Top stories

  1. etcd patches a Watch API authorization bypass that reads past a single-key grant etcd patched an authorization bypass in Watch API where read access to one key leaked all lexicographically greater keys.
  2. Oh My Posh runs commands taken from directory names Oh My Posh executed template commands in directory names when rendering the prompt, reaching code execution on directory traversal.
  3. GNU C Library 2.44 adds system-wide tunables and fixes four CVEs glibc 2.44 fixed DNS response handling and buffer issues affecting processes that resolve addresses or convert encodings on untrusted data.
  4. Security camera firmware shipped a GitHub organization admin token Hanwha camera firmware dumped a GitHub organization admin token from CI environment into compiled web UI bundles via Vite misconfiguration.
  5. Fly.io changes CEO and refocuses the company on computers for agents Fly.io installed Docker's former CEO and refocused on Sprites as computers for agents rather than sandboxes.

AI

  1. PyTorch Monarch runs single-controller distributed training on AMD GPUs PyTorch Monarch ran 256-GPU Llama training on AMD MI355 with fault recovery and participant fluctuation without full job restarts.
  2. A 28.9M-parameter language model runs on an $8 microcontroller A project ran 28.9M parameters on an ESP32-S3 by moving embeddings to flash and computation to SRAM, reaching nine tokens per second.

ML research

  1. Dense per-step rewards collapse GRPO-trained agents into a degenerate policy Adding dense prediction rewards to GRPO drives agents into a dark room where accuracy maxes while task success falls to zero.
  2. Windowing only the speculative draft head cuts million-token decode cost by up to 44 percent Windowing KV cache only on the speculative draft model reduces per-step cost 28 to 44 percent at million tokens while keeping full verification.

Security

  1. Default SM2 key generation in a widely used npm crypto package is predictable sm-crypto 0.4.0 generated SM2 keys from Math.random() instead of secure randomness on Node.js, making keys derivable from observable output.
  2. kin-openapi request validation crashes on one unauthenticated request kin-openapi's request validator crashes on content parameters without schemas, reachable without credentials on conforming OpenAPI specs.
  3. GrapheneOS publishes its locked-device data extraction defenses in detail GrapheneOS detailed rate-limit budgets and fingerprint attempt limits that block forensic extraction from locked devices.
  4. MCP OpenAPI adapter re-fetched specs through an unguarded fetch FrontMCP's spec-change poller bypassed SSRF protections when re-fetching specs on a timer, exposing metadata and internal services.

Outages

  1. Anthropic logs model-serving error incidents on six consecutive days Anthropic logged model-serving errors on six consecutive days from 2026-07-21 through 2026-07-26, with no published root cause.
  2. OpenAI ChatGPT conversation errors pass 15 hours without a published cause OpenAI's ChatGPT incident persisted 15 hours after mitigation with no published root cause for the conversation failures.

Developer tools

  1. marimo ships a JetBrains plugin for its reactive Python notebooks marimo released a PyCharm plugin for its notebooks as plain Python files, removing the need to keep notebook work outside repositories.
  2. Ruff 0.16.0 raises the default lint rule count from 59 to 413 Ruff 0.16.0 expanded default rules sevenfold, turning a routine upgrade into a CI failure for projects relying on previous defaults.
  3. PEP 836 makes a 20 percent speedup the condition for keeping the CPython JIT PEP 836 sets a 20 percent speedup gate for keeping CPython's JIT in main, measured on the free-threaded build by Python 3.17 beta 1.

Infrastructure

  1. Cloudflare splits AI bot controls into Search, Agent, and Training with new defaults on 2026-09-15 Cloudflare split bot controls into Search, Agent, and Training, blocking Agent and Training by default on ad pages starting 2026-09-15.

Engineering posts

  1. Wide SIMD on edge-edge tests cuts a Box3D collision benchmark by more than half Box3D's convex-hull collision tests were sped twofold by processing multiple units at once with SIMD, with SSE2 doing most of the work.
  2. Proof-of-work gate is measured as costing humans more than the scrapers it targets Proof-of-work gates cost an estimated 230 person-years per year worldwide, landing on legitimate readers rather than determined scrapers.
  3. A walkthrough of how Fedora turns a git push into ISOs and images A walkthrough traces Fedora from git pushes through Koji builds, Bodhi gates, and Pungi composition, with freezes by commit hash.

New videos

  1. Talk reports frontier models doing the reconnaissance but missing the logic leap in an access-control exploit GPT-5.5 and Opus probed a target environment and reached an access-control flaw but did not make the inference needed to exploit.
  2. Talk describes a bit-exact reproducibility gate on pre-training runs Poolside describes a reproducibility gate where two pre-training replicas must match bit-for-bit or the run is killed, catching precision bugs.

Markets and companies

  1. DeepSeek suspends a second funding round after leaked founder remarks DeepSeek suspended a second ten-billion-yuan round after leaked founder remarks on persistent compute gaps versus US labs.

Hacker News

  1. ARC-AGI leaderboard thread splits on whether the Opus 5 gap is real The ARC Prize leaderboard reached HN top with commenters questioning whether the Opus 5 lead reflects generalization or contamination.
  2. Open-weight AI compared to Kubernetes draws pushback on the analogy and on the cost claim Commenters disputed an open-weight-as-Kubernetes analogy but agreed open weights provide price stability against frontier API changes.