2026-06-19
Top stories
- Splunk Enterprise unauthenticated file-write flaw CVE-2026-20253 is under active exploitation Unauthenticated arbitrary file write in Splunk Enterprise PostgreSQL sidecar under active exploitation, CISA three-day deadline in effect.
- Noam Shazeer leaves Google to join OpenAI as AI architecture lead Noam Shazeer, Gemini co-lead and Attention Is All You Need co-author, is leaving Google for OpenAI as Lead for AI Architecture Research.
- Apple says price increases are unavoidable as the AI-driven memory shortage bites Tim Cook told the WSJ Apple will raise product prices to offset AI-driven DRAM and NAND demand, saying increases are unavoidable.
- TypeScript 7.0 reaches release candidate with the native Go compiler TypeScript 7.0 RC rewrites the bootstrapped compiler to Go, achieving roughly 10x speedup, with config defaults breaking existing projects.
- MCP Enterprise-Managed Authorization extension reaches stable MCP Enterprise-Managed Authorization stabilizes, letting organizations control which MCP servers employees access through their IdP.
- Anthropic says Fable 5 and Mythos 5 access should return in coming days Anthropic managing director Chris Ciauri said in Seoul Fable 5 and Mythos 5 should be available within coming days after export control block.
- Researcher catalogs about 10,000 GitHub repositories distributing Trojan archives Roughly 10,000 look-alike GitHub repositories copy real commit history and profiles, then serve trojanized archives that evade URL scanning.
AI
- DeepSeek adds a Vision image-understanding mode to its chat DeepSeek added Vision mode to its chat for image understanding alongside its existing expert and flash modes.
- Anthropic Fable 5 and Mythos 5 restoration SK Telecom identified as the Korean telecom at center of Mythos dispute; Anthropic said access should return within coming days.
Agentic coding
- Datasette Apps run sandboxed HTML and AI-generated code over a database Datasette Apps are sandboxed HTML and JavaScript applications that run read-only SQL directly against a Datasette instance.
- Enterprise-Managed Authorization for MCP IdP-governed single-sign-in for MCP server access is now stable across Claude, Claude Code, Cowork, and VS Code integrations.
Security
- Splunk Enterprise CVE-2026-20253 under active exploitation Splunk Enterprise CVSS 9.8 file-write flaw is actively exploited; affects 10.0.0-10.0.6 and 10.2.0-10.2.3, patched in 10.0.7 and 10.2.4.
- AMD removes TSME memory encryption from consumer Ryzen CPUs in firmware AGESA 1.2.7.0 firmware disabled Transparent Secure Memory Encryption on consumer Ryzen parts while leaving BIOS toggle visible but inert.
- GitHub repositories distributing Trojan archives Look-alike GitHub repositories serve trojanized archives that evade URL-based scanning, extending developer-targeted supply-chain abuse.
Outages
- Let's Encrypt production ACME API logs errors after an upstream network event Let's Encrypt production ACME API suffered upstream network disruption 2026-06-18; most requests succeeded but some received error responses.
- OpenAI logs FedRAMP and enterprise SSO incidents on 2026-06-18 OpenAI recorded three incidents on 2026-06-18: ChatGPT loading failures, SSO login errors for Enterprise, and FedRAMP workspace degradation.
Developer tools
- Godot 4.7 released as stable Godot 4.7 brings HDR output, AreaLight3D, redesigned Asset Store, standalone Android export, and Android XR and Steam Frame day-one support.
- Practitioner write-up: migrating dotfiles from GNU Stow to chezmoi A 2026-06-18 post details migrating dotfiles from GNU Stow symlink farms to chezmoi's templated source-state model with secret handling.
- Emacs 31 daily-driving notes ahead of the 31.1 release A practitioner write-up covers Emacs 31 tree-sitter defaults and editable xref workflow to help early adopters before the 31.1 release.
- .gitignore is not the only way to ignore files in Git A reference post walks through Git's ignore mechanisms beyond .gitignore: .git/info/exclude, core.excludesFile, and skip-worktree options.
Languages and runtimes
Linux and kernel
Infrastructure
Engineering posts
- American Express details a cell-based architecture for payment resilience American Express runs payments on independent cells, each with its own microservices and databases, routing by deterministic data locality.
- Mark Nottingham on how to define a well-known URI RFC 8615 co-author Mark Nottingham published guidance on designing .well-known URIs for discovery, cautioning against shortener misuse.
Markets and companies
Hacker News
- Ask HN: tools for AI-assisted code review An Ask HN thread collected what practitioners use for AI-assisted code review, alongside parallel thread on agent-review failures.
- Show HN: Are You in the Weights? A Show HN project lets users probe whether they appear memorized in LLM weights, surfacing concerns about training-data provenance.
- Project Valhalla explainer trends as JEP 401 nears JDK 28 A JVM Weekly explainer of Project Valhalla trended; value objects without identity enable inlining and flattening, heading toward JDK 28 preview.
- Ask HN: Is anyone using the A2A protocol? An Ask HN thread asks whether Agent2Agent protocol for agent interoperability sees production adoption beyond announcements versus MCP.