2026-07-25
Top stories
- Redis ships seven security releases for remote-code-execution flaws surfaced with AI agents Redis shipped seven releases for two memory-corruption classes in RESTORE payloads, both marked as possibly leading to remote code execution.
- UK and US security institutes publish measured cyber-capability numbers for Kimi K3 UK and US security institutes assessed Kimi K3 at 32 percent on ExploitBench, above GLM 5.2 at 24 percent but below frontier models.
- SharedRoot escapes Claude Cowork's local sandbox onto the host Mac A writeup chains six steps to escape Claude Cowork's VM using a public kernel vulnerability to poison caches and reach the host filesystem.
- AMD launches the MI455X and its first rack-scale AI system with gigawatt customer commitments AMD launched the Instinct MI400 Series and Helios rack with commitments for two gigawatts of deployment, starting in the first half of 2027.
- AWS us-west-2 loses external connectivity for about an hour AWS us-west-2 lost external connectivity for an hour due to an issue with network devices routing traffic from the region to the Seattle metro.
- Debian opens competing General Resolutions on LLM contributions Debian opened two competing General Resolutions on LLM contributions, one proposing a ban and the other permitting use under stated conditions.
- Seven stable Linux kernels land in what maintainers call possibly the largest update set ever Greg Kroah-Hartman released seven stable kernels, including 7.1.5 with over 2,000 patches, following the kernel CVE team publishing 432 CVEs.
AI
- Black Forest Labs and mimic robotics decode robot actions from a video model Black Forest Labs published FLUX-mimic, reading robot actions from FLUX 3 video features with twice the sample efficiency of video-only models.
- AMD publishes a full Mixture-of-Experts training recipe run on its own accelerators AMD published Instella-MoE-16B trained end to end on Instinct GPUs with full training recipes under a research-only license.
ML research
- Per-token API timing leaks model architecture and inference optimizations A preprint recovers model architecture from per-token API timing, placing correct Llama configurations in top ten over 90 percent of the time.
- Black-box audit detects when a gateway swaps or dilutes the model you asked for A preprint audits LLM gateways to detect model substitution and dilution, reporting 0.99 AUROC on backend separation within Qwen families.
Agentic coding
- Anthropic publishes a Claude Cookbook on the platform docs Anthropic published the Claude Cookbook on its platform docs, a categorized collection of runnable guides backed by a public repository.
- Anthropic removes 80% of Claude Code's system prompt for the Claude 5 models Anthropic removed 80 percent of Claude Code's system prompt for Opus 5, replacing explicit rules with pattern-matching from surrounding code.
- Block's Buzz gives each agent its own keys and audit trail in a shared workspace Block's Buzz led GitHub trending as a self-hosted workspace where agents hold individual keys and audit trails over a signed Nostr relay.
Security
- DNS poisoning on hotel Wi-Fi gateways harvests Microsoft 365 credentials ReliaQuest reported attackers compromising hospitality Wi-Fi gateways to redirect authentication requests to fake Microsoft 365 login pages.
- Sequential user IDs expose 719,000 prayer app accounts for six months A researcher disclosed an insecure object reference exposing 719,000 Click to Pray accounts with email, name, and birthdate for six months.
Outages
- GitHub records three incidents in a single day GitHub recorded three incidents on 2026-07-24, including an abuse-filter configuration that blocked 0.25 percent of requests for 16 hours.
- Copilot loses the whole GPT model family for half an hour GitHub reported all GPT models degraded in Copilot on 2026-07-25, attributed to an upstream model provider issue without more detail.
- Cloudflare logs six incidents in one day, including R2 errors across APAC Cloudflare recorded six incidents on 2026-07-24, including R2 errors in APAC and an email outage that delayed password reset and MFA messages.
Developer tools
- Firefox 153 previews containers built into the browser Mozilla announced native containers in Firefox 153, moving Multi-Account Containers into the browser with per-container cookie isolation.
- Zed 1.12.0 adds git staging groups and multi-select finders Zed 1.12.0 added git staging groups and multi-select finders, plus format-on-save options targeting only changed lines.
- Proposal would stop Android's ADB daemon from accepting loopback connections A feature request proposes restricting Android ADB to Wi-Fi to fix a wireless bug, but this breaks on-device tooling that connects over loopback.
- FreeBSD rewrites ports history after a 150MB binary broke the GitHub mirror FreeBSD rewrote ports history after a 150MB Copilot CLI binary exceeded GitHub's file-size limit, forcing every downstream committer to rebase.
Languages and runtimes
- JEP 541 proposes deprecating the macOS/x64 JDK port JEP 541 proposes deprecating macOS/x64 JDK, citing Apple's shift to AArch64 and maintenance costs, with Oracle discontinuing support at JDK 27.
- Wasmtime 47 ships WebAssembly garbage collection and exception handling Wasmtime 47 shipped WebAssembly garbage collection using indices instead of pointers, keeping sandbox boundaries intact if the collector fails.
- Fil-C talk argues runtime enforcement is the memory-safety bar, not compile-time proof Filip Pizlo argues Fil-C makes C and C++ memory safe through runtime garbage collection, accepting panics as the cost of compatibility.
Infrastructure
Engineering posts
- Batching pushes Postgres LISTEN/NOTIFY from 2.9K to 60K writes per second DBOS found Postgres LISTEN/NOTIFY capped at 2.9K writes per second by a global lock, but batching notifications reaches 60K writes per second.
- Walkthrough traces a Fedora package from git push to installable image A walkthrough traces a Fedora package from git push through Koji builds, Bodhi testing gates, and Pungi composition to release artifacts.
New videos
- Talk argues coding models cannot hold a codebase together because nothing rewards it Dex Horthy argues coding models cannot hold architecture because nothing in their training reward prevents costly architectural decisions.
- Talk reports replacing the model running a real unstaffed cafe after it lost money Lukas Petersson describes replacing the model running Andon Labs' Stockholm cafe after six thousand dollars in losses from price coordination.
Hacker News
Reddit and social pulse
- r/LocalLLaMA splits on Poolside's Laguna S 2.1 Local-inference practitioners attributed Laguna S 2.1 reasoning issues to quantization, not model weights, across divided evaluation reports.
- Salvatore Sanfilippo argues the agent-era skill is Torvalds's, not the kernel author's Salvatore Sanfilippo argues coding agents demand a Torvalds skill: stopping implementation to hold design direction and coordinate maintainers.