Top stories

  1. Anonymous GitHub account dumps exploit PoCs framed as undisclosed 0-days An anonymous account published exploits framed as 0-days, but researchers assessed them as rederived PoCs for documented CVEs, still functional.
  2. Asian AI labs ship Mythos-style cyber models as Anthropic export ban persists Sakana AI released Fugu and 360 unveiled Tulongfeng, security-focused models filling the US export-ban gap for Anthropic Mythos and Fable.
  3. Codeberg offline after power loss at primary location The nonprofit Forgejo platform went offline after a power outage at its primary location, blocking pushes, pulls, and issue access for users.

ML research

  1. RiVER trains LLMs with reinforcement learning and no ground-truth answers RiVER applies RL to score-based tasks without ground truth, using deterministic execution feedback as a continuous-valued reward signal.

Agentic coding

  1. Codex still lacks a built-in way to exclude sensitive files from agent reads A long-open enhancement request seeks to prevent sensitive files like .env from being read by Codex agents, keeping secrets out of model context.

Linux and kernel

  1. One developer maintains parallel RISC-V kernel ports The Register profiled a maintainer carrying two kernel codebases for RISC-V targets, detailing the duplication burden and upstreaming friction.

Infrastructure

  1. ClickHouse rewrites WAL-G PostgreSQL backups in Rust as WAL-RUS ClickHouse released WAL-RUS, a Rust port of WAL-G, reducing memory usage by 70% through streaming I/O on no-overcommit hosts for Postgres.

Engineering posts

  1. Fintech Engineering Handbook A practitioner handbook collects fintech patterns covering idempotency keys, monetary amounts, and ledger design for payment systems.
  2. Teardown of Reddit's anti-spam internals An independent researcher documented Reddit's spam pipeline combining Perspective API, Lua rules, Flink streaming, OCR, and live URL inspection.
  3. Clustering two AMD Strix Halo machines over RDMA for local LLM inference A guide clusters two AMD Strix Halo machines over 100G RDMA for tensor-parallel inference, noting PCIe 4.0 and memory-bandwidth constraints.

Markets and companies

  1. Google caps Meta's Gemini capacity amid compute shortage Google limited Meta's Gemini access after demand exceeded available capacity around March, disrupting and delaying some Meta AI projects.
  2. Austria lobbies EU to host Anthropic after US foreign-access curbs Austria proposed the EU host Anthropic within the bloc, responding to US export-control rules limiting foreign access to Fable and Mythos.

Hacker News

  1. DeepSeek DSpark speculative-decoding paper tops Hacker News The DeepSeek DSpark paper topped Hacker News, presenting a lossless inference speedup as a module attachable to existing model checkpoints.
  2. Crates.io maintainer dissects a fake-recruiter supply-chain lure A crates.io maintainer documented a fake-recruiter VC lure delivering a booby-trapped TypeScript repo, avoided by inspecting code with AI.