2026-07-26
Top stories
- etcd patches a Watch API authorization bypass that reads past a single-key grant etcd patched an authorization bypass in Watch API where read access to one key leaked all lexicographically greater keys.
- Oh My Posh runs commands taken from directory names Oh My Posh executed template commands in directory names when rendering the prompt, reaching code execution on directory traversal.
- GNU C Library 2.44 adds system-wide tunables and fixes four CVEs glibc 2.44 fixed DNS response handling and buffer issues affecting processes that resolve addresses or convert encodings on untrusted data.
- Security camera firmware shipped a GitHub organization admin token Hanwha camera firmware dumped a GitHub organization admin token from CI environment into compiled web UI bundles via Vite misconfiguration.
- Fly.io changes CEO and refocuses the company on computers for agents Fly.io installed Docker's former CEO and refocused on Sprites as computers for agents rather than sandboxes.
AI
- PyTorch Monarch runs single-controller distributed training on AMD GPUs PyTorch Monarch ran 256-GPU Llama training on AMD MI355 with fault recovery and participant fluctuation without full job restarts.
- A 28.9M-parameter language model runs on an $8 microcontroller A project ran 28.9M parameters on an ESP32-S3 by moving embeddings to flash and computation to SRAM, reaching nine tokens per second.
ML research
- Dense per-step rewards collapse GRPO-trained agents into a degenerate policy Adding dense prediction rewards to GRPO drives agents into a dark room where accuracy maxes while task success falls to zero.
- Windowing only the speculative draft head cuts million-token decode cost by up to 44 percent Windowing KV cache only on the speculative draft model reduces per-step cost 28 to 44 percent at million tokens while keeping full verification.
Security
- Default SM2 key generation in a widely used npm crypto package is predictable sm-crypto 0.4.0 generated SM2 keys from Math.random() instead of secure randomness on Node.js, making keys derivable from observable output.
- kin-openapi request validation crashes on one unauthenticated request kin-openapi's request validator crashes on content parameters without schemas, reachable without credentials on conforming OpenAPI specs.
- GrapheneOS publishes its locked-device data extraction defenses in detail GrapheneOS detailed rate-limit budgets and fingerprint attempt limits that block forensic extraction from locked devices.
- MCP OpenAPI adapter re-fetched specs through an unguarded fetch FrontMCP's spec-change poller bypassed SSRF protections when re-fetching specs on a timer, exposing metadata and internal services.
Outages
- Anthropic logs model-serving error incidents on six consecutive days Anthropic logged model-serving errors on six consecutive days from 2026-07-21 through 2026-07-26, with no published root cause.
- OpenAI ChatGPT conversation errors pass 15 hours without a published cause OpenAI's ChatGPT incident persisted 15 hours after mitigation with no published root cause for the conversation failures.
Developer tools
- marimo ships a JetBrains plugin for its reactive Python notebooks marimo released a PyCharm plugin for its notebooks as plain Python files, removing the need to keep notebook work outside repositories.
- Ruff 0.16.0 raises the default lint rule count from 59 to 413 Ruff 0.16.0 expanded default rules sevenfold, turning a routine upgrade into a CI failure for projects relying on previous defaults.
- PEP 836 makes a 20 percent speedup the condition for keeping the CPython JIT PEP 836 sets a 20 percent speedup gate for keeping CPython's JIT in main, measured on the free-threaded build by Python 3.17 beta 1.
Infrastructure
Engineering posts
- Wide SIMD on edge-edge tests cuts a Box3D collision benchmark by more than half Box3D's convex-hull collision tests were sped twofold by processing multiple units at once with SIMD, with SSE2 doing most of the work.
- Proof-of-work gate is measured as costing humans more than the scrapers it targets Proof-of-work gates cost an estimated 230 person-years per year worldwide, landing on legitimate readers rather than determined scrapers.
- A walkthrough of how Fedora turns a git push into ISOs and images A walkthrough traces Fedora from git pushes through Koji builds, Bodhi gates, and Pungi composition, with freezes by commit hash.
New videos
- Talk reports frontier models doing the reconnaissance but missing the logic leap in an access-control exploit GPT-5.5 and Opus probed a target environment and reached an access-control flaw but did not make the inference needed to exploit.
- Talk describes a bit-exact reproducibility gate on pre-training runs Poolside describes a reproducibility gate where two pre-training replicas must match bit-for-bit or the run is killed, catching precision bugs.
Markets and companies
Hacker News
- ARC-AGI leaderboard thread splits on whether the Opus 5 gap is real The ARC Prize leaderboard reached HN top with commenters questioning whether the Opus 5 lead reflects generalization or contamination.
- Open-weight AI compared to Kubernetes draws pushback on the analogy and on the cost claim Commenters disputed an open-weight-as-Kubernetes analogy but agreed open weights provide price stability against frontier API changes.