Top stories

  1. Cursor executes a repository's git.exe without confirmation on Windows, unpatched after seven months Mindgard disclosed an unpatched Cursor flaw on Windows where a malicious git.exe in a repository root runs automatically with no prompt.
  2. Claude memory exfiltrated through web_fetch link-following prompt injection Ayush Paul showed Claude.ai memory exfiltration through webfetch via a fake CAPTCHA with alphabetical links spelling out user data.
  3. Dependabot adds a default cooldown before opening version-update pull requests GitHub added a default package cooldown to Dependabot version updates, delaying version-update pull requests but not security patches.
  4. Bonsai 27B compresses a Qwen model to run on a phone with reported quality tradeoffs PrismML published Bonsai 27B, shrinking Qwen 3.6 from 54 GB to 3.8 GB through extreme quantization to ternary for on-device inference.

Conferences and events

  1. EuroPython 2026 runs through 2026-07-19 EuroPython 2026 runs from 2026-07-13 through 2026-07-19, covering CPython internals, typing, packaging, and the scientific Python stack.

AI

  1. Star Fleet reports Lean-verified Erdős-problem solutions from parallel Codex agents Colin Snyder published Star Fleet, running parallel Codex agents to emit machine-checked Lean 4 proofs for open Erdős problems.

Agentic coding

  1. Juggler models coding-agent sessions as branching CRDT documents Juggler is an open-source coding agent replacing linear chat with branching Yjs CRDT documents navigated through Miller-column UI.
  2. Guest essay argues domain-specific languages make LLM output more reliable An essay on martinfowler.com argues domain-specific languages improve LLM reliability by constraining output and enabling self-correction.

Security

  1. Microsoft ships a record July Patch Tuesday with two actively exploited zero-days Microsoft's July 2026 Patch Tuesday addressed a record 569 CVEs, including two actively exploited zero-days in ADFS and SharePoint Server.
  2. CISA adds an actively exploited SharePoint auth-bypass and two SonicWall SMA1000 flaws to KEV CISA added CVE-2026-56164, an authentication-bypass in SharePoint Server, to KEV with a three-day federal remediation deadline.
  3. Tailscale SSH argument injection let a crafted username dump the passwd file Tailscale SSH argument-injection via leading-dash usernames allowed getent to output the passwd file to authorized tailnet principals.

Outages

  1. OpenAI reports short ChatGPT incidents on 2026-07-14 and 2026-07-15 OpenAI reported short ChatGPT incidents on 2026-07-14 and 2026-07-15 affecting voice mode and conversation features, with the API unaffected.
  2. Cloudflare R2 errors in Western Europe continue during Barcelona maintenance Cloudflare R2 continued elevated errors in Western Europe through 2026-07-15 during scheduled maintenance in its Barcelona datacenter.

Developer tools

  1. Homebrew 6.0.11 adds a brew vulns command and OSV advisory export Homebrew 6.0.11 adds a brew vulns command and OSV advisory export, moving dependency scanning closer to the package install path.

Engineering posts

  1. High-speed camera measurements find X11 and native Wayland input latency roughly equal Marco Nett measured X11 and native Wayland input latency both at 4 milliseconds, showing driver and compositor matter more than protocol.

Markets and companies

  1. S&P cuts Oracle to one notch above junk over AI datacenter debt S&P cut Oracle to BBB- on AI datacenter debt, projecting fiscal 2027 capex of 90 to 95 billion dollars with OpenAI accounting for half.

Hacker News

  1. A Claude Code hook to rewrite the model's repeated verbal tics Johanna Larsson described a Claude Code hook that rewrites recurring phrases like load-bearing and stock responses before display.

Reddit and social pulse

  1. Armin Ronacher argues agents let a software tower keep rising after shared understanding collapses Armin Ronacher argues agents remove coordination friction but let isolated changes accumulate into incoherent systems over time.