September 22, 2026
Today's top tech stories, deduped across the newsletters I read and briefly summarized. Click a source to open the original article.
AI
Xiaomi releases MiMo v2.6
Xiaomi has shipped a new version of its MiMo model family, MiMo v2.6, drawing heavy attention from AI developers on Hacker News.
xAI launches Grok 4.7
xAI has announced Grok 4.7, the latest version of its language model, and the release was one of the week's most-discussed AI stories.
"Decision models": a new model category emerges with Jev and Kev
TypeSafe AI has launched Jev, its first example of what it calls "System One models" or decision models, and shortly after the open-source project Kev appeared, built on Qwen3.5 with the same approach.
NVIDIA simplifies model serving across multiple GPUs with TensorRT
NVIDIA has released TensorRT multi-device inference, a new capability in Dynamo-Triton that makes it easier to serve generative AI as compute and memory demands outgrow what a single GPU can provide.
Security
CISA warns of active exploitation of three Linux kernel flaws
The US Cybersecurity and Infrastructure Security Agency warns that hackers are actively exploiting three Linux kernel vulnerabilities, one of them rated critical.
WordPress "Click2Shell" flaw lets hackers execute PHP on the server
Technical details and a proof-of-concept exploit have been published for a new CSRF vulnerability in WordPress's Core component, dubbed "Click2Shell," that lets attackers execute PHP on the server.
BigCommerce alerts merchants of data breach linked to Ribon apps
E-commerce platform BigCommerce has alerted multiple merchants to a data breach after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores.
Google fined €403 million over location data privacy violations
Ireland's Data Protection Commission has fined Google €403 million ($463 million) for multiple GDPR violations related to processing users' location data.
Why does "mathmain" need an encrypted loader?
Security researchers at SafeDep flag a suspicious package called mathmain that uses an encrypted loader, a possible red flag for a supply chain attack in the package ecosystem.
Dev
Cloudflare Python Workers are now generally available
After a two-year preview, Cloudflare's support for running Python code on its Workers platform is now stable and production-ready.
Simon Willison defends MCP against the critics
Responding to a Hacker News debate claiming "MCP was always a bad idea," Simon Willison argues the criticism misses the value the protocol actually delivers to developers today.
Other
NASA's Mars Sample Return mission is dead
NASA's ambitious mission to bring samples from Mars back to Earth has officially been shut down, after years of budget overruns and delays.