THE LAB #113: Obscura browser against Akamai
Obscura, a from-scratch Rust browser engine that embeds V8 and claims to run in about 30 MB of RAM, was tested against Akamai Bot Manager on Radisson's booking pages, where it failed to clear the anti…
Obscura, a from-scratch Rust browser engine that embeds V8 and claims to run in about 30 MB of RAM, was tested against Akamai Bot Manager on Radisson's booking pages, where it failed to clear the anti…
OpenAI launched GPT-5.6-Cyber on August 10 through its Daybreak Red program, making it the first model to reach 'High' cybersecurity capability under its Preparedness Framework, and it found two vulne…
OpenAI launched GPT-5.6-Cyber, a specialized model for approved security researchers, as part of its expanded Daybreak cybersecurity program, warning that AI could compress the time defenders have to …
OpenAI has introduced GPT-5.6-Cyber, a specialized AI model designed for advanced cybersecurity tasks, available through its Daybreak Red program. The model achieved a 95.0% completion rate on OpenAI'…
OpenAI shipped GPT-5.6-Cyber on August 10, 2026, a model designed to find zero-days and build exploit chains, which discovered two Chrome V8 vulnerabilities that chain into a full sandbox escape and c…
OpenAI launched GPT-5.6-Cyber on Monday, a purpose-trained model for approved security researchers that completes 95% of advanced exploit-development requests compared to 1.5% for standard GPT-5.6 Sol…
Check Point Research found five memory-corruption bugs in Cloudflare's workerd runtime, which underpins both Cloudflare Workers and Cloudflare Code Mode, and exploited them to break out of the sandbox…
Meta's Muse Code R708.1 launch build, released August 5, contains a hidden 'muse workflows' command, JavaScript bindings for sequencing AI agents (host.agent, host.pipeline, host.parallel), and a gate…
A developer proposes building a TypeScript compiler on top of the Go compiler to give TypeScript native concurrency and performance, arguing this would let it compete with Go for high-performance back…
Cloudflare has open-sourced its Cloudflare OS platform, an internal workspace that lets non-coders build apps using AI agents, and claims thousands of employees use it daily. The platform's security m…
A developer has created a tool to score the semantic density of MCP tool descriptions, arguing that verbose, human-friendly descriptions cause LLM agents to hallucinate and fail. The tool, available a…
A developer proposes TypeScript-Ultra-Strict, a stricter TypeScript variant that removes null, undefined, classes, and var, replacing them with Option<T> and Result<T, E> types, and introduces a macro…
A solo developer, HN user coolwulf, claims his from-scratch Zig browser engine, cwbrowser, passes the Acid3 test with a perfect 100/100 score, but the project has no source code, binary, or license, o…
Google fixed more Chrome security bugs in June 2026 than in the previous two years combined, using AI-powered vulnerability discovery agents built with Gemini and other models. The Chrome Security tea…
Researchers demonstrated that a single malicious webpage visit can compromise the Tor Browser, highlighting that serious JIT and memory corruption vulnerabilities are not unique to Firefox. The findin…
On July 22, 2026, high-school student Ruikai Peng (@ruikai) announced Rolling in the Diffs, an LLM-based tool he claims has discovered over 60 vulnerabilities in open-source projects including the Lin…
Google released three Flash-tier models on Monday, including Gemini 3.6 Flash, which cuts cost per task from $0.59 to $0.50 and time per task from 2.7 minutes to 1.3, while Gemini 3.5 Flash-Lite runs …
Google shipped three new Gemini models this week, including Gemini 3.5 Flash Cyber, which found 55 confirmed vulnerabilities in Chrome's V8 JavaScript engine during testing — 10 of which were missed b…
GPT-5.6 Sol Ultra built a full Chrome V8 exploit chain from patch commits, achieving arbitrary code execution on a recent Chrome build (V8 14.9.207.35) after three days of autonomous work, while Grok …
OpenAI shipped GPT-5.6 on July 9 with Programmatic Tool Calling, a feature that lets the model write JavaScript to orchestrate tool calls in a V8 sandbox, reducing tokens by up to 63.5% and model turn…