The US Federal Trade Commission has launched an investigation into OpenAI, Anthropic, and other major artificial intelligence firms. The probe targets potential consumer dangers and deceptive practices under the FTC Act. The agency plans to issue civil investigative demands forcing executive testimony and document disclosures to examine security controls and product risks.
EDG's C++ front‑end source code was released on September 30, 2026 under the C++ Alliance’s stewardship, making the long‑used production‑quality compiler front‑end open for contributions. The repository now accepts pull requests, publishes maintenance updates immediately, and outlines funded feature tracks, enabling broader community development.
Cohere released Embed 5, featuring Pro and Fast tiers designed for enterprise search and RAG workflows. Both models support a 128K context window, multimodal inputs, and 100-plus languages within a shared embedding space. The Pro tier prioritizes retrieval quality, while the Fast tier optimizes for low-latency workloads at lower cost.
Databricks released ai_decide, an AI Function that evaluates questions against text and returns probabilities or scores, enabling low‑latency structured decisions from SQL or REST. The blog details use cases like review tagging and routing prompts, noting beta availability and compatibility with TypeSafe AI.
Google Cloud releases Data Agent Kit to general availability, providing Model Context Protocol tools and open source skills for integrating Google Data Cloud services into coding agents. The kit supports BigQuery, Bigtable, and Apache Spark access across popular editors and IDE extensions to supply environment context.
NVIDIA released a step‑by‑step guide showing how to serve a generative recommender model using Dynamo‑Triton, detailing container setup, model conversion and scaling hints. The blog includes example code and performance notes, enabling developers to deploy similar systems on NVIDIA hardware today.
Google Cloud announced the preview of its Google Cloud CLI remote MCP server, bringing the Model Context Protocol to gcloud and BigQuery CLI tools. Operating within a managed sandbox, this setup lets AI agents run cloud infrastructure tasks and command-line operations securely without requiring local CLI binary installations.
Microsoft announces the general availability of Fabric IQ in Microsoft Copilot Chat and Cowork, allowing users to query enterprise data grounded in business context. Additional updates include preview availability for natural language app building in Power BI, a centralized Database Hub, and SQL Server on Azure Local.
AMD demonstrates that the MolmoAct2 vision‑language‑action model can interpret plain‑English commands and control a robot arm entirely on a Ryzen AI Max+ 395 mini PC using the ROCm stack. The blog shows local inference without cloud or external accelerators, highlighting edge AI feasibility for robotics.
OpenAI introduced the Decisions API, a preview service that returns probability‑based classifications for tasks such as image categorisation or agent behaviour selection. The API aims to cut latency and cost compared with full LLM calls while keeping safety features, but performance details remain unpublished.
Vercel adds Browserbase Search and Fetch tools to its AI Gateway, allowing developers to grant models web search and content retrieval capabilities using a unified API key. The helpers are available in AI SDK version 7.0.116 and later, supporting consistent tool calling across different model providers with standard configuration parameters.
The Defense Manpower Data Center disclosed that unauthorized users exploited a file-sharing vulnerability from October 2025 to July 2026. The breach exposed unencrypted records for 2.8 million living and 300,000 deceased individuals, including Social Security numbers. The Pentagon states it has no indication of misuse, though it did not explain how it reached that conclusion.
CISA added CVE-2026-76504, affecting Cisco Catalyst SD-WAN Manager, to its Known Exploited Vulnerabilities catalogue. It could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request. Federal agencies must remediate by October 3, 2026.
SecuritySep 30CISA Known Exploited VulnerabilitiesRead summary
Cisco announced Live Protect, a runtime shielding capability that mitigates known vulnerabilities without rebooting campus networks, followed by permanent fixes later. The feature integrates with Cisco PSIRT workflows and supports staged updates, aiming to keep critical traffic online while reducing exposure windows.
SentinelOne is retiring its legacy Management Console UI, switching the default to the Singularity Operations Center on November 2, 2026, with full retirement scheduled for June 1, 2027. All new capabilities will be delivered only in Ops Center, while API integrations remain unaffected. Customers are urged to transition now to avoid last‑minute changes.
DeepMind introduced SynthID Bio, a proof‑of‑concept method that embeds invisible watermarks into AI‑generated protein sequences while preserving function, demonstrated on VEGF‑A, SARS‑CoV‑2 spike and PD‑L1 binders. The claim relies on internal experiments without public code or data.
Vals AI publishes evaluation results for Harvey's legal agent benchmark, showing Muse Spark 1.2 leading the leaderboard at twenty five percent accuracy while tracking criteria pass rates across various task types and open weight models.
Cohere introduces Rubric-Calibrated Preferences nDCG@10, an evaluation methodology designed to measure enterprise retrieval quality using explicit relevance criteria and a calibrated AI judge. The approach addresses limitations in traditional nDCG by avoiding reliance on incomplete pre-existing relevance labels, providing a new way to benchmark search model performance.
Hugging Face launched an open text-to-speech leaderboard designed to evaluate models using objective metrics like intelligibility and speed rather than subjective human preferences. The platform addresses fragmented evaluation across thousands of open-source speech models by providing scalable automated ranking for multilingual generation and voice cloning.
A flu forecasting model built with Google AI ranked first in predicting hospital admissions during the 2025-26 season according to CDC evaluation results. The forecasts were generated using Empirical Research Assistance, an AI tool that creates optimization algorithms across scientific fields, with underlying technology available to trusted testers.
ResearchSep 30Google Research (blog.google)Read summary
Anthropic releases a robot exposure index measuring how many US job tasks current robots can perform. The report finds robots can handle 74% of physical tasks, covering 34% of work hours, but are cost‑competitive for only 0.3% of tasks. It highlights gender, education and pay disparities in exposed jobs.
ClickHouse Cloud now supports SCIM 2.0 provisioning, letting identity providers automatically create, update, and remove user accounts and role assignments. The blog details the endpoint, API key setup, and group‑to‑role mapping, reducing manual admin work and preventing orphaned accounts.
Amazon S3 Vectors now supports metadata pre-filtering, evaluating attribute filters before similarity searches to deliver higher recall on filtered queries. Each vector stores up to 2 KB of filterable metadata, and queries support up to 100 filter constraints with prefix matching for paths and URLs at no additional cost.
Google Cloud has released the general availability of Spanner Omni, the self-hosted, containerized version of its distributed SQL database. This release enables developers to run consistent, ACID-compliant relational workloads across on-premises servers, Kubernetes, private datacenters, or alternative cloud providers, bypassing the previous requirement to use Google Cloud infrastructure.
ClickHouse shared engineering insights on managing memory safety when building PostgreSQL extensions in C++. The post details how PostgreSQL's exception-handling and MemoryContext systems conflict with C++ constructors, destructors, and standard allocations. It outlines how ClickHouse solved these challenges across four extensions, including rewriting libraries in plain C to ensure safety.
Cloudflare launched Issues, a built-in error monitoring tool for Cloudflare Workers now in open beta. Enabled with a single line of configuration in the runtime, it groups exceptions, failed invocations, and 5xx responses without requiring an external SDK. The system can automatically package logs, traces, and worker versions to trigger configured coding agent workflows.
Amazon S3 Tables now support every Apache Iceberg V3 data type, including variant, nanosecond timestamps, geometry, geography, and unknown, plus deletion vectors and row lineage. The update lets users create new V3 tables or upgrade V2 tables in place while S3 Tables continue automatic compaction and maintenance. Existing pipelines gain native handling of semi‑structured and geospatial data without custom workarounds.
Amazon Aurora PostgreSQL now lets you run SQL queries that read Apache Iceberg and Parquet files directly from S3, eliminating ETL pipelines. The feature embeds DuckDB inside Aurora, enabling live and historical data joins with standard PostgreSQL syntax. Existing tools work unchanged, but query latency depends on lake size.
ClickHouse announces pg_clickhouse v0.11.0 and chdb v0.1.2, adding a check_encoding server option that lets users choose how to handle invalid byte sequences in text columns. The update supports fail, remove, replace, and truncate modes, reducing data‑import errors for PostgreSQL foreign tables linked to ClickHouse.
Cloudflare has updated its User Insights feature within AI Gateway to help teams identify model overkill and trace task complexity against token consumption. The new additions let developers analyze whether specific users or agents route routine tasks to overly capable models, with the capabilities available for free to AI Gateway users.
Databricks makes IP Functions generally available, enabling native IP address, CIDR, and subnet operations in lakehouse SQL. This removes the need for custom UDFs or external pipelines, improving performance and governance for high‑volume network analytics.
AMD ROCm adds a unified OpenAI‑compatible API and container workflow that works across Radeon GPUs, Instinct accelerators and EPYC CPUs, simplifying profile discovery and deployment for developers. The blog outlines the cross‑hardware commands but notes existing tooling remains required for full pipelines.
Cloudflare releases the Auto Router in public beta for its AI Gateway, automatically directing each request to the smallest model that can handle the task. Internal testing reports up to 30% cost savings versus always using frontier models, though results may vary per workload.
GitHub Enterprise Cloud with data residency will stop accepting TLS connections from clients restricted solely to X25519 for key agreement. Affected systems must enable FIPS-approved groups like P-256 before the deadline to prevent connection failures. The update impacts isolated proxies, appliances, or explicit TLS libraries lacking alternative configurations, while SSH access remains unaffected.
Vercel CDN no longer caches origin responses when the Vary header includes Cookie to prevent high cardinality cache bloat. Responses are served normally without being stored in the shared cache, and developers can identify these events using runtime logs and specific headers.
NVIDIA introduced the cuObject API and SCADA Server SDK, letting developers map GPU memory directly to file and object storage for AI workloads. The blog details supported platforms and sample code, enabling faster data pipelines without extra copies. Early adopters should verify compatibility with their storage stacks.
CoreWeave announced the production availability of NVIDIA Vera Rubin NVL72 systems featuring Spectrum-X 102.4T Ethernet networking. Additionally, CoreWeave introduced the CoreWeave Forge environment for training and refining models, alongside offering the NVIDIA Vera CPU. Cognition is deploying early workloads on this infrastructure, reporting notable throughput improvements for real-world software engineering tasks.
Patch Management Engine 2.14.1 is generally available, updating component communication to modernise the architecture and block unauthorised remote connections. Existing probes retain backward compatibility without requiring manual configuration changes from administrators.
Cloudflare updates its registrar platform with a faster search interface, a testing sandbox, and expanded programmatic access. Developers can now manage domain searches, purchases, and transfers using a new CLI tool and Model Context Protocol integrations, enabling automated workflows and agent-driven registration tasks without manual intervention.
AMD releases the TraceLens analysis agent, a tool that profiles GPU workloads to locate performance bottlenecks such as low kernel throughput, collective stalls, or host‑side idle time. The README shows installation steps and example usage for improving training and inference efficiency.
NVIDIA adds tracing support to NeMo Relay, letting developers visualize agent harness steps and spot inefficient paths that increase latency. The blog demonstrates tracing of failed searches and redundant file reads, though integration still requires enabling the new feature in the toolkit.
GitHub expands the HydraFusion research preview to Visual Studio Code and the GitHub Copilot app, enabling multi-model workflow orchestration. HydraFusion optimizes execution patterns across single, cascade, and critique workflows using capability signals from multiple models, available for Copilot Pro, Business, and Enterprise users with preview features enabled.
Vercel Agent supports fetching dependencies from protected repositories by utilizing shared environment variables for authentication. Node package managers execute within agent sessions while credentials remain protected outside the sandbox environment. Team administrators configure authentication tokens or configuration files through development and preview settings to enable private registry access.
npm’s trusted publishing now includes an optional permission to manage dist‑tags via short‑lived OIDC credentials, removing the need for long‑lived tokens for tag operations. The setting is off by default and can be enabled per configuration, keeping existing token workflows unchanged.
Open Jarvis provides a configurable harness that retargets five primitives to run any open-weight LLM locally, restoring up to 77% of the performance gap seen on PinchBench. The blog details spec editing, engine selection, and tool integration, but the repository and installation steps are not linked.
Kotlin 2.5.0 introduces experimental companion blocks and extensions, allowing static‑like members on any class and enabling cross‑platform compilation changes. The feature requires compiler flags –Xcompanion-blocks and –Xcompanion-blocks-and-extensions, and impacts Kotlin Multiplatform static member handling.
Reddit announced plans to end support for RSS feeds and public API access, citing automated scraping and abuse concerns. RSS feeds will cease functioning in November, while public API access is scheduled to end in March 2027. The platform recommends moderators migrate to alternative tools, though general RSS users will lose access without a direct replacement.
Cove 26.9 drops the requirement for globally unique customer and site names, allowing different MSPs to reuse names. The change also adds reliability fixes for Exchange backup speed, memory usage, archive recycle bin, and license detection, all detailed in the product update.