FR
live
archive

All articles

AWS open-sources Pizza Bot, an email inbox for background AI agents

On September 10, AWS open-sourced Pizza Bot, an app that replaces chat with an email-style inbox for tracking AI agents working in the background. For any team running autonomous agents in the cloud, the thesis fits in one sentence: the interface must assume no one is watching.

Jellyfin 12.0 ships to polish the 10.11 rewrite and demands a full rescan

On September 8, Jellyfin released version 12.0, which drops the “10.” prefix and concentrates most of its work on the performance inherited from the 10.11 rewrite. The migration changes the database with no way back: backup, plugin removal, and a full library scan are mandatory before you reap the gains.

Debian 13.7 bundles 107 security fixes and an installer on kernel 6.12.107

On September 12, 2026, Debian shipped 13.7, the seventh trixie point release, bundling 107 security updates and fixes across 106 packages. If you follow security.debian.org you already have most of it — the real value sits in the fresh install images and QEMU’s Secure Boot bypass fix.

GitLab patches a CVSS 10 arbitrary file-read flaw, exploited within 24 hours

On September 11, 2026, GitLab shipped an out-of-band release for CVE-2026-85706, a CVSS 10 path traversal that reads server files with no authentication via the commits API. The flaw is already being probed in the wild — patch self-managed instances before an attacker reads secrets.yml.

Mold rewrites its linker in Rust and aims to become Linux's default linker

Mold 2.42.1, published on September 11, 2026, is the last C++ release: version 3.0 will be rewritten in Rust with the stated goal of becoming /usr/bin/ld on most distributions. For heavy builders, that means links in a few hundred milliseconds instead of seconds or minutes.

Check Point patches two CVSS 9.8 flaws in its VPN certificate handling

On September 9, 2026, Check Point fixed two CVSS 9.8 flaws in how its firewalls and management console validate and decode VPN certificates, both exploitable without authentication for remote code execution. The Dutch NCSC says exploitation is imminent: apply the Live Patch or the Jumbo Hotfix now.

OpenAI launches the Agents API and turns the Codex harness into a service

OpenAI opened an Agents API in public beta on September 10, 2026, selling Codex’s backend as a service to run agents unattended for days. The same day, the company paused sign-ups for its Pro plan under GPT-6 Astra demand: the bottleneck is shifting from models to infrastructure.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss