GitHub Copilot retires Opus 4.7, Kimi K2.7 Code, and 2 Gemini Flashes
The Oct 2 cull moves you to Opus 5.5, Kimi K3, and Gemini 3.8 Flash — plus critical RCE/auth-bypass bugs in GitLab and AWS AI gateways, and Ai2's 1T-MoE stack.

Copy markdown
Four models leave Copilot, everywhere
As of Oct 2, GitHub Copilot dropped Gemini 3.5 Flash, Gemini 3.6 Flash, Kimi K2.7 Code, and Claude Opus 4.7 across every surface — chat, inline edits, ask and agent modes, and completions. The suggested swaps are Gemini 3.8 Flash, Kimi K3, and Opus 5.5; if your Enterprise admin gates models, those replacements may need enabling in model policies before they show up.
Patch self-hosted GitLab AI Gateway now
CVE-2026-90970 (CVSS 9.9) lets an authenticated Duo Agent user escape the prompt-template sandbox via a crafted flow config and run arbitrary commands on the gateway. Fixed in 19.2.4, 19.3.2, and 19.4.1; affected builds run 18.1.6 through 19.4.0. GitLab.com and Dedicated are unaffected, and there are no in-the-wild exploits yet — upgrade before that changes.
AWS Loom hands admin to anyone with no IdP
A newly disclosed auth-bypass (CVE-2026-103956, CVSS 10) in AWS's open-source agent orchestrator Loom lets any network client seize the control plane when no identity provider is configured — registering malicious tool servers, pulling stored integration credentials, and rewriting IAM policies. Upgrade to Loom 1.7.0 and rotate secrets; the same advisory includes a SageMaker command-injection bug (CVE-2026-104019).
Ai2 open-sources a trillion-param MoE trainer
Olmo-core 3 rebuilds AI2's open training stack for giant mixture-of-experts models: 52,000 tokens/sec/GPU on eight NVIDIA B300s, roughly 2.7x its previous throughput, with MXFP8 precision adding about 21% over a BF16 baseline. The team pushed it to 1.2T total params (58B active) on 512 GPUs. If you're training your own MoE, the code is on GitHub at allenai/olmo-core.
Copilot gets desktop control and coded workflows
Two Oct 1 Copilot previews worth a look: computer use is now in public preview in the Copilot CLI and the macOS/Windows app, letting the agent click through desktop apps on your behalf; and dynamic workflows let you define an orchestration in code — across the CLI, the app, and the SDK — for repeatable multi-step runs instead of one-shot prompts.