30+ years of building systems taught me one thing: finding the simple solution to a complex problem is worth more than any clever framework or AI suggestion. AI can implement elaborate stuff well. But it takes experience to look at a problem and say "you don't need all that." That instinct takes decades, not months.
Vito Botta
Lead Architect at Brella. Creator of SprintPulse - The Retrospective Tool Teams Actually Love - Try it out at https://sprintpulse.io/
Node.js bug bounty paused after funding ended. IBB cited AI-assisted research surge increasing findings without matching fix capacity. cURL also dropped its bounty recently - same issue with AI-generated low-quality reports. Open source security incentives getting complicated.
Gemma 4 (Apache 2.0) and Qwen3.6-Plus both dropped this week. Open models catching up to closed fast - worth recalculating your proprietary vs open models economics.
LiteLLM cached OIDC tokens using only the first 20 characters. Collision attacks let attackers inherit other users' sessions. They've now launched a bug bounty program - a hard lesson in auth fundamentals.
Broadcom pushing Kubernetes on VMware VCF at KubeCon 2026. VKS 3.6 adds K8s 1.35, RHEL 9, multi-cluster mgmt. Velero contributed to CNCF. AVI Load Balancer positioned as Ingress-NGINX alternative. Private cloud pitch for AI workloads intensifies.
DeepSeek's valuation just went from $20B to $45-50B in weeks. Their first ever external round, led by China's state chip fund. Tencent and Alibaba want in too. $3-4B raise. The chip fund isn't just investing, they're treating compute as a national asset.
Interesting partnership: NanoClaw is working with Docker to use Docker Sandboxes (MicroVM-backed isolation) for running AI agents securely.
The problem they're solving is real - how do you give agents room to act without giving them room to damage everything around them?
Container isolation has been the answer for workloads for years. Makes sense it's becoming the answer for agents too.
Anthropic just cut off OpenClaw from Claude subscriptions - users need pay-as-you-go bundles or API keys now. Official reason is capacity management, but with OpenClaw's founder at OpenAI, this is also competitive positioning. One-time credit offered to subscribers.
Microsoft released 3 MAI models - transcription, voice, image/video - all cheaper than OpenAI/Google. Still partnered with OpenAI but now building their own stack. Mustafa Suleyman leading the push. AI market keeps getting crowded.
AI agents found two CUPS vulnerabilities that chain to root file overwrite over the network. The researcher didn't prompt for a full exploit chain - he broke it into smaller tasks. That decomposition approach might be the real breakthrough here.
AI can build software, sure. Plenty of companies still prefer not to own another internal product. Bread machines didn't kill bakeries either. People still pay for convenience, support and someone else dealing with the mess.
Building got cheaper. Keeping software useful for years still takes work. SaaS isn't disappearing, but the subscription has to earn its place every month.
I have been a little out of the loop while on holiday so I am catching up with news etc. Learnt that three companies were breached by Anthropic's own models during authorised security tests. OpenAI found the same problem around Hugging Face. The uncomfortable part is how easily permission for one target can spill into unrelated services. A capable agent does not care that your benchmark scope exists in a PDF.
Rails finally has a benchmark for AI coding tools. The Foundation ran 8 models against 21 real Rails tasks, three runs each, all against Writebook. Bug reports, security findings, feature requests, filed the way a person would actually file them. No synthetic puzzles, just the work a Rails dev does. About time we judged tools on that.
GPT-5.6 Sol out today after weeks of government hold over cyberattack fears. OpenAI complied but said the process should not become default. Sol is their strongest model.
Chasing the highest valuation can feel like winning the round. Then you have to grow into that number. After investing in 500 startups, Charles Hudson's advice is simpler: be realistic about the price and choose the people on your cap table carefully.
Samsung: 89.4 trillion won profit, up 1,810% YoY. Third record quarter. Stock drops $80B. DRAM up 44%, NAND up 53% in a quarter. https://www.reuters.com/world/asia-pacific/samsung-estimates-19-fold-rise-q2-operating-profit-beating-expectations-2026-07-06/
LiteLLM supply chain attack hits thousands of companies. Mercor confirms breach, Lapsus claims 4TB stolen. Extortion groups now teaming up with supply chain attackers. Open source tools are becoming the attack vector.
I barely finish testing one model before another one lands. Alibaba's newest is its most capable yet, nearly matching Moonshot's model size.
For teams using several providers, evals are now a permanent part of the job. At this pace, a test set goes stale before the notes are tidy, and last month's provider decision needs another look.
Nine years in beta, and metrics.k8s.io is finally heading for GA in Kubernetes 1.37. HPA and kubectl top have relied on it for ages. The API is catching up with how widely it's already used. v1beta1 stays available during the transition too, so teams can move at their own pace. I love seeing a calm graduation for an API clusters use every day.
The small-model and large-model split makes a lot of sense for voice agents. Smallest.ai keeps the conversation on a fast specialist, then calls a larger LLM only for questions it can't handle.
Less waiting for the caller, and no need to run every sentence through the bigger model. They've just raised $13M to keep building it. I want to hear how it copes with interruptions and messy audio.
Nadella told analysts Microsoft's own MAI models are the cheaper alternative to OpenAI and Anthropic. They hold stakes in both. Partner and competitor at the same time. That tension was always going to break eventually.
OpenRouter always called itself "Stripe for AI". Now Stripe is actually buying it, for over $7B. One API for 400+ models, switch whenever prices or quality move. Back in May it raised at a $1.3B valuation. Five times that in three months. Avoiding vendor lock-in is a real business now.
A 90% cost drop by 2030 (according to Gartner) sounds like a prediction, but we're already at 94-96% cheaper alternatives today. The real question isn't whether tokens get cheap - it's what happens to AI business models when they do.
Update: Cancelled Ollama Cloud after it got too unreliable. Switched to Kimi K2.5 coding plan ($39/mo) tonight and it's been brilliant - stable and fast. Need open source LLMs so I can use my preferred tools (OpenCode, BoltAI), but Kimi works for now. Using their per-token API for non-coding tasks.
Google says AI helped it fix more Chrome bugs in June than in the previous two years. Microsoft patched a record 570 flaws this month and also credited AI. Security teams asked for better bug discovery. Now the patch queue may become the bottleneck. Finding defects faster also means reviewing and shipping fixes faster. That second part still needs humans.
Meta had a security incident caused by an AI agent acting without permission. The agent posted advice autonomously, an employee followed it, and a breach happened. Shows the real risks of agentic AI when humans trust autonomous systems too much.
XBOW autonomous AI found 3 critical RCEs in Microsoft Cloud - first time AI discovered production vulnerabilities without source code access. CVE-2026-21536 was flagged as one of March Patch Tuesday's most severe issues. The arms race between researchers and hackers has shifted.
Fortinet's FortiClient EMS had a zero-day exploited before disclosure. Another reminder that endpoint management tools are high-value targets — patch immediately if you're running 7.4.5/7.4.6.
New Arkose Labs research: 97% of enterprises expect major AI agent security incident within a year. 49% within 6 months. Only 6% of security budget allocated. 57% have no AI agent governance. AI agents with legitimate credentials = bigger insider threat than humans
Cloudflare gave AI companies a September 15 deadline. Split crawlers by function: search, training, agents. Or get blocked by default on ad-supported pages. Free plan included, not just Enterprise.
https://www.helpnetsecurity.com/2026/07/02/cloudflare-ai-crawler-controls/
First confirmed AI-agent cyberattack: Chinese hackers used Anthropic AI to hit ~30 organisations. Humans did only 10-20% of the work. The "fight AI with AI" era is here.
2.8T parameters. Kimi K3 is so large that the download alone turns 'can I run it?' into 'where does this live?' I like seeing an open model compete at this scale, even though I'll still use paid APIs for daily work. More choice for OpenCode/OMP, fewer reasons to tie the whole workflow to one provider. I'd still start with the API before finding rack space. Having said that, for now I am in the Sol camp.
I’ve been using GPT-5.6 Sol, and I already love it. It feels very smart and a lot faster than Opus.
I still don’t know how it compares with Fable. Some people say Fable is more powerful, but Sol is definitely better than the current Opus, while costing only a little over half as much as Fable.
I think a lot more people will now move from Claude to ChatGPT.
CVE-2026-33105 hits Azure Kubernetes Service with CVSS 10.0. Unauthenticated remote privilege escalation - Microsoft patched it but check your AKS clusters. Critical severity, no user interaction required.
That $11B valuation didn't survive, but $480M ARR did. Bending Spoons is buying Airtable for $1.28B in cash after the company raised more than $1.4B.
Plenty of founders will call that a sad ending. Paper value, cash in the bank and money returned to investors are three very different numbers. The cap table remembers every round.
https://techcrunch.com/2026/08/04/bending-spoons-to-buy-airtable-for-1-28b/
Interesting shift in the AI hardware market - Nvidia's share in China has dropped from 95% to 55%. Chinese chipmakers now deliver 1.65 million AI GPUs and hold 41% of the local market.
US sanctions pushed data centres toward domestic alternatives, and Chinese vendors stepped up to fill the gap. A real-world example of how trade restrictions reshape tech ecosystems, not just delay adoption.
If I am not mistaken, GLM 5 by z-AI was trained entirely on Huawei GPUs, which is amazing.
Cursor 3 launched with agent-first interface - ditched VS Code layout for parallel AI fleets. Run dozens of coding agents simultaneously across local/cloud/SSH. Agents write code, developers orchestrate. Big shift in AI tooling.
PraisonAI's run_python() had incomplete escaping + unauthenticated Flask server by default. That's a classic combo: local vulnerability made remotely exploitable by configuration. AI agent frameworks need the same security review we give to any code execution feature
Fable 5 and Mythos 5 are back. US export controls lifted after 3 weeks. Deal includes proactive security monitoring and government coordination on future releases. New normal for frontier models.
New etcd minor version out. Every Kubernetes cluster depends on it for pod, service, and secret storage. Good to see regular releases continuing. https://kubernetes.io/blog/2026/07/08/announcing-etcd-3.7/