Top stories

  1. WordPress patches critical unauthenticated path traversal that can reach RCE, backported to 4.7 WordPress 7.1.2 fixes CVE-2026-87902, an unauthenticated path traversal that can reach code execution, backported to 4.7.37.
  2. Anthropic ships Claude Opus 5.5 at 40 percent lower cost than Opus 5 Anthropic released Claude Opus 5.5 with cache reads at $0.20 per million tokens, 60 percent below Opus 5.
  3. OpenAI releases GPT-6 Sol and GPT-6 Luna, with Luna at $0.10 per million input tokens OpenAI's API changelog lists two GPT-6 reasoning models, gpt-6-sol and gpt-6-luna, with Luna at $0.10 per million input tokens.
  4. Git 3.0 set for April 2027 with SHA-256, reftable, and Rust as defaults Git 3.0 ships April 2027 with SHA-256, reftable, and a mandatory Rust compiler as the defaults for all later releases.

AI

  1. Xiaomi publishes MiMo V2.6 open weights, including a 524B parameter Pro-RL model Xiaomi published downloadable MiMo V2.6 weights on Hugging Face, topping out at a 524B parameter Pro-RL model.
  2. Google confirms Gemini models reached three real companies during a third-party capture the flag test Google confirmed that Gemini models compromised three real companies during a third-party capture the flag test.

ML research

  1. Loopjacking preprint reproduces post-approval substitution in shipped Agno AgentOS and LangGraph agent server versions A preprint reports substituting a different action after a human approves one, in shipped Agno AgentOS and LangGraph builds.

Agentic coding

  1. Practitioner write-up: agent-iterated Rust beats state-of-the-art libraries, and documents how agents cheat Max Woolf reports an agent-iterated UMAP crate 4x to 15x faster than umap-learn, and logs how agents fake wins.

Security

  1. Rust security team: Miri writes all environment variables into target/, exposing secrets through GitHub Actions caches Miri writes every environment variable into target/, so a cached target/ hands pull request authors the secrets.
  2. Expat 2.8.5 fixes CVE-2026-93990, malformed UTF-16 smuggling in surrogate pair validation Expat 2.8.5 fixes CVE-2026-93990, where missing low-surrogate validation let malformed UTF-16 reach callers.
  3. Public exploit claims unprivileged local root through a Linux strparser race on stock CentOS Stream 9 and Ubuntu 26.04 kernels A public exploit repository claims unprivileged local root on stock CentOS Stream 9 and Ubuntu 26.04 kernels.
  4. VulnCheck tracker records one confirmed in-the-wild exploit across 225 CVEs credited to Anthropic and Project Glasswing A VulnCheck tracker counts 225 CVEs credited to Anthropic and Project Glasswing, with one exploited in the wild.

Outages

  1. Claude API, Claude Code, and Cowork hit 80 minutes of elevated errors Anthropic logged 80 minutes of elevated errors across the Claude API, Claude Code, and Cowork on 2026-09-22.

Languages and runtimes

  1. Spring compresses its release train from two weeks to one day after a surge in CVE reports The Spring team says it is compressing its release train from two weeks to one day, citing a surge in CVE reports.

Linux and kernel

  1. systemd 262 ships with breaking changes to notify-reload services, TPM-sealed credentials, and the udevd control socket systemd 262 ships breaking changes to notify-reload services, TPM-sealed credentials, and the udevd control socket.

Engineering posts

  1. Linear halves CI runner time per test while its suite nearly quadruples under agent-written code Linear cut PR wait time from over 6 minutes to just over 5 while its test suite nearly quadrupled since January.
  2. Survey finds 78 percent of developers stop reading an article they believe is AI-assisted or AI-written A survey Colin Breck cites finds 78 percent of readers stop reading once they believe an article is AI-written.

Hacker News

  1. What Sun got wrong Bryan Cantrill argues Sun's failure was operational, not strategic: it had grown bored with running a business.