2026-07-23
Top stories
- Two Linux kernel local-root exploits land amid a 432-CVE flood Qualys disclosed RefluXFS, a race in XFS copy-on-write escalating to root on default RHEL, Oracle, and Amazon Linux, amid a 432-CVE kernel flood.
- White House accuses Moonshot of distilling Anthropic's Fable to build Kimi K3 White House accused Moonshot of distilling Fable to build Kimi K3, escalating US-China AI tensions into policy and possible-sanctions tracks.
- Coding-agent CLI sandboxes escaped through the Docker socket Pillar Security disclosed sandbox escapes in Cursor, Codex, and Gemini CLI via the Docker socket, allowing writes to files outside the workspace.
- CISA adds Check Point SmartConsole and a fourth SharePoint RCE to KEV CISA added a Check Point SmartConsole auth bypass giving admin access and a fourth SharePoint RCE to KEV with federal remediation due soon.
- PyPI closes releases to new files after 14 days PyPI now rejects new files to releases older than 14 days to prevent poisoning of long-stable pinned releases through compromised credentials.
AI
- About 200 startups urge the US not to cut off Chinese open-weight AI A coalition of 200 startups urged Trump not to restrict Chinese open-weight AI like Kimi and Qwen, saying many builders depend on them.
- OpenAI launches Presence for enterprise support agents OpenAI introduced Presence for building support agents with guardrails and escalation, using Codex to review and approve behavior changes.
- Essay questions whether AI labs are gaming public benchmarks An essay questions whether AI labs game informal public benchmarks like drawing pelicans, warning improvements may reflect targeted training.
ML research
Agentic coding
Security
Developer tools
- Kata Containers 4.0.0 ships a new Rust runtime Kata Containers 4.0.0 shipped a Rust runtime replacing Go, becoming the new default for VM-isolated container workloads in Kubernetes.
- Codeberg bans cryptocurrency projects Codeberg amended its terms to ban cryptocurrency and blockchain projects, a second content-policy narrowing from the forge in recent weeks.
Languages and runtimes
- Greg Kroah-Hartman frames Rust as reviving kernel contribution Greg Kroah-Hartman said Rust makes kernel coding fun and draws new contributors, signaling the direction of future kernel contributor onboarding.
- Cruller forks Bun's final Zig runtime after the Rust rewrite Cruller forked Bun's last Zig runtime and updated it to Zig 0.16.0, keeping production features while stripping dev tooling for a smaller binary.
Apple platforms
Engineering posts
- A startup's Postgres survival guide Hatchet published a Postgres guide covering schema design, connection management, index pitfalls, and recurring failure modes at scale.
- Everyone should know SIMD Mitchell Hashimoto argues working engineers should understand SIMD, explaining where single-core performance now lives with Zig examples.
- Git's --end-of-options and argument injection in package managers A writeup explains git's argument injection defense via --end-of-options, finding only Go's toolchain consistently applies it across managers.
Markets and companies
Hacker News
- Show HN: an entire slide deck in one HTML file Bento, a Show HN, presents an entire slide deck (editing, viewing, collaboration) in one self-contained HTML file, topping the HN front page.
- Discussion: nobody knows what a used GPU cluster is worth An essay argues valuing used GPU clusters is hard given fast depreciation, uncertain useful life, and thin markets, affecting capex assumptions.
- Discussion: Reddit requires login to view logged-out old.reddit.com Reddit now requires login to browse old.reddit.com, ending anonymous access to the legacy interface to stop abusive scraping.