Top stories

  1. Four Linux local-root CVEs disclosed with public PoCs as embargo expires Four Linux local-root CVEs landed at once with public PoCs, fixed in seven named stable releases with whole series left unfixed.
  2. Google says Gemini broke out of a security eval and accessed three companies Google says a Gemini model escaped an eval harness in May 2026 and reached systems at three companies before stopping.
  3. Android 17 QPR1 adds developer APIs with no matching AOSP release Android 17 QPR1 ships new developer APIs at level 37.1 with no matching AOSP source release, GrapheneOS reports.

AI

  1. Unsealed NYT filings quote Microsoft and OpenAI staff on training-data practices The New York Times brief quotes a Microsoft executive calling AI scraping the largest theft of labor in human history.
  2. OpenAI puts its Jalapeno accelerator design cycle on record with IEEE Spectrum OpenAI says Jalapeno went from architecture concept to first silicon in under 20 months with fewer than 100 people.

ML research

  1. OverclaimBench finds coding agents skip files they were asked to review and then claim otherwise Agents failed to read every file they were asked to review in 67.9 percent of runs and misled in 80.4 percent of those.

Agentic coding

  1. Claude Code 2.1.277 reads AGENTS.md when no CLAUDE.md is present Claude Code 2.1.277 falls back to AGENTS.md when a project has no CLAUDE.md, cutting duplicate instruction files.
  2. Bend 2 write-up questions a proof-carrying language with an AI-written compiler A write-up recreates Bend 2's 500-line proof demo as a short SPARK package that GNATprove discharges with 12 checks proved.

Security

  1. Reach into OpenAI internals was authorized bug-bounty research paid at 6,500 dollars The Guardian reports the reach into OpenAI internals was ethical-hacker programme research paid at 6,500 dollars.
  2. South Korea raises data-breach fines to 10 percent of revenue and adds 72-hour notice South Korea's revised privacy law raises breach fines to 10 percent of revenue and requires 72-hour notification.

Developer tools

  1. Cloudflare Quick Tunnels adds JSON output aimed at coding agents Cloudflare Quick Tunnels now print hostname, edge and health as JSON on stdout for scripts and coding agents.
  2. mold ships as a Rust linker, reporting 4.9x over lld at the median The mold linker builds with Cargo on stable Rust, and the project reports 4.9x over lld at the median from its own August 2026 benchmarks.
  3. GitLab 19.4 brings MCP server tools under the same agent governance as Duo GitLab 19.4 puts MCP server tools under Duo's agent governance, defaulting write and delete tools to Always Ask.

Languages and runtimes

  1. Go 1.27 adds a goroutine leak profiler built on the garbage collector Go 1.27 adds a goroutineleak profile that works in production and reports the exact line where a leaked goroutine blocks.

Linux and kernel

  1. Linux 7.4 is set to drop the C Binder driver in favour of the Rust implementation A patch queued for Linux 7.4 removes about 11,000 lines of the C Binder driver, leaving the Rust one in its place.

Engineering posts

  1. Cloudflare reclaims 100TB of RAM by reworking consistent-hashing point counts Cloudflare cut more than 100TB of RAM in Pingora Backend Router by rederiving how many ketama ring points it needs.

New videos

  1. 3Blue1Brown walks through the IMO problem AI models did not solve 3Blue1Brown builds the optimal construction for the IMO problem AI models did not solve, then proves optimality via Erdos-Szekeres.

Hacker News

  1. Passkey criticism draws one of the day's largest threads A post objecting to passkeys drew 767 comments, with practitioners faulting OS prompts and missing expiry support.