Automata

A tech digest, every weekday. About

212 items across 29 sources in the last seven days. The email carried the 37 that mattered most.

Automatic summaries were unavailable for this edition; a classifier chose and ranked the stories.

Google Unveils Gemini 4 Argon, Retaking Benchmark Lead Over OpenAI and Anthropic

Google has unveiled Gemini 4 Argon, a new frontier AI model that it says leads or ties rivals on 13 of 18 disclosed benchmarks. The model is initially being released only to trusted cyber defenders and select pre-release testers, with broader availability planned later. VentureBeat reports: Google is not claiming that Gemini 4 Argon wins every benchmark. But across the benchmark table disclosed in

The Internet has a second audience

More than half the traffic reaching sites on Cloudflare is now automated, and AI agents are the fastest-growing part of it. We're giving site owners the tools to see who's visiting, decide who gets in, and charge for access.

AI & LLMs

Quoting Matthew Green

[...] Put these pieces together and you have the two halves of a worm: a payload that hijacks the agent, and an agent that will carry the payload to the next agent. Agents in separately-isolated sandboxes discovered that they could leave instructions for each other in a shared package cache, and those instructions changed what the recipients did. Replace the package cache with email, Slack and sha

Cut your AI spend with AI Gateway's Auto Router

Cloudflare AI Gateway now features a model router that evaluates request complexity using an edge-deployed classifier to select the optimal model. By balancing expected output quality against token costs, organizations can dramatically cut AI spend while maintaining performance.

Web & Frontend

Vercel CDN no longer caches responses with Vary: Cookie

Vercel CDN no longer caches origin responses when Vary includes Cookie. Vary tells a cache which request headers may change the response. Because cookies often contain visitor-specific values, varying by Cookie can create many cache entries that are rarely reused. The response is still served normally but isn't stored for future requests.You can identify these responses by checking the x-vercel-ca

Devtools & Platform

Vercel Agent now installs private packages from npm and custom registries

Vercel Agent can install private dependencies from npm and custom registries using credentials stored as shared environment variables on Vercel. npm, pnpm, and classic Yarn running in Agent sessions authenticate as they do in Vercel builds.To get started, add a shared environment variable for Development or Preview:Use NPM_TOKEN for private packages hosted on registry.npmjs.org.Use NPM_RC to confi

Opt-in dist-tag permissions for npm trusted publishing

Trusted publishing configurations for npm can now be granted permission to manage dist-tags (e.g., promoting a version to latest, updating next and beta pointers) using short-lived OIDC credentials instead of… The post Opt-in dist-tag permissions for npm trusted publishing appeared first on The GitHub Blog.

Vercel Sandbox now supports Secure Compute

Vercel Sandbox now supports Secure Compute, connecting sandboxes to a team's dedicated network. Public-internet traffic exits through the network's static IPs, and sandboxes can reach private resources in an AWS VPC through VPC peering.You can attach a sandbox to your network in your code or via the CLI. In your code, pass an existing Secure Compute network ID when creating a sandbox:In the CLI, a

X25519-only TLS ends for GHE.com on October 7

Beginning October 7, 2026, GitHub Enterprise Cloud with data residency will no longer accept TLS connections from clients that offer only X25519 for key agreement. Most customers don’t need to… The post X25519-only TLS ends for GHE.com on October 7 appeared first on The GitHub Blog.

GitHub Advanced Security trials for GitHub Team

GitHub Team customers can now start self-serve trials of GitHub Advanced Security to evaluate GitHub Code Security and GitHub Secret Protection. Start a trial from your organization’s Overview page, Billing… The post GitHub Advanced Security trials for GitHub Team appeared first on The GitHub Blog.

Deep Dives

Quick Hits

Major rsync upgrade in Debian because of 33 CVEs

apt-listchanges --which=both -f text --since=3.4.1+ds1-5+deb13u4 /var/cache/apt/archives/rsync_3.5.0+ds1-0+deb13u1_amd64.deb apt-listchanges: Reading changelogs... apt-listchanges: News rsync (3.5.0+ds1-0+deb13u1) trixie-security; urgency=medium In order to fix 33 CVEs, I have decided to bump the package to 3.5.0 rather than backporting all patches individually. After analysing the extra changes

Reddit Is Killing RSS Feeds, Ending Public API Access

An anonymous reader quotes a report from TechCrunch: Amid a number of updates for moderators and developers announced Wednesday comes bad news for supporters of a more open web: Reddit is ending support for RSS feeds. Reddit says RSS has now become a "common surface for large-scale scraping and automated abuse," which is why it's made the decision to wind down RSS feeds on its platform. "We know R

Hackers Stole Millions of US Military Personnel Records During Months-Long Data Breach

A months-long breach of the Defense Manpower Data Center exposed personal information belonging to roughly 2.8 million living current and former U.S. military personnel and staff, plus records for nearly 300,000 deceased people. Attackers reportedly exploited a file-sharing vulnerability between October 2025 and July 2026, accessing unencrypted records that included Social Security numbers, dates

From the timeline

Stop saying they are using it wrong.

Stop saying they are using it wrong. Listen without defense. @marktechson.com on the two feedback paths you can actually act on. Full episode and notes: https://www.epicproduct.engineer/lead-with-empathy-and-listen-without-defense-product-sense-with-mark-techson~5z61q

A distributed system is one in which the failure of a computer you did not even know existed can render your own computer unusable.Leslie Lamport