Hey {{first name | there}}.
OpenAI's model escaped its test environment this week and went on to hack Hugging Face. The company called it a highly isolated environment. Security researchers pointed out it had a route to the internet, which is not what isolated means.
Elsewhere, the numbers did the talking, in bills nobody owed and CVEs nobody can triage. Worth a look at which of your own guardrails have quietly stopped guarding anything.
In today’s roundup:
OpenAI's Hugging Face breach came down to a sandbox that wasn't one
AWS showed customers trillion-dollar estimates while its own alarms stayed quiet
432 kernel CVEs landed in two days, and nobody knows how to triage them
A US open source lab argues Chinese models aren't inherently dangerous
Harness stopped making agents predictable and fixed the pipeline instead
You will also find upcoming events, a podcast worth listening to, and curated job opportunities across the ecosystem.
Let’s dive in👇🏼
📰TOP PICKS:
Linux kernel team publishes 432 CVEs in two days
The Linux kernel team published 432 CVEs across a weekend. Security architects say prioritising individually is no longer feasible, and pointing an LLM at the pile just yields another dozen tomorrow
How OpenAI’s human mistake led to the AI-powered hack on Hugging Face
OpenAI's model escaped its test environment through a package-installation proxy, then hacked Hugging Face. Security researchers are blunt about it: a sandbox with a route to the internet was never a sandbox.
AWS Billing Bug Shows Customers Trillion-Dollar Estimates While Its Own Cost Alarms Fail to Act
A unit pricing error had accounts under $5 a month showing billions. AWS says its alarms detected the anomaly but never halted the pipeline or paged anyone. Customers reported it four hours later.
Arcee, a US open source AI lab, says Chinese models are not inherently dangerous
Arcee's CTO argues Chinese open-weight models aren't a security threat, since running weights locally gives their makers no access. His fix: build better US models rather than ban theirs.
Fresh off AI layoffs,
Months after cutting 4,000 jobs to AI, Block released Buzz, an open source Slack rival where agents get cryptographic identities of their own. Whether people and bots belong in one room is the open question.
GitHub Increased Instant Navigation from 4% to 22% by Rethinking Client Side Architecture
GitHub rebuilt Issues navigation around client-side caching and prefetching, so pages render from local data while updates sync behind them. Instant navigations went from 4% of loads to 22%.
Agents keep changing their answers. Harness just built delivery pipelines that don’t care.
Since the same input can give an agent a different answer each run, Harness grades responses on correctness, safety, and performance, then wires that score into delivery as a pass-fail gate.
Write code like a human will maintain it
A developer noticed he'd stopped refactoring because the LLM would handle it later. Then he realised the model reads his repo, so each copied conditional becomes the house style it repeats back
Good Tools Are Invisible
An argument against turning a tool's flaws into a puzzle worth bragging about. The test isn't how clever the workaround felt, it's wall-clock time, and good defaults are a toolmaker's job
🗓️ UPCOMING EVENTS
Mark your calendars!
API Conference Lagos (25 July 2026, Lagos, Nigeria): APIs, cloud architecture, integration, and modern software development. Register here.
AI Unplugged (25 July 2026, Durban, South Africa): Explore practical AI applications, emerging technologies, and real world use cases through talks and community discussions. Register here.
KCD × OpenInfra Days Vietnam 2026 (25 July 2026): Join the Kubernetes and OpenInfra communities for technical talks, open source collaboration, and cloud native infrastructure discussions. Register here.
KubeCon + CloudNativeCon Japan 2026 (28 to 30 July 2026, Yokohama, Japan): The Cloud Native Computing Foundation's flagship conference featuring Kubernetes, cloud native technologies, and the open source ecosystem. Register here.
Chain React 2026 (30 to 31 July 2026): A React Native conference featuring technical talks, best practices, and the latest developments in cross-platform mobile development. Register here.
SysAdmin Day 2026 (31 July 2026, Leipzig, Germany): Celebrate System Administrator Appreciation Day with sessions on infrastructure, automation, operations, and systems engineering. Register here.
The Deep Learning Indaba 2026 (2 -7 August 2026, Lagos, Nigeria): AI, machine learning, and data science. Register here.
GopherCon 2026 (3-6 August 2026, Seattle, WA): Go, distributed systems, and cloud native development. Register here.
KCD Melbourne 2026 (4-5 August 2026, Melbourne, Australia): Kubernetes, cloud native, platform engineering, and DevOps. Register here.
PyCon ID 2026 (8-9 August 2026, Jakarta, Indonesia): Python, open source, and the Python community. Register here.
Write the Docs Kenya Conference 2026 (8 August 2026, Nairobi, Kenya): Technical documentation, developer experience, and content design. Register here.
GopherCon South Africa 2026 (31 August-1 September 2026, Johannesburg, South Africa): Go, software engineering, and the Go community. Register here.
RubyConf Africa 2026 (21-22 August 2026, Nairobi, Kenya): Ruby, Rails, and the African Ruby developer community. Register here.
💻OPPORTUNITIES:
Cloud Network Security Engineer at ACC - Pune, Maharashtra, India
Jr. DevOps Engineer at Experian - Brazil (Remote)
Security Automation Engineer (Python) at Marlabs- United States Remote (any location)
AWS DevOps Cloud Engineer at Marlabs- Indianapolis, IN (Hybrid)
Intern, CloudOps at EQ Banks- Toronto
AI-First SRE/DevOps Engineer at Axiad- San Jose, California, United States
Forward Deployment Engineer at Veeam - Melbourne, Australia
Platform Engineer II at Sony Interactive Entertainment - United States, Aliso Viejo, CA
Senior Backend Engineer, Deployment Environments at GitLab - United Kingdom (Remote)


