Top stories

  1. Shai-Hulud worm compromises keyv and cacheable npm packages and spreads to more than 400 others A compromised keyv maintainer published a malicious preinstall hook spreading to 434 npm packages with 2 billion monthly installs.
  2. FFmpeg 9.0 "Lei" released FFmpeg 9.0, codenamed Lei, released on 2026-08-04 with new sonames for all core libraries, requiring rebuilds for downstream users.
  3. Apple caps bug bounty submissions as AI-generated reports flood the inbox Apple capped bug bounty submissions per researcher due to AI-generated report floods, causing a real macOS flaw to go unreported.
  4. Cloudflare previews @cloudflare/computer, an agent runtime spanning isolates and containers Cloudflare previewed @cloudflare/computer, an agent runtime spanning isolates and containers backed by a durable SQLite-backed filesystem.

AI

  1. Cloudflare quantizes KV cache and weights to serve Kimi and GLM FP8 KV cache quantization lets Cloudflare admit 64 concurrent requests where BF16 exhausts at 32, with minimal per-token quality loss.

Agentic coding

  1. The npm worm plants autostart hooks in .claude/settings.json and .vscode/tasks.json The npm worm injects SessionStart hooks in .claude/settings.json and folderOpen tasks in .vscode/tasks.json, activating without npm install.
  2. Lilian Weng surveys harness engineering as the layer between a model and its task Lilian Weng surveys harness engineering as the layer between model and task, from instruction prompts through optimizer code.

Security

  1. keyv@6.0.0 shipped a valid npm provenance attestation, and the payload's dead-man's switch fires on credential revocation keyv@6.0.0 passed npm provenance attestation despite malicious source because the build workflow was already compromised.
  2. DPRK npm packages hide their C2 address in the recipient of an empty Ethereum transfer DPRK-linked npm packages encode command-and-control addresses in the recipient field of zero-value Ethereum transfers.

Outages

  1. DDoS against Norway's ID-porten resolved after degrading national login into a second day A DDoS attack on Norway's ID-porten identity provider degraded login to ten public services into a second day before resolution.

Developer tools

  1. Twenty years of Pandoc Twenty years of Pandoc: from 3000 lines of Haskell to 51 input and 76 output formats through a central AST design.
  2. C-Kermit 11 is the first full Kermit release in 15 years C-Kermit 11, the first full release in 15 years, modernizes a VMS-era codebase with IPv6, memory-safety fixes and new test coverage.

Apple platforms

  1. macOS Mail contacts iCloud when sending mail from a non-iCloud account macOS Mail contacts iCloud when sending from non-iCloud accounts despite iCloud being disabled in settings, cause unconfirmed.

Linux and kernel

  1. Torvalds attributes part of the 7.2-rc6 networking backlog to conference timing Linus Torvalds attributes part of Linux 7.2-rc6's networking backlog to conference timing, according to the original announcement.

Engineering posts

  1. A single-MI300X DeepSeek V4 Flash deployment with two named correctness fixes A DeepSeek V4 Flash MI300X deployment documents correctness fixes for mixture-of-experts masking and FP8 scale divergence between AMD chips.
  2. LLMs reward expertise LLMs reward expertise: domain knowledge of a specific codebase beats general system-design principles when directing a model.

Hacker News

  1. Don't be a meat proxy Relaying model output verbatim into Slack and reviews without validation moves the reading cost onto recipients as a 'meat proxy.'
  2. Prevent cognitive debt by manually retyping LLM-generated code Practitioners debate whether manually retyping LLM-generated code restores comprehension or is merely a throughput tax.