Happy Saturday, everyone! Here on Global Nerdy, Saturday means that it’s time for another “picdump” — the weekly assortment of amusing or interesting pictures, comics, and memes I found over the past week. Share and enjoy!






































































































Happy Saturday, everyone! Here on Global Nerdy, Saturday means that it’s time for another “picdump” — the weekly assortment of amusing or interesting pictures, comics, and memes I found over the past week. Share and enjoy!






































































































Here’s what’s happening in the thriving tech scene in Tampa Bay and surrounding areas for the week of Monday, September 21 through Sunday, September 27!
This list includes both in-person and online events. Note that each item in the list includes:
✅ When the event will take place
✅ What the event is
✅ Where the event will take place
✅ Who is holding the event

Tuesday from 10:00 a.m. to 11:00 a.m. (online): Computer Coach, via their Tampa Cybersecurity Training Meetup group, presents Career Changing Successfully!
Ready for a career change? Join our webinar, “Career Changing Without Resetting Your Journey,” and learn actionable steps to transition successfully. Recognize your current skills and seize new opportunities without starting from scratch. Register now and take the next step in your career!
Find out more and register here.
Tuesday from 5:30 to 8:30 p.m. at Hidden Springs Ale Works (Tampa): It’s the September edition of TampaTech Taps & Taco Tuesday!
This is a once-a-month gathering of Tampa Bay’s tech community for good company, good conversations, 15% off the regular beer prices, and most importantly, FREE TACOS!
Find out more and register here.
Tuesday from 7:30 to 9:00 p.m. (online): Tampa AI Applications Meetup Group presents Mastering Guardrails for Generative AI Testing!
This session explores key strategies for testing and validating AI guardrails: covering bias detection, hallucination control, and output validation. Gain valuable insights into building trustworthy AI systems and effectively testing generative models in real-world applications.
Find out more and register here.
Wednesday from 12:30 to 1:30 p.m. (online): Heart of Agile St. Pete – Tampa – Orlando is hosting an online coffee corner!
The Heart of Agile Coffee Corner brings people together from around the world via Zoom in a casual setting to share and discuss ways we Collaborate, Deliver, Reflect, and Improve.
We explore the kinds of topics people ask for: real-world stories of Agile in practice, small high-leverage changes in how we work together, and the intersections between Heart of Agile and emerging areas like AI — shaped by who’s in the room and what you bring.
The Heart of Agile is not just for software teams. It applies anywhere people work together — healthcare, education, community work, product development, coaching, and beyond — so you’re welcome whether or not you work in tech.
This is not a formal talk or webinar. Expect an informal, conversational space where you can join for as much time as you have, listen in, and contribute when you’re ready.
Find out more and register here.
Wednesday from 6:00 – 9:00 p.m. at Coppertail Brewing (Tampa): ISACA West Florida Chapter is hodling their Q3 2026 Networking Event!
Whether you’re deep in tech or work in a technology-adjacent field, this is the perfect chance to connect with fellow professionals, share ideas, and just have a good time.
Find out more and register here.
Thursday at 5:45 p.m. at Hillsborough Community College’s Dale Mabry Campus (Tampa): TampaBay AI Meetup / Tampa QA Meetup / Tampa Java User Group present Known and Unknowns: Testing AI-Generated Code!
Billy Korando (developer advocate at Oracle) is visiting from Kansas City and will be here to walk us through three distinct phases of testing AI-generated code, from defining expected business behavior and covering edge cases to uncovering bugs and risks you may not have anticipated. Telling your coding agent to “write tests” isn’t enough, and Billy’s here to show us ways that work.
Find out more and register here.
Thursday from 5:30 – 7:00 p.m. at University of Tampa’s Skyview/TECH 694 (Tampa): IEEE Florida West Coast and Women in Engineering present Data Science & AI in Action : Industry Perspectives!
This event will feature 5 lightning talks from industry leaders, followed by an open panel discussion.
Find out more and register here.
Friday at noon to 1:00 p.m. (online): Computer Coach, via their Tampa Cybersecurity Training Meetup group, presents Back To Basics: The Fundamentals That Still Matter!
Back to Basics is a practical look at the fundamentals that can make a difference in your job search. This presentation will discuss what is working for candidates, along with the importance of preparation, professionalism, and knowing how to make a strong impression.
The conversation will cover:
Find out more and register here.
| Event name and location | Group | Time |
|---|---|---|
| Osceola Toastmasters Club Kissimmee Utility Authority (KUA) |
Toastmasters Division E | 7:30 AM to 9:00 AM EDT |
| Computer Repair Clinic 2079 Range Rd |
Tampa Bay Technology Center | 8:30 AM to 12:30 PM EDT |
| Back To Basics: The Fundamentals That Still Matter Online event |
Tampa Cybersecurity Training | 12:00 PM to 1:00 PM EDT |
| Age of Sigmar: Escalation League Battlebrush Games |
Battlebrush Games: Paint Minis & Play Warhammer/Warmachine | 5:00 PM to 9:00 PM EDT |
| Friday Board Game Night Bridge Club |
Tampa Gaming Guild | 5:30 PM to 11:00 PM EDT |
| MTG: Commander FNM Critical Hit Games |
Critical Hit Games | 6:00 PM to 11:00 PM EDT |
| Modern FNM Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh! |
Sunshine Games | 7:00 PM to 10:30 PM EDT |
| Friday Pokemon Tournament Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh! |
Sunshine Games | 7:30 PM to 11:30 PM EDT |
| Return to the top of the list | ||
| Event name and location | Group | Time |
|---|---|---|
| Ice Cream Social Carrolwood village Park |
Geekocracy! | 12:00 PM |
| Meeting 7: Gangsters of Capitalism by Jonathon Katz Heights Lounge (Coffee, Kombucha, Herbal Teas, Hookah) |
The Culture Club – A Nonfiction Book Club | 1:00 PM to 3:00 PM EDT |
| Adventures of the Tomb of Annihilation (5e 2024 D&D Campaign) Cozy Dragon Games |
Adventurers of Central Florida | 2:00 PM to 6:00 PM EDT |
| Sunday Chess at Wholefoods in Midtown, Tampa Whole Foods Market |
Chess Republic | 2:00 PM to 5:00 PM EDT |
| D&D Adventurers League Critical Hit Games |
Critical Hit Games | 2:00 PM to 7:30 PM EDT |
| Sunday Pokemon League Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh! |
Sunshine Games | 4:00 PM to 8:00 PM EDT |
| Escape Room & Dinner! ️♂️ 2480 East Bay Drive |
St. Pete Life & Fun 50+ | 4:00 PM to 7:00 PM EDT |
| Community Hang-out Night Online event |
Nerdbrew Events | 6:00 PM to 9:00 PM EDT |
| A Duck Presents NB Movie Night Discord.io/Nerdbrew |
Nerd Night Out | 7:00 PM to 11:30 PM EDT |
| Return to the top of the list | ||

How do I put this list together?
It’s largely automated. I have a collection of Python scripts in a Jupyter Notebook that scrapes Meetup and Eventbrite for events in categories that I consider to be “tech,” “entrepreneur,” and “nerd.” The result is a checklist that I review. I make judgment calls and uncheck any items that I don’t think fit on this list.
In addition to events that my scripts find, I also manually add events when their organizers contact me with their details.
What goes into this list?
I prefer to cast a wide net, so the list includes events that would be of interest to techies, nerds, and entrepreneurs. It includes (but isn’t limited to) events that fall under any of these categories:
Yes, it’s short notice, but if I can do a talk on short notice, perhaps your schedule might allow you to show up TONIGHT (Thursday, September 17) to attend the first Machine Learning / AI / Technology / Risk + Happy Hour event, taking place from 4 – 9 p.m. at Schiller International University in downtown Tampa!
This event brings together technologists and technology-adjacent professionals to connect, share knowledge, learn and grow together.
Yes, it’s last minute, but a lot of people have signed up already, and for those of you collecting cybersecurity CPEs, attending this one will earn you 2!
With AI model performance and tooling evolving at a breakneck pace, the lifecycle of technical feasibility has compressed. Solutions deemed impractical just months ago are frequently production-ready today. We will examine how enterprise leaders and practitioners are navigating this shifting baseline—reassessing former roadblocks, managing risk, and executing sustainable AI transformation strategies.
Panelists:
Computed Tomography (CT) scans are used to train machine learning models to predict cancer outcomes. Datasets are frequently composed of images collected using different devices or settings, which can reduce classifier accuracy.
This talk covers an automated method for screening CT datasets to detect features that make models learn spurious associations – called confounders – and other unwanted variations in data. By understanding what affects data quality, we can mitigate these issues or adjust image acquisition processes to prevent them from happening in the future.
Speaker: Nikolai Fetisov
Every clinical decision draws on labs, coded history, notes, and imaging at once. Most deployed models read one. The work began as an ONC engagement, built as a physician assistant and trained with split learning, so records never left the institutions holding them. Asked which task would earn a place in their day, physicians answered consistently: help with the differential. The 2015 National Academies report found that most people will experience at least one diagnostic error in their lifetime. These are usually failures of consideration rather than knowledge: the right diagnosis was never placed on the list.
Solution is valuesets governed data trained with multimodal model built with fusion architecture. Each branch is projected to a shared width, given its own self-attention, and combined in one late fusion feeding condition heads that share a representation. Results are early with no prospective study with clinicians yet, but the validation metrics looks promising. Future improvements with contrastive learning and focal loss will drastically increase recall and additional testing is carried out by analyzing Krippendorf alpha.
The opportunities of this engine serve six workflows: diagnostic support, risk adjustment, trial recruitment in phase3, quality measurement, Hedis scoring, and rare disease detection. Only the label set, the threshold, and the recipient change.
Differential diagnosis is the capability. The opportunity remains open.
Speaker: Sravan K. Elineni
As cyber threats targeting patient data grow more sophisticated, healthcare providers are turning to AI to stay ahead. Rather than reacting after damage is done, AI-powered tools spot unusual activity early, streamline HIPAA compliance, and speed up incident response—helping protect EHRs, medical devices, and telehealth systems while preserving the trust patients place in their care.
Speaker: Yukti Goyal
(previously presented at 2026 BSides Tampa)
Active Directory (AD) became the de facto standard for Windows-centric organizations to add security, but today, removing AD or minimizing its footprint is considered a security enhancement.
More than a technical optimization, switching from hybrid-AD to cloud-native Entra ID is a risk reduction strategy. Have the capabilities of cloud native reached a tipping point where more organizations can seriously consider reducing or eliminating AD? This session will discuss a regulated organization’s journey to cloud native, reasons to do so, challenges, and lessons learned.
Speaker: Daniel Jarboe
The tech job market has been sending signals for two years. Most of us have been too busy surviving it to read them. After 15+ years in tech and a recent job search that took me across a couple dozen companies, I came away with both a new role and something just as valuable: a pattern.
Job descriptions have quietly shifted. Hiring panels are asking different questions. “ROI” means something specific now that it didn’t mean in the zero-interest 2010s or the Great Resignation era of a couple of years ago. The skills companies say they want versus the skills that actually get you hired don’t look like they come from the same list.
This talk is an honest, experience-based, practitioner-level read of what the market is telling us about where tech is headed. It doesn’t have any LinkedIn takes or recycled frameworks; just patterns from the front lines, with implications for how you position yourself, make the case for your team, and think about the next few years of your career.
Speakers: Joey de Villa (and maybe Anitra Pavka)
Singer: Kat Casperson

The event will take place at Schiller International University, which is located in Park Tower, located in downtown Tampa at 400 N Tampa St, on the 9th floor.
There will be food and drink, sponsored by ISACA West Florida Chapter.
On Monday, September 14, Pratik Patel gave his talk, Building a Mini-Software Factory using Pi.dev and Local LLMs, to a full room at the Entrepreneur Collaborative Center in Tampa’s Ybor City neighborhood. Here are my notes from his talk.
The quite-full ECC was about three-quarters software developers, and Pratik had just finished taking a headcount of the Java people, the TypeScripters, the Pythonistas, and of course, the Rustaceans (“most people want to rewrite everything in Rust, and I find it extremely annoying”). That’s when he said what would’ve gotten him tarred, feathered, and run out of a Java meetup if we’d been back in the days of Java SE 18 or 19:
“One of the things that you may get from this session is that the programming language doesn’t even really matter anymore.”

Of course, his paln was to prove that statement by the end of the night, as well as the conclusion that you should draw if you still plan to remain in software: If you hand the coding off to a machine, the valuable work moves up the stack.
Pratik is a longtime Java/JVM guy, one of the organizers behind the DevNexus conference in Atlanta, and as of about a month ago, he works at Hugging Face. He also polled the room on what Hugging Face actually does, and enjoyed the answers (mine: “Hang out with Jensen!”). The correct one, which he eventually told us, was that they own Transformers and the rest of the library stack that lets you download, and better still run the models.
It takes time for an software factory to build things, even on a late-model MacBook with 64GB RAM like Pratik’s. Sp he started the demo at the beginning and then talked over it, which I suppose is the new version of “live coding”. I do that myself (both live agentic coding as well as raw-dogging the code the old-fashioned way), so I have to respect Pratik’s boldness.
He asked the room for an app idea. Someone suggested a horse-boarding scheduler, which was too big. Charles, who works for a sports organization, suggested a playoff odds calculator. Pratik assessed that it was doable within the given time, so he agreed to build that.
Pratik opened Gemini and, off the cuff, dictated a rough spec: look at the remaining season schedule for all 30 MLB teams, calculate each team’s chance of making the playoffs, and let the user tweak the metrics on the page to try different scenarios.
Gemini spat out a 255-line spec in a few seconds. He pasted that into his software factory, told it “Create a new app called MLB Odds, here’s the spec, let me know when it’s finished and what the URL will be,” hit enter, and walked away from it to start the actual presentation.
“Again,” he said, “this may be a total disaster. It may not work, but let’s see how it goes.”
Pratik was upfront that this is the most undefined term in the industry right now: “If you ask 10 people in this room what a software factory is, you’ll probably get 10 different answers.” Here’s his:
An AI software factory is a system, not a team, that turns human-written specifications and intent into working software, using agents to perform most or all of the coding, testing, review, and release work.
The key word is system. You say “go build this,” walk away, and come back hours or a day later to working software. It’s like handing a project to a team of engineers and going off to do something else (or hey, nothing. You’re the boss!).
And critically, a software factory is not one-shotting. Telling Claude or ChatGPT “build me this website” and pasting in a detailed description relies entirely on the raw intelligence of the model. A factory applies rigorous software engineering process around the model: planning, architecture, implementation, testing, QA, security review, version control. The process is the product.
Pratik walked through a progression that got a lot of nodding in the room:






His take: most working developers are somewhere between L2 and L4 right now, depending on how much freedom their employer gives them.
Pratik clearly flagged this part as his own opinion. Like a lot of developers, myself included, he went through the “there’s no way AI replaces me” phase. He concluded that it doesn’t replace software engineers, but it does dramatically change what they spend their day doing, which is the remaining high-value work. I get the feeling that programmers went through something similar when going from assembly to higher-level languages.
With AI writing the code, the process of programming becomes even higher-level, with these becoming our main activities:
He also noted, to the product managers in the room, that the line between PM and engineer is blurring fast in both directions.
At minimum, Pratik argues, a software factory has to do four things:
The single most important artifact in all of this is architecture.md. That file is where you, the engineer, do the system design: “This is a web app, use Vue, this is the backend, these are the performance targets, this is how we build things around here.” It’s exactly what you’d tell a new team lead. The factory can’t extrapolate it from your brain.
Specs are a separate thing from architecture: specs are the features, architecture is the system. For spec format, Pratik mostly writes Markdown, though he noted that larger teams use a more rigid PRD structure, and GitHub’s Spec Kit is out there if you want something opinionated.
Here’s what he’s running, top to bottom:
Hermes Agent as the front office. Hermes (the open-source, self-hosted personal agent from Nous Research, in the same category as OpenClaw) is his always-on orchestrator. It runs on a server, it’s reachable via Telegram, Discord, Slack, or email, and it has persistent memory that turns repeated requests into reusable skills. Hermes takes his request, polishes it into a formal spec, finds the right project directory, and dispatches a headless job to the factory floor. He runs it on a 35B-A3B Qwen model, which has 35 billion parameters, but only 3 billion active per token, so it fits on a modest server.
pi.dev as the factory floor. pi.dev is Mario Zechner’s minimal terminal coding harness. It ships with four tools: read, write, edit, bash. It has a tiny system prompt, and hooks for everything else. That’s it: it’s a build-your-own coding agent, not a sealed product. Pratik picked it over Claude Code, Codex, Cursor, OpenCode, Kiro, and the rest because it’s lightweight, it doesn’t burn tokens, and you can point it at any model you want.
Someone reasonably asked why he didn’t simplyu use Hermes for the coding too, since Hermes can code. His answer was about context hygiene: he wants Hermes to be the manager and pi to be the worker, and he doesn’t want to pollute the coding agent’s context with all the management and channel-routing overhead. “It doesn’t have memory. It doesn’t have learning. I don’t want all that stuff for my worker software monkey that’s going and building the code.”
A local LLM. Qwen 3.6 27B, running on a 5090 at home rather than on his laptop for the demo. (Qwen 3.8 27B had landed a few weeks earlier and he said the jump was a substantial improvement.)
A context MCP server. This is the piece I think people will underrate. Qwen 3.6’s knowledge cutoff is roughly a year stale, which means it doesn’t know current Vue and Nuxt APIs. So he plugs pi into an MCP server loaded with current docs and code samples for whatever he’s building (HTML/CSS, Vue.js, Nuxt) so that it builds against Nuxt 4, not whatever it “half-remembers” from last year.
And there isn’t one factory, there are three: a front-end one (Vue/Nuxt), a Java/Spring Boot one for performance-sensitive backends, and a Python one for utilities. Same seven-step process in all three, different tooling underneath.
Inside the project’s .pi directory, Pratik has one extension defining the seven-step workflow, plus a set of skills: spec analyst, architect, developer, QA engineer, reviewer. He keeps them project-local rather than global precisely because he wants a tight, specialized harness per project type.
He opened up the spec analyst skill live, and the reveal was how short it is:
The whole thing is barely a screen’s worth of text telling the model it’s a technical product manager who reads requirements systematically and translates them into concrete action plans with features, data models, and API contracts, followed by a handful of instructions: do requirements gathering, document assumptions, create a data model, define the API contract. That’s it. And you could see it working: the analyzer had taken his 255-line Gemini spec and decomposed it into four sub-specs before any code got written.
The QA engineer skill was similarly plain (use Vitest, use test-utils to mount components), and he was candid: “probably needs a little bit more work if I want to make it more rigorous.”
For visual QA he uses a Playwright plugin. The model has vision capability, so it screenshots the running page and checks it: I can’t read the text on this button because it’s overflowing, make the button bigger.
Two reasons, and Pratik was blunt about both.
Reason one is intellectual property. Yes, there’s a checkbox that says don’t train on my data. Do you believe it? “They already trained their models on everything on the internet, including copyrighted material they pirated. I don’t know if I trust these guys with stuff I care about.” If you’re building something proprietary, running the whole pipeline on hardware you own removes the question entirely.
Reason two is cost, and this is where the harness argument lands. The most quotable thing Pratik said all night:
“The harness that calls the underlying LLM matters actually much more than the LLM does.”
The corollary is the one that should change how you spend money: you can burn a fortune on frontier-model tokens, or you can build a really good harness and run a much cheaper model and get the same or better results. He has the receipts; he built the same project roughly 50 times while tuning his seven-step flow.
He’s not a purist about it, either. When he starts something from scratch, or when he wants a rigorous final security pass, he’ll swap the model out and point the last three steps at something enormous like DeepSeek V4 or GLM 5.3 via OpenRouter or Hugging Face inference providers. Same harness, better LLM, but only where it’s worth paying for.
Pratik spent a useful chunk of the talk on quantization, because it’s the thing that determines whether any of this runs on your machine.
A 27B model at full BF16 precision is roughly 65–70 GB of weights, which is more VRAM than almost anyone has. Quantization reduces the precision of each weight from 16 bits down to 8, 6, 4, or a mix. Qwen 3.6 27B at Q6 comes down to about 22 GB, which fits comfortably on a 5090 with headroom for context and the vision projector. By his own testing and what he’s read, Q6 retains about 96% of full BF16 quality while running at around 120 tokens/second on that card. On his MacBook with MLX (64 GB of unified memory, which you can allocate generously to the GPU), he gets 40–50 tokens/second, which is what he uses on planes and bad hotel Wi-Fi.
Someone asked whether ~27B is the floor for useful coding models. His answer: currently yes, but a good harness lets you go smaller, and a coding-specialized fine-tune like Qwen3-Coder-Next punches well above its size (while being terrible at anything that isn’t code).
The bad news: now is a terrible time to buy hardware for this. The 5090 that cost someone in the room $2,500 a year ago is around $5,000 now. An RTX Pro 6000 with 96 GB went from roughly $8,000 to $16,000. His maxed-out 512 GB Mac Studio cost $8,000 eighteen months ago and would fetch $25–30K on eBay today. His recommendation if you must buy: a recent MacBook with at least 64 GB of unified memory, and if you can stretch to 128 GB, do it and stop thinking about it.
This came out of an audience question and it’s worth pulling out, because it’s one of the most common misconceptions Pratik runs into.
People say “I want to fine-tune a model on my company’s data”, such as sales numbers, houses sold in Tampa in 2025, whatever. That’s the wrong tool. Fine-tuning changes the shape of a model: its behavior, its vocabulary, its domain nomenclature. If you’re a hospital and your ophthalmologists describe eye conditions in very specific language the base model doesn’t handle well, that’s a fine-tuning job.
Hard data should be pulled in as late as possible, via MCP or straight into the context window, because models hallucinate data. Note that he deliberately corrected himself mid-sentence from “data” to “information” when describing fine-tuning inputs. That distinction is the whole point.
Two solid challenges came from the audience, and Pratik didn’t dodge either.

“Isn’t this just waterfall, which we spent 20 years learning to hate?” His defense: there are feedback loops built in (test failures bounce back to development, review failures bounce back further) and the harness doesn’t implement the whole spec at once. It scaffolds, then builds the user page, then the admin page, then the REST endpoints. Also, and someone in the room pointed this out to general delight, if you actually read Royce’s original waterfall paper, it had iteration in it. The verdict was tabled for the bar.
“Every one of those artifacts is itself a product you have to maintain.” The test suite, the architecture doc, the QA config, and the CI all evolve and none of them are set-and-forget. Pratik conceded the point. This is the honest counterweight to the whole “walk away and come back” pitch.

Sort of. Which is more honest than most demos.
The first run got killed partway through because it wasn’t doing what he asked. The restart did finish: the app built, started on port 3099, and served a real page with real interactivity. Clicking around ran an actual simulation under the hood.
The problems were exactly the ones you’d predict. Normally, the factory produces properly styled Vue 3 + Nuxt sites for him normally, and he suspects the ad-libbed spec was the culprit. And the numbers were nonsense. The Rays were given a 0.3% shot; someone noted the data looked very old. Pratik’s response: “I didn’t tell it where to go get the data from. So yeah, I was very lazy.”
That’s not a failure of the factory. That’s a failure of the spec, which is precisely the point he’d spent an hour making.
Someone in the room summed it up generously and accurately: “It’s better than most demos I’ve seen.”
architecture.md first.If you only keep five things from this one:
architecture.md is your job and nobody else’s. The factory will happily build the wrong system beautifully. System design, security, and “does this actually meet the user’s requirements” are the work that doesn’t get automated away. Be the team lead, not the typist.Pratik’s software factory code is on his GitHub, and he does in-person workshops, including a new one on using AI to build features that could only exist with AI in them, as opposed to using AI to build software. He gave that one at KCDC last week. He’s also promised to come back to Tampa for a hands-on lab version, which I fully intend to hold him to.
Oh, and DevNexus 2027 is running ten tracks, seven of them AI. If you’re looking for a conference to go deep on this stuff, that’s the one.
The latest edition of NetFoundry’s regular Reachability Watch articles, covering September 4 – 10, 2026 and written by Mark Jaffe, our Chief Strategy and Marketing Officer, is up:
https://netfoundry.io/ai/reachability-watch-cve-kev-tracker-2026-09-11/
And with this edition, a new “back of the envelope” drawing by Yours Truly, which shows the “env var” pattern behind two of the CVEs in this report.
In this edition:
Microsoft shipped 15 critical network CVEs in a single release, 14 of them at 9.8, across DNS, DHCP Server, RPC Runtime, USB Mass Storage, and Telnet Client.
The most notable part of this Reachability Watch is this set of CVEs:
CONTAINER_NAME being setexcel-mcp-server reads and writes arbitrary files when EXCEL_FILES_PATH is blankThe CVEs come from four different projects, but they all have the same shape: reachable by default, with authentication either optional or absent. In two of them, the auth check exists as real code, wired behind a conditional on an environment variable, and it fails open when the variable is missing. It’s not that anyone turned security off; instead nobody confirmed it was on.
Here’s my own opinion of what the main take-away for this edition is: The environment variable may be the headline, but the bind address is the actual exposure. AutoAgent’s server binds every interface by default, not loopback. These tools get written with a localhost mental model (it feels like a library, not a network service) and then inherit 0.0.0.0 from whatever framework default was closest to hand.
The auth flag and the bind address are two independent decisions, and the second one is what turns a local misconfiguration into something an attacker can reach. If AutoAgent’s default bind was loopback, the attack approach would have resulted in a configuration bug and not an unauthenticated RCE, and it wouldn’t have required anyone to write an auth system at all.
All this is the argument for handling reachability underneath the app: An overlay doesn’t care whether the service remembered to check a password, because an unauthorized requester never gets a path to the port in the first place.
Once again, the latest edition is Reachability Watch is here:
https://netfoundry.io/ai/reachability-watch-cve-kev-tracker-2026-09-11/
Here’s what’s happening in the thriving tech scene in Tampa Bay and surrounding areas for the week of Monday, September 14 through Sunday, September 20!
This list includes both in-person and online events. Note that each item in the list includes:
✅ When the event will take place
✅ What the event is
✅ Where the event will take place
✅ Who is holding the event

Monday at 5:45 at Entrepreneur Collaborative Center (Tampa): Join Tampa Bay AI Meetup for a rare Monday meetup where Pratik Patel from Hugging Face (yes, that Hugging Face) will talk about pi.dev.
pi.dev is an open-source, terminal-based agent harness that strips away the bloat to give local LLMs direct access to a minimal toolset (read, write, edit, bash). Most AI coding assistants are sealed cloud platforms heavy on dashboards and light on local control, and pi.dev addresses that gap.
This talk will explore how to harness a minimalist architecture to build a local “mini-software factory.” Pratik will show you how to feed a structured application specification to pi.dev and watch it autonomously architect, generate, and test a project end-to-end. You’ll see the exact configuration, prompt engineering tricks, and custom extensions needed to make this work seamlessly using a 100% local LLM pipeline.
Find out more and register here.

How do I put this list together?
It’s largely automated. I have a collection of Python scripts in a Jupyter Notebook that scrapes Meetup and Eventbrite for events in categories that I consider to be “tech,” “entrepreneur,” and “nerd.” The result is a checklist that I review. I make judgment calls and uncheck any items that I don’t think fit on this list.
In addition to events that my scripts find, I also manually add events when their organizers contact me with their details.
What goes into this list?
I prefer to cast a wide net, so the list includes events that would be of interest to techies, nerds, and entrepreneurs. It includes (but isn’t limited to) events that fall under any of these categories:
Happy Saturday, everyone! Here on Global Nerdy, Saturday means that it’s time for another “picdump” — the weekly assortment of amusing or interesting pictures, comics, and memes I found over the past week. Share and enjoy!





































































































