GitLab's September 10 patch release closes CVE-2026-85706, a CVSS 10.0 path confinement failure in the repository commits API. GitLab.com was already patched, so the exposure sits with self-managed servers.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 62%
- Investor
- Investor 5%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives30
- Confidence70
IBM's Bob coding agent now runs air-gapped inside customer networks on two supported local models, Nvidia's Nemotron and Poolside's Laguna. Banks can keep their code in-house, though fully local work runs on a shorter model list than the Claude, Mistral and Granite mix IBM pitches for Bob.
Reality
- Evidence62
- Adoption25
- Hype gap+20
- Incentives70
- Confidence60
AWS's Deception Benchmark found AI vulnerability scanners catch up to 95% of real bugs but flag 41% to 99% of safe code. Its samples were built to fool models, so teams still need their own false-alarm count before sizing the triage work.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence40
Git 2.56 adds a staging flag that aborts on leftover conflict markers and cuts one Chromium diff from about eight minutes to 0.07 seconds. Teams get the speed by upgrading, but they get the safety only by editing the scripts their developers and coding agents run.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence62
GitHub's agentic autofix now saves a pattern from each security fix it creates in Copilot Memory and passes those patterns to code review and the cloud agent. Teams that enable Memory now decide whether an agent's fixes deserve to guide reviews across a repository.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives45
- Confidence50
Anthropic has redesigned Claude Projects so one development goal can run as several Claude Code sessions at once. What used to be one chat to read is now several branches, and the usage allowance moves with it.
Perspective Coverage
3 publishers
- Builder
- Builder 60%
- Operator
- Operator 33%
- Investor
- Investor 7%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence62
Enterprise Cloud owners can now pull owner, scope, expiry and last-use data for SSH keys, PATs and app tokens as a CSV. The export stops at credentials GitHub issued, so secrets pasted into repositories stay out of scope.
Reality
- Evidence58
- Adoption20
- Hype gap+5
- Incentives70
- Confidence62
The new Strands harness ships the tools, memory and context handling most teams assemble themselves, and AWS attributes its 28% saving to offloading bulky tool output to files and reusable caches across six unnamed benchmarks.
Reality
- Evidence29
- Adoption
- Insufficient
- Hype gap+34
- Incentives71
- Confidence37
Cycode's Workstation Protection, now in early access, screens installs against a threat intelligence feed and holds back packages updated too recently to vet. It ships inside the device management module Cycode already installs.
Reality
- Evidence28
- Adoption10
- Hype gap+34
- Incentives78
- Confidence38
Z.ai has disabled the feature, deleted the cloud data and commissioned two outside assessments. For teams buying coding assistants, the test this leaves behind is measuring what the process sends before approving it.
Reality
- Evidence55
- Adoption35
- Hype gap+10
- Incentives72
- Confidence52
Version 2.1.277 reads a shared AGENTS.md when no CLAUDE.md is in scope. The documented exceptions cover first sessions, telemetry-disabled runs, Bedrock, Vertex and Foundry, and the hooks governance tooling watches.
Reality
- Evidence68
- Adoption58
- Hype gap+12
- Incentives62
- Confidence64
Oren Yomtov of Accomplish found two ways out of the Codex sandbox, both silent and neither stopped by an approval prompt. OpenAI patched them within eight days, and other researchers have found the same design in rival agents.
Reality
- Evidence68
- Adoption45
- Hype gap−5
- Incentives55
- Confidence62
GitHub's workflow execution protections went generally available on September 17, and the evaluate mode that shows what a rule would block before enforcement is documented as an Enterprise Cloud capability.
Reality
- Evidence58
- Adoption25
- Hype gap+12
- Incentives58
- Confidence54
The tool boots the running app once an agent finishes a feature, sends findings to Claude Code or Copilot, and rescans to confirm the fix. It costs $10 a seat a month and meters that loop at 50 scans.
Reality
- Evidence32
- Adoption18
- Hype gap+30
- Incentives75
- Confidence38
Java 27 shipped ML-KEM hybrid key exchange for TLS 1.3 on September 15. Oracle's published plan gives it to JDK 25 in October and to JDK 8 and 11 in the second half of 2027, and The Futurum Group's Mitch Ashley says that order inverts the risk.
Reality
- Evidence45
- Adoption20
- Hype gap+12
- Incentives65
- Confidence50
Wiz reports multiple threat actors independently exploiting three patched JFrog Artifactory flaws, and its telemetry puts 49% to 62% of scanned instances still missing the fixes weeks after release. Two of the three chain into admin.
Reality
- Evidence55
- Adoption70
- Hype gap+12
- Incentives65
- Confidence55
Version 1.133 runs agents in a standalone host that survives window closes and can be reached over SSH, and the session protocol is now an MIT-licensed spec.
Reality
- Evidence52
- Adoption20
- Hype gap+18
- Incentives58
- Confidence55
After five incidents in August 2026, GitHub says its shared infrastructure has not kept up with Actions growth. Which services failed together is the part platform teams can plan around before the next one.
Reality
- Evidence64
- Adoption55
- Hype gap+12
- Incentives58
- Confidence62
Mid-size engineering teams can now run GitHub Advanced Security against their own repositories for 30 days without a sales call, and then they have to decide what a good result looks like. Mitch Ashley of The Futurum Group says the bottleneck was procurement.
Reality
- Evidence44
- Adoption
- Insufficient
- Hype gap+12
- Incentives56
- Confidence48
The Rust compiler team's first debugging survey found that 46% of respondents use a debugger, and the reasons given are about legibility rather than taste, with 74% reporting poor value rendering and 55% unable to reliably inspect a variable.
Reality
- Evidence55
- Adoption55
- Hype gap+10
- Incentives45
- Confidence58
Earlier coverage
- GitHub moves Copilot's sandbox lock into the JetBrains plugin itself
Product · September 9, 2026 · 1 publisher
- Dependabot now authenticates to GHCR with the same token Actions already carries
Product · September 9, 2026 · 1 publisher
- GitHub's HydraFusion turns model selection into a routing decision Copilot makes for you
Product · September 8, 2026 · 1 publisher
- GitHub lets Copilot's sign-off count toward a repository's required approvals
Product · September 2, 2026 · 1 publisher
- Debian settles AI policy with eight-option ballot, placing review burden on developers
Product · September 1, 2026 · 1 publisher
- Summarizing a webpage was enough to run attacker code in Claude Code's Auto Mode
Product · August 31, 2026 · 1 publisher
- VS Code 1.135 sends an agent's work to a second model for review
Product · August 31, 2026 · 1 publisher
- GitHub will charge for Copilot seats before developers can use them
Product · August 31, 2026 · 1 publisher
- Harness gives the coding agent its own permissions and its own audit trail
Product · August 27, 2026 · 1 publisher
- AI's 4x code generation ships with a doubled review cycle and tripled post-merge fixes
Build · August 21, 2026 · 1 publisher
- Tessl moves review standards into the repo, and hands teams the homework
Product · August 20, 2026 · 1 publisher
- CodeQL 2.26.3 treats workflow files as code, and cache poisoning as a finding you must triage
Product · August 20, 2026 · 1 publisher
- Harness hands vulnerability triage to agents, and concedes code fixes cannot keep pace
Product · August 19, 2026 · 2 publishers
- LangChain's dcode and NVIDIA's NemoClaw sell controls, not code quality
Product · August 19, 2026 · 1 publisher
- Adronite's Codistry makes token count, not context window, the axis of competition
Product · August 19, 2026 · 2 publishers
- Claude Code's 50% boost expires tonight, and your sprint capacity was a promotion
Product · August 19, 2026 · 1 publisher
- Dynatrace pays $915M for Arize, and LLM observability stops being its own category
Product · August 17, 2026 · 1 publisher
- Copilot drops the flagship model, and the build record does not follow
Product · August 16, 2026 · 1 publisher