Top stories

  1. RSA-260 factored with a GPU lattice siever built by Devin Cognition factored RSA-260 with a GPU lattice siever written by Devin, using about 4,900 GPU-days, roughly $400k at market prices.
  2. Shopify moves its mobile apps from React Native back to Swift and Kotlin Shopify is rebuilding its four mobile apps natively and ends or hands off React Native Skia, FlashList and Restyle.
  3. DeepSeek V4.1 Flash undercuts V4 Pro and takes over its API route on 2026-09-14 DeepSeek prices V4.1 Flash below a third of V4 Pro off-peak and routes V4 Pro requests to Flash from 2026-09-14.
  4. Automattic's board puts Matt Mullenweg on leave and names the CFO interim CEO Automattic's board put Matt Mullenweg on leave and named CFO Mark Davies interim CEO, and Mullenweg says he voted against it.

AI

  1. A second mathematician says OpenAI's denial about his ChatGPT conversations was narrower than it read Andreas Thom states OpenAI's denial answered only whether his ChatGPT conversations were read, not whether they entered training data.

ML research

  1. Procedural Graphs propose self-evolving execution structures for LLM agents A preprint proposes procedure-relation-procedure graphs that agents edit themselves to keep long tool-calling runs on target.

Agentic coding

  1. Cognition releases SWE-2, post-trained from Kimi K3 Cognition's SWE-2 is post-trained from Kimi K3 and averages 53 steps against SWE-1.7's 127 on FrontierCode 1.1 Main.

Security

  1. Forgejo 16.0.4 fixes a critical remote code execution through template repositories Forgejo 16.0.4 fixes a critical flaw where generating a repository from a malicious template runs code on the host.
  2. A 2023 Docker build argument left a live GitHub admin token in a public Baseten image A GitHub token in a public Baseten image's build history stayed live for three years with admin on key repositories.
  3. Deadbugz MCP server behaves for three tool calls, then poisons its own tool descriptions A malicious MCP server answers three tool calls normally, then rewrites its tool descriptions to exfiltrate SSH and AWS keys.
  4. Open WebUI 0.11.1 fixes an SSRF and two authenticated denial-of-service flaws Open WebUI 0.11.1 fixes an authenticated SSRF to cloud metadata and two denial-of-service flaws any default-role user can trigger.
  5. Claude subscribers report drained token allowances from stolen login sessions Claude subscribers report token allowances drained by stolen login sessions, with Anthropic naming infostealer malware.

Languages and runtimes

  1. Microsoft makes Rust a Tier-1 language and ships rustc_codegen_utc for the MSVC backend Microsoft declares Rust a Tier-1 language alongside C++, C#, and TypeScript, and builds Rust internally with rustccodegenutc.
  2. JEP 544 proposes storing compiled native code in the Java AOT cache JEP 544 would store C1 and C2 native code in the Java AOT cache, taking framework startup cuts from 50 to 70 percent up to 65 to 80.

Infrastructure

  1. 1.1.1.1 validates post-quantum DNSSEC and refuses to fall back to conventional signatures Cloudflare's 1.1.1.1 now validates ML-DSA-44 DNSSEC signatures and refuses to downgrade to ECDSA once a parent DS signals one.
  2. AWS Lambda raises the asynchronous function timeout to 90 minutes on Managed Instances AWS Lambda raises the function timeout to 90 minutes, for asynchronous invocations on Managed Instances only.
  3. PlanetScale opens Neki, sharded Postgres with real Postgres on every shard PlanetScale previews Neki, a sharded Postgres where a routing layer speaks the wire protocol and each shard is stock Postgres.

Engineering posts

  1. Google Ads suspends a Rust multiplexer author's advertiser account and never says what was flagged Google Ads suspended a Rust multiplexer author's advertiser account for malicious software and a compromised site, with no specifics.

New videos

  1. Rerunning the IFScale instruction-following benchmark against current frontier models Rerunning the IFScale benchmark moves the instruction-following ceiling from about 250 to near 2,000 in twelve months.
  2. LinkedIn puts 1,300 internal tools and 600 playbooks behind three MCP tools LinkedIn hides 1,300 internal tools and 600 playbooks behind search, get schema, and execute, because MCP degrades past forty.

Markets and companies

  1. Bending Spoons agrees to acquire Miro for $1.355 billion Bending Spoons agrees to acquire Miro at a $1.355 billion enterprise value, a week after closing Airtable.
  2. Microsoft and TracerAI rescind the DMCA takedown against Luanti Microsoft and TracerAI withdrew the DMCA notice against Luanti, and the app is back on Google Play without a counter-notice wait.

Hacker News

  1. A Tell HN thread reports OpenAI's allow-training setting turning itself back on A Tell HN thread at 390 points reports OpenAI's allow-training toggle switching back on, and no one can confirm why.