Top stories

  1. TypeScript 7.0 ships the native Go compiler as a stable release Microsoft shipped TypeScript 7.0 stable with the Go compiler, achieving 8-12x faster full builds and 13x faster editor open times.
  2. AI-assisted audit finds seven real bugs in Cloudflare's CIRCL zkSecurity's AI-assisted audit surfaced seven genuine bugs in Cloudflare's CIRCL cryptography library, including proof forgery issues.
  3. Adobe ColdFusion path traversal CVE-2026-48282 is exploited within hours CVE-2026-48282, a CVSS 10.0 ColdFusion path traversal reaching code execution, saw active exploitation within hours of public disclosure.
  4. OpenAI clears GPT-5.6 Sol, Terra, and Luna for public release on 2026-07-09 OpenAI released GPT-5.6 Sol, Terra, and Luna publicly on 2026-07-09 after government testing lifted the staggered-release restriction.
  5. GitLost tricks GitHub agentic workflows into leaking private repositories Noma Security disclosed GitLost, a prompt-injection attack tricking GitHub Agentic Workflows into leaking private repository content.
  6. Anthropic extends included Fable 5 access to 2026-07-12 Anthropic extended included Fable 5 through 2026-07-12, moving after to credits at $10 input and $50 output per million tokens.

Conferences and events

  1. ICML 2026 runs through 2026-07-11 The International Conference on Machine Learning runs through 2026-07-11, concentrating model and tooling release timing.

AI

  1. Mistral ships Robostral Navigate, an 8B single-camera robotics navigation model Mistral published Robostral Navigate, an 8B vision-language robotics model achieving 79.4 percent success, beating multi-sensor systems.

Security

  1. GhostLock CVE-2026-43499 gives local root and container escape on most Linux distributions GhostLock (CVE-2026-43499) is a 15-year-old stack use-after-free in Linux kernel rtmutex code with public root-and-container-escape exploit code.
  2. Tenda router firmware ships an authentication backdoor CVE-2026-11405 CVE-2026-11405 is an undocumented authentication backdoor in Tenda router firmware that grants administrative access with no available patch.
  3. OpenBSD sysv_sem use-after-free allows local root CVE-2026-57589 CVE-2026-57589 is a use-after-free in OpenBSD's sysvsem.c that allows local privilege escalation to root with no patched release yet named.

Developer tools

  1. Astro 7.0 rewrites its compiler and Markdown pipeline in Rust Astro 7.0 moved its .astro compiler and Markdown pipeline to Rust, achieving 15-61 percent build-time improvements and requiring markup fixes.
  2. chezmoi 2.71.0 adds init revision pinning and Windows MSIX packages chezmoi 2.71.0 added --revision and --tag flags to the init command for pinning a dotfiles checkout to a fixed state.

Languages and runtimes

  1. l is a new runtime for the k and q array languages A new runtime for k and q array languages reached Hacker News, signaling continued practitioner interest in the array-language niche.

Infrastructure

  1. PgDog routes Postgres session state through a Rust proxy PgDog is a Rust-based Postgres connection pooler that preserves SET and LISTEN/NOTIFY under transaction pooling, removing barriers to deployment.
  2. Cloudflare details Meerkat, a global consensus service built on QuePaxa Cloudflare detailed Meerkat, its global consensus service implementing QuePaxa, a leaderless algorithm reporting 10x throughput versus Raft.

Hacker News

  1. EU Parliament Chat Control votes draw heavy discussion EU Parliament voted on extending a temporary message-scanning regime as part of Chat Control, drawing heavy discussion on Hacker News.
  2. Decoding the obfuscated bash script on a Uniqlo t-shirt A reverse-engineered obfuscated bash script printed on a Uniqlo t-shirt animates text in a sine wave, reaching over 1,000 Hacker News points.

Reddit and social pulse

  1. Reddit pulse: GPT-5.6 launch anticipation and AI-agent isolation debate Reddit threads centered on GPT-5.6 launch anticipation and debate over kernel-level isolation for AI coding agents following escape disclosures.