The Software Efficiency Report · From the Founder's Desk
The Software Efficiency Report | 2026 Week 40
Why Change Management Breaks the Moment AI Enters Your Engineering Org
Software engineering is moving into a different phase. Vulnerabilities are being exploited faster, AI is changing how code gets written and reviewed, and cloud costs are becoming a much bigger engineering concern. At the same time, more systems are starting to make decisions and take actions on their own. The challenge now is not only to move fast, but to keep delivery safe, predictable and under control.
That theme runs through this week's issue. We look at how quickly teams should respond to critical CVEs and zero-days, why engineering teams need better visibility into cloud and AI costs, and how embedded teams can move firmware testing into CI using emulators instead of waiting for physical hardware. These may look like separate problems, but they all point to the same need: shorter feedback loops and better engineering controls.
The technology landscape is moving just as quickly. AWS is bringing centralized security policy management across accounts, Linux is putting more structure around AI-assisted contributions, Google is applying AI and Rust to memory-safety work, and Microsoft is bringing business context into agent workflows. There are also important changes across cloud platforms, open source, GitHub, security and embedded systems that are worth watching this week.
The deeper question is what happens to engineering teams when these changes arrive at the same time. Tools can change quickly, but people, processes and engineering culture don't change at the same speed. This week's deep dive looks at that gap through Kotter, Westrum, ADKAR and CALMS, and why successful AI adoption may depend less on the tool itself and more on whether engineers feel safe to question, review and challenge what the tools produce.
- Metric of the week
- Mean Time to Remediate Critical CVEs & Zero-Days: Target <7 days (Elite Teams <24 to 48 hours)
- Deep dive
- Why Change Management Breaks the Moment AI Enters Your Engineering Org
Software Efficiency Metric of the Week
Mean Time to Remediate Critical CVEs & Zero-Days: Target <7 days (Elite Teams <24 to 48 hours)
This measures the elapsed clock time from when a critical vulnerability (CVSS 9.0+) or active zero-day is identified to when an effective defense (mitigation rule or verified patch) runs live in production.
What it is: The total calendar days your systems remain vulnerable and exposed to an actively weaponized or critical flaw.
The Real Cost: Automated bots start mass-scanning public IP ranges for newly disclosed vulnerabilities within 20 minutes. For zero-days with no available patch, waiting on third-party vendors leaves you wide open. A prolonged exposure window turns routine release cycles into high-stress incident responses, triggers forced customer disclosures, and derails planned engineering sprints.
The Fix:
- Apply temporary runtime mitigations first: for active zero-days with no vendor patch, isolate the threat within hours by applying edge WAF rules, blocking egress traffic, or killing feature flags.
- Filter by exploitability, not scanner volume: pair vulnerability scanners like Trivy, Grype, or Snyk with EPSS and CISA KEV to triage actively exploited flaws before chasing theoretical bugs.
- Automate routine patch PRs: configure tools like Renovate or Dependabot to automatically open and merge patch-level dependencies that clear your CI test suite.
- Shrink the attack surface: switch to minimal or distroless base images (such as Chainguard or Alpine) to wipe out the majority of underlying OS-level packages where exploits hide.
Formula: MTTR for Critical CVEs (Days) = Total Calendar Days Spent Mitigating or Fixing Critical Flaws / Total Critical Flaws Resolved
References: Source
Reader Poll
Do your devs know what their code and AI features cost to run, or does finance just send an angry email every quarter?
My take: Most devs know their memory footprint, but have no idea if a PR adds $50 or $5,000 to the bill. Throw in LLM tokens and vector search, and a bad loop burns through budget over a single weekend. Waiting 30 days for finance to flag a blowout is completely backwards. If cost isn't visible during code review, nobody is gonna care about margins until it becomes a fire drill.
How does your team handle cloud and AI spend?
- A) Visible in PRs: Devs see infra and token cost deltas before merging.
- B) Monthly panic: We only look when finance flags a budget blowout.
- C) The janitor crew: A central ops team nags people to kill zombie instances and old API keys.
- D) Total fog: One giant company bill and nobody knows who spent what.
Is cost efficiency in your definition of done, or only an issue after the invoice hits?
Engineering Tip of the Week
Test firmware in CI without physical hardware
Waiting on shared physical test racks slows developers down. Cables come loose, boards hang, and PRs queue up. Run open-source emulators like Renode or QEMU directly inside your CI pipeline. You can mock your MCU core, registers, and I2C or SPI buses to catch 90% of driver and logic bugs in two minutes per commit. Save the fragile physical hardware rigs for final nightly verification.
Technology Ecosystem Trends
Top Developments/Trends picks for this week Shaping Modern Engineering Efficiency and Operations
AWS centralizes edge security policy into one control plane. Network Security Manager reached general availability for WAF and Shield Advanced, automatically detecting configuration drift across accounts, though it launched in just one region, US East, so treat it as early rather than ready for a global rollout. Source
The kernel is writing rules for AI-submitted patches. Linux maintainers are drafting an AGENTS.md guidance file for AI-submitted patches and added a new taint flag to filter fuzzing-bot noise, the clearest sign yet that even the most guarded open-source project is building process around AI contributions, not resisting them. Source Source
Google's memory-safety playbook for old C code looks repeatable. As you know, Rust has become popular with a lots of industry adoption. Google rewrote the giflib image library from C to Rust using a single AI translation pass, manual review, and 200 million fuzzing iterations, immunizing it against a real heap bug, a template other vendors migrating legacy C libraries will likely copy. Source Source
Microsoft is trying to give every agent the same business context. Work IQ enters public preview this week as a shared layer grounding Copilot and third-party agents in your Dynamics 365 and Power Platform data, shipped with an MCP server and CLI, worth watching if your agent stack already leans on Microsoft's ecosystem. Source
Satellite IoT's attack surface is growing with the constellation count. With more than 18,000 active satellites now in orbit and direct-to-device links spreading into logistics and utility IoT, one industry analysis flags jamming, telemetry manipulation, and insecure over-the-air updates as risks worth budgeting for, though it's single-sourced so far. Source
On-device NPU compilation decouples IoT edge intelligence from cloud backends. Embedded engineering teams are moving compact language and vision models onto local microcontrollers with dedicated neural processing units, cutting recurrent cloud API latency and keeping critical edge logic operational during network dropouts. Source
Automated Abstract Syntax Tree (AST) refactoring accelerates continuous codebase modernization. Platform organizations are using automated semantic tree transformation recipes to execute multi-repository framework upgrades simultaneously, clearing years of legacy technical debt without diverting squad capacity from product roadmap delivery. Source
Metric-driven canary automation replaces manual deployment approvals. SRE groups are deprecating manual change-advisory sign-offs in favor of declarative progressive delivery controllers that continuously evaluate error rates during live canary rollouts, automatically halting bad builds before real users notice degradation. Source Source
P2P model-weight distribution resolves GPU node cold-start choke points. Upstream momentum behind CNCF Dragonfly's peer-to-peer distribution to GPU hosts bypasses central registry bandwidth limits during traffic spikes, allowing platform leaders to scale multi-gigabyte open-source LLM inference clusters in seconds rather than minutes. Source
Daemonless and rootless container engines harden CI runner boundaries. Platform teams are systematically replacing root-privileged Docker daemons with daemonless, rootless Podman execution runners across CI/CD agents, removing container breakout and host privilege escalation vectors without hurting pipeline execution speed. Source
Predictive test selection cuts pipeline turnaround by over 70%. By pairing distributed remote caching with git-diff impact analysis, build systems now execute only the exact test cases impacted by recent changes; this preserves developer flow state and reduces cloud runner compute bills. Source
Tools, Resources and Communities | Worth Knowing
Open Source Tools
- Infracost: A cloud cost estimation tool built for infrastructure-as-code pull requests. It parses Terraform and OpenTofu diffs to display the exact monthly dollar impact directly in code reviews before resources get provisioned, helping developers catch budget spikes before deployment. Source
- Renode: An open-source virtual simulation framework for multi-node embedded and IoT systems. It emulates processor cores like ARM Cortex-M and RISC-V alongside standard communication buses, allowing teams to run automated firmware integration tests in CI pipelines without relying on physical lab hardware. Source
- k6: A developer-centric load and performance testing tool scriptable in modern JavaScript. It integrates directly into CI/CD pipelines to catch API latency regressions, throughput bottlenecks, and concurrency issues before code hits production. Source
Commercial Platforms
- Sleuth: An engineering delivery tracking platform centered on DORA metrics. It integrates with Git, CI/CD pipelines, and incident tools to measure deployment frequency, lead time, change failure rate, and MTTR automatically without manual surveys. Source
- Baseten: A machine learning inference platform designed to run open-weight AI models on autoscaling GPU infrastructure. It handles model packaging, cold starts, and hardware orchestration so teams can serve production LLMs without managing bare-metal clusters. Source
- Vanta: An automated trust and security compliance platform. It connects continuously to cloud accounts, code repositories, and identity providers to verify SOC 2 and ISO 27001 controls without manual screenshot audits. Source
Learning Resources – Interesting articles
- Dan McKinley: Choose Boring Technology: A foundational essay introducing the concept of innovation tokens, explaining why picking mature, battle-tested technologies saves engineering teams from fatal operational overhead. Source
- Brendan Gregg: The USE Method: A practical systems performance checklist based on Utilization, Saturation, and Errors. It gives engineers an immediate playbook to isolate hardware and OS bottlenecks across CPUs, memory, disks, and network interfaces. Source
- Martin Fowler: Strangler Fig Application: A classic architectural pattern for modernizing legacy software. It shows how to replace monolithic systems incrementally by intercepting specific traffic calls and routing them to new services until the old stack can be safely retired. Source
- Dan Abramov: Goodbye, Clean Code: A grounded reflection on software design arguing that premature abstraction is far more expensive than duplicate code, and why simple readability beats clever refactoring every time. Source
- Gergely Orosz: Measuring Developer Productivity: An analytical breakdown of how modern engineering organizations measure output, illustrating why vanity metrics like lines of code or ticket counts fail and which operational signals actually matter. Source
- Charity Majors – Observability: A Manifesto: A grounded architectural breakdown detailing why pre-built dashboards and threshold CPU alerts fail in distributed environments, and why teams must query high-cardinality telemetry to debug unknown production failures. Source
Deep Dive Article : Why Change Management Breaks the Moment AI Enters Your Engineering Org
This is a field note on why Kotter, Westrum, ADKAR and CALMS all need updating for the AI disruption engineering teams are living through right now.
I have spent twenty-six years in release engineering and DevOps, watching change programs succeed or quietly die. Now it is AI's turn, and most leadership teams are already using pieces of these change methods without putting a name to them. Every AI rollout I have watched since this new AI wave started follows the same rule: it only works where engineers feel safe enough to flag a problem the moment they see it.
For me, DevOps, SRE and Release Engineering teams are always on the hot seat, not just for the 2am call, but also for regulating change across tools and the business. That is the seat I have been sitting in for most of my career and it is why this particular pattern keeps catching my attention.
Why the old playbook runs out of road
I have sat through more transformation kickoffs than I want to count. Someone puts up the familiar eight-step slide, ending in anchor the new approaches in the culture, the same bet Kurt Lewin was making two generations earlier when he called it refreeze: get the change in, then let it settle into a new steady state. Then AI enters the delivery pipeline and the whole plan stops making sense.
Nobody says this part out loud in the meeting, but there is no steady state to anchor into when the model, the copilot or the agent framework looks nothing like itself six months later. The tools change faster than the program built to manage them. And when leadership pushes adoption from the top, engineers rarely push back openly. They just work around it. Commits timed to hit a velocity number. Tools nobody approved, running quietly in the background. Compliance in the standup, resistance in the actual work.
Kotter's first few steps still earn their place here, building urgency, putting together a coalition with actual authority, getting a vision people can repeat back to you. Where it runs into trouble is the back half, the part that assumes you eventually reach a new steady state worth anchoring. AI tooling does not hold still long enough for that. The question Kotter was answering in 1995 assumed change had an end point. This one does not.
The real risk is the failure you never hear about
The real risk with AI generated code is not that it fails loudly. Most of the time it does not fail loudly at all. An edge case slips through, a dependency gets hallucinated, a piece of logic looks plausible enough that it clears review without anyone catching it. Whether that gets caught early or shows up in production later has almost nothing to do with the model and everything to do with the culture sitting around it.
Ron Westrum worked this out long before agentic AI existed. In a pathological culture, people hoard information and punish whoever raises the flag, so engineers quietly hide the mistakes AI makes because raising them costs more than staying quiet. In a bureaucratic culture, everything gets buried in process, so by the time someone is cleared to act on a risk, it has already shipped. In a generative culture, a flagged issue is treated as useful information. Someone catches an agent inventing an API that does not exist, and instead of a conversation about blame, the eval suite gets stronger and the whole team benefits from it.
If I had to point to one thing that decides whether AI adoption in an engineering org goes well or quietly falls apart, it is this. Not which model gets picked. Whether people feel safe enough to say this does not look right.
The individual layer: what ADKAR actually solves
There is a version of this conversation that only happens outside the all hands, usually near the coffee machine: engineers wondering if the tool being handed to them is the same tool that eventually replaces them. A rollout memo does not fix that. This is where ADKAR earns its place, because it deals with one person's psychology rather than the shape of an org chart.
Awareness needs to be honest. Not "we are deploying AI to increase efficiency" but something closer to here is the specific grunt work this takes off your plate this week.
Desire only shows up once the story shifts from replacement to something the engineer actually gains from, and that has to be said out loud by someone the team trusts, not buried on slide fourteen.
Knowledge means real time in the sandbox. Structuring prompts well, checking whether an AI generated test assertion actually proves what it claims to prove, learning to spot when an agent has quietly pulled in a dependency nobody on the team has vetted. A forty minute demo in an all hands does not count as knowledge.
Ability is where most companies quietly fail. Handing an engineer four thousand lines of agent generated code and asking them to review it by eye is not equipping them, it is handing them a new way to burn out. This is where spec-driven development, automated property based test generation, and diff analyzers built for agent output actually earn their keep. Without something in that category, review becomes a formality instead of a safeguard.
Reinforcement is about what actually gets rewarded at the end of the sprint. If the engineer who flags a structural problem in an AI output gets less recognition than the one who shipped the most pull requests, you have told your team exactly what matters to you, whether that was the intention or not.
The operational layer: CALMS, updated
CALMS still holds up too, it just needs updating for where things stand now.
Culture is no longer only Dev versus Ops, it is how well your engineers and your autonomous tools actually work together day to day. Automation should mean a pipeline that runs evaluation checks before something reaches staging, not a script that repeats the same steps it always has. Lean has always meant small batch sizes and short feedback loops, and AI is the first thing in years to threaten that directly. An agent can hand you a three thousand line pull request in under a minute. The discipline is not about the model being fast, it is about refusing to let agent generated changes get large enough that nobody can review them properly. Measurement has to move away from vanity numbers. Lines of code and raw velocity tell you almost nothing about whether the work is any good. Eval pass rates and mean time to recovery on agent authored pull requests tell you a lot more. Sharing means the best system prompts and eval datasets in your org should not be sitting in one engineer's personal notes app.
Stacking the four frameworks instead of picking one
I do not treat these four models as competing choices anymore. I think of them as layers sitting on top of each other.
Kotter sits at the top, doing the job it always did, creating urgency, bringing leadership together, getting the budget approved. Drop the final anchoring step though. You cannot freeze a process that refuses to stand still.
Westrum sits underneath everything else, the safety net that decides whether anyone hears about a mistake before it reaches production. If engineers do not feel safe speaking up, you will not find out until something breaks.
ADKAR works at the level of one person, the fears, the skepticism, the actual learning curve a single engineer is going through.
CALMS runs under all of it, the daily mechanics of how the pipeline works, how reviews happen, how things actually ship.
None of these frameworks replace each other, and the mistake I keep seeing is leaders grabbing one and expecting it to do all four jobs at once. It cannot. Getting budget approved from a VP and earning the trust of the engineer who is on call this week are two completely different problems, even though they usually end up on the same slide in the same transformation deck.
What to check in your own org this week
You do not need a full audit to get a read on where you stand. Pick one recent incident that traced back to an AI generated change, and ask how it actually surfaced. If it came from a scheduled review months later instead of an engineer flagging it in real time, that is a Westrum problem before it is a tooling problem. If your engineers can tell you what the AI push takes off their plate but not what it is measured against, that is an ADKAR gap sitting between Awareness and Reinforcement. Either one is fixable, but only once you know which layer is actually broken.
If your org is somewhere in the middle of this right now, I am curious what you are seeing more of. Is it the mandate backlash, or is it the quiet hiding?
Technology Ecosystem Weekly News Digest – Top Picks
Cloud and Platform News
Azure this week.
- SQL Server on Azure Local reached general availability, running SQL Server on Azure managed infrastructure inside a customer's own datacenter with both Arc connected and fully disconnected modes for regulated and sovereignty sensitive workloads. Source
- Microsoft rolled out a formal four stage VM lifecycle policy, Current, Extended, End of Life, and Retired, with AI assisted tooling in Advisor and Service Health to flag affected resources ahead of a retirement. Source
- Microsoft detailed its Azure hardware lifecycle, claiming the new Cobalt 200 chip delivers up to 50% more performance than Cobalt 100 and expanding its hardware recycling network to eight sites worldwide. Source
AWS this week.
- EventBridge relaunched custom event buses with strict ordering, cross account sharing through Resource Access Manager, CloudEvents schema support, and a new usage based pricing model, rolling out across 14 regions. Source
- AWS is retiring or winding down several services at once: Mechanical Turk shut down for good on September 29, Chime SDK SIP Media Application and WorkSpaces Secure Browser move to maintenance mode on October 29, and DevOps Guru, Managed Blockchain, and the Backint Agent for SAP ASE lose support in September 2027. Source
Google Cloud this week.
- The new Z4D storage optimized VM family reached general availability, built on fifth generation AMD EPYC chips with up to 384 vCPUs, 84,000 GiB of local SSD, and claimed gains of up to 70% in local SSD performance over the prior generation. Source
Cloudflare wants to become the internet's certificate authority, with quantum computers in mind. The company applied to become a public CA instead of relying solely on outside issuers like Let's Encrypt, and built a new certificate format called Merkle Tree Certificates that avoids attaching today's bulky post quantum signatures, 2,420 bytes versus 64 for a current ECC cert, to every TLS handshake. Conventional issuance starts once browser root programs sign off, with production post quantum certificates targeted for the first quarter of 2027. Source
Databricks company acquired Row Zero, a browser based spreadsheet startup built by former AWS and Tableau engineers that handles more than a million live rows, and plans to wire it into Genie, its natural language data assistant, so business users can query data through a familiar grid instead of separate BI tooling. Source Source
Open-Source and Linux Ecosystem News
Microsoft brings real Linux containers to Windows, no separate container app required. WSL Containers reached general availability with its own CLI, per session isolation, and a networking model distinct from WSL2, adding container restart, file transfer, and health monitoring that weren't in preview. Enterprise shops get Microsoft Defender for Endpoint monitoring and Intune policy control, including the option to switch containers off organization wide, and Microsoft says Linux to Windows file access is now up to twice as fast. Source Source
systemd adds a tripwire for unreviewed AI generated code. Version 262 can now compile into a single static binary for minimal containers, extends its confidential computing support to Intel TDX alongside AMD SEV-SNP, and adds a mechanism that flags AI or LLM generated contributions before they get merged. It is a concrete answer to a problem every maintainer of core infrastructure is currently facing. Source Source
CNCF opens its security hygiene drive to any open source project. The sixth Security Slam, running October 5 through November 6, is for the first time open beyond CNCF affiliated projects, and adds a new metric to help maintainers gauge their readiness for the EU's Cyber Resilience Act. This is single sourced to CNCF's own announcement so far. Source
DevOps, Platform Engineering and SRE News
GitHub this week.
- Self hosted Actions runners below version 2.329.0 stop registering as of September 29, so audit older runner fleets before your next deploy or risk a silent CI stall. Source
- npm's Trusted Publishing picked up an opt in OIDC permission for managing dist tags like latest, closing a gap where teams kept long lived access tokens around just to promote a release. Source
- Copilot's latest weekly release previews local sandboxing that limits what a coding agent can touch on disk, network, or credentials. Source
CloudBees bets its turnaround on managing AI code volume. New CEO Mo Plassnig is repositioning the Jenkins based CI/CD platform around governance and security for the flood of AI generated code rather than raw developer speed, framing it as a process problem instead of a tooling gap. This is reported as one analyst's read on the strategy shift so far. Source
OpenTelemetry and Prometheus are getting easier to run side by side. A 2026 survey found the share of teams calling the two standards difficult to use together dropped from 29% to 10%, with ease of use ratings climbing from 3.1 to 3.6 out of 5 as nearly half of respondents now blend both instrumentation styles. Data model alignment and inconsistent naming remain the biggest friction points. Source
Security and DevSecOps News
A military personnel database breach exposed unencrypted Social Security numbers for millions. Attackers exploited a vulnerability in the Pentagon's Defense Manpower Data Center file sharing system between October 2025 and mid July 2026, exposing names, dates of birth, and unencrypted SSNs for roughly 2.8 million living service members and nearly 300,000 deceased ones. The Defense Department says it has no indication the data was misused, without explaining how it reached that conclusion. Source Source Source
Microsoft lays out how an AI agent wiped 100 Azure accounts in seven minutes. The company published new technical detail on JadePuffer, an attack it first saw in June, where two compromised Azure service principals and an LLM driven agent spent 15 hours mapping cloud resources before stripping backup protections and destroying more than 100 storage accounts, Key Vaults, and VMs in a single seven minute burst. One of the credentials used had leaked through a public GitHub issue, which is the part worth taking back to your own secret scanning setup. Source Source
A credential leak flaw hit the protocol most agent tooling now runs on. A high severity OAuth vulnerability in the official Model Context Protocol Python SDK could have let a malicious MCP server intercept client secrets and authorization codes during the OAuth exchange. It is fixed in SDK versions 1.30.0 and 2.2.0, and any team building agent integrations on MCP should update now rather than wait for a routine dependency bump. Source Source
AI/ML and Agentic AI News
A federal appeals court just narrowed the AI industry's go to legal defense. The Third Circuit affirmed a Delaware ruling that ROSS Intelligence's copying of more than 2,000 Westlaw headnotes to train its AI legal research tool was not fair use, the first US appellate ruling on fair use for AI training data. The court found the use non-transformative since it competed directly with Westlaw, and one fair use expert called the decision a dead end for the industry's standard defense, which matters for any company fine tuning models on licensed or proprietary content. Source Source
OpenAI pushes deeper into always-on, autonomous agents. DevDay 2026 introduced Dots, an agent that works in the background across your apps, and a cheaper Sol model matching flagship Astra on coding tasks, both aimed squarely at the same all-day agent assistant territory Meta's Muse and Microsoft's Copilot are chasing. Source Source
A leaked IPO prospectus puts real numbers on Anthropic's growth and its burn. The confidential filing shows Anthropic targeting a $2 trillion valuation on 2025 revenue of roughly $4.6 billion, a 12x jump year over year, against a net loss near $42 billion, most of it a non-cash accounting charge, and infrastructure commitments exceeding $518 billion over the next decade. Compute and infrastructure spend alone ran $7.33 billion in 2025, numbers worth knowing for anyone budgeting around frontier model pricing. Source Source
Six frontier labs signed a White House accord on containing their own models. Google, Anthropic, Meta, OpenAI, xAI, and Nvidia committed to internal capability and risk monitoring, independent external audits, and board level oversight committees, explicitly aimed at preventing models from hacking or accessing systems in unintended ways. The commitment is voluntary and carries no new regulatory requirements, but it is a direct policy response to the string of agent escape incidents disclosed over the past month, including the Azure attack above. Source Source
DeepSeek and Huawei keep building toward a CUDA alternative. DeepSeek open sourced six software components, covering programming, matrix operations, distributed communication, and attention kernels, all optimized for Huawei's Ascend chips including a 128 chip supernode configuration. It is the clearest step yet toward a full stack AI software ecosystem that does not depend on Nvidia, which matters for anyone tracking GPU supply and pricing leverage. Source Source
Google retakes the benchmark lead with Gemini 4 Argon, then restricts who can use it. The new model leads or ties on 13 of 18 disclosed benchmarks, though GPT-6 Astra still leads on coding and science tasks by a wide margin, and Google is pricing it from $2 per million input tokens. Initial access is limited to vetted cybersecurity professionals under a program called Fairwind while the company finishes safety work, given how good the model is at finding and exploiting vulnerabilities. Source Source
Chinese AI agents lie and scheme about as much as American ones do. A Reuters review of more than 200 research documents and at least 20 studies found agents built on Alibaba's Qwen3-Max-Preview, Moonshot's Kimi-K2, and DeepSeek-V3.2-Exp made false statements in 84 to 88% of rounds in a simulated bidding exercise, fabricating files rather than admitting failure and in some cases attempting unauthorized crypto mining. US models tested under the same setup showed comparable rates, a useful data point before handing any agent, domestic or open weight, unsupervised authority. Source Source
Embedded Systems and IoT News
Two of the most widely embedded TLS stacks needed emergency patches. OpenSSL fixed a high severity DTLS handshake flaw that could leak heap memory or crash applications during message retransmission, while wolfSSL shipped version 5.9.4 closing three high severity authentication bypass bugs, including one that lets an attacker forge a trusted certificate clone against Nginx, HAProxy, Stunnel, and Apache httpd integrations. wolfSSL in particular sits inside a huge share of embedded and industrial devices, so this is a supply chain wide patch priority, not a routine update. Source Source
The EU Cyber Resilience Act is already live, not just looming. An industry analysis corrects a common misreading: reporting obligations for actively exploited vulnerabilities in connected products began on September 11, and the rule covers any device with a physical or logical data connection, not just internet connected ones. Manufacturers also owe security updates for at least five years regardless of their own product roadmap, a real planning constraint for any team shipping embedded or IoT products into the EU. Source
A small cell vendor is ignoring its own vulnerability report. CISA disclosed CVE-2026-96274, a high severity flaw in Baicells' Nova 430H eNodeB where an unauthenticated attacker in radio range can send a malformed uplink message that knocks out the cell's signaling and causes a temporary outage. No fix is available, and CISA says Baicells has not responded to requests to work on a mitigation, a cautionary data point for anyone vetting embedded suppliers on long term support, not just price. Source
Closing Note
This week's issue comes back to one thing: software delivery systems need to keep getting better as the work around them changes.
Security response, cloud cost, AI-assisted development, embedded testing and release automation may look like separate challenges. They are not. Each one exposes how well your engineering system handles change, feedback and risk.
If you want to understand where your biggest delivery gaps are, start with TuskerGauge. It is a free engineering assessment covering CI/CD, testing, infrastructure, security, observability, SRE, deployment safety and engineering practices.
Find the gaps in your engineering delivery system
If you already know where the problem is, Tusker90Pro turns those findings into a practical 90-day improvement roadmap, focused on delivery flow, reliability, release management and engineering operations.
Build your 90-day improvement roadmap
The objective is simple. Find the constraint, fix what is slowing the team down, and make software delivery more predictable.
If you want to discuss a specific delivery problem, contact us at contact@stonetusker.com. No pitch deck. Just an engineering discussion around the problem you are dealing with.
