2026-08-16
Top stories
- AmnesiaStealer clones a macOS Chromium profile into a headless browser the operator drives live Jamf reports malware cloning Chromium profiles into hidden browsers the attacker drives, stealing sessions appearing from the victim's host.
- SpaceX completes its acquisition of Cursor, reported at $60B SpaceX completes Cursor acquisition at $60B, consolidating the editor, AI model, and infrastructure into a single vendor for standardized users.
- Zsh 5.9.2 fixes a silent history truncation that discarded years of entries Zsh 5.9.2 fixes a silent bug that could truncate years of shell history when interrupted during exit, producing no error or visible warning.
- A validation-centric agent workflow ports a 250,000-line Fortran weather code to GPU at 5.1x An agent workflow ported 250K lines of Fortran weather code to GPU at 5.1x, but a validation harness caught five of 162 kernels as wrong.
AI
ML research
Agentic coding
Security
- A threat actor sells Azure directory exports totalling millions of records from McDonald's, TCS, Vodafone, and six other enterprises Hudson Rock reports an actor selling Azure directory exports from nine enterprises, naming employees and admins in records totalling millions.
- A full-access Composio key returns the live Gmail, GitHub, and CircleCI tokens behind it in a vendor lab test Cyera demonstrates a Composio full-access key returns Gmail, GitHub, and CircleCI tokens, requiring separate revocation of each grant.
Languages and runtimes
- GCC 16 guarantees trampoline-free nested functions and GCC 17 merges builtins that extend it to captures GCC 16 guarantees nested functions do not need trampolines, allowing C code to drop the executable-stack requirement hardened systems reject.
- Dmitry Grinberg argues RISC-V optionality and compressed encodings fail both ends of the market Dmitry Grinberg argues RISC-V optionality serves neither embedded nor high-end markets, making it hard to ship portable binaries.
Infrastructure
- DuckDB v2.0 will read Parquet and CSV asynchronously, cutting an S3 benchmark from 8.2 to 2.8 seconds DuckDB v2.0 adds asynchronous reads for Parquet and CSV on S3, cutting a benchmark query from 8.2 to 2.8 seconds by fixing request concurrency.
- AWS Lambda adds public preview runtimes, starting with Node.js 26 and Python 3.15 AWS Lambda preview runtimes for Node.js 26 and Python 3.15 graduate to GA without configuration change, letting teams test early with no SLA.
- A Cloudflare customer argues product surface area has outgrown the platform's observability A Cloudflare customer argues the platform ships faster than observability tooling, with traces stopping at the boundary and 0 ms compute time.