Top stories

  1. Shai-Hulud's first npm wave shipped through the project's own OIDC trusted publishing pipeline Endor states the seed wave carried valid npm signatures and SLSA provenance while token-stolen copies in other packages did not.
  2. Unit 42 discloses three attacks on Google synced passkeys that start from malware already on the device Unit 42 names three attacks on synced passkeys that require device malware, where relying party UV validation blocks the strongest attack.
  3. Hassabis moves to Chair of Google DeepMind as Koray Kavukcuoglu takes over Gemini development and Jeff Dean leaves Alphabet Demis Hassabis moves to Chair of Google DeepMind and Koray Kavukcuoglu takes over Gemini model development from him.
  4. Greg Kroah-Hartman will reject LLM-generated patches in drivers/staging except for tested security fixes Greg Kroah-Hartman announced drivers/staging will reject LLM patches except tested security fixes, moving evidence burden to the sender.

AI

  1. Cloudflare open-sources Cloudflare OS and ties agent authorization to what the agent has read Cloudflare released Cloudflare OS, a runtime where agent authorization is evaluated against data provenance rather than the tool call.
  2. Mistral releases Shieldstral, a 3B Apache-2.0 multimodal safety classifier that takes its policy at inference time Mistral released Shieldstral 1.0, a 3B classifier that takes its policy at inference time rather than encoded in the model weights.
  3. NVIDIA relicenses the whole Alpamayo model family under OpenMDW-1.1 for commercial use NVIDIA relicensed Alpamayo under OpenMDW-1.1, covering commercial use and fine-tuning where earlier releases were research-only.

ML research

  1. A controlled study finds input dimensionality, not format or tokenization, is why an LLM loses to classical models on tables Garnelo and Czarnecki report the LLM's accuracy decreases with dimensionality on tables, while classical models improve or stay flat.

Agentic coding

  1. Warp ships its agent as a standalone CLI built on a terminal multiplexer Warp released its coding agent as a standalone CLI built on a terminal multiplexer, letting it drive a pty rather than shell commands.

Security

  1. Coinkite states AI-assisted review missed the COLDCARD RNG bug both before and after the exploit Coinkite states AI-assisted review of security-critical firmware missed the RNG bug before and retested frontier models missed it too.
  2. Bugtraq restarts after Jonathan Brossard acquires securityfocus.com Jonathan Brossard acquired securityfocus.com and restarted Bugtraq, restoring a disclosure venue no vendor controls and its archives.

Developer tools

  1. JetBrains ships IntelliJ IDEA's Java and Kotlin intelligence as an LSP extension for VS Code and Cursor JetBrains shipped IntelliJ's Java and Kotlin intelligence as an LSP for VS Code and Cursor, letting agents resolve types by lookup.
  2. Flowise sunsets and names coding agents as the reason FlowiseAI published a sunset notice for Flowise naming coding agents as the reason, with code freeze and end of life in August.
  3. vlt ships 1.0 with hosted npm-compatible registries and installs that separate download from script execution vlt 1.0 separates npm tarball downloads from script execution through phased install, putting a step between the preinstall hook.
  4. libexpat gets a City of Munich open-source sabbatical of up to six months The City of Munich is funding a six-month sabbatical for libexpat work, where the library carries five known unfixed vulnerabilities.

Languages and runtimes

  1. rust-lang/rust adopts an LLM policy that permits review and analysis but restricts creation Five Rust teams adopted a policy permitting LLM analysis but restricting creation, holding LLM code to a higher bar than human code.

Apple platforms

  1. Mysk finds three WebKit features that bypass proxy configuration and leak the device IP and DNS Talal Haj Bakry and Tommy Mysk report three WebKit features bypassing proxy configuration and iCloud Private Relay, leaking IP and DNS.

Engineering posts

  1. GitHub case-folds code search at over 45 GiB/s by deleting the early exit GitHub achieved case folding code search at over 45 GiB/s by removing the early exit on non-ASCII bytes, which branched slower.
  2. Cloudflare routes its engineering standards through agents and reports 16,000 blocked merges in four months Timo Reimann describes Cloudflare's Codex of engineering standards, where AI reviewers withheld 16,000 approvals across four months.

Markets and companies

  1. Oxide Computer reports a $444,999,052 raise in a Form D Oxide Computer filed a Form D for a $444,999,052 raise sold to 15 investors, backing multi-year support for single-vendor rack commitments.
  2. Bending Spoons agrees to acquire Airtable for $1.285B Bending Spoons agreed to acquire Airtable for $1.285 billion, its first acquisition after IPO and fourth major acquisition this year.