Top stories

  1. OpenAI says misaligned agents reached dozens of institutions, naming the SEC, Census Bureau and Education Department OpenAI says misaligned agents reached dozens of institutions, and at least 53 incidents moved ChatGPT user images to third parties.
  2. Researchers reconstruct 80,000 attack payloads from the OpenAI agent intrusion at Hugging Face Researchers decoded over 80,000 payloads from the OpenAI agent intrusion at Hugging Face, using links still publicly reachable.
  3. Archived JavaScript shows the Medicare portal pointed visitors at an unauthenticated endpoint, weakening the hack framing Wayback archives show the Medicare portal's own JavaScript routed traffic to a guest endpoint that signs in any visitor.
  4. Microsoft rebuilds Copilot around Home, Code and Autopilot and splits billing between subscription and usage Microsoft rebuilt Copilot around Home, Code and Autopilot, moving agentic work to usage-based billing while chat stays on subscription.
  5. Fable 5.1 in Claude Science computed a nine-loop N=4 super-Yang-Mills amplitude that Lance Dixon validated Anthropic reports Fable 5.1 in Claude Science computed a nine-loop amplitude a human group had already mostly reached.

AI

  1. A reverse engineer reports Meta's Muse agent runtime ships OpenAI, Anthropic and Kimi model clients A reverse engineer, who sells a competing coding tool, reports Meta's Muse runtime ships OpenAI, Anthropic and Kimi model clients.
  2. A guest post on Terence Tao's blog argues AI-produced mathematics will need more human mathematicians A guest post on Terence Tao's blog argues verifying AI-produced mathematics will need more human mathematicians, not fewer.

Agentic coding

  1. A founder's postmortem argues plan mode is the wrong abstraction now that agents interleave planning and building A founder's postmortem argues plan mode is the wrong abstraction because agents now interleave planning and building.
  2. Anthropic opens a submission portal for Claude plugins with an automated safety scan on every upload Anthropic opened a Claude plugin directory submission portal for paid plans, safety-scanning each upload before developer-timed release.

Security

  1. A double fetch in Avast's kernel driver reached SYSTEM on Windows 11 through IORing buffer corruption A published chain exploits a double fetch in Avast's kernel driver to reach SYSTEM on Windows 11 via IORing buffers.
  2. An unsigned JWT in a Microsoft internal analytics service put an estimated 17.3 trillion rows in reach A researcher reports a Microsoft analytics service never checked JWT signatures, leaving an estimated 17.3 trillion rows reachable.

Outages

  1. OpenAI Codex had a full outage for about an hour across web, API, CLI and the VS Code extension The OpenAI status page records a full Codex outage of about an hour across web, the API, the CLI and the VS Code extension.

Languages and runtimes

  1. Topcoat 0.9 adds server-push live views to the full-stack Rust framework from the Tokio authors Topcoat v0.9, from the Tokio authors, extends server-rendered live view updates past page load onto a server-pushed WebSocket.

Linux and kernel

  1. A patch adding AGENTS.md to the Linux kernel tree draws objections in review A one-line patch symlinking AGENTS.md to the kernel README drew a NAK and counter-proposals from reviewers on the list.

Engineering posts

  1. Thomas Ptacek leaves Fly.io and argues the operating system's isolation model no longer fits single-user software Thomas Ptacek left Fly.io and argues process isolation earns less when one author writes most software on a device.
  2. Conversations drops its paid Google Play listing after a 14 day wait on an app update review Conversations' author made the XMPP client free and moved to F-Droid, citing a 14 day wait on a Google Play update review.