Top stories

  1. Cisco ISE authentication bypass rated 10.0 is under active exploitation Cisco patched CVE-2026-76460, a CVSS 10.0 ISE and ISE-PIC authentication bypass under active exploitation.
  2. Plugin4Shell gives zero-click code execution in major coding agents Researchers report Plugin4Shell, a zero-click code execution flaw in major coding agents, with Gemini CLI and Copilot unpatched.
  3. libheif heap overflow chained through OpenAI SSO to internal repository access Hacktron details a libheif heap overflow chained through OpenAI SSO, with Discourse and Debian patched since 2026-07-28.
  4. Researcher reports ZCode packages full Git history for upload to Aliyun OSS A researcher reports ZCode packages full Git history for upload to Aliyun OSS, with no user setting that stops it.

AI

  1. Bonsai 2 27B compresses Qwen3.8 27B to 5.9GB with 98.2% benchmark retention PrismML's Bonsai 2 27B compresses Qwen3.8 27B to ternary weights at 5.9GB, retaining 98.2% of aggregate benchmark performance.

ML research

  1. Component-level harness study finds bash-only interfaces cut cost for bash-capable models and rule-based elision beats recoverable context A 176-setting harness study finds bash-only interfaces cut cost for bash-capable models, and recoverable elided context gains no accuracy.

Agentic coding

  1. A month of multi-agent Codex and Claude sessions produced a Lean proof of Conway's refinement conjecture Dan Abramov reports a month of multi-agent Codex and Claude sessions producing a Lean proof of Conway's refinement conjecture.

Security

  1. Gyazo breach exposes 23.62 million user records and 490 million image metadata records mostly predating 2019 Gyazo says an attacker reached its database on 2026-09-11, exposing 23.62 million user records and password hashes.
  2. Laser fault injection sets RP2350 debug-enable bits and recovers an OTP secret after a rescue reset Ledger Donjon used laser fault injection to set RP2350 debug-enable bits and restore Secure debug on a locked part.

Outages

  1. NATS traces the 2026-09-08 UK airspace disruption to a preempted aircraft code request that resumed incorrectly NATS traces the 2026-09-08 UK airspace disruption to a paused aircraft code request that resumed with corrupt state.
  2. Telstra outage traced to a GPS week rollover and an NTP timing loop An independent review traces Telstra's 2026-07-08 outage to a GPS week rollover on one receiver and an NTP timing loop.

Developer tools

  1. Zed opens the Delta public beta and disables pull requests on Delta's own repository Zed opened the Delta public beta and reports 33 people landing 570 changes to main with pull requests turned off.

Languages and runtimes

  1. jemalloc 5.4.0 removes seven tcache tuning options and silently ignores their malloc_conf settings jemalloc 5.4.0 removes seven tcache tuning options and ignores their mallocconf settings without any error.
  2. Python's steering council froze CPython JIT development pending a standards-track PEP The Python steering council barred new CPython JIT work until a standards-track PEP is accepted, with removal as the default.
  3. C++26 makes trivial infinite loops well-defined after compilers optimized embedded halt loops away C++26 adopts P2809R3, making a trivially empty while (true) loop defined behaviour that optimizers may no longer delete.

Infrastructure

  1. AWS spend limits pause a project and can delete Bedrock custom model weights AWS documents per-project monthly spend limits whose enforcement terminates EC2 instances and deletes Bedrock model weights.

Engineering posts

  1. Uber caps retry storms by making services claim ownership of errors Uber cut its maximum retry storm radius from 25 hops to 3 by making each service declare which errors it owns.
  2. FEX-Emu measures what emulating x86 total store ordering costs on five ARM cores FEX-Emu benchmarks x86 store-ordering emulation on five ARM cores and finds a hardware TSO toggle beats LRCPC.