Copilot just made every employee an app builder

The news: Microsoft relaunched Copilot on 25 September with three modes: Home, Code and an always-on agent called Autopilot. With Code, any employee can describe an app and Copilot builds and hosts it in your tenant.

Why it matters: Those apps run on Copilot Managed Runtime, connect to live data and get shared with teammates. No developer wrote them, and your app intake was never built to see them.

What to do: Code reaches Frontier program tenants at month end. This week, check whether you are enrolled and name who approves what runs on Managed Runtime.


From the people who send this

CXO Brief is published by DoGood. More than seventy enterprise vendors are currently paying for 30-minute briefings with IT and security leaders on AI governance, third-party risk, identity, observability and infrastructure. You choose which vendors to meet, if any. Every completed briefing pays you up to $500, as a premium gift card, cash, or a donation to a charity you pick if your employer restricts gifts. Membership is free and by invitation.

Claim your invite

Or reply to this email with the word "briefing" and Ryan will set you up personally.


Two NetScaler zero-days, and the patch won't say if they got in

Citrix shipped fixes on 27 September for two NetScaler flaws rated 9.5, CVE-2026-88771 and CVE-2026-88772. Both were exploited before a fix existed. One hits DTLS, which is on by default for Gateway VPN. Boxes patched in August stay exposed until they run 14.1-73.37 or 13.1-64.23. Snapshot and pull logs before you upgrade, because the update can erase the evidence of who got in first.


Oracle hedged its own flagship AI data center

Oracle sent a force majeure notice on 24 September on Project Jupiter, its 2.45-gigawatt Stargate campus in New Mexico. It lets Oracle delay payments if the site misses its 2028 date, though Oracle says it is on schedule. The pipeline meant to power it has slipped to February 2027 after repeated permit denials. When a tenant files for a delay it says won't happen, believe the filing. If your 2028 AI plan assumes new frontier capacity, ask providers which sites it rides on.


Watch This

A hijacked npm package for an MCP server shipped malware on 9 September with valid provenance. The attestation was true: it proved where the code was built, not whether the source was honest. Under trusted publishing, push access is publish access, so expect attackers to target CI identities next.


The CXO Brief is published by DoGood, the network where enterprise IT leaders are paid for 30-minute vendor briefings.

Know a CIO who needs this? Forward it and they can subscribe here.

Run IT or security at a $100M+ company? Claim your invite.