2026-07-15
Top stories
- Cursor executes a repository's git.exe without confirmation on Windows, unpatched after seven months Mindgard disclosed an unpatched Cursor flaw on Windows where a malicious git.exe in a repository root runs automatically with no prompt.
- Claude memory exfiltrated through web_fetch link-following prompt injection Ayush Paul showed Claude.ai memory exfiltration through webfetch via a fake CAPTCHA with alphabetical links spelling out user data.
- Dependabot adds a default cooldown before opening version-update pull requests GitHub added a default package cooldown to Dependabot version updates, delaying version-update pull requests but not security patches.
- Bonsai 27B compresses a Qwen model to run on a phone with reported quality tradeoffs PrismML published Bonsai 27B, shrinking Qwen 3.6 from 54 GB to 3.8 GB through extreme quantization to ternary for on-device inference.
Conferences and events
AI
Agentic coding
- Juggler models coding-agent sessions as branching CRDT documents Juggler is an open-source coding agent replacing linear chat with branching Yjs CRDT documents navigated through Miller-column UI.
- Guest essay argues domain-specific languages make LLM output more reliable An essay on martinfowler.com argues domain-specific languages improve LLM reliability by constraining output and enabling self-correction.
Security
- Microsoft ships a record July Patch Tuesday with two actively exploited zero-days Microsoft's July 2026 Patch Tuesday addressed a record 569 CVEs, including two actively exploited zero-days in ADFS and SharePoint Server.
- CISA adds an actively exploited SharePoint auth-bypass and two SonicWall SMA1000 flaws to KEV CISA added CVE-2026-56164, an authentication-bypass in SharePoint Server, to KEV with a three-day federal remediation deadline.
- Tailscale SSH argument injection let a crafted username dump the passwd file Tailscale SSH argument-injection via leading-dash usernames allowed getent to output the passwd file to authorized tailnet principals.
Outages
- OpenAI reports short ChatGPT incidents on 2026-07-14 and 2026-07-15 OpenAI reported short ChatGPT incidents on 2026-07-14 and 2026-07-15 affecting voice mode and conversation features, with the API unaffected.
- Cloudflare R2 errors in Western Europe continue during Barcelona maintenance Cloudflare R2 continued elevated errors in Western Europe through 2026-07-15 during scheduled maintenance in its Barcelona datacenter.