August 21, 2026
Today's top tech stories, deduped across the newsletters I read and briefly summarized. Click a source to open the original article.
AI
NVIDIA: Generative recommenders are redefining RecSys at scale
NVIDIA's developer blog explains how generative recommender models are changing the way consumer internet companies build and train recommendation engines. Traditional RecSys architectures are notoriously hard to train and scale, and generative approaches promise a simpler path forward.
ChatGPT search now uses the site: operator at scale
Simon Willison shows that ChatGPT search now systematically uses the site: operator to pull results from specific domains, feeding the emerging "GEO" (Generative Engine Optimization) industry — SEO for chatbots. The finding offers a rare look under the hood at how AI search engines actually retrieve information.
Security
AliExpress runs hidden WebAudio fingerprinting that breaks Bluetooth multipoint
A researcher found AliExpress silently uses WebAudio fingerprinting for tracking, which inadvertently disconnects Bluetooth headphones running in multipoint mode. The discovery shows how invasive tracking techniques can produce unexpected hardware side effects.
Malicious Rust crate arrayref ran a build-time infostealer payload
Attackers hijacked the maintainer account behind the widely used Rust crate arrayref and inserted a malicious build-time payload that installed an infostealer on developers' machines during compilation. It's the latest in a string of supply-chain attacks against package registries.
Citrix urges admins to patch new NetScaler flaws immediately
Citrix is warning customers about two new vulnerabilities affecting NetScaler Gateway and NetScaler ADC appliances and urging immediate patching. Remote-access gateways like these are a favorite target for attackers.
CISA warns hackers are exploiting a critical MLflow vulnerability
CISA has warned federal agencies that threat actors are actively exploiting a critical vulnerability in MLflow, the open-source platform used to manage machine learning experiments. Organizations running MLflow should patch immediately.
smolmachines / smolvm as a sandbox for untrusted Python and JavaScript
Simon Willison tasked Claude Fable 5 running in Claude Code with researching smolmachines/smolvm as a lightweight sandbox for safely running untrusted Python and JavaScript code. The project highlights a growing need for solid isolation primitives as LLM agents run more code on their own.
Dev
Mojo is now open source
Modular has open-sourced Mojo, its programming language built for high-performance AI and systems programming. The move opens the door for a broader community to contribute to a language that pairs Python-like syntax with C-level performance.
Cursor on Git at any scale
Cursor shares techniques for working with Git repositories efficiently regardless of codebase size. The post digs into the performance challenges and fixes needed for large monorepos.
Bun 1.4 ships Bun.WebView — Simon Willison builds a shot-scraper-style JSON API on it
Bun 1.4 is now stable and introduces Bun.WebView, and Simon Willison demonstrates using the new feature to build a shot-scraper-style JSON API for scraping web pages. The release gives Bun developers a built-in way to programmatically control a browser.
IT
GitHub reflects on the August 17 outage
GitHub published a retrospective on its major August 17 outage, detailing the remediation work still ahead to improve platform reliability. The outage affected a broad swath of developers who depend on GitHub daily.
Other
Aaron Swartz was prosecuted for scraping — Meta faces no consequences
A viral post argues Aaron Swartz, co-creator of RSS, was criminally prosecuted for scraping while Meta does similar large-scale data harvesting without consequence, reigniting debate over uneven enforcement of computer-crime law.