2026-08-23
Top stories
- Encrypted reasoning traces are interchangeable across sessions, users, and models at Anthropic, OpenAI, and Google Encrypted reasoning blocks from Anthropic, OpenAI and Google are not bound to requests, replaying across sessions within ecosystems.
- Zimbra command injection added to the CISA exploited catalog with a 2026-08-24 due date CVE-2026-73570 command injection in Zimbra is exploited in the wild with a remediation due date of 2026-08-24.
- Rust 1.98 miscompiles a boxed async trait object into a null vtable slot Rust 1.98.0 emits zero-filled vtable entries for boxed async trait objects, causing safe code to dispatch through null.
- Kernel fix stops the Intel Xe driver from handing compression storage out as usable VRAM Intel Xe published compression-reserved memory to the VRAM allocator, silently corrupting whoever landed there.
- Changing only the vLLM attention backend flips tokens and breaks tool calls on identical weights Changing only the vLLM attention backend produces token flips breaking tool calls, proving inference configuration affects correctness.
Agentic coding
Security
- Microsoft publishes a CVSS 10.0 Entra ID deserialization flaw as already mitigated Microsoft's CVSS 10.0 Entra ID deserialization flaw was fixed service-side with no customer action needed.
- TrueConf Server flaws added to the CISA exploited catalog, one with a 2026-08-23 due date TrueConf Server flaws allow unauthenticated code execution and environment breakout, exploited in the wild.
- More than 9,300 exposed AWS keys still authenticate, 768 of them with full control of a company account Truffle Security found 9,300 exposed AWS keys still authenticating with 768 holding full account control.
- Unpatched NTFS3 flaw turns a crafted NTFS image into local root on Linux Unpatched NTFS3 reads setuid bits from disk, making a crafted USB stick give local users euid 0 on mount.
- Malware reached Android car head units through the DoFun firmware updater DoFun firmware updater delivers malware through vendor-controlled MQTT, opening a proxy botnet polling every 90 minutes.
Languages and runtimes
Apple platforms
Linux and kernel
- Linux 7.3 replaces Steve French as CIFS maintainer Paulo Alcantara and Namjae Jeon take over CIFS and SMB3 maintenance from Steve French starting in Linux 7.3.
- An LSFMM+BPF session proposes proving scheduler and XDP invariants with Verus LSFMM+BPF proposes using Verus to prove scheduler and XDP invariants, since the verifier only guarantees no crash.