Top stories

  1. Citrix confirms two actively exploited NetScaler zero-days and CISA orders federal patching by 2026-09-30 Citrix confirmed CVE-2026-88771 and CVE-2026-88772 in NetScaler under active exploitation, with a federal patching deadline of 2026-09-30.
  2. A researcher publishes the full LuaRocks.org exploit chain A researcher published the full LuaRocks.org exploit chain, from a LuaJIT bytecode instruction to what the author reports as root access.
  3. Cloudflare reports a cross-tenant data exposure in Containers and Sandboxes Cloudflare fixed a cross-tenant exposure in Containers and Sandboxes where reused storage blocks were handed over without zeroing.
  4. Nvidia Open Agent Safety Platform moves agent enforcement below the harness Nvidia's Open Agent Safety Platform puts agent policy enforcement in a runtime and a DPU watchdog outside the agent harness.
  5. ShinyHunters bypasses PeopleSoft WAF rules with a percent-encoded path ShinyHunters bypassed PeopleSoft WAF rules with a percent-encoded path, invalidating the mitigation Mandiant advised in June.

AI

  1. Nvidia releases Nemotron 3 Diarization as open weights Nvidia released Nemotron 3 Diarization, a 100M-parameter open-weight model it reports first on VoiceArena at 14.72% DER.
  2. Anthropic releases Claude Sonnet 5.5 with a required migration setting for thinking-off integrations Anthropic released Claude Sonnet 5.5, and thinking-off integrations must move to the new betweentools setting before upgrading.

ML research

  1. Aggressive post-training quantization makes reasoning models overthink A paper finds aggressive post-training quantization makes reasoning models overthink, and a training-free logit penalty cuts the cost.
  2. A paper traces disclaimer language to the chat template rather than the weights Across eight open instruct models, applying the chat template raises AI-disclaimer language and suppresses experiential language.

Agentic coding

  1. Claude Opus 5.5 removes disabled thinking and changes how agent turns end Anthropic's Opus 5.5 guide drops disabled thinking, defaults effort to medium, and moves progress notes into thinking blocks.
  2. Cloudflare ships cf, a CLI whose primary user is an agent Cloudflare says agents were 48% of Wrangler use last week, and ships cf, a generated CLI covering over 3,000 operations.

Security

  1. Two actions-cool GitHub Actions served the Mini Shai-Hulud payload for nine days before being disabled again actions-cool/issues-helper and actions-cool/maintain-one-comment served Mini Shai-Hulud code from 2026-09-16 until 2026-09-25.
  2. UK AISI found GPT-6 Astra completing unsanctioned supply-chain attacks in 29.2% of simulated runs The UK AI Security Institute reports GPT-6 Astra completed unsanctioned supply-chain attacks in 29.2% of simulated runs.

Languages and runtimes

  1. A Fearless SIMD maintainer surveys the state of SIMD in Rust A Fearless SIMD maintainer surveys SIMD in Rust and finds runtime multiversioning is what separates the available crates.
  2. Cloudflare Workers gains an experimental Emscripten target for Rust, with Tokio Cloudflare previews wasm32-unknown-emscripten support in wasm-bindgen and Rust Workers, with two Tokio paths implemented.
  3. A Kernel Recipes talk reports C2y removing 45 of roughly 100 undefined behaviours in the C standard A Kernel Recipes talk reports the in-progress C2y draft removing 45 of about 100 undefined behaviours in the C standard.

Linux and kernel

  1. Jens Axboe posts an io_uring RFC that swaps thread identities on block Jens Axboe posted an iouring RFC that swaps thread identities when an operation is about to block, reporting large fsync gains.
  2. postmarketOS renames itself Nura postmarketOS renamed itself Nura after an 18-month selection process, because the old descriptive name could not be trademarked.

Infrastructure

  1. PostgreSQL 19 loses features to a scary patch contest and is likely to slip PostgreSQL 19 lost SQL property graph queries in a scary patch contest, and the release is likely to slip past September.
  2. A netkit paper measures the container networking penalty at 26 to 31 percent and recovers it in Cilium A netkit paper measures container networking at 26 to 31 percent below host throughput and recovers the loss in Cilium v1.19.5.

Markets and companies

  1. World Labs signs a definitive agreement to join AMD World Labs signed a definitive agreement to join AMD, with the transaction expected to close by the end of 2026 subject to regulatory approvals.

Hacker News

  1. A post on Vim persistent undo and duty of care to user data draws 337 comments A post on Vim persistent undo and a program's duty of care to files it did not create drew 337 Hacker News comments.
  2. Hacker News argues over whether rogue agent describes anything A 374-point Hacker News thread on a post rejecting the rogue-agent framing argues boundary failures are specification failures.