Skip to contentTop stories
- Anthropic releases Claude Fable 5 Claude Fable 5 is now generally available with 1M-token context, always-on adaptive thinking, and $10/$50 per megatoken pricing. confirmed AI
- Microsoft June 2026 Patch Tuesday: record 206 CVEs, wormable kernel flaw, one zero-day exploited Microsoft released 206 CVEs including wormable TCP/IP kernel flaw CVE-2026-45657 and unauthenticated HTTP.sys RCE CVE-2026-47291. confirmed Security
- Check Point VPN CVE-2026-50751 exploited by Qilin ransomware affiliate CVE-2026-50751 is an authentication bypass in Check Point IKEv1 VPN that attackers have exploited since May 7, linked to Qilin ransomware. confirmed Security
- LiteLLM CVE-2026-42271 exploited in the wild, chains to unauthenticated RCE CVE-2026-42271 is command injection in LiteLLM MCP endpoints that chains with Starlette's host-header bypass for unauthenticated RCE. confirmed Security
- Oracle PeopleSoft CVE-2026-35273 unauthenticated RCE, CVSS 9.8 Oracle published CVE-2026-35273 affecting PeopleTools 8.61 and 8.62, an unauthenticated RCE in Updates Environment Management with CVSS 9.8. confirmed Security
- Anthropic and OpenAI file confidential S-1s; SpaceX prices IPO at $135 Anthropic filed S-1 at $965B valuation with $47B annualized revenue; OpenAI at $852B; SpaceX priced IPO at $135 for $75B raise. confirmed Markets
- Cloudflare Agents Week 2026: agentic cloud infrastructure release Cloudflare shipped Dynamic Workers, Sandboxes GA, Mesh, Outbound Workers, improved Workflows concurrency, and Email Service public beta. confirmed Infrastructure
Security
- Microsoft June 2026 Patch Tuesday: record 206 CVEs Microsoft released 206 CVEs including wormable TCP/IP kernel flaw CVE-2026-45657 and unauthenticated HTTP.sys RCE CVE-2026-47291. confirmed
- CISA KEV additions 2026-06-08 and 2026-06-09 CISA added five exploited vulnerabilities to KEV: LiteLLM injection, Check Point VPN auth bypass, Chromium V8, Arista, and Cisco SD-WAN. confirmed
- GitLab security release 19.0.2, 18.11.5, 18.10.8 GitLab patched 12 CVEs including CVE-2026-6552, a SAML account-takeover flaw affecting GitLab EE from version 15.5 with CVSS 8.7. confirmed
- FBI advisory: FIFA World Cup 2026 phishing and credential-theft campaign The FBI warned of spoofed FIFA websites operating since August 2025, with 4,300 fraudulent domains and banking malware in pirate streaming apps. confirmed
- Ivanti Sentry CVE-2026-10520 and CVE-2026-10523: unauthenticated RCE and admin bypass, PoC published Ivanti Sentry CVE-2026-10520 is root-level command injection in versions 10.7.0 and earlier; watchTowr published a PoC on June 10. confirmed
- Veeam Backup and Replication CVE-2026-44963: domain-user RCE on backup servers Veeam patched CVE-2026-44963 allowing any authenticated domain user on domain-joined Veeam v12 servers to execute arbitrary code. confirmed
- SAP June 2026 Security Patch Day and Fortinet patches: critical SAML and command injection flaws SAP patched CVE-2026-44748, a SAML XML-signature wrapping flaw affecting NetWeaver and ABAP Platform versions 702-919. confirmed
- ServiceNow unauthenticated API access exploited against customer instances ServiceNow disclosed attackers exploited an unauthenticated REST endpoint on Australia platform customers between June 2 and June 3. confirmed
- RoguePlanet: new unpatched Windows Defender zero-day grants SYSTEM on fully patched Windows 10/11 Nightmare Eclipse released RoguePlanet, exploiting a Defender quarantine race condition to grant SYSTEM on fully patched Windows 10/11. confirmed
- Jenkins Security Advisory 2026-06-10: deserialization, credential exposure, and redirect vulnerabilities Jenkins 2.568 and LTS 2.555.3 restrict deserialization types and fix credential-exposure, improper-redirect, and permission-check CVEs. confirmed
Developer tools
- Homebrew 6.0.0: tap trust model, internal JSON API default, Linux build sandboxing Homebrew 6.0.0 requires explicit tap trust, defaults to JSON API, sandboxes Linux builds, and moves Intel macOS to Tier 3 in September. confirmed
- Google I/O 2026: WebMCP open standard for browser-based AI agents Google and Microsoft proposed WebMCP at I/O, a standard for developers to expose JavaScript and HTML interfaces to browser-based AI agents. confirmed
- Neovim v0.12.3 released Neovim v0.12.3 was released on June 10 as a patch in the v0.12 series, accumulating bug fixes from the redesigned terminal and cursor styling. confirmed
- GitHub Copilot moves to token-based AI Credits billing; developers report 10x to 100x cost increases GitHub Copilot switched to token-metered billing on June 1; Pro includes 1,500 credits, Pro+ 7,000 credits, Max 20,000 credits per month. confirmed
- Claude Fable 5 generally available in GitHub Copilot Claude Fable 5 is now generally available in GitHub Copilot for Pro+, Max, Business, and Enterprise users with 30-day data retention. confirmed
- GitHub CLI v2.94.0: native Discussions support and sub-issue management GitHub CLI v2.94.0 adds gh discussion commands for list, view, create, edit, and comment; also adds sub-issue and dependency management. confirmed
HN and Reddit pulse
- Claude Fable 5 release, guardrails, and data retention The Fable 5 launch thread drew 2,562 HN points with discussion on model guardrails, 30-day data retention, pricing, and model deprecation. discussion
- SpaceX, OpenAI, and Anthropic blocked from S&P 500 entry S&P 500 index committee blocked fast-track inclusion for SpaceX, OpenAI, and Anthropic, citing index rules and profitability requirements. discussion
- PgDog funding and transparent Postgres sharding PgDog announced funding for a connection pooler that shards Postgres at wire-protocol layer without application changes or extensions. discussion
- Microsoft June 2026 Patch Tuesday record discussion Discussion on Hacker News focused on patch fatigue and monthly update viability after the record 206-CVE release with wormable flaws. discussion
- πFS: data-free filesystem based on pi HN discussed πFS, a filesystem using pi digits, with commenters noting coordinate representation requires as much storage as the data itself. discussion
- GitHub Copilot billing shock dominates developer discussion GitHub's June 1 switch to token-based billing generated backlash with developers reporting Pro+ bills jumping from $39 to $750 monthly. discussion
- Nightmare Eclipse RoguePlanet zero-day and Defender campaign discussion Security practitioners noted RoguePlanet's timed zero-day release on Patch Tuesday, characterizing it as a responsible-disclosure retaliation. discussion