tools. Read more
  • F-Droid released version 2.0, its largest update in a decade, rewritten in Kotlin and Jetpack Compose, with redesigned Material Design UI, unified three-panel navigation (Discover/Search/My Apps), expanded search across descriptions and translations, and Android pre-approval API for streamlined app installation. Read more
  • Peking University DCAI Team open-sourced DataFlex-RL, a reinforcement learning data strategy framework that makes data selection, sample reweighting, and domain proportion adjustment configurable components within a unified RLVR/GRPO training process, reducing need to repeatedly modify trainer code. Read more

Dev Tools & IDEs

  • Hedera contributed its hashgraph-developed CLPR (Consensus Layer Protocol Replacement) to Linux Foundation Decentralized Trust Labs, making the project openly developed through LFDT Labs GitHub with a structured path to top-level LFDT status. Read more
  • TIER IV released a reference design for autonomous racing kart systems built on Autoware, including autonomous driving software, simulator, and design information on GitHub, enabling Autonomous Driving AI Challenge participants to focus on algorithm development without rebuilding entire systems. Read more

Enjoyed this issue?

Get this in your inbox

Join 1,000+ developers getting daily tech updates.

Subscribe free
Start a project

Have something in mind? Skip the forms, just write to us.

Available for new projectsWe reply within 24 hours. No decks, no lock-in.