we_are_coded.by CODE · The world, decoded
БГ
we are coded

News, p. 28

News

427 stories · page 28 of 48
Security
NVD4 August 2026Vulnerability

A 9.8 hole in Langflow is under active exploitation: two open endpoints hand out full-access code execution

CVE-2026-9198 in Langflow - the visual builder for AI applications - lets anyone on the network issue themselves a SUPERUSER token and run arbitrary code, no password needed. On 4 August CISA added it to the catalog of actively exploited vulnerabilities. The patch is version 1.10.1.

Read →
Builders
GitHub Engineering4 August 2026Tools

GitHub slices the giant AI pull request into layers: gh-stack turns 1700 lines into a reviewable ladder

Agents write code faster than a person can review it - and it all lands in one giant pull request. GitHub released gh-stack: a command-line extension that splits the work into ordered, independently reviewable layers. A change in the middle propagates up the stack on its own.

Read →
Frontier
Mistral AI4 August 2026Models

Shieldstral: Mistral releases an open guard model that reads your rules at the moment of the check

Mistral released Shieldstral - a European, multimodal safety classifier with 3 billion parameters and open weights under Apache 2.0. The moderation policy goes in as plain text at the call itself, with no retraining. According to Mistral, the model holds its own against systems up to 7 times larger, and does it on a single card with 16GB of memory.

Read →
Frontier
Liquid AI (Hugging Face blog)4 August 2026Local models

LFM2.5: 2.6 billion parameters trained for agent work right on the device

Liquid AI released LFM2.5-2.6B - a model built from the ground up for agents on phones and laptops: it follows instructions, handles tools, delivers 220 tokens per second on an Apple M5 Max CPU, and the weights are free on Hugging Face. According to the company, it leads its class on most agentic benchmarks.

Read →
Audio
Spotify Newsroom4 August 2026Music

Fan covers on Spotify go under license: with credit and money for the original artist

Spotify and Merlin - the voice of independent labels with about 15% of the global market - reached a deal for the upcoming fan cover and remix tool. Participation is the artist's choice; every derivative track carries credit, compensation, and a link back to the original. Small detail, big difference.

Read →
Frontier
Alizila3 August 2026Models

Alibaba showed its biggest model - and promised its weights for next week

Qwen3.8-Max carries 2.4 trillion parameters and a context of one million tokens, already available through the API. The real news is different: Alibaba says that in days it will release the weights freely - a top-class model anyone will be able to download.

Read →
Builders
Cloudflare3 August 2026Agents

Cloudflare gives the agent a computer: files, git and shell without a container for everyone

Agents Week opened with empty talk. @cloudflare/computer is the first real meat - an open library that gives the agent a file system, git, and code execution. The lightweight mode carries most of the work; a real Linux container only fires up for the heavy stuff.

Read →
Security
CISA3 August 2026

A second patch for N-able N-central: the first one was incomplete, and the hole is already being exploited

CISA added CVE-2026-18577 to the catalog of actively exploited vulnerabilities: authentication bypass and account takeover in N-central - the tool providers use to manage other people's networks. The vulnerability is the result of an incomplete earlier fix.

Read →
Control
OpenAI3 August 2026Law

'Apple is getting this wrong': OpenAI answers the trade-secrets lawsuit by releasing the message logs

Apple is suing OpenAI over trade secrets allegedly carried out by former employees, and is seeking an injunction. OpenAI answered publicly, in a post titled 'Apple is getting this wrong', and attached the actual emails and messages: by their account, Apple's own people reached out to the departed engineer for help, and Apple's lawyers wrote to the wrong person.

Read →