Hey {{first name | there}}. A teenager found a way into a Microsoft analytics service and ended up with access to 17.3 trillion records. Elsewhere, Docker is working on a way to package AI agent permissions with the image itself, while OpenAIās new agents can keep working after you log off.
Kestra also released 2.0, with changes aimed at running data, infrastructure, and business workflows through one orchestration layer.Ā
In todayās roundup:
The 16-year-old who reached 17.3 trillion Microsoft records
How Kestra 2.0 brings data, infrastructure, and business workflows together
OpenAIās agents that keep working after you log off
Dockerās plan to package agent permissions into the image
LATEST DEVELOPMENT
š§ PRESENTED BY EVERYTHINGDEVOPS
A $200 AI certification can be a good investment. It can also be $200 you didn't need to spend.
There are hundreds of AI certifications now, so we compared four separate rankings and looked for the ones that kept showing up.
The interesting part is that some of the certifications you see everywhere didn't make it, and a few that did are much more useful depending on where you want to work.
The breakdown covers what each certification teaches, who should take it, what it costs, and which ones to leave alone.
Before you pay for one, check this list.
Subscribe: @EverythingDevOpsHQ for deeper dives on agents, Kubernetes, MLOps, and AI infrastructure.
š16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows
The Rollout: A 16-year-old researcher who goes by Faav found an authentication flaw in Titan, Microsoft's internal analytics platform, that let him gain admin access and run SQL queries with no valid credentials, reaching databases holding an estimated 17.3 trillion rows. Microsoft has since fixed it and paid him a $5,000 bounty.
The details:
Titan validated everything inside the login token tenant, app ID, user, but didnāt check the token's signature. Faav changed the token's username to "admin," which Titan resolved to local user ID 1 and its admin role.
That opened the metadata database and, from there, the application tables: around 25,000 account records, 18,000 employee emails, plus org hierarchy, job titles, and 356 database configs.
Testing archived routing values, he found 30 still live, resolving to 17 analytics databases across 9,863 table names. The 17.3 trillion figure is a metadata estimate that likely includes historical and duplicated data.
Why this matters: The whole breach came down to one skipped check. Titan had every piece of access-control logic you would want and still handed admin to anyone, because it never verified the token's signature, the part that proves a token is real. Faav's note is worth passing to any developer or coding agent writing auth: verify the signature above all else.
The rollout: Kestra has released Kestra 2.0, a major update to its workflow orchestration platform. The idea is straightforward: instead of managing automation across disconnected tools, teams can coordinate different workloads through one governed orchestration layer.
The details:
Workloads can now run in segmented, sovereign, and air-gapped environments without workers needing to connect back to a central database, which matters for teams operating in restricted or highly regulated environments.
AI agents can interact with production workflows as controlled tools, with access controls, approval steps, and audit logging around what they are allowed to execute.
Teams sharing infrastructure can use reserved capacity to prevent one workload from consuming resources needed by another, while stronger failure handling helps teams manage what happens when workflows break.
Kestra says its rebuilt engine can deliver up to twice the throughput on the same infrastructure.
Why this matters: Enterprise automation tends to spread across teams and systems. Data teams have their workflows, infrastructure teams have theirs, and business processes often live somewhere else entirely. Kestra 2.0 is trying to put those workloads under the same orchestration layer without requiring everything to run in the same environment.
The Rollout: Microsoft has made GitHub-hosted agents and pay-as-you-go pricing generally available in Azure Pipelines. Instead of buying parallel-job capacity upfront, you pay only for the execution time you use, billed per minute at a rate set by the agent SKU. macOS SKUs are GA; Linux and Windows are in public preview.
The details:
The new pool runs on the same infrastructure as GitHub Actions and adds hardware the old pool lacked, native Apple silicon and larger Linux and Windows machines up to 16 cores and 64 GB RAM.
Billing is fully separate from parallel jobs. These agents do not consume your existing parallel-job allocation, but there is no free tier or free minutes, every run is charged.
Each job gets a fresh, isolated VM that is reimaged after it finishes. Existing pipelines stay on their current pool unless you move them explicitly.
Why this matters: For teams whose pipeline load is spiky, paying per minute instead of pre-buying parallel jobs can match actual usage better, and the bigger machines and Apple silicon fill real gaps, especially for iOS builds. The trade-off is no free allocation, so costs track usage directly. Set budget alerts before rolling it out widely.
The Rollout: At DevDay, OpenAI introduced Dots, persistent agents built on GPT-6 Astra that run on their own cloud computers, use their own browsers, and reach more than 4,000 apps through OpenAI's plugin ecosystem. A Dot keeps working when you step away, juggles several projects, and carries context across ChatGPT, Slack, and Teams.
The details:
For developers, a Dot can watch customer feedback for recurring requests, scope a fix, build and test it, and hand back a finished pull request with a video of what changed.
When you are not working with it, a Dot can scan connected apps for ways to help, but it cannot send messages, change content, or drive a browser until you act.
Anything that touches your accounts passes an auto-review step that checks it against your instructions and custom rules. Some tasks, like changing a password, always stay with you.
Why this matters: The shift is to an agent that acts on its own schedule instead of waiting for a prompt, useful and harder to supervise in equal measure. OpenAI's answer is to split finding work from doing it: read-only until you approve action, with an activity log you can watch. Whether that holds under real use is the open part, since a Dot reading thousands of apps is a wide surface for malicious instructions.
The Rollout: Docker is bringing its Sandbox Kit Specification to the CNCF, aiming to make what an AI agent can access as portable as the agent itself. The Apache 2.0 spec, now at v3, packages an agent, its tools, and a typed list of the hosts, credentials, and volumes it requests into an ordinary OCI image.
The details:
The grants that make agents like Claude Code and Codex useful, bind mounts, broad tokens, opened firewall rules, usually live in shell history and memory rather than a reviewable artifact. A Kit puts them in the image, so pinning the digest pins content and permissions together.
Permissions are typed, versioned, and deny-wins. A GitHub example allows api.github.com but blocks DELETE on repos. Credentials can be proxy-injected, so only a sentinel value exists inside the sandbox.
A Kit only requests permissions; the host decides. Without a conforming runtime, the annotation is inert, and Docker Sandboxes is currently the only one.
Why this matters: Agent permissions today are scattered and unauditable, a real problem as agents act on your behalf. Packaging them in the OCI image means your existing registries, scanners, and signing tools handle them unchanged, and a runtime can refuse any update that widens access. The catch: enforcement lives in the runtime, and with only Docker's implementation so far, the promised portability is unproven.
QUICK LINKS
š EVENTS
šŖšŗ š¬š§Europe
Title | Date | Location |
October 6, 2026 | Prague, Czechia | |
October 7, 2026 | Belval, Luxembourg |
šŗšøšØš¦North America
Title | Date | Location |
5-6 October 2026 | Toronto, Canada |
šAsia
Title | Date | Location |
October 3ā4, 2026 | Rajasthan International Centre, Jaipur |
š³š¬Africa
Title | Date | Location |
October 07- 11 | Speke Resort Munyonyo Kampala Uganda | |
October 24 | Lagos, Nigeria |







