TLDR IT 2026-08-18
GitHub goes down 🌐, AI kills another SaaS tool 🤖, Dynatrace bets $915M on AI observability 📈
Make zero CVEs your new default (8 minute read)
Docker has announced updates aimed at making zero-CVE container images the default across the software supply chain. The company says its Hardened Images catalog now extends to hardened Alpine and Debian packages, supports patching beyond software end of life, and offers customization with maintained provenance, while Docker AI Governance records agent policy decisions in Docker Cloud and streams them to existing SIEM systems.
GitHub outage disrupts developers worldwide (3 minute read)
GitHub suffered a widespread outage Monday that disrupted repositories, APIs, GitHub Actions, Copilot, and enterprise authentication services, including SAML, OIDC, and SCIM. Error rates reached roughly 20% across web and API traffic and about 50% for raw repository and archive downloads before GitHub identified the faulty component and restored service later in the day.
Agentic AI in the enterprise: How to balance autonomy with constraints (8 minute read)
Enterprise AI agents become much easier to operate safely when their autonomy is bounded by explicit controls around permissions, tool access, verification, state, and approvals. Treat agents like production systems: use narrow tool permissions, durable audit trails, deterministic checks before writes, staged rollouts, cost and step limits, and human approval for higher-impact actions.
How to level up from IT management to IT leadership (14 minute read)
Moving from IT management into senior leadership requires more than technical depth: leaders need business acumen, strong communication, stakeholder trust, and the ability to connect technology investments to measurable outcomes. CIOs and rising technology executives also emphasize taking on high-impact projects, learning from failed initiatives, prioritizing what not to do, and developing mentors who can help broaden their perspective.
Why It Hasn't Happened Yet (31 minute read)
Recent AI-related hacking incidents at OpenAI, Anthropic, AISI, and Hugging Face should prompt an urgent, industry-wide effort to strengthen operational security. Although limited damage occurred because the models lacked malicious intent, the incidents demonstrated powerful capabilities that could become more dangerous as models improve. Existing protections include alignment training, security classifiers, abuse detection, and conventional security, but each has weaknesses.
Short-lived database privileges eliminate static credentials for AI agents (Sponsor)
Now that AI agents are touching production data, shared database passwords pose a bigger security risk. Teleport provides examples demonstrating how short lived certificates, policy-enforced hardware-backed authentication, and centralized audit logs help secure database access.
Learn more.Dynatrace Acquires Arize as AI Agents Deepen the Observability Challenge (3 minute read)
Dynatrace is acquiring AI observability company Arize for roughly $915 million, combining Arize's visibility into model outputs, agent behavior and tool use with Dynatrace's application and infrastructure telemetry. The goal is to give DevOps and platform teams a clearer way to trace AI-agent failures back through the services, transactions and systems they affect.
Alipay Unveils Full-Stack Agentic Commerce Infrastructure in China (3 minute read)
Alipay introduced a full-stack agentic commerce foundation and its AHA multi-agent, cross-device interconnection protocol suite at an AI ecosystem conference in Hangzhou. The initiative gives merchants tools to convert services into agent-accessible capabilities, while enabling agents across devices and vendors to coordinate authorization, fulfillment, and settlement, with Alipay reporting thousands of adapted services and partnerships across smartphones and automakers.
We Churned Notion After 7 Years. Our AI Agent Took Its Last Job. (6 minute read)
SaaStr canceled Notion after seven years, not because of pricing, support, or a competing product, but because an internal AI agent gradually absorbed the last workflow it was being used for. This creates a new kind of SaaS churn: narrow-purpose tools can disappear from the stack as agents connect directly to company data and take over their jobs, making traditional usage and customer-health metrics less reliable.
Humanity in Open Source (13 minute read)
End-to-end AI agents are flooding open-source maintainers with low-quality issues and pull requests, shifting effort away from coding and toward review. While AI-assisted human contributions can be useful, open source also depends on qualities that automated patches cannot replace, such as human conversation, relationships, and sustained collaboration.
Curated news 🗞️ and trends 📈 in IT strategy 💻, information security 🔐, and cloud computing ☁️.
Join 570,000 readers for
one daily email