TLDR daily

28 September 2026

🚀 BIG TECH & STARTUPS

Sonnet 5.5 — 19:58

Claude Sonnet 5.5 is now available as a faster, lower-cost model for well-scoped tasks, bug fixing, and document, slide, and spreadsheet creation. It scores 70.6% on Terminal-Bench 4.0 versus Sonnet 5’s 10.3%, generates output 30%+ faster, and is priced at $2 per million input tokens and $10 per million output tokens. Developers can use `claude-sonnet-5-5` on the Claude Platform, though thinking-off users must switch to the `between_tools` setting before migrating.

anthropic.com · 7 min read

OpenAI’s AI agents need to catch up — 20:45

OpenAI is rumored to announce a continuously running consumer AI agent called Aeon at DevDay as it tries to catch up with rivals including Meta’s Muse, Instinct, and Google’s Gemini Spark. Muse has reached 600,000 daily active users in the US, while Gemini Spark has more than 30 external service partners such as Dropbox, Uber, and Spotify. Developers will be watching whether Aeon can provide useful integrations while addressing security risks that have let attackers take over accounts and reportedly exposed private information.

theverge.com · 3 min read

🔬 SCIENCE & FUTURISTIC TECHNOLOGY

⚙️ PROGRAMMING, DESIGN & DATA SCIENCE

Parley: Federated, decentralised chat that speaks plain IRC — 12:30

Parley is a working proof-of-concept federated chat network that lets ordinary IRC clients communicate across independently run instances without plugins. Instances discover peers through DNS and well-known identity documents, then exchange JSON events over HTTPS with detached ed25519 signatures. Developers can run an instance for their own domain while retaining IRC compatibility with clients such as irssi, WeeChat, and Textual.

git.mills.io · 16 min read

The problem is not AI code, but not knowing about system architecture or intent — 18:11

AI-generated code is not the core problem; teams can lose the system architecture, intent, and plans needed to understand the software they ship. When specs, code, tests, PRDs, tickets, and reports are generated through Claude Code without review, teams may push changes without resolving bugs or understanding the system. For developers, maintainability depends on retaining fundamentals, design, architecture, and human direction as generated pipelines, apps, and dashboards accumulate.

ssp.sh · 4 min read

Coding Is Not Solved — 15:52

Current LLM coding tools can generate code but do not solve the maintenance, reliability, security, scalability, and accountability required for production software. The systems rely on harnesses that feed syntax and runtime errors back into models, while accuracy declines as inputs and context windows grow. Developers should treat AI as a tool for tasks such as proofs of concept and personal software rather than substitute verification in low-risk-tolerance systems.

blog.alexewerlof.com · 25 min read

How we found 24 Android vulnerabilities using our open source AI security agent — 21:00

GitHub Security Lab’s open-source Taskflow Agent found and reported 24 Android vulnerabilities by using targeted prompts to audit mobile entry points and vulnerability classes. One OsmAnd flaw let any app send attacker-controlled extras to its exported MapActivity, enabling silent settings imports that could route map-tile requests to an attacker server and expose location data. Developers should review AI findings manually because models can report low-impact issues and misjudge severity.

github.blog · 10 min read

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation — 17:08

Dutch authorities arrested 23-year-old convicted cybercriminal Pepijn van der Stap on suspicion of aiding ShinyHunters data thefts and extortions. ShinyHunters then claimed breaches of the FBI’s job application site and Cl0p, while Mandiant and Google Threat Intelligence Group said the group mass-exploited CVE-2026-35273 in Oracle PeopleSoft to steal data from dozens of systems. Developers using PeopleSoft should apply Oracle’s fix, as ShinyHunters reportedly bypassed suggested web application firewall rules with URL encoding.

krebsonsecurity.com · 8 min read

Next.js applications, powered by Vite: introducing Vinext 1.0 — 16:51

Cloudflare has released Vinext 1.0, a Vite-backed framework that makes Next.js applications portable across platforms including Cloudflare Workers, Netlify, and AWS Lambda. It supports both App Router and Pages Router applications, with more than 99% test compatibility excluding Cache Components. Developers can migrate existing projects with `npx vinext check && npx vinext init` and prerender or warm caches before deployment.

blog.cloudflare.com · 7 min read

Introducing cf: the agentic CLI for the entire Cloudflare API — 16:50

Cloudflare has introduced cf, an agent-focused CLI in open beta that provides access to its entire API. Generated from OpenAPI schemas through the Forge pipeline, cf expands coverage from Wrangler’s roughly 280 command paths to more than 3,000 API operations. It defaults to JSON, adds natural-language command discovery through `cf cli search`, and introduces TypeScript-based `cloudflare.config.ts` configuration.

blog.cloudflare.com · 9 min read

How fast is the web? Explore billions of real-user measurements with BEACON — 16:43

Cloudflare has published BEACON, an anonymized dataset of real-user web performance measurements that is publicly available in Google BigQuery. The dataset contains billions of daily records from 10,000 large websites, reports Core Web Vitals as full histograms, and removes domain names and URL paths before aggregating records with fewer than five data points discarded. Developers can use its LCP and INP sub-parts to identify whether delays come from resource discovery, rendering, JavaScript execution, or presentation.

blog.cloudflare.com · 8 min read

All days →