Top stories

  1. Developer-targeted npm backdoor delivered through a fake LinkedIn job offer A developer received a LinkedIn recruiter request for a repository containing a backdoor that executed arbitrary commands on npm install.
  2. Cisco Catalyst SD-WAN Manager zero-day CVE-2026-20262 exploited, added to CISA KEV Cisco patched a path-traversal zero-day in Catalyst SD-WAN Manager that let attackers run arbitrary commands as root via file upload.
  3. US directive suspending Fable 5 and Mythos 5 stays in force as Anthropic lobbies in Washington A US export-control directive suspended Fable 5 and Mythos 5 access worldwide, and Anthropic flew staff to Washington to dispute the directive.
  4. SpaceX to acquire Anysphere, maker of the Cursor coding agent, for $60B SpaceX agreed to acquire Anysphere, maker of Cursor, in all-stock deal valued sixty billion, expected to close in Q3 2026.

AI

  1. Cohere releases North Mini Code, an open-weight agentic coding model Cohere released North Mini Code 1.0, a 30B-parameter mixture-of-experts model under Apache 2.0 license, requiring just one H100 GPU to run.
  2. OpenRouter adds Fusion, a multi-model deliberation API OpenRouter added Fusion to run prompts through multiple models in parallel with web search, then synthesize outputs into structured results.

Security

  1. CISA adds two exploited vulnerabilities on 2026-06-15 CISA added two known-exploited vulnerabilities: the Cisco SD-WAN Manager path-traversal flaw and a LiteSpeed cPanel symbolic-link vulnerability.

Developer tools

  1. Typst 0.15.0 released Typst 0.15.0 added variable-font support, bundle export for multiple formats, MathML in HTML, and multiple bibliographies per document.
  2. Homebrew 6.0.2 hardens the install sandbox Homebrew 6.0.2 tightened the sandbox to deny access to the home directory, limiting what malicious formulas can read during package builds.

Languages and runtimes

  1. Project Valhalla value classes (JEP 401) reach preview, targeting JDK 28 Value classes from Project Valhalla reached preview for JDK 28, enabling the JVM to flatten and inline objects for better memory and performance.

Engineering posts

  1. How memory-safety CVEs differ between Rust and C/C++ Rust and C/C++ differ in memory-safety CVE standards: Rust flags unsafe behavior in safe code as library bugs, C/C++ as caller error.
  2. How TimescaleDB compresses time-series data TimescaleDB's Hypercore compression reorganizes rows into columnar batches with typed codecs, trading per-row updates for storage and scan gains.
  3. Raymond Chen on an x86 emulator team patching bad code during emulation An x86-on-ARM emulator special-cased pathological code, fixing it during JIT translation rather than translating instructions faithfully.

Hacker News

  1. Ask HN: replacing cloud models with a local model for daily coding An Ask HN thread found developers have not yet successfully replaced cloud coding models with local alternatives for interactive coding work.