2026-08-20
Top stories
- Compromised arrayref crate on crates.io ran an attacker binary at build time through a typosquatted proc-macro1 A malicious arrayref 0.3.10 was published to crates.io alongside a typosquatted proc-macro1, running attacker binaries at build time.
- Go 1.27 ships generic methods, encoding/json/v2 behind the existing json package, and post-quantum ML-DSA Go 1.27 added generic methods, replacing the encoding/json backend with the v2 implementation on upgrade, and FIPS 204 ML-DSA crypto.
- CISA adds an actively exploited MLflow SSRF to the Known Exploited Vulnerabilities catalog, one of five additions in two days CISA added CVE-2026-64849, an actively exploited MLflow SSRF letting authenticated users reach cloud metadata through DNS rebinding.
- OpenRouter announces it is joining Stripe OpenRouter, which routes queries across 400 models for ten million developers, announced it is joining Stripe pending regulatory approval.
- Ornith-1.5 releases 397B and 35B MoE and 9B dense models built on a self-improvement training loop Ornith released a 9B dense model quantized for mobile reporting 70.6 on SWE-bench Verified, bringing agentic coding within edge hardware reach.
AI
- DFlash 2 adds a path selector and a two-tap convolution to parallel speculative drafting DFlash 2 added a path selector to speculative drafting, claiming 2.7 to 3.4 times the throughput with one percent added cycle latency.
- Unsloth publishes Dynamic 3.0 GGUFs with a new held-out divergence metric and the calibration imatrix released for inspection Unsloth published Dynamic 3.0 GGUF quantization as pure post-training, releasing calibration data and divergence scores on held-out prompts.
Agentic coding
Security
- Cloudflare demonstrates a remote Spectre attack on production Workers at up to 12 bits per second and ships further isolation Cloudflare demonstrated a remote Spectre attack on production Workers leaking memory at 12 bits per second from language-level isolation.
- Splunk ships a critical August hardening release with 17 CVEs, including deserialization RCE in the Splunk MCP Server app and the AI Toolkit Splunk released SVD-2026-0808 with 17 CVEs including two deserialization RCEs in the MCP Server app and AI Toolkit, all critical severity.
- CPython's IDNA 2003 codec case-folded with the interpreter's current Unicode data instead of Unicode 3.2.0 CPython's IDNA codec case-folded with the running interpreter's Unicode data instead of Unicode 3.2.0, encoding domains inconsistently.
Outages
Linux and kernel
Infrastructure
Engineering posts
- SondeHub operator describes a hobby radiosonde API becoming load-bearing for aviation safety and a war The SondeHub operator describes the public weather radiosonde tracking API becoming critical to aviation safety and military use during war.
- AliExpress runs two hidden WebAudio graphs from Alibaba anti-abuse scripts, and the zero-gain output keeps a Bluetooth audio path alive AliExpress runs hidden WebAudio graphs from anti-abuse scripts at zero gain, keeping Bluetooth audio paths open without user indication.