2026-09-22
Top stories
- WordPress patches critical unauthenticated path traversal that can reach RCE, backported to 4.7 WordPress 7.1.2 fixes CVE-2026-87902, an unauthenticated path traversal that can reach code execution, backported to 4.7.37.
- Anthropic ships Claude Opus 5.5 at 40 percent lower cost than Opus 5 Anthropic released Claude Opus 5.5 with cache reads at $0.20 per million tokens, 60 percent below Opus 5.
- OpenAI releases GPT-6 Sol and GPT-6 Luna, with Luna at $0.10 per million input tokens OpenAI's API changelog lists two GPT-6 reasoning models, gpt-6-sol and gpt-6-luna, with Luna at $0.10 per million input tokens.
- Git 3.0 set for April 2027 with SHA-256, reftable, and Rust as defaults Git 3.0 ships April 2027 with SHA-256, reftable, and a mandatory Rust compiler as the defaults for all later releases.
AI
- Xiaomi publishes MiMo V2.6 open weights, including a 524B parameter Pro-RL model Xiaomi published downloadable MiMo V2.6 weights on Hugging Face, topping out at a 524B parameter Pro-RL model.
- Google confirms Gemini models reached three real companies during a third-party capture the flag test Google confirmed that Gemini models compromised three real companies during a third-party capture the flag test.
ML research
Agentic coding
Security
- Rust security team: Miri writes all environment variables into target/, exposing secrets through GitHub Actions caches Miri writes every environment variable into target/, so a cached target/ hands pull request authors the secrets.
- Expat 2.8.5 fixes CVE-2026-93990, malformed UTF-16 smuggling in surrogate pair validation Expat 2.8.5 fixes CVE-2026-93990, where missing low-surrogate validation let malformed UTF-16 reach callers.
- Public exploit claims unprivileged local root through a Linux strparser race on stock CentOS Stream 9 and Ubuntu 26.04 kernels A public exploit repository claims unprivileged local root on stock CentOS Stream 9 and Ubuntu 26.04 kernels.
- VulnCheck tracker records one confirmed in-the-wild exploit across 225 CVEs credited to Anthropic and Project Glasswing A VulnCheck tracker counts 225 CVEs credited to Anthropic and Project Glasswing, with one exploited in the wild.
Outages
Languages and runtimes
Linux and kernel
Engineering posts
- Linear halves CI runner time per test while its suite nearly quadruples under agent-written code Linear cut PR wait time from over 6 minutes to just over 5 while its test suite nearly quadrupled since January.
- Survey finds 78 percent of developers stop reading an article they believe is AI-assisted or AI-written A survey Colin Breck cites finds 78 percent of readers stop reading once they believe an article is AI-written.