2026-07-08
Top stories
- TypeScript 7.0 ships the native Go compiler as a stable release Microsoft shipped TypeScript 7.0 stable with the Go compiler, achieving 8-12x faster full builds and 13x faster editor open times.
- AI-assisted audit finds seven real bugs in Cloudflare's CIRCL zkSecurity's AI-assisted audit surfaced seven genuine bugs in Cloudflare's CIRCL cryptography library, including proof forgery issues.
- Adobe ColdFusion path traversal CVE-2026-48282 is exploited within hours CVE-2026-48282, a CVSS 10.0 ColdFusion path traversal reaching code execution, saw active exploitation within hours of public disclosure.
- OpenAI clears GPT-5.6 Sol, Terra, and Luna for public release on 2026-07-09 OpenAI released GPT-5.6 Sol, Terra, and Luna publicly on 2026-07-09 after government testing lifted the staggered-release restriction.
- GitLost tricks GitHub agentic workflows into leaking private repositories Noma Security disclosed GitLost, a prompt-injection attack tricking GitHub Agentic Workflows into leaking private repository content.
- Anthropic extends included Fable 5 access to 2026-07-12 Anthropic extended included Fable 5 through 2026-07-12, moving after to credits at $10 input and $50 output per million tokens.
Conferences and events
AI
Security
- GhostLock CVE-2026-43499 gives local root and container escape on most Linux distributions GhostLock (CVE-2026-43499) is a 15-year-old stack use-after-free in Linux kernel rtmutex code with public root-and-container-escape exploit code.
- Tenda router firmware ships an authentication backdoor CVE-2026-11405 CVE-2026-11405 is an undocumented authentication backdoor in Tenda router firmware that grants administrative access with no available patch.
- OpenBSD sysv_sem use-after-free allows local root CVE-2026-57589 CVE-2026-57589 is a use-after-free in OpenBSD's sysvsem.c that allows local privilege escalation to root with no patched release yet named.
Developer tools
- Astro 7.0 rewrites its compiler and Markdown pipeline in Rust Astro 7.0 moved its .astro compiler and Markdown pipeline to Rust, achieving 15-61 percent build-time improvements and requiring markup fixes.
- chezmoi 2.71.0 adds init revision pinning and Windows MSIX packages chezmoi 2.71.0 added --revision and --tag flags to the init command for pinning a dotfiles checkout to a fixed state.
Languages and runtimes
Infrastructure
- PgDog routes Postgres session state through a Rust proxy PgDog is a Rust-based Postgres connection pooler that preserves SET and LISTEN/NOTIFY under transaction pooling, removing barriers to deployment.
- Cloudflare details Meerkat, a global consensus service built on QuePaxa Cloudflare detailed Meerkat, its global consensus service implementing QuePaxa, a leaderless algorithm reporting 10x throughput versus Raft.
Hacker News
- EU Parliament Chat Control votes draw heavy discussion EU Parliament voted on extending a temporary message-scanning regime as part of Chat Control, drawing heavy discussion on Hacker News.
- Decoding the obfuscated bash script on a Uniqlo t-shirt A reverse-engineered obfuscated bash script printed on a Uniqlo t-shirt animates text in a sine wave, reaching over 1,000 Hacker News points.