Top stories

  1. Splunk Enterprise unauthenticated file-write flaw CVE-2026-20253 is under active exploitation Unauthenticated arbitrary file write in Splunk Enterprise PostgreSQL sidecar under active exploitation, CISA three-day deadline in effect.
  2. Noam Shazeer leaves Google to join OpenAI as AI architecture lead Noam Shazeer, Gemini co-lead and Attention Is All You Need co-author, is leaving Google for OpenAI as Lead for AI Architecture Research.
  3. Apple says price increases are unavoidable as the AI-driven memory shortage bites Tim Cook told the WSJ Apple will raise product prices to offset AI-driven DRAM and NAND demand, saying increases are unavoidable.
  4. TypeScript 7.0 reaches release candidate with the native Go compiler TypeScript 7.0 RC rewrites the bootstrapped compiler to Go, achieving roughly 10x speedup, with config defaults breaking existing projects.
  5. MCP Enterprise-Managed Authorization extension reaches stable MCP Enterprise-Managed Authorization stabilizes, letting organizations control which MCP servers employees access through their IdP.
  6. Anthropic says Fable 5 and Mythos 5 access should return in coming days Anthropic managing director Chris Ciauri said in Seoul Fable 5 and Mythos 5 should be available within coming days after export control block.
  7. Researcher catalogs about 10,000 GitHub repositories distributing Trojan archives Roughly 10,000 look-alike GitHub repositories copy real commit history and profiles, then serve trojanized archives that evade URL scanning.

AI

  1. DeepSeek adds a Vision image-understanding mode to its chat DeepSeek added Vision mode to its chat for image understanding alongside its existing expert and flash modes.
  2. Anthropic Fable 5 and Mythos 5 restoration SK Telecom identified as the Korean telecom at center of Mythos dispute; Anthropic said access should return within coming days.

Agentic coding

  1. Datasette Apps run sandboxed HTML and AI-generated code over a database Datasette Apps are sandboxed HTML and JavaScript applications that run read-only SQL directly against a Datasette instance.
  2. Enterprise-Managed Authorization for MCP IdP-governed single-sign-in for MCP server access is now stable across Claude, Claude Code, Cowork, and VS Code integrations.

Security

  1. Splunk Enterprise CVE-2026-20253 under active exploitation Splunk Enterprise CVSS 9.8 file-write flaw is actively exploited; affects 10.0.0-10.0.6 and 10.2.0-10.2.3, patched in 10.0.7 and 10.2.4.
  2. AMD removes TSME memory encryption from consumer Ryzen CPUs in firmware AGESA 1.2.7.0 firmware disabled Transparent Secure Memory Encryption on consumer Ryzen parts while leaving BIOS toggle visible but inert.
  3. GitHub repositories distributing Trojan archives Look-alike GitHub repositories serve trojanized archives that evade URL-based scanning, extending developer-targeted supply-chain abuse.

Outages

  1. Let's Encrypt production ACME API logs errors after an upstream network event Let's Encrypt production ACME API suffered upstream network disruption 2026-06-18; most requests succeeded but some received error responses.
  2. OpenAI logs FedRAMP and enterprise SSO incidents on 2026-06-18 OpenAI recorded three incidents on 2026-06-18: ChatGPT loading failures, SSO login errors for Enterprise, and FedRAMP workspace degradation.

Developer tools

  1. Godot 4.7 released as stable Godot 4.7 brings HDR output, AreaLight3D, redesigned Asset Store, standalone Android export, and Android XR and Steam Frame day-one support.
  2. Practitioner write-up: migrating dotfiles from GNU Stow to chezmoi A 2026-06-18 post details migrating dotfiles from GNU Stow symlink farms to chezmoi's templated source-state model with secret handling.
  3. Emacs 31 daily-driving notes ahead of the 31.1 release A practitioner write-up covers Emacs 31 tree-sitter defaults and editable xref workflow to help early adopters before the 31.1 release.
  4. .gitignore is not the only way to ignore files in Git A reference post walks through Git's ignore mechanisms beyond .gitignore: .git/info/exclude, core.excludesFile, and skip-worktree options.

Languages and runtimes

  1. TypeScript 7.0 release candidate The Go-rewritten TypeScript compiler reaches RC at roughly 10x 6.0's speed with config-default breaking changes including rootDir and types.

Linux and kernel

  1. SteamOS 3.8 released as stable Valve promoted SteamOS 3.8 stable; the Arch-based immutable Linux distribution underpins Steam Deck and feeds changes back to Linux gaming.

Infrastructure

  1. Ubiquiti launches an Enterprise NAS built on ZFS Ubiquiti announced Enterprise NAS with eight Arm cores, 64GB ECC memory, 16 expandable drive bays, dual NVMe cache, and dual 25Gbps ports.

Engineering posts

  1. American Express details a cell-based architecture for payment resilience American Express runs payments on independent cells, each with its own microservices and databases, routing by deterministic data locality.
  2. Mark Nottingham on how to define a well-known URI RFC 8615 co-author Mark Nottingham published guidance on designing .well-known URIs for discovery, cautioning against shortener misuse.

Markets and companies

  1. AI talent and hardware cost signals Noam Shazeer's move to OpenAI and Apple's signal of AI-driven memory-cost price increases reflect talent concentration and DRAM-NAND contention.

Hacker News

  1. Ask HN: tools for AI-assisted code review An Ask HN thread collected what practitioners use for AI-assisted code review, alongside parallel thread on agent-review failures.
  2. Show HN: Are You in the Weights? A Show HN project lets users probe whether they appear memorized in LLM weights, surfacing concerns about training-data provenance.
  3. Project Valhalla explainer trends as JEP 401 nears JDK 28 A JVM Weekly explainer of Project Valhalla trended; value objects without identity enable inlining and flattening, heading toward JDK 28 preview.
  4. Ask HN: Is anyone using the A2A protocol? An Ask HN thread asks whether Agent2Agent protocol for agent interoperability sees production adoption beyond announcements versus MCP.