2026-08-30
Top stories
- California AB 1856 carves open-source distributors out of the Digital Age Assurance Act by license terms rather than by named license California AB 1856 exempts open-source distributors from the age-verification law by license terms, naming no license.
- kernel.org reports 20 percent of its serving capacity rendering git commits for AI scrapers kernel.org reports 20 percent of its serving capacity rendering git commits for AI scrapers, with 2 percent of traffic legitimate.
- Tencent open-sources Hy4 preview at 770B parameters with 49B active Tencent open-sourced Hy4 preview, a 770B-parameter model with 49B active and a context window over 1M tokens.
- vLLM v0.28.0 raises the default batched token budget and moves bitsandbytes out of tree vLLM v0.28.0 ships 584 commits, raises the default batched token budget to 16384, and drops in-tree bitsandbytes.
- Sony Music Publishing and Warner Chappell sue Anthropic over training data Sony Music Publishing and Warner Chappell sued Anthropic over training data, naming Dario Amodei and Benjamin Mann as defendants.
Security
- RestrictedPython guard hooks can be shadowed through positional-only arguments RestrictedPython before 8.3 lets positional-only arguments shadow its guard hooks, bypassing the sandbox policy.
- MariaDB Connector/Node.js allows SQL injection in Buffer parameters on five character sets MariaDB Connector/Node.js allows SQL injection through Buffer parameters on big5, gbk, sjis, cp932 and gb18030.
- MariaDB Connector/R2DBC 1.4.1 fixes cleartext password disclosure and charset confusion MariaDB Connector/R2DBC 1.4.1 fixes cleartext password disclosure to a hostile server and charset confusion.
- Qubes OS bulletin QSB-118 reports dom0 arbitrary code execution through the qvm-copy-to-vm error path Qubes bulletin QSB-118 reports dom0 arbitrary code execution through an unsanitised filename in the copy-to-vm error path.
- Qubes OS bulletin QSB-117 covers five Intel microcode advisories it cannot assess Qubes bulletin QSB-117 states it cannot assess five Intel microcode advisories, and Intel withdrew the Meteor Lake update.
- Omarchy put its default user in the docker group, giving every session process passwordless root until 4.0.1 Omarchy put its default user in the docker group before 4.0.1, giving every session process passwordless root on the host.