Top stories

  1. Two Linux kernel local-root exploits land amid a 432-CVE flood Qualys disclosed RefluXFS, a race in XFS copy-on-write escalating to root on default RHEL, Oracle, and Amazon Linux, amid a 432-CVE kernel flood.
  2. White House accuses Moonshot of distilling Anthropic's Fable to build Kimi K3 White House accused Moonshot of distilling Fable to build Kimi K3, escalating US-China AI tensions into policy and possible-sanctions tracks.
  3. Coding-agent CLI sandboxes escaped through the Docker socket Pillar Security disclosed sandbox escapes in Cursor, Codex, and Gemini CLI via the Docker socket, allowing writes to files outside the workspace.
  4. CISA adds Check Point SmartConsole and a fourth SharePoint RCE to KEV CISA added a Check Point SmartConsole auth bypass giving admin access and a fourth SharePoint RCE to KEV with federal remediation due soon.
  5. PyPI closes releases to new files after 14 days PyPI now rejects new files to releases older than 14 days to prevent poisoning of long-stable pinned releases through compromised credentials.

AI

  1. About 200 startups urge the US not to cut off Chinese open-weight AI A coalition of 200 startups urged Trump not to restrict Chinese open-weight AI like Kimi and Qwen, saying many builders depend on them.
  2. OpenAI launches Presence for enterprise support agents OpenAI introduced Presence for building support agents with guardrails and escalation, using Codex to review and approve behavior changes.
  3. Essay questions whether AI labs are gaming public benchmarks An essay questions whether AI labs game informal public benchmarks like drawing pelicans, warning improvements may reflect targeted training.

ML research

  1. GigaToken reports roughly 1000x faster tokenization GigaToken, a Rust tokenizer, reports 989x faster throughput than Hugging Face and 681x over tiktoken on GPT-2 BPE with SIMD pretokenization.

Agentic coding

  1. Review grades 36 MCP servers on agent usability A practitioner review graded 36 MCP servers on agent usability, finding a third scored poorly on descriptions, bloated responses, and errors.

Security

  1. Fake take-home interview project carried a git-hook malware operation A developer found staged git pre-commit hook malware in a fake take-home project delivered via social-engineered fake recruiting outreach.

Developer tools

  1. Kata Containers 4.0.0 ships a new Rust runtime Kata Containers 4.0.0 shipped a Rust runtime replacing Go, becoming the new default for VM-isolated container workloads in Kubernetes.
  2. Codeberg bans cryptocurrency projects Codeberg amended its terms to ban cryptocurrency and blockchain projects, a second content-policy narrowing from the forge in recent weeks.

Languages and runtimes

  1. Greg Kroah-Hartman frames Rust as reviving kernel contribution Greg Kroah-Hartman said Rust makes kernel coding fun and draws new contributors, signaling the direction of future kernel contributor onboarding.
  2. Cruller forks Bun's final Zig runtime after the Rust rewrite Cruller forked Bun's last Zig runtime and updated it to Zig 0.16.0, keeping production features while stripping dev tooling for a smaller binary.

Apple platforms

  1. Safari Technology Preview 248 released Safari Technology Preview 248 shipped with WebKit fixes and platform features across CSS, JavaScript, rendering, and web APIs.

Engineering posts

  1. A startup's Postgres survival guide Hatchet published a Postgres guide covering schema design, connection management, index pitfalls, and recurring failure modes at scale.
  2. Everyone should know SIMD Mitchell Hashimoto argues working engineers should understand SIMD, explaining where single-core performance now lives with Zig examples.
  3. Git's --end-of-options and argument injection in package managers A writeup explains git's argument injection defense via --end-of-options, finding only Go's toolchain consistently applies it across managers.

Markets and companies

  1. Report: five US tech giants carry $1.65T in off-balance-sheet AI debt Nikkei Asia reports Alphabet, Amazon, Meta, Microsoft, and Oracle carry $1.65 trillion in off-balance-sheet AI-infrastructure debt through SPVs.

Hacker News

  1. Show HN: an entire slide deck in one HTML file Bento, a Show HN, presents an entire slide deck (editing, viewing, collaboration) in one self-contained HTML file, topping the HN front page.
  2. Discussion: nobody knows what a used GPU cluster is worth An essay argues valuing used GPU clusters is hard given fast depreciation, uncertain useful life, and thin markets, affecting capex assumptions.
  3. Discussion: Reddit requires login to view logged-out old.reddit.com Reddit now requires login to browse old.reddit.com, ending anonymous access to the legacy interface to stop abusive scraping.

Reddit and social pulse

  1. Cursor users praise Grok 4.5 on price and performance r/cursor reports strong satisfaction with Grok 4.5 on cost and coding quality, continuing adoption sentiment for lower-cost models in agents.