Top stories

  1. OpenSSH 10.5 ships three security fixes and the project will release more often for now, after AI-found bugs were independently rediscovered OpenSSH 10.5 ships three security fixes and the project will increase release frequency after AI-found bugs were independently rediscovered.
  2. Checkly reports an attacker used a Metabase Cloud zero-day to read its analytics warehouse for 26 minutes An attacker exploited a Metabase Cloud zero-day to read Checkly's analytics warehouse for 26 minutes on 2026-08-03.
  3. A public exploit lands for CVE-2026-53361, an AF_UNIX garbage collection race the author uses to escape containers A public exploit landed for CVE-2026-53361, an AFUNIX garbage collection race that researchers use to escape containers.
  4. Mojo reaches 1.0 with a primarily-additive change policy, while the compiler stays closed Mojo reached 1.0 under Qualcomm ownership with a primarily-additive change policy, while the compiler remains closed-source.
  5. CloudSEK publishes a victim list for the March 2026 LiteLLM supply chain compromise, naming 2,500 organizations and 434,000 CI/CD pipelines CloudSEK published a list of the March 2026 LiteLLM supply-chain exposure, naming 2,500 organizations and 434,000 CI/CD pipelines.

AI

  1. NVIDIA releases NeMo Switchyard, an open source model-routing library, with partner cost figures NVIDIA released NeMo Switchyard, an open-source library that routes agent steps to cost-optimized models from a mixed provider set.
  2. xAI launches Grok Bot in beta, gated behind SuperGrok Heavy and Cursor paid tiers xAI launched Grok Bot in beta behind SuperGrok Heavy and Cursor Ultra subscriptions, with always-on agents that share cloud infrastructure.
  3. Qwen publishes 2.4T-parameter weights under a licence requiring a separate agreement above 50 million dollars of model-as-a-service revenue Qwen published 2.4T-parameter weights under a licence requiring separate agreement once deployment passes 50 million dollars in revenue.
  4. xAI releases Grok 4.6 at 2 dollars per million input tokens and 6 per million output xAI released Grok 4.6 with published pricing of two dollars per million input tokens and six per million output tokens.

ML research

  1. A case study reports tightened bounds on the Grothendieck constant reached with an AI research system A case study reports tightened bounds on the Grothendieck constant obtained with an AI research system, documenting method and failures.

Security

  1. MongoDB patches an authorization bypass reachable by sending a collection name as a BSON symbol instead of a string MongoDB patched CVE-2026-18690, an authorization bypass exploitable by sending a collection name as a BSON symbol instead of string.
  2. Expat 2.8.3 fixes CVE-2026-72522, an out-of-bounds read in UTF-16 decoding reachable over the network Expat 2.8.3 fixes CVE-2026-72522, an out-of-bounds read in UTF-16 decoding causing denial of service over the network.

Outages

  1. GitHub Issues and Pull Requests returned 500 errors for 25 minutes after an index hint outlived the index a migration removed GitHub returned 500 errors for 25 minutes when a query hint outlived a database index that a migration had removed.

Developer tools

  1. llama.cpp publishes llama.app as an official install site with a unified llama command llama.cpp published llama.app as its official install site with a unified llama command for cli and serve subcommands.

Languages and runtimes

  1. A Google post argues language choice now matters for review rather than for writing speed Google argues that once agents write code, language choice matters for review rather than speed, favoring explicitness and small feature surface.

Infrastructure

  1. pg_clickhouse v0.10.0 pushes down 16 of 22 TPC-H queries and adds guards for a NULL semantics mismatch that silently inverted NOT IN pgclickhouse v0.10.0 pushes down 16 of 22 TPC-H queries and adds guards for a NULL-semantics mismatch that inverted NOT IN queries.

Engineering posts

  1. Tailscale traces six months of database corruption to a SQLite WAL checkpoint data race the SQLite developers date to at least 16 years Tailscale traced six months of database corruption to a SQLite WAL checkpoint data race the developers date to at least 16 years old.
  2. Compression is prediction, an explainer connecting entropy coding to language modeling An explainer post connects arithmetic coding and entropy to language modeling, arguing they measure the same quantity from different ends.