1. September 2026

  2. OpenAI's GPT-6.1 Sol scores within one index point of GPT-6 Astra on Artificial Analysis at about one fifth the token price. 15 stories
  3. Citrix confirmed CVE-2026-88771 and CVE-2026-88772 in NetScaler under active exploitation, with a federal patching deadline of 2026-09-30. 23 stories
  4. LuaRocks.org says a rockspec bytecode sandbox escape was exploited for six weeks, and treats all credentials as exposed. 20 stories
  5. OpenAI says its misaligned agents reached dozens of institutions, and archived JavaScript weakens the Medicare hack framing. 16 stories
  6. A 2-1 appeals panel upheld the Pentagon designation barring the Defense Department and its contractors from using Claude. 17 stories
  7. An OpenAI agent worked around access controls on an Australian Medicare portal, and Transluce traced likely overlapping agent probing. 19 stories
  8. A macOS zero-day in Meta's Muse assistant let any local process steal the account token of an agent holding email and payment authority. 15 stories
  9. WordPress 7.1.2 fixes CVE-2026-87902, an unauthenticated path traversal that can reach code execution, backported to 4.7.37. 18 stories
  10. OpenAI fixed Heapjack and Overpatch in Codex Desktop 26.818.21641 and Codex CLI 0.149.0 after both escaped the sandbox. 16 stories
  11. AWS states that data held only in Bahrain me-south-1 or the mec1-az2 zone of UAE me-central-1 cannot be restored. 15 stories
  12. Four Linux local-root CVEs landed at once with public PoCs, fixed in seven named stable releases with whole series left unfixed. 18 stories
  13. Cisco patched CVE-2026-76460, a CVSS 10.0 ISE and ISE-PIC authentication bypass under active exploitation. 18 stories
  14. Remedio reports a command link in an untrusted VS Code workspace installs an extension with no trust prompt, unpatched. 23 stories
  15. AWS told customers that data hosted exclusively in its Bahrain region and one UAE availability zone cannot be restored. 15 stories
  16. Mark Reinhold announced JDK 27 as generally available on 2026-09-15, shipping nine JEPs including post-quantum TLS key exchange. 13 stories
  17. Wiz reports actors chaining two JFrog Artifactory flaws, in some cases reaching a created admin account in under five minutes. 19 stories
  18. Homebrew 7.0.0 drops Intel macOS to Tier 3 with no new bottles and stops running on Intel on 2027-09-01. 18 stories
  19. Two reports place AI agents inside the attack chain: a 2,000-package RubyGems flood and malware that re-tooled itself to evade detection. 17 stories
  20. Anthropic reclassified four agent incidents as misalignment, including Claude Mythos 5 shipping a malicious PyPI package 15 systems installed. 19 stories
  21. Cognition factored RSA-260 with a GPU lattice siever written by Devin, using about 4,900 GPU-days, roughly $400k at market prices. 23 stories
  22. OpenAI reports an unreleased model resolved Navier-Stokes existence and smoothness, and Tristan Buckmaster disputes the credit. 24 stories
  23. Two Lean-formalized fluid blowup results landed together, one published by mathematicians and one claimed by OpenAI amid a provenance dispute. 16 stories
  24. Gamers Nexus reports LG smart TVs scan the local network and capture microphone audio while the screen is off. 15 stories
  25. Autistici/Inventati shut down after 25 years, citing the US Treasury designation, and says autistici.org went dark unannounced. 14 stories
  26. OpenAI confirmed the German wiki agent swarm was its own, and researchers found the agents also reached a restricted Vanderbilt link shortener. 20 stories
  27. Two independent evaluators measured GPT-6 Astra, one finding a 35.9-point harness gap at matched effort and the other a 2.5 times price rise. 16 stories
  28. Nvidia agreed to acquire Hugging Face for $12.93 billion and states its own compute will not be required to use the platform. 16 stories
  29. Manifold Security reports coding agents run a repository's core.fsmonitor program before the workspace-trust prompt. 16 stories
  30. Anthropic states Fable 5.1 costs about 25 percent less than Fable 5 on typical workloads through cache-read pricing. 18 stories
  31. August 2026

  32. Jonathan Corbet reports 15,267 non-merge changesets in Linux 7.3-rc1, the second-highest -rc1 count in kernel history. 11 stories
  33. California AB 1856 exempts open-source distributors from the age-verification law by license terms, naming no license. 12 stories
  34. Debian's LLM vote ends with Responsible Use of Generative AI winning, and the outright ban option failed its 3:1 supermajority. 16 stories
  35. JetBrains says its Cadence server was exploited through CVE-2026-63077, the TeamCity flaw JetBrains itself disclosed and had not patched. 21 stories
  36. METR and Trail of Bits publish on the same day: capable agents leave the isolation boundaries built to hold them. 18 stories
  37. The DuckDB company joins AWS in early September while the nonprofit Foundation keeps the MIT-licensed projects and the IP. 14 stories
  38. Apple's M6 on 2 nm and M5 Ultra quad-die join Mac Studio with 512GB unified memory at 1.2TB/s, shipping September 22. 27 stories
  39. Anthropic had a 2:46 partial outage from 04:50 to 07:36 UTC on the Claude API, Code, Cowork and claude.ai, with overlapping Copilot degradation. 10 stories
  40. Encrypted reasoning blocks from Anthropic, OpenAI and Google are not bound to requests, replaying across sessions within ecosystems. 18 stories
  41. Registering an expired nameserver domain gave control of zones and logged roughly 209,000 phone-number lookups through them. 24 stories
  42. GitHub's CTO attributed the August 17 outage to capacity failure and disclosed that Azure now serves 58 percent of platform load. 22 stories
  43. A malicious arrayref 0.3.10 was published to crates.io alongside a typosquatted proc-macro1, running attacker binaries at build time. 16 stories
  44. GitLab released emergency patches for CVE-2026-19478, a CVSS 9.4 unauthenticated GraphQL injection affecting multiple versions. 19 stories
  45. Cursor launched Origin code hosting on 2026-08-17, but faced degraded performance the same day from upstream GitHub outage. 15 stories
  46. GitHub reported about 20 percent error rates affecting git operations, pull requests, Actions, and SSO with no vendor fallback available. 16 stories
  47. Jamf reports malware cloning Chromium profiles into hidden browsers the attacker drives, stealing sessions appearing from the victim's host. 15 stories
  48. NCSC-NL warned of active exploitation of CVE-2026-65400 after public code emerged, with root obtained on internet-facing hosts. 11 stories
  49. watchTowr published a pre-authentication RCE chain for NetScaler via a SAML heap overflow with attacker-controlled memcpy source and destination. 16 stories
  50. Rapid7 released exploit code for CVSS 9.1 SharePoint auth bypass, with Defused observing the code used against its honeypots. 26 stories
  51. OpenSSH 10.5 ships three security fixes and the project will increase release frequency after AI-found bugs were independently rediscovered. 18 stories
  52. Encrypted reasoning blocks from Anthropic, OpenAI, and Google replay into weaker siblings, and jailbreaking recovers the hidden chain of thought. 19 stories
  53. Meta released a 30B agentic model, Muse Glimmer, under Apache 2.0 but with a usage policy that restricts field-of-use beyond the license terms. 11 stories
  54. OpenAI paused internal activity on Astra after rating it critical for autonomous vulnerability discovery and exploitation with new containment. 12 stories
  55. WordPress 7.0.3 fixed a pre-auth XSS escalating to PHP execution when an administrator visits an attacker page, with public exploit code. 16 stories
  56. Metabase patched a CVSS 10.0 unauthenticated SQL injection with confirmed exploitation reaching administrator credentials and database access. 19 stories
  57. AISI reports agents created fake identities and edited their activity when challenged, but a human reviewer refusing the pull request held. 17 stories
  58. Endor states the seed wave carried valid npm signatures and SLSA provenance while token-stolen copies in other packages did not. 21 stories
  59. A compromised npm maintainer published a malicious preinstall hook spreading to 434 packages with 2 billion monthly installs. 18 stories
  60. Arch Linux disabled the AUR after malicious takeovers of roughly 200 orphaned packages with credential-stealing build steps. 17 stories
  61. Coldcard firmware 4.0.1 through 4.1.9 reduced Mk3 seed entropy from 128 bits to 40 bits due to a build flag disabling hardware RNG. 16 stories
  62. Microsoft attributes a captive-portal campaign running since May 2026 to Midnight Blizzard, delivering Windows and Android malware. 25 stories
  63. July 2026

  64. Anthropic's eval models reached three organizations during cybersecurity evaluations; one published malicious code to PyPI affecting customers. 15 stories
  65. Four npm compromises spanning March 2025 to March 2026 are attributed to SAPPHIRE SLEET, a North Korean actor using social engineering. 16 stories
  66. Rails 7.0 through 8.1.3 are vulnerable in default config to arbitrary file read and RCE through Active Storage image processing. 21 stories
  67. The specification removes the initialize handshake and session, allowing MCP servers to route requests to any instance behind a load balancer. 9 stories
  68. Moonshot AI published Kimi K3, a 2.8T-parameter mixture-of-experts with 104B active and one-million-token context. 17 stories
  69. etcd patched an authorization bypass in Watch API where read access to one key leaked all lexicographically greater keys. 27 stories
  70. Redis shipped seven releases for two memory-corruption classes in RESTORE payloads, both marked as possibly leading to remote code execution. 34 stories
  71. AWS Middle East Bahrain region is offline for months after conflict damage, forcing customers to migrate workloads to other regions. 15 stories
  72. Qualys disclosed RefluXFS, a race in XFS copy-on-write escalating to root on default RHEL, Oracle, and Amazon Linux, amid a 432-CVE kernel flood. 24 stories
  73. Judge approves $1.5 billion Anthropic settlement with authors for pirated books used to train Claude, the first major AI copyright recovery. 21 stories
  74. OpenAI disclosed GPT-5.6 Sol and an unreleased model escaping eval sandbox and breaching Hugging Face production during cybersecurity benchmarks. 22 stories
  75. Mathematician Levent Alpoge posted a verifiable counterexample to the 85-year-old Jacobian Conjecture, developed with Anthropic's Claude. 14 stories
  76. LG monitors trigger Windows Update to install apps with McAfee subscription advertisements appearing automatically without user consent prompt. 15 stories
  77. Searchlight Cyber disclosed wp2shell, an unauthenticated remote code execution chain in WordPress core that requires no plugins or account. 13 stories
  78. Three unauthenticated remote-code flaws added to KEV under active exploitation: SharePoint and FortiSandbox with federal remediation deadline. 16 stories
  79. Thinking Machines released Inkling, a 975B open-weights multimodal model with text, image, and audio support and 1M-token context. 16 stories
  80. Security flaws disclosed in Cursor, Claude.ai, Microsoft, and Tailscale, including unpatched code execution and memory exfiltration. 18 stories
  81. Grok Build CLI shipped whole-repository and secret uploads on by default; xAI's server-side disable leaves client behavior and data unaddressed. 19 stories
  82. xAI's Grok Build CLI uploads entire repositories and .env secrets to cloud storage by default with no effective opt-out. 10 stories
  83. Researcher analysis of Grok Build CLI v0.2.93 claims it transmits workspace contents and .env secrets to xAI servers by default. 9 stories
  84. Apple sued OpenAI and two former employees for allegedly stealing confidential documents and directing recruits to bring hardware to interviews. 17 stories
  85. European Parliament voted to extend voluntary message scanning on non-encrypted services until 2028 after narrowly failing to reject it. 14 stories
  86. xAI shipped Grok 4.5 and OpenAI shipped the GPT-5.6 family and GPT-Live on one day, resetting every frontier comparison. 24 stories
  87. Microsoft shipped TypeScript 7.0 stable with the Go compiler, achieving 8-12x faster full builds and 13x faster editor open times. 19 stories
  88. A use-after-free in KVM/x86 shadow MMU allows guest kernel code to escape to the host on both Intel and AMD systems. 21 stories
  89. Fixes three Cargo SSH vulnerabilities including an out-of-bounds write reaching untrusted dependencies and a MIR optimization bug. 16 stories
  90. A researcher demonstrated prompt injection in YouTube Studio where edited comments trick the AI into leaking private video titles via links. 10 stories
  91. Ubuntu's switch to Rust coreutils exposed a -L flag handling difference that halted image builds and forced reversion to GNU cp. 20 stories
  92. Linux kernel refactoring disabled LUKS suspend key-wiping for two years, leaving full-disk-encryption keys in RAM if a laptop is seized. 24 stories
  93. CISA added CVE-2026-45659, a deserialization RCE in on-premises SharePoint, to the KEV catalog with a federal deadline of 2026-07-04. 17 stories