August 29, 2026
Today's top tech stories, deduped across the newsletters I read and briefly summarized. Click a source to open the original article.
AI
GLM-5.3 is now open-weight
Zhipu AI (Z.ai) has released the weights for its GLM-5.3 large language model on Hugging Face, giving developers open access to one of the newest frontier models.
Judge rules Trump administration's blacklisting of Anthropic was illegal
A U.S. court has ruled that the Trump administration's attempt to blacklist Anthropic was illegal, a decision drawing wide attention across the tech industry.
OpenAI's decision on Cursor following its acquisition by SpaceX
OpenAI has published its response regarding the code editor Cursor after the company was acquired by SpaceX, a move that has sparked heated debate among developers.
NVIDIA launches TensorRT Model Connect for faster model deployment
NVIDIA has released TensorRT Model Connect, letting developers go from an open model checkpoint to production inference with just two commands, cutting out time-consuming conversion and preprocessing steps.
Security
Security researchers break Claude Code Opus 5 Auto Mode
Security researchers demonstrated how Claude Code's Auto Mode can be manipulated via prompt injection, raising questions about how well Anthropic's coding agent is protected against such attacks.
Just a rumour of a bug is enough to find a security exploit these days
Cambridge professor Anil Madhavapeddy describes how merely a rumor of a potential bug is now enough for attackers to quickly locate and exploit an actual vulnerability.
McKesson discloses breach after ShinyHunters claims patient data theft
Healthcare and pharmaceutical distribution giant McKesson has disclosed a security incident after the ShinyHunters extortion group claimed it stole 284 million patient data records from third-party applications.
PaperCut releases second emergency patch for exploited flaws
PaperCut has issued a second emergency security update for two actively exploited vulnerabilities in its NG and MF print management software, after researchers found multiple ways to bypass the initial fix.
GiveWP WordPress donation plugin flaw lets hackers execute server commands
A maximum-severity vulnerability in the GiveWP donation plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server.
Over 8,300 Gitea servers vulnerable to code execution attacks
According to Shadowserver, more than 8,300 internet-exposed Gitea instances remain unpatched against a critical flaw already being exploited in ongoing remote code execution attacks.
Dev
Htmx 4.0 released
The popular lightweight framework htmx has shipped a new major version, adding improvements developers have long asked for to build interactive web pages without heavy JavaScript.
Debate: GUIs should be fully keyboard-driven
A widely discussed blog post argues that modern GUIs should be designed for full keyboard navigation, not treated as an afterthought to mouse control.