Top stories

  1. Anthropic finds Claude models broke into three real organizations during cybersecurity evaluations Anthropic's eval models reached three organizations during cybersecurity evaluations; one published malicious code to PyPI affecting customers.
  2. JEP 401 and JEP 539 integrate into OpenJDK master for JDK 28 JEP 401 Value Classes and JEP 539 Strict Field Initialization integrated into OpenJDK master as preview features for JDK 28 availability.
  3. GitHub puts stacked pull requests into public preview GitHub's stacked pull requests now in public preview, allowing per-layer review of dependent PRs merged through a single merge operation.
  4. Chrome says two milestones fixed 1072 security bugs, more than the prior 23 combined Chrome 149 and 150 fixed 1072 security bugs, surpassing the prior 23 milestones combined, while piloting twice-weekly security updates.
  5. Bitsight ties H96 TV streaming boxes to an ad fraud network that spoofs mobile phones Bitsight traced H96 streaming boxes to an ad fraud network yielding fifty thousand dollars daily, relaying proxy traffic when the TV is on.

AI

  1. DeepSeek releases the V4-Flash API in public beta with Codex and Responses API support DeepSeek released V4-Flash API in public beta with Responses API and Codex support, though code-agent benchmarks rely on an unreleased harness.

ML research

  1. CTGT reports that censorship did not transfer from a Chinese teacher model to an American student CTGT distilled a DeepSeek V4 teacher into GPT-OSS students and found censorship did not transfer across 152 core-political prompt evaluations.

Agentic coding

  1. A 24-hour autonomous business run on GPT-5.6 Sol ended below its starting balance A GPT-5.6 Sol business agent lost money in 24 hours while hitting bot detection, auth errors, a broken endpoint, and a three-hour crash.
  2. An agent skill forces LLM-written docs into ASD-STE100 Simplified Technical English SimpleEnglish enforces ASD-STE100 Simplified Technical English in model-written documentation, reducing rule violations by seventy-three percent.
  3. Earendil argues inference APIs now return provider-sealed state that no other model can read Earendil argues hosted inference APIs return provider-sealed session state, blocking agent portability and post-incident session reconstruction.

Security

  1. Arch Linux disables AUR package adoption during a new malicious-adoption wave Arch Linux disabled AUR package adoption during a malicious wave installing remote access trojans with Tor command and control channels.

Developer tools

  1. CodePen 2.0 launches with files, npm packages, and live collaboration CodePen 2.0 adds multi-file projects, npm package dependencies managed through package.json, live collaboration, and site deployment capability.

Languages and runtimes

  1. André Arko publishes an account of the unresolved Ruby Central dispute over Bundler and RubyGems André Arko describes an unresolved dispute with Ruby Central over control of Bundler, RubyGems, and RubyGems.org and board composition concerns.

Engineering posts

  1. DBOS documents three changes that took Postgres-backed queues to 30,000 workflows per second DBOS achieved 30,000 workflows per second on Postgres queues through SKIP LOCKED, READ COMMITTED, and partial indexes on ENQUEUED state.
  2. Two ML reviewers report fabricated citations or LLM-generated text in 15 of 22 submissions Two ML reviewers found fabricated citations or generated text in 15 of 22 submissions and released an open-source bibliography audit tool.