A follow-up security fix shows why wrapper capabilities need path restrictions as well as origin checks: tinyjs 0.48.0 now confines direct PDF writes and requires user confirmation for other locations.
From December 3, agent workflows that ask Atlassian's Teamwork Graph for cross-product context will need a cost budget. Most enriched tool calls use 1–10 Rovo credits, with paid overages at $0.01 per credit.
The release is more than routine maintenance. OpenSSH is changing cryptographic defaults, sacrificing some compression effectiveness for side-channel safety, and warning that AI-assisted security reports are pushing it toward a faster release cadence.
The broad result survives a meaningful refresh of the living dataset: observable SaaS pricing is still not predominantly per-seat, but the exact model mix moved enough that the old 41% flat/platform figure should no longer be quoted as current.
Together Link connects six existing coding-agent/desktop harnesses to open models with reversible profiles, per-session routing and cost receipts. The important shift is portability at the harness boundary, not Together's unverified savings claim.
The useful part of Kanbanchi’s case is that it did not need a new product category or a giant ad budget. A 25-person bootstrapped team changed the economics and presentation of an existing product, made team savings visible and progressively moved its customer mix toward multi-seat accounts.
The sharpest operational trap is CVE-2026-91768: PHP-FPM’s listen.allowed_clients can treat an allowed IPv6 address as an entire /96 prefix. Teams relying on that ACL should patch rather than assuming the configured address restriction is exact.
This was not a Firecracker escape or access to a live victim disk. It was a storage-isolation failure underneath the sandbox: researchers recovered foreign directory structures, database pages and complete SQLite databases from reused blocks, and Cloudflare had to fix allocation plus retire existing disks and cached snapshots.
Search Console now separates both generative-AI visibility and multimodal image-led searches, giving publishers a clearer first-party view of how content is discovered outside conventional typed queries.
The 10GB Hobby storage cap has not changed, but the consequence of crossing it has. Vercel has removed the previous 30-day grace period for non-exempt deployments, shrinking the rollback and preview history free-plan builders can assume will remain available.
Cloudflare’s crawler controls now distinguish between refusing AI training and refusing the crawler itself. The new Disallow AI Training option is designed to keep search discoverability while expressing a training opt-out to operators that meet Cloudflare’s Accountable requirements.
The corrected rollout matters for supply-chain configuration: teams can still remove PATs for qualifying GitHub Packages, but GitHub changed the precedence model after some npm update jobs were mistakenly routed through GitHub Packages.
This is not a normal ranking update. Google is changing the structure of commercial search results in the EEA under the Digital Markets Act, creating explicit result surfaces for vertical search services and suppliers that do not appear the same way elsewhere.
This is not a speculative browser bug. The vulnerable code sits in Chrome’s JavaScript and WebAssembly engine, exploitation is confirmed, and the remediation boundary is concrete: desktop Chrome needs the September 3 patched build or later.
This is a compiler-correctness fix rather than a routine patch. Code built with Rust 1.98.0 can be wrong even when the source is valid, so teams that adopted that stable release should update and rebuild affected artifacts.
A third-party GEO dataset recorded an 86.4% relative collapse in Reddit’s visible ChatGPT Search citation share while Google AI citation changes were much smaller. The result is a useful warning against building an AI-discovery strategy around one source platform, not proof of an OpenAI penalty or Reddit removal.
Cloud CDN can now honor CDN-Cache-Control separately from browser-facing Cache-Control. That gives builders a standards-based way to set shared-cache behavior at the edge while preserving different client-side caching rules.
Hy4 preview is a very large sparse model with public full and FP8 weights, native speculative decoding and a 1M-token context path. Its open release makes Tencent’s claims testable, while the 1.56TB full checkpoint keeps self-hosting firmly in server-scale territory.
Google Play’s 2026 target-API cutoff has two separate consequences: most new submissions and updates need API 36, while existing apps below API 35 can lose distribution to new users on newer Android devices. Developers who need more time can request an extension to November 1.
CircleCI has consolidated three config-breaking changes onto a September 21 cutoff. Teams using legacy v2.0 syntax, out-of-scope parameters or unsupported regex constructs need to migrate before pipelines begin failing at compilation time.