CERT-EU has updated its advisory on critical vulnerabilities in Microsoft SharePoint Server, confirming active exploitation of CVE-2026-50522 (CVSS 9.8), a deserialisation flaw allowing remote code execution. This is part of a wider series of recently patched critical bugs — CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644 — affecting on-premise SharePoint Server instances, some exploitable without authentication.
Citrix disclosed 8 vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateway, including 2 critical unauthenticated RCE flaws with CVSS 9.5 that Citrix confirms are being actively exploited. CERT-EU urges immediate patching and compromise assessment for internet-facing appliances. Other flaws include HTTP request smuggling, memory overflow bugs leading to RCE/DoS, a policy bypass, and a TCP ISN prediction issue.
Anthropic has launched the Claude Frontier Academy, a $100 million program designed to address a shortage of skilled staff capable of implementing AI inside large organizations. The goal is to certify a large number of so-called Frontier Deployed Engineers by the close of 2027, with early participants coming from firms including Accenture, Bain, Capgemini, Commonwealth Bank of Australia, Deloitte, McKinsey, Morgan Stanley and Novo Nordisk. The flagship course, a residency modeled loosely on medical training, combines an in-person intensive with a 12-week supervised project inside the engineer's own company before certification.
AWS released a step-by-step walkthrough showing how to give Claude Desktop (on Amazon Bedrock) live internet access through Amazon Bedrock AgentCore Gateway, closing the gap left by the model's training cutoff. The setup wires AWS IAM Identity Center SSO through Amazon Cognito as a SAML-to-OAuth federation layer, issuing JWTs that the AgentCore Gateway validates on every request. The Web Search capability itself is MCP-compatible and runs on an internal Amazon web index covering tens of billions of documents, so no query traffic leaves AWS and no third-party API key is needed. The feature is currently limited to three AWS Regions: us-east-1 (N. Virginia), eu-west-1 (Ireland), and ap-northeast-1 (Tokyo).
NVIDIA released a detailed workflow for fine-tuning its Nemotron 3.5 ASR multilingual streaming model on Saudi Arabic dialects (Najdi and Hijazi). Using minimal data curation, replay mixing with FLEURS data, duration-based bucketing, and partial encoder unfreezing, they reduced word error rate on the target dialects from 55.05% to 29.96% while also slightly improving English and other Arabic performance. The post also covers decoding tweaks and speaker diarization extensions for multi-speaker transcription.
Allen Institute for AI (Ai2) has open-sourced AstaBrief 8B, a model built on Qwen3-8B that turns research questions and retrieved literature excerpts into cited scientific reports. It's now live in Ai2's Asta platform as a 'Fast mode' alongside a Claude-powered 'Thinking mode', generating reports in about 51.1 seconds on average compared to 178.5 seconds for the Claude pipeline — roughly 3.5x faster. Ai2 trained the model using supervised fine-tuning on 47K examples (from 90K filtered real research queries) followed by DPO on about 6K preference pairs, and found that filtering training data for citation density was the single most effective lever for improving grounding quality.
Microsoft Research has unveiled Quine, a research system combining a multimodal 'world model' of biology with an interactive harness linking AI models, scientific literature, lab tools, and researchers. Built jointly across data types such as genomics, proteins, chemistry, RNA/cell state, and bioimaging, the model aims to predict how biological systems respond to interventions before costly lab experiments are run. Working with the Broad Institute of MIT and Harvard, Microsoft used Quine to rank thousands of compounds for their potential to shift pancreatic cancer cells between therapeutic states, and the top-ranked candidates were validated in wet-lab assays within a single weekend. Microsoft is now opening a 'Quine Fellows' program to give selected scientists early access, while cautioning that the system is experimental, research-only, and not intended for clinical use.
A Google Cloud TPU engineering team worked with Ai2 to rebuild Olmo 3 7B's pre-training from scratch using MaxText, Google's JAX/XLA training framework, running on TPUs instead of Ai2's original PyTorch/GPU setup. They matched Ai2's published results not just on the training loss curve but on four independent held-out evaluation surfaces across the full ~5.93-trillion-token, 1.41-million-step stage-1 run plus the stage-2 annealing phase. Along the way they ported Olmo 3's unusual architecture (reordered-norm blocks, QK-norm, 3:1 sliding/global attention ratio) into MaxText and caught a data-loader bug that had been quietly inflating apparent performance through memorization rather than genuine learning.
Google engineers describe how they implemented sparse spatio-temporal attention for video diffusion models on TPU v6e chips, converting the theoretical sparsity of the Sparse VideoGen (SVG) approach into real hardware speedups. Through a progression of kernel optimizations (full/boundary tile specialization, tile-size tuning, and mask-tile alignment), they reduced attention kernel latency from 96.37ms (naive sparse) to 32.76ms, a 2.40x speedup over dense Splash Attention on a single TPU v6e chip, using 75.6K tokens, 10 heads, and head dimension 128.
Mistral AI announced a new hub in Munich, Germany, focused on Physics AI and Industrial AI, serving enterprise partners in automotive, energy, aerospace, and manufacturing. The hub follows Mistral's acquisition of Emmi AI in May 2026, bringing over 30 physicists and engineers to the company. Mistral is working with BMW on crash simulations and Siemens Energy on industrial AI applications, and has formed a research partnership with TUM on automotive aerodynamics.
Google DeepMind unveiled SynthID Bio, a watermarking technology that embeds an imperceptible, verifiable signature into AI-designed proteins and 3D structures without compromising their biological function. The system was tested on protein binders (VEGF-A, SARS-CoV-2 spike RBD, PD-L1) using AlphaProteo and a modified ProteinMPNN, and also fine-tuned into AlphaFold 3's diffusion network for watermarking predicted 3D structures. DeepMind is also collaborating with Stanford's Hie lab and Arc Institute to apply the approach to Evo 2, a genomic model, to watermark designed bacteriophage genomes. The goal is to strengthen biosecurity by helping DNA synthesis screening providers and public databases verify the provenance of AI-generated biological designs.
Google Cloud introduced, in public preview, a remote MCP server that exposes the gcloud and bq command-line tools to AI agents via two tools: run_gcloud_command and run_bq_command. The server runs in an isolated, network-restricted sandbox on Google Cloud infrastructure, removing the need for agents to install or maintain local CLI binaries. It uses Agent Identity, OAuth 2.0, and IAM for authentication, integrates with Model Armor to screen for prompt injection, and supports Cloud Audit Logging for full visibility into tool calls.
NVIDIA is releasing a new 64GB unified memory configuration of its DGX Spark personal AI supercomputer, available from partners like Acer, ASUS, Dell, HP, Gigabyte and MSI starting Oct. 23 at $4,999. The system runs up to 100-billion-parameter models locally on device, and two units can be clustered via NVIDIA Sync Cluster Assistant to pool memory to 128GB and support models up to 200 billion parameters, with up to 1.7x performance gains in NVIDIA's Qwen 3.8 27B test. It ships with the NVIDIA Agent Toolkit, CUDA-X AI libraries, Nemotron models and support for Ollama, vLLM and PyTorch out of the box.
Google announced that its Antigravity SDK now supports running agentic workflows locally and offline, with initial support for Gemma 4 26B A4B running via Google AI Edge's LiteRT. Developers can build agents that run entirely on-device, without cloud API costs or internet dependency. Google also demonstrated a hybrid 'Architect-Builder' pattern where a cloud model (Gemini 3.8 Flash) plans tasks and a local swarm of Gemma 4 26B instances does the heavy execution, keeping source code off the cloud.