2026-08-15
Top stories
- NCSC-NL reports active exploitation of the macOS Screen Sharing authentication bypass NCSC-NL warned of active exploitation of CVE-2026-65400 after public code emerged, with root obtained on internet-facing hosts.
- CyberPanel ships a hard-coded WebTerminal JWT secret that yields an unauthenticated root shell Researchers found CyberPanel 2.4.2 through 2.4.6 with a hard-coded WebTerminal JWT secret yielding unauthenticated root on port 8888.
- Debian opens voting on LLM contributions with a nine-option ballot, closing 2026-08-28 Debian opened voting on LLM contributions with nine ranked choices from banning to explicit permission, closing 2026-08-28.
- A contract-grade verifier finds 39.5 percent of already-accepted LLM-generated GPU kernels broken beyond tolerance A verifier found 39.5 percent of 2,638 LLM-generated GPU kernels already accepted by the system's own harness to be broken.
AI
- Anthropic describes Claude's text watermark as a SynthID-Text variant Anthropic described Claude's text watermark as a SynthID-Text variant biasing low-stakes token choices with no hidden characters or extra tokens.
- Google publishes HEIR, a compiler that runs model inference on homomorphically encrypted inputs Google published HEIR, an open-source compiler running model inference on homomorphically encrypted inputs without requiring manual rewriting.