PEAKS No 51: GPT-5.6, IBM's Sub-1nm Chip, and the Cordyceps Supply-Chain Flaw
Hi there!
“So Good They Can't Ignore You” by Cal Newport is the best career book that I’ve ever read. I just finished it last week, and I believe it’s even more relevant in the AI-hype era than it was 14 years ago, when it was published. Basically, it deconstructs the "follow your passion" myth and lays out a path to building career capital — rare and valuable skills — that leads to a fulfilling career built on three traits: control, creativity, and impact.
Hopefully, I’ll have time to come back with an in-depth analysis. Anyway, just read it.
🛡️ Security & Privacy
- The Linux Foundation launched Akrites, a coordinated vulnerability-disclosure initiative backed by AWS, Microsoft, Google, Anthropic, JPMorganChase and others, aiming to fix AI-discovered open-source flaws before exploits hit critical infrastructure. More
- LastPass is notifying users after attackers breached market-research partner Klue, exposing CRM and support-case data (names, emails, phone numbers) tied to its Salesforce/Gong integrations — vaults themselves weren't touched. More
- A new free-speech essay warns that the global wave of social-media age-verification laws (Australia, UK, US states, KOSA) effectively forces identity verification on everyone, multiplying breach and surveillance risk. More
- Researchers disclosed "Cordyceps," a systemic CI/CD supply-chain flaw letting any GitHub user chain low-privilege workflows into high-privilege ones to hijack repos at Microsoft, Google, Apache and Cloudflare; AI-generated workflow configs are spreading the same insecure pattern at scale. More
- Microsoft's UEFI Secure Boot certificates began expiring June 24, with billions of Windows and Linux machines needing key updates to stay protected against firmware-level bootkits. More
- Indian manufacturer Tata Electronics, a key Apple and Tesla supplier, confirmed a breach after 630GB of alleged internal data — including supplier specs and a ransom demand — surfaced on a hacker forum. More
🛸 Tech
- A WisdPi 10G Ethernet expansion card for Framework laptops reveals USB-C's hidden bandwidth complexity — real-world speeds depend on which USB 3.2 generation each port actually supports, and the module runs hot enough to flag thermal-safety limits. More
- For the first time, an entire sealed Herculaneum scroll (PHerc. 1667) — a Stoic ethics treatise from the 2nd century BC — has been virtually unwrapped and read end-to-end using synchrotron X-rays and machine learning, all under an open license. More
- New Hygon patches extend Linux's Cache Aware Scheduling into hierarchical, topology-aware task aggregation, delivering up to 360% faster MySQL performance in early benchmarks. More
- IBM unveiled the first sub-1nm "nanostack" 3D transistor architecture (0.7nm/7Å node), packing ~100 billion transistors per chip with up to 50% more performance or 70% better efficiency than its 2nm node. More
- Meta paused its Model Capability Initiative — a keystroke-and-screen-tracking tool meant to train internal AI agents — after a security lapse exposed prompts, transcripts and private employee data across 45,000 internal data tables. More
🤖 AI
- OpenAI began a limited preview of GPT-5.6 (Sol, Terra, Luna), its strongest model yet for coding and cybersecurity, paired with a heavier safeguard stack after pressure from the US government around dual-use cyber capability. More
- OpenAI unveiled Jalapeño, its first custom inference chip built with Broadcom, designed (with help from its own models) to cut inference costs and reduce Nvidia dependence. More
- DeepReinforce released Ornith-1.0, an open-source, MIT-licensed family of self-improving agentic coding models (9B–397B) that beat similarly sized Qwen and Gemma models on SWE-bench and Terminal-Bench. More
- Mistral AI launched OCR 4, a multilingual document-extraction model scoring 85.2% on OlmOCRBench with bounding boxes and confidence scores, though some researchers disputed its benchmark claims. More
- Anthropic launched Claude Tag (@Claude), an always-on, shared AI agent for Slack channels that proactively flags updates and retains context across conversations, now in research preview for Enterprise/Team customers. More
🛠️ Tools
- Inkeep's open-knowledge is a new local-first, agent-native knowledge base combining an Obsidian-style editor, CRDT sync, MCP support and git, for teams managing docs and SOPs. More
- Hacker Trends is a free tool charting how any tech topic, tool or person has trended across 18 years and 45M Hacker News posts and comments. More
- Cursor's new Developer Habits Report shows AI-assisted coding speed has roughly doubled year-over-year, with the top 1% of developers now producing 46x more code than the median user. More
📕 Misc
A free, comprehensive Fintech Engineering Handbook distills patterns for building trustworthy money systems — covering ledgers, idempotency, reconciliation, and audit trails — for engineers entering the payments/banking space. More
📩 Please feel free to share this article with colleagues and friends who will find it valuable.
Thanks for reading!
Have a great day!
Bogdan