Top stories

  1. Anthropic releases Claude Fable 5 Claude Fable 5 is now generally available with 1M-token context, always-on adaptive thinking, and $10/$50 per megatoken pricing.
  2. Microsoft June 2026 Patch Tuesday: record 206 CVEs, wormable kernel flaw, one zero-day exploited Microsoft released 206 CVEs including wormable TCP/IP kernel flaw CVE-2026-45657 and unauthenticated HTTP.sys RCE CVE-2026-47291.
  3. Check Point VPN CVE-2026-50751 exploited by Qilin ransomware affiliate CVE-2026-50751 is an authentication bypass in Check Point IKEv1 VPN that attackers have exploited since May 7, linked to Qilin ransomware.
  4. LiteLLM CVE-2026-42271 exploited in the wild, chains to unauthenticated RCE CVE-2026-42271 is command injection in LiteLLM MCP endpoints that chains with Starlette's host-header bypass for unauthenticated RCE.
  5. Oracle PeopleSoft CVE-2026-35273 unauthenticated RCE, CVSS 9.8 Oracle published CVE-2026-35273 affecting PeopleTools 8.61 and 8.62, an unauthenticated RCE in Updates Environment Management with CVSS 9.8.
  6. Anthropic and OpenAI file confidential S-1s; SpaceX prices IPO at $135 Anthropic filed S-1 at $965B valuation with $47B annualized revenue; OpenAI at $852B; SpaceX priced IPO at $135 for $75B raise.
  7. Cloudflare Agents Week 2026: agentic cloud infrastructure release Cloudflare shipped Dynamic Workers, Sandboxes GA, Mesh, Outbound Workers, improved Workflows concurrency, and Email Service public beta.

AI

  1. Microsoft Build 2026: MAI model family launched Microsoft launched seven MAI models at Build, including MAI-Code-1-Flash integrated in GitHub Copilot with a 16-point SWE-Bench Pro lead.
  2. Anthropic Claude Managed Agents public beta Claude Managed Agents on the Claude Platform now support scheduled execution and authenticated CLI tool access in public beta.
  3. Google Gemini 3.1 Ultra with 2M-token context window Google released Gemini 3.1 Ultra with native 2M-token multimodal context and Gemini 3.1 Flash-Lite delivering 2.5x faster responses.

ML research

  1. The Self-Correction Illusion: LLMs correct others but not themselves LLMs correct external claims more reliably than their own; correction rates jump 23 to 93 percentage points when claims appear external.
  2. NF-CoT: Latent reasoning with normalizing flows NF-CoT proposes reasoning in continuous states via normalizing flows rather than discrete tokens, potentially cutting inference costs.

Agentic coding

  1. Claude Code Dynamic Workflows: parallel subagent orchestration in research preview Claude Code Dynamic Workflows enable task decomposition across parallel subagents with coordinated output verification.
  2. Windsurf rebranded as Devin Desktop; Cascade agent reaches end of life 2026-07-01 Cognition rebranded Windsurf to Devin Desktop with ACP support; Cascade local agent ends July 1, replaced by Devin Local in Rust.

Security

  1. Microsoft June 2026 Patch Tuesday: record 206 CVEs Microsoft released 206 CVEs including wormable TCP/IP kernel flaw CVE-2026-45657 and unauthenticated HTTP.sys RCE CVE-2026-47291.
  2. CISA KEV additions 2026-06-08 and 2026-06-09 CISA added five exploited vulnerabilities to KEV: LiteLLM injection, Check Point VPN auth bypass, Chromium V8, Arista, and Cisco SD-WAN.
  3. GitLab security release 19.0.2, 18.11.5, 18.10.8 GitLab patched 12 CVEs including CVE-2026-6552, a SAML account-takeover flaw affecting GitLab EE from version 15.5 with CVSS 8.7.
  4. FBI advisory: FIFA World Cup 2026 phishing and credential-theft campaign The FBI warned of spoofed FIFA websites operating since August 2025, with 4,300 fraudulent domains and banking malware in pirate streaming apps.
  5. Ivanti Sentry CVE-2026-10520 and CVE-2026-10523: unauthenticated RCE and admin bypass, PoC published Ivanti Sentry CVE-2026-10520 is root-level command injection in versions 10.7.0 and earlier; watchTowr published a PoC on June 10.
  6. Veeam Backup and Replication CVE-2026-44963: domain-user RCE on backup servers Veeam patched CVE-2026-44963 allowing any authenticated domain user on domain-joined Veeam v12 servers to execute arbitrary code.
  7. SAP June 2026 Security Patch Day and Fortinet patches: critical SAML and command injection flaws SAP patched CVE-2026-44748, a SAML XML-signature wrapping flaw affecting NetWeaver and ABAP Platform versions 702-919.
  8. ServiceNow unauthenticated API access exploited against customer instances ServiceNow disclosed attackers exploited an unauthenticated REST endpoint on Australia platform customers between June 2 and June 3.
  9. RoguePlanet: new unpatched Windows Defender zero-day grants SYSTEM on fully patched Windows 10/11 Nightmare Eclipse released RoguePlanet, exploiting a Defender quarantine race condition to grant SYSTEM on fully patched Windows 10/11.
  10. Jenkins Security Advisory 2026-06-10: deserialization, credential exposure, and redirect vulnerabilities Jenkins 2.568 and LTS 2.555.3 restrict deserialization types and fix credential-exposure, improper-redirect, and permission-check CVEs.

Outages

  1. Google Cloud India network disruption, 2026-06-09 to present A fire at Tata Communications' Delhi data center on June 9 isolated Google Cloud's PoP, causing ongoing elevated latency across India.
  2. Cloudflare US Eastern network performance issue, 2026-06-02 Cloudflare experienced elevated latency and intermittent connectivity in US Eastern region between 13:39 and 14:06 UTC on June 2.
  3. Google Gemini 7-hour outage, 2026-06-11 Google Gemini experienced a widespread 7-hour service failure on June 11, with users seeing error 1076 and error 1099 consistently.

Developer tools

  1. Homebrew 6.0.0: tap trust model, internal JSON API default, Linux build sandboxing Homebrew 6.0.0 requires explicit tap trust, defaults to JSON API, sandboxes Linux builds, and moves Intel macOS to Tier 3 in September.
  2. Google I/O 2026: WebMCP open standard for browser-based AI agents Google and Microsoft proposed WebMCP at I/O, a standard for developers to expose JavaScript and HTML interfaces to browser-based AI agents.
  3. Neovim v0.12.3 released Neovim v0.12.3 was released on June 10 as a patch in the v0.12 series, accumulating bug fixes from the redesigned terminal and cursor styling.
  4. GitHub Copilot moves to token-based AI Credits billing; developers report 10x to 100x cost increases GitHub Copilot switched to token-metered billing on June 1; Pro includes 1,500 credits, Pro+ 7,000 credits, Max 20,000 credits per month.
  5. Claude Fable 5 generally available in GitHub Copilot Claude Fable 5 is now generally available in GitHub Copilot for Pro+, Max, Business, and Enterprise users with 30-day data retention.
  6. GitHub CLI v2.94.0: native Discussions support and sub-issue management GitHub CLI v2.94.0 adds gh discussion commands for list, view, create, edit, and comment; also adds sub-issue and dependency management.

Languages and runtimes

  1. Go 1.26.4 and 1.25.11 security patch releases Go 1.26.4 and 1.25.11 were released on June 2 with security fixes to crypto/x509, mime, and net/textproto, affecting TLS and HTTP headers.
  2. Rust 1.95.0 is current stable Rust 1.95.0 stabilizes cfgselect! macro for compile-time cfg matching, eliminating common cfg-if dependency for multi-platform crates.
  3. .NET 11 Preview 5 and C# 15 union types featured at Build 2026 Microsoft featured C# 15 union types at Build 2026, the largest type-system addition since nullable reference types, targeting November GA.

Apple platforms

  1. Apple WWDC 2026: Xcode 27, Foundation Models LanguageModel protocol, Swift 6.2 Apple shipped Xcode 27 with dual-engine agentic coding and Foundation Models LanguageModel protocol enabling provider-agnostic AI swapping.

Linux and kernel

  1. Seven stable kernels released 2026-06-01 Greg Kroah-Hartman released seven stable kernel updates on June 1, including CVE-2026-46243 fix for local privilege escalation in CIFS.
  2. LWN Weekly Edition 2026-06-11: splice()/vmsplice() removal proposal; LLM-driven kernel bug reports Kernel developers propose removing splice() and vmsplice() over security vulnerabilities found by LLM automated scanning tools.

Infrastructure

  1. Kubernetes v1.37 Production Readiness Freeze; v1.33 EOL approaching Kubernetes v1.37 entered Production Readiness Freeze on June 10, and v1.33 reaches end-of-life on June 28 without security patches.

Engineering posts

  1. Cloudflare: firmware reboot time investigation using UEFI debugging Cloudflare investigated why firmware updates caused four-hour core server reboots, using UEFI analysis and iPXE automation to cut boot time.
  2. Cloudflare: Town Lake unified analytics platform and Skipper AI agent Cloudflare described Town Lake, their unified internal analytics platform, and Skipper, an AI agent answering operational queries.

Markets and companies

  1. Anthropic confidential S-1 filing Anthropic submitted confidential Form S-1 on June 1 at $965B valuation with $47B annualized revenue after closing a $65B Series H.
  2. OpenAI confidential S-1 filing OpenAI submitted confidential Form S-1 on June 8 at $852B last-round valuation, advised by Goldman Sachs and Morgan Stanley.
  3. SpaceX prices IPO at $135, Nasdaq listing 2026-06-12 SpaceX priced IPO at $135 per share for $75B raise at $1.77T valuation, bypassing standard roadshow for fixed-price offering.
  4. OpenAI acquires Ona to expand Codex agent capabilities; models available on Oracle Cloud OpenAI acquired Ona, providing pre-configured cloud environments for multi-step agents, and made models available via Oracle Cloud credits.

HN and Reddit pulse

  1. Claude Fable 5 release, guardrails, and data retention The Fable 5 launch thread drew 2,562 HN points with discussion on model guardrails, 30-day data retention, pricing, and model deprecation.
  2. SpaceX, OpenAI, and Anthropic blocked from S&P 500 entry S&P 500 index committee blocked fast-track inclusion for SpaceX, OpenAI, and Anthropic, citing index rules and profitability requirements.
  3. PgDog funding and transparent Postgres sharding PgDog announced funding for a connection pooler that shards Postgres at wire-protocol layer without application changes or extensions.
  4. Microsoft June 2026 Patch Tuesday record discussion Discussion on Hacker News focused on patch fatigue and monthly update viability after the record 206-CVE release with wormable flaws.
  5. πFS: data-free filesystem based on pi HN discussed πFS, a filesystem using pi digits, with commenters noting coordinate representation requires as much storage as the data itself.
  6. GitHub Copilot billing shock dominates developer discussion GitHub's June 1 switch to token-based billing generated backlash with developers reporting Pro+ bills jumping from $39 to $750 monthly.
  7. Nightmare Eclipse RoguePlanet zero-day and Defender campaign discussion Security practitioners noted RoguePlanet's timed zero-day release on Patch Tuesday, characterizing it as a responsible-disclosure retaliation.