ALEXKRI.NET
Resume Contact

News

Dev, Sec, Ops, Infra, Cloud and AI news worth checking.

Beam: Reflection's 501B open-weight model

Open weights are getting genuinely large. Beam is a 501B-parameter sparse MoE with 23B active, Apache 2.0, 1M context, and 80.9 on SWE-Bench Verified. The training footnote I enjoyed most: over 100 million RL rollouts on 10,500 GB300s in four weeks. Reflection claims reasoning comparable to GLM-5.2 at 3-4x less inference compute. Weights are promised this month, which is the bit that actually matters if you self-host.

Scaling Kubernetes Workloads with Node Swap

Swap on Kubernetes nodes went from “absolutely not” to GA in v1.34, and this post finally puts numbers on it: Python sandboxes on gVisor from 80 to 240 concurrent pods per node, headless Chrome 80 to 160, and a kernel build finishing faster on half the RAM limit (374s vs 433s). The honest part is the ceiling, squeezing the same build to 200 MB cost 40%+ latency in thrashing. Insurance for burst memory, not a replacement for RAM.

ReviewBench: An open benchmark for AI code review

We all added AI review bots to our PRs, and then measured them by vibes. GitHub’s ReviewBench scores them on 219 real pull requests from 187 repos across 19 languages, deliberately weighted toward multi-file changes using distributions drawn from 103.9M PRs. Senior engineers agreed with its golden true-positives 96.6% of the time, and the runner is self-serve. Precision and recall per severity, in the open, is a good trade for the noise.

Exploitation Hits Rejetto HFS Vulnerability Discovered by AI

This one was found by doing maths, not fuzzing. HFS generated session cookies with Math.random(), and Horizon3.ai used Anthropic’s Mythos to work out that xorshift128+ output is reversible, so a handful of login responses hands you the signing key. That’s CVE-2026-61500, CVSS 9.3: forged admin cookies, then RCE. Patched in 3.2.1 on July 13, exploitation started October 2. The patch gap is still the whole story.

Google halts open-source bug bounty program amid AI spam surge

Automated reports just closed a bug bounty. Google paused product vulnerability submissions to its Open Source VRP on October 5, citing a rise in automated submissions “the vast majority of which are not valid” — this for a programme that paid $17.1M to over 700 researchers in 2025. Supply chain reports and Patch Rewards stay open, with a reformat promised in Q1 2027. Triage capacity is the part of security nobody budgets for 😅

Citrix patches NetScaler SAML zero-day exploited in attacks

Patching last week’s NetScaler zero-days bought you about four days. CVE-2026-88779 (CVSS 8.7) is a memory buffer flaw in SAML SP/IdP configs, and appliances already sitting on 14.1-73.37 are getting hit, with shell commands stuffed into the username field. Fixed in 14.1-73.41 and 13.1-64.28, and CISA’s federal deadline is October 7. If SAML auth is on your Gateway, this is tonight.

Strata: run Qwen3.8-Flash-Next (125B) on consumer hardware

A 125B model on a 12 GB gaming GPU at 94 tokens/s. Strata runs Qwen3.8-Flash-Next by spreading weights across GPU, RAM and SSD, with a small draft model proposing tokens so the big one verifies them in batches. That number is an RTX 5070 with a Ryzen 5 7600 at Q2_0, so heavily quantised, but it’s MIT-licensed and speaks the OpenAI API. The “you need an H100” assumption keeps shrinking.

Pizza Bot: Open-Source Inbox for Background AI Agents

The interesting thing about Pizza Bot is its shape: an inbox, not a chat window. A few AWS engineers open-sourced the tool they’d been running internally since April 2025, and the argument is that a background agent task is a thread you come back to, not a session you sit and watch. Scheduled and webhook-triggered runs, human approval checkpoints, state in local folders you own, Apache 2.0.

scroll for more