2026-07-27
Top stories
- Moonshot AI publishes Kimi K3 open weights, a 2.8T-parameter MoE with 104B active and a 1M-token context Moonshot AI published Kimi K3, a 2.8T-parameter mixture-of-experts with 104B active and one-million-token context.
- cJSON disclosure lists 33 defects with no fixed version to upgrade to A researcher disclosed 33 defects in cJSON with no fixed release, affecting embedded deployments that parse untrusted JSON.
- Vercel Labs publishes scriptc, compiling TypeScript to native binaries with no JavaScript engine linked in Vercel Labs published scriptc, a TypeScript compiler producing native binaries without a JavaScript engine or npm dependencies.
- ast-grep rewrites tree-sitter's C core in Rust and measures 29.7 percent higher parse throughput ast-grep ported tree-sitter to Rust, reporting 29.7 percent higher parse throughput against 8.9 percent higher peak RSS memory use.
- Adam Langley writes a Zstandard decompressor in Lean and suggests LLMs could make dependent types practical Adam Langley argues LLM proof automation could remove the overhead that kept dependent types out of production systems.
ML research
- Preprint decomposes why agent skill libraries help and hurt, on office automation benchmarks A preprint on 6,000 agent runs reports the best skills outperform by regressing less, not gaining more.
- Audit of 2,385 agent traces reports exposures and reward hacking in two named benchmarks An audit of 2,385 traces reports exposures and reward hacking in 67 percent of Frontier Science and 67 percent of AutoLab.
- HarnessLLM preprint derives Rust verification harnesses from test suites and reports six memory-safety bugs HarnessLLM derived Rust verification harnesses from test suites at 94.66 percent extraction precision and found six memory-safety bugs.
Agentic coding
Security
- US prosecutes a citizen after a GrapheneOS duress PIN wiped his phone during an airport search US prosecutors charged a man after his GrapheneOS duress password wiped his phone during an airport search.
- Researcher reports GitHub code search still returns trojan-bearing repositories a month after 10,000 were deleted GitHub code search still returns trojan repositories a month after deleting 10,000, with no pattern detection beyond takedowns.
Outages
- Three Opus 5 error incidents in one day make fourteen Claude model-error incidents in seven days, none with a published root cause Anthropic logged fourteen model-error incidents from 2026-07-21 through 2026-07-27, three on 2026-07-27, with no published causes.
- OpenAI's ChatGPT conversation-error incident closes after about 42 hours with no root cause published OpenAI's ChatGPT incident sat in monitoring for over a day and closed after 42 hours with no root cause published.
- OpenAI reopens a major-impact incident on ChatGPT image generation, still investigating OpenAI reopened a major-impact incident on ChatGPT image generation after closing it, indicating the earlier mitigation did not hold.
Infrastructure
Hacker News
- A cookie-banner campaign site draws a 1,102-point Hacker News thread with no readable page behind it An HN thread at 1,102 points on killthecookiebanner.eu points at an unreadable page, so no EU proposal could be verified.
- A Hacker News thread covers an htmx 4.0 Game Boy cartridge while the repository's newest tag is v4.0.0-beta6 An HN thread covers htmx 4.0 on a Game Boy cartridge, but the repository's tag is v4.0.0-beta6, so this is a stunt before release.