All newsletters
2026-09-28
3 min read
AIAI Coding ToolsDevOpsSecurityOpen SourceDev Tools

NaiveAI Launches 309B MoE Model & TeamCity Ransomware Alert & Citrix NetScaler Zero-Days

NaiveAI releases a 309B parameter MoE model with 1M-token context, ransomware actively exploits TeamCity CI/CD servers, and Citrix patches two critical NetScaler RCE zero-days under active exploitation.

AI & ML


  • NaiveAI releases Naive-N0.5-Flash, a 309B MoE model with 15.5B active parameters designed for coding and AI R&D. It supports a native 1M-token context window using a hybrid of Sliding-Window Attention (SWA) and lightweight DeepSeek Sparse Attention (DSA), enabling efficient inference without full-attention layers. Read more
  • Refract AI Labs launches Orion Flagship Mini, a ~219B parameter custom-architecture causal language model and instruction-tuned assistant focused on maximum capability with minimum parameters. The group announced its separation from SmilyAI and is exploring efficient language-model architectures beyond dense Transformers. Read more
  • A developer built an open-source XSS security model prototype that revealed an architectural insight: reliable AI systems shouldn't depend on making the model trustworthy—instead, reasoning models should never be the source of truth. The system achieved 94.1% precision and 100% recall by moving confirmation authority to an independent execution layer rather than trusting the model's output directly. Read more

AI Coding Tools


  • Explyt AI Agent plugin for JetBrains IDEs enables developers to debug, refactor, and test code directly through the IDE using an AI agent, reducing token usage by staying within the editor rather than using terminal commands. Read more

DevOps & Cloud


  • Kubernetes 1.37 shipped on August 26, 2026, with HorizontalPodAutoscaler (HPA) scale-to-zero now in beta and enabled by default. This feature allows workloads to scale down to exactly zero running pods and automatically restart when traffic returns, significantly reducing GPU infrastructure costs. AKS preview availability started September 2026 with October 2026 GA targeted; GKE's Rapid channel has it available as of September 26; EKS timeline not yet confirmed. Read more
  • Google SecOps now automatically enriches logs ingested via direct ingestion with the Google Cloud organization ID, improving log visibility. New documentation covers threat intel integration, federated search for MSSPs, and self-provisioning of additional tenants. Read more
  • BNP Paribas signs a 5-year Google Cloud partnership to deploy intelligent agents using Gemini Enterprise across corporate credit memos, sales, trading, research, and structuring. The bank keeps sensitive customer data, medical information, and critical operations on-premises while moving appropriate workloads to Google Cloud. Read more
  • Autodesk Platform Services (APS) is evolving from a platform developers build on to "a platform that builds with you." The platform now exposes granular data models for AEC and manufacturing at element and property level, with Design Automation running engines like Revit and AutoCAD in the cloud. Read more

Security


  • CVE-2026-87902 is a critical remote code execution vulnerability in WordPress versions 4.7.0 to 7.1.1 that exploits path traversal to load arbitrary PHP files, bypassing authorization. WordPress released a patch on September 22, but exploitation attempts began within hours. Update to version 7.1.2 or higher immediately. Read more
  • CVE-2026-63077 (CVSS 9.8), a critical remote code execution flaw in JetBrains TeamCity, is now actively exploited by ransomware gangs targeting over 30,000 development teams. CISA confirmed ransomware campaigns on September 23, 2026, two months after the patch shipped on July 2026. The flaw lets unauthenticated attackers run arbitrary commands on CI/CD servers that hold deployment keys, cloud credentials, and signing certificates. Read more
  • CVE-2026-88771 and CVE-2026-88772 are two critical remote code execution zero-days in Citrix NetScaler ADC and Citrix NetScaler Gateway (CVSS 9.5 each) exploited in the wild before patches existed. CVE-2026-88771 involves improper input validation affecting default configurations; CVE-2026-88772 is a memory overflow in DTLS (enabled by default for VPN virtual servers). Citrix released fixes on September 27, 2026. Organizations that patched the earlier CVE-2026-19490 with builds 14.1-73.32 and 13.1-63.21 remain vulnerable and must update to newer builds. Read more

Open Source


  • awesome-free-models repository curates open-source tools for AI development, including Semantic Kernel (Microsoft) for orchestrating agentic workflows, Dify for LLM app development with visual workflow builders, Flowise for low-code visual flow building, and Smolagents (Hugging Face) as a minimalist agent library where agents "think in code." Read more

Dev Tools & IDEs


  • XSD Companion plugin for JetBrains IDEs provides an active "XSD Structure" tool window that follows the editor and displays XML schema details for improved schema-aware development (version 0.3.1). Read more

Enjoyed this issue?

Get this in your inbox

Join 1,000+ developers getting daily tech updates.

Subscribe free
Start a project

Have something in mind? Skip the forms, just write to us.

Available for new projectsWe reply within 24 hours. No decks, no lock-in.