August 13, 2026
Today's top tech stories, deduped across the newsletters I read and briefly summarized. Click a source to open the original article.
AI
Alibaba releases Qwen3.8-2.4T-A95B, its largest open model at 2.4 trillion parameters
Alibaba has released open weights for Qwen3.8-2.4T-A95B (Qwen3.8-Max), its largest open-weight model yet, bringing near-frontier capabilities to the open-weight ecosystem. NVIDIA detailed how to serve the model with configurable reasoning on its GB300 NVL72 platform.
Lovable raises $400 million in Series C funding
AI app-building platform Lovable raised a $400 million Series C round to help more people run their businesses through AI-generated applications.
DeepSeek launches V4 Pro 0813, API-only
The latest DeepSeek Pro model is now available via OpenRouter, though DeepSeek has not published its own announcement page. Simon Willison had to link to OpenRouter in the absence of an official release post.
Debate: Is AI removing the middle class of software engineering?
A post from Florian Herrengt on AI tools struggling to fix tricky bugs sparked a major Hacker News debate over whether AI is eliminating mid-level software engineering jobs. Simon Willison highlighted the example of a team repeatedly asking AI to fix the same bug without success.
xAI launches Grok 4.6
xAI has released Grok 4.6, the latest version of its language model, drawing significant attention on Hacker News.
Security
Over 737 fake Chrome VPN extensions routed traffic through a proxy
More than 737 browser extensions on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies run by a single provider.
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
Attackers are exploiting a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms that can let them hijack customer accounts.
Lazarus hackers exploited a Windows zero-day to target defense firms
North Korean Lazarus hackers exploited a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign.
'City-Forum' attacks steal data from Salesforce and ServiceNow portals
An ongoing data-theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals.
Researchers show how reasoning traces can be stolen from proprietary AI APIs
A new research paper demonstrates how the reasoning traces of proprietary language models from Anthropic, OpenAI, and Google can be extracted even when providers withhold them from API responses.
Dev
Tailscale traces database corruption to a 16-year-old SQLite WAL-reset bug
Tailscale found and documented a 16-year-old bug in SQLite's write-ahead log reset mechanism that caused database corruption in production. The writeup became one of the top stories on Hacker News this week.
Zed introduces Delta, a new code editor feature
The Zed team introduced Delta, a new feature for its code editor, and the announcement quickly climbed the Hacker News front page.