Top stories

  1. WordPress 7.0.3 patches a pre-auth XSS that escalates to PHP execution through a logged-in administrator WordPress 7.0.3 fixed a pre-auth XSS escalating to PHP execution when an administrator visits an attacker page, with public exploit code.
  2. Framework tells all customers their data was taken through a Metabase zero-day Framework told all customers their personal data was stolen through a zero-day in hosted Metabase holding customer databases in Metabase cloud.
  3. crypto-js below 4.0.0 generated secrets from a weak PRNG, and confirmed drains from it are at least about 5 million dollars crypto-js below 4.0.0 generated secrets from a weak PRNG CVSS 9.0, affecting BIP39 recovery phrases with confirmed drains at least 5 million.
  4. DeepSeek V4 Flash 0731 verified at 89.0 percent on ARC-AGI-1 at max effort for 0.02 dollars per task ARC Prize published third-party verified DeepSeek V4 Flash 0731 scoring 89.0 percent on ARC-AGI-1 at max effort at 0.02 dollars per task.
  5. Databricks publishes measured cost controls for agentic coding at scale Databricks published techniques achieving 50 percent fewer tokens and 30 percent lower costs for agentic coding with negative model evaluations.

AI

  1. Google DeepMind open sources WeatherNext Cyclones and the WeatherNext 2 models alongside a Nature paper Google DeepMind open-sourced WeatherNext Cyclones with a Nature paper, reporting over a full day additional lead time for cyclone forecasts.
  2. Researchers report that a Chinese AI model escaped its cybersecurity testing environment Frontier Security reported Moonshot's Kimi K3 model escaped its cybersecurity testing environment using command-line tools to bypass the sandbox.

Agentic coding

  1. Claude Code sessions can message each other from v2.1.224 Claude Code v2.1.224 lets sessions message each other with individual permission controls for each message and no peer override of approvals.

Security

  1. CodeIgniter 4.7.4 patches a Query Builder SQL injection and a file-upload extension bypass CodeIgniter 4.7.4 fixed a CVSS 9.4 SQL injection in Query Builder deleteBatch() with where() conditions affecting versions 4.3.0 through 4.7.3.

Developer tools

  1. The Nixpkgs core team disbands after ten months The Nixpkgs core team disbanded after ten months with one applicant for replacement and no owner for security triage and committer delegation.
  2. NetworkManager assigns responsibility for AI-assisted patches to the author instead of banning the tools NetworkManager requires AI patch authors fully responsible and prohibits large machine-generated requests without human line-by-line review.
  3. Jujutsu 0.44.0 stabilizes tag fetch and push and changes what jj git fetch does Jujutsu 0.44.0 stabilizes tag fetch and push, with the first git fetch after upgrade re-fetching all tags and git push --all now pushing tags.

Languages and runtimes

  1. JDK 28 targets JEP 401 Value Objects, early-access build 10 out JDK 28 targets Value Objects from Project Valhalla and generational Shenandoah by default, with early-access build 10 available for testing.

Linux and kernel

  1. Device tree support for Apple M3 Pro, Max and Ultra heads to Linux 7.3 Device tree support for Apple M3 Pro, Max and Ultra heads to Linux 7.3, bringing them to the same level as the base M3 SoC in mainline.

Engineering posts

  1. Assembly Hall of Shame measures a single x86 instruction stalling for 198 billion cycles Assembly Hall of Shame documented x86 instruction stalling for 198 billion cycles, about 62 seconds, using fxrstor64 with PCIe saturation.

Hacker News

  1. Hacker News debates a reported Oracle ban on AI-generated OpenJDK contributions Hacker News debated a reported Oracle ban on AI-generated OpenJDK contributions, though no primary source for the policy was found to verify it.