Top stories

  1. DuckLabs will join AWS in early September, and DuckDB stays MIT licensed under the nonprofit DuckDB Foundation The DuckDB company joins AWS in early September while the nonprofit Foundation keeps the MIT-licensed projects and the IP.
  2. Nitter and XCancel both stop after cease and desist letters, and XCancel names X Corp as the sender Nitter and XCancel are both stopped after cease and desist letters, and XCancel names X Corp as the sender of its letter.
  3. Researcher signs forged C2PA images on a fully patched Pixel, and Google closes the report as Won't fix (infeasible) A researcher signed forged C2PA images on a fully patched Pixel, and Google closed the report as Won't fix.
  4. OpenAI publishes the first Jalapeno benchmarks at Hot Chips 2026, and SemiAnalysis reports the 700W part beating Blackwell on throughput per megawatt OpenAI published the first Jalapeno benchmarks at Hot Chips 2026, and every performance number came from OpenAI.
  5. PromptArmor established an attacker command loop inside the Microsoft Copilot Cowork sandbox, and Microsoft confirmed a mitigation on 2026-08-19 PromptArmor held an attacker command loop inside the Microsoft Copilot Cowork sandbox, mitigated on 2026-08-19.

AI

  1. Qwen3.8-Flash-Next ships open weights at 125B total and 6B active, billed as an experimental preview of the Qwen4 architecture Qwen3.8-Flash-Next ships open weights at 125B total and 6B active under a community license, not a permissive one.
  2. Z.ai releases GLM-5.3-Flash under MIT at 320B total and 18B active, the first natively multimodal model in the GLM-5 series Z.ai publishes GLM-5.3-Flash under MIT at 320B total and 18B active, the first natively multimodal GLM-5 model.

Security

  1. CVE-2026-18963 lets an unauthenticated attacker complete a Keycloak password reset without the verification link CVE-2026-18963 lets an unauthenticated attacker finish a Keycloak password reset without the verification link.

Outages

  1. GitHub opens a critical Actions incident at 15:11 UTC, and a database primary failover does not fully mitigate GitHub Actions has been at major outage since 15:11 UTC, with recovery observed at 16:50 UTC and the incident still open.

Developer tools

  1. The mold author publishes a linker paper reporting 2.4x to 16.1x over lld, accepted to ASPLOS 2027 The mold author published a linker design paper reporting 2.4x to 16.1x over lld, accepted to ASPLOS 2027.
  2. Firefox 157 will ship JPEG XL on all platforms using a Rust decoder Mozilla required before it would ship the format Mozilla will ship JPEG XL in Firefox 157 on all platforms, using the Rust decoder it required before shipping the format.

Languages and runtimes

  1. Fenris Creations begins moving EVE Online's 2.4 million lines of Python 2.7 to Python 3 and deploys the first stage to Tranquility Fenris Creations began moving EVE Online's 2.4 million lines of Python 2.7 to Python 3 and shipped stage one.

Linux and kernel

  1. First public release of the multikernel Linux tree runs several kernels on one machine on bare metal without a hypervisor The multikernel Linux tree's first public release runs several kernels on one machine with no hypervisor.

Engineering posts

  1. A follow-up on executables as SQLite databases shows a webserver storing its own state in the file it runs from A follow-up on executables as SQLite databases demonstrates a webserver storing its state in the file it runs from.