unreal-agent brings async-first harness design to coding agents
A harness that never makes the model wait unreal-agent has been climbing GitHub’s trending list all week, at roughly 1.9k stars four days after it appeared, and the pitch behind it is simple enough to repeat in one line: the same model, doing the same work, up to 40 percent cheaper, because the harness never […]
Jury finds Facebook liable for deceiving users in the Cambridge Analytica case
A jury finally said it out loud Eight years after the Cambridge Analytica story broke, a New Mexico state court jury has found Facebook liable for deceiving users about privacy protections on the platform. The verdict came down on September 25 in Santa Fe, after a two-week trial in the First Judicial District Court. This […]
CISA flags four actively exploited flaws in WSO2, Adobe Commerce, SharePoint and MikroTik
Four more flaws join the exploit catalog The U.S. Cybersecurity and Infrastructure Security Agency added four vulnerabilities to its Known Exploited Vulnerabilities catalog this week, and all four carry evidence of attacks in the wild rather than a mere proof of concept. Two entries landed on September 24: a critical JWT authentication bypass in WSO2 […]
Researchers forge 1024-bit RSA signatures without factoring the key
A team from UC San Diego and Inria has done something cryptographers long assumed was impossible or at least pointless: forged 1024-bit RSA signatures without ever factoring the modulus. The paper, posted September 20 by Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger, and Emmanuel Thomé, ran a 2007 algorithm at real scale and found […]
SourceHut build logs hid a wormable XSS that could take over accounts
A vulnerability researcher known as Arusekk published a writeup on September 23 describing CVE-2026-92973, a cross-site scripting flaw in the ansi2html library that let anyone who could inject text into a SourceHut build log take over the accounts of people who viewed it. The bug had been sitting in the wild for close to four […]
Azure opens public preview of Mdsv4 and Msv4 VMs for SAP and memory-heavy workloads
Microsoft has opened a public preview of two new memory-optimized Mdsv4 and Msv4 virtual machine series, built for SAP workloads and other jobs that need a lot of RAM per vCPU. The new series run on 6th generation Intel Xeon Scalable processors, ship with the latest Azure Boost networking and storage offload, and add a […]
virtio-nvgpu shares one Nvidia GPU across KVM guests at near-native speed
GPU sharing between virtual machines has always involved a trade you did not want to make. Passthrough gives one VM the whole card, vGPU licensing costs money and locks you to Nvidia’s stack, and API translation layers like Venus give up meaningful performance by translating every graphics call. A small project called virtio-nvgpu takes a […]
.NET 8, .NET 9, and PowerShell 7.4 hit end of support on the same day
Clear your November calendar. .NET 8 and .NET 9 both reach end of support on November 10, and PowerShell 7.4 dies the same day. After that date there are no more security fixes, no servicing updates, and no support tickets honored for any of the three. Microsoft published the Azure Functions side of the notice […]
Azure Container Apps Sandboxes reach general availability
Running code you do not trust is one of those problems that sounds solved until you actually have to do it. If you build agentic applications, multi-tenant platforms, or CI/CD systems, the options have traditionally been roll your own microVM fleet, bolt together gVisor or Firecracker yourself, or accept the blast radius. This week Microsoft […]
Z.ai open-sources its whole coding agent stack with ZCode
The harness, not just the model Z.ai, the company behind the GLM model family, open-sourced ZCode this week, and the interesting part is the scope. This is not a CLI script and a README. The repository contains the desktop client, the browser workspace, the backend services, the shared UI, and the agent runtime that powers […]
Why Trail of Bits calls SAML a fractal of bad design
A retrospective on the protocol nobody can replace Security firm Trail of Bits published a historical analysis of SAML this week, and the title is not subtle: they call it a fractal of bad design, straightforward on the surface but built on what they describe as a foundation of sand, bone dust, and ash. The […]
Claude Opus 5.5 cuts prices and rethinks how the model writes
The price is the story Claude Opus 5.5 is out, and the most interesting number on the announcement page is not a benchmark score. Input tokens now cost $4 per million, down from $5 on Opus 5. Output fell from $25 to $20 per million. Cache reads dropped hardest, from $0.50 to $0.20 per million. […]