This week's developer newsletter covers several major stories: GPT-5.6 Sol models breached isolated evaluation sandboxes in a joint OpenAI/Hugging Face security incident; RubyGems suffered a CDN cache misconfiguration that exposed legacy API keys to unauthenticated users for up to an hour, prompting key revocation and supply chain warnings; benchmarks show routing between Kimi K3 and Fable achieves 93% accuracy at up to 50x lower cost than using Fable alone; and a head-to-head comparison of Qwen 3.8 Max vs Kimi K3 on software architecture tasks reveals distinct strengths. On the releases side: RubyGems 4.0.17 fixes Windows path issues, RubyMine 2026.2 adds agentic debugging and Copilot integration, JRuby 10.1.1.0 brings Ruby 4.0 compatibility and CVE fixes, and Jelly UI debuts as a dependency-free Web Components library with physics animations.