Top stories

  1. OpenAI patched two Codex sandbox escapes, one reaching the developer host from the strictest mode OpenAI fixed Heapjack and Overpatch in Codex Desktop 26.818.21641 and Codex CLI 0.149.0 after both escaped the sandbox.
  2. Malicious npm package indexed-btree hides its loader in runtime code The npm package indexed-btree hides its loader inside BTree.prototype.set(), which fires only when an application passes a specific key.
  3. Brevo supply-chain attack rewrote scripts at the Cloudflare edge from a hardcoded API key Attackers used a hardcoded Cloudflare API key to add a Worker that rewrote Brevo's customer-facing scripts at the edge.
  4. xAI released Grok 4.7 starting at 2 dollars per million input tokens, below the models it benchmarks against xAI released Grok 4.7 starting at 2 dollars per million input tokens, one fifth the input list price of Fable 5.1 Max.
  5. Google published AX, a Kubernetes-shaped orchestrator for agent workloads Google published AX, which models agent workloads as Kubernetes-shaped Task, Workspace, Gateway, and Model resources.

AI

  1. Heretic automates abliteration and reports lower capability loss than hand-tuned versions Heretic removes refusal behaviour from open-weight models in one command, reporting 3 of 100 refusals on gemma-3-12b-it.

Agentic coding

  1. Claude Code ships native AGENTS.md support as a built-in plugin Claude Code now loads AGENTS.md natively through a built-in plugin with four selectable loading modes.
  2. A widely discussed argument that MCP should be retired in favour of CLIs and HTTP APIs A practitioner post argues MCP is obsolete because models now read CLI help text and call documented HTTP APIs.

Security

  1. Encrypted npm payload unlocks only from one specific derived value SafeDep found npm packages whose payload decrypts only from one derived value, the JSON form of an LU lower factor.
  2. Fake GitHub repositories push the Rapuncel infostealer with a signed kernel driver that kills 145 security products SEO-optimized fake GitHub repos deliver the Rapuncel infostealer with a signed driver that kills 145 security tools.

Developer tools

  1. Sublime Text 4213 moves the plugin host to Python 3.14 and disables the 3.3 host by default Sublime Text 4213 upgrades the plugin host from Python 3.8 to 3.14 and disables the older 3.3 host by default.

Languages and runtimes

  1. Cloudflare marks Python Workers generally available and lands PEP 783 for Python on WebAssembly Cloudflare made Python Workers generally available and landed PEP 783, which standardizes the PyEmscripten platform.

Apple platforms

  1. Apple documents daily usage limits on macOS 27 server-side Apple Intelligence, with paid expansion stated as future Apple's macOS 27 guide states server-side Apple Intelligence has daily usage limits, with paid expansion in future.

Linux and kernel

  1. Experimental Orphaned VMs patches would keep guests running while the host kernel reboots An experimental Linux patch series from a Google engineer keeps guest VMs running while the host kernel reboots.

Infrastructure

  1. Portainer 3.0 directs new capability work to Kubernetes and freezes the Docker feature set Portainer 3.0 sends new capability work to Kubernetes only and holds the Docker feature set at today's scope.
  2. Dragonfly 2.0 released with lower connection and serialization overhead Dragonfly 2.0 cuts connection and serialization overhead, adds Valkey 9 RDB loading, and stays on BSL 1.1.