US-Iran ceasefire expires — Iran declares a "fully offensive" military posture; a vessel is struck in the Strait of Hormuz, crew casualty reported. Just Security
Russia kills 10 in Ukraine's Kharkiv region — Ukraine counters overnight with 620 drones targeting Moscow and surrounding areas. Just Security
DRC Ebola: 5,000+ cases, 2,320 deaths — Africa CDC says the outbreak is now taking one life every 30 minutes. Africa CDC
USS Benfold adrift four days — An engineering failure in the South China Sea last month left the destroyer without power, water, or working toilets. Democracy Now
### ON THE TRAIL
WEEKEND PICKS — Sat–Sun, Aug 22–23
Most of the Cascades take a hit Saturday: 43% rain on US-2 West, 45% on Mountain Loop and Hwy 20, 26% on I-90. Two routes hold up.
Surprise and Glacier Lakes / Trap Pass PCT | Stevens Pass West · US-2 near Index · ~1 hr from Issaquah
An Aug 17 WTA report found fewer than ten people all day; the reporter had Surprise Lake entirely to themselves. The trail follows a creek through old-growth forest at a comfortable grade — boardwalk over muddy sections near the trailhead — then opens to two turquoise alpine lakes with multiple lunch spots and water. Round-trip distance including both lakes and a push up toward Trap Pass: roughly 10.5 miles, just over 3,000 feet of gain. For an overnight, camp at Surprise Lake on Day 1 and explore Glacier Lake; return Day 2 (~5 miles each way approximate). No snow, no bugs reported, no fords. Weather: US-2 West Saturday "Chance Light Rain, 43%" — this route works best as a Sunday overnighter. Sunday clears to "Partly Sunny, 12%," high 73°F. Aug 17 WTA report
Dewey Lake | Mt Rainier Area · Chinook Pass / Hwy 410 · ~1.5 hrs from Issaquah (no ferry; do not approach via White River — closed for the Grand Park 2 fire)
An Aug 16 WTA report confirms clear skies, zero bugs, trail in good condition to the lake, and "plenty of opportunities to camp around the lake." Water at the lake; Forest Service rangers active in the area. Mileage was not included in the trip report — check the WTA trail page before you go. This Hwy 410 approach is unaffected by the White River/Sunrise closures. Weather: Mt Rainier area Saturday "Slight Chance Light Rain, 17%," 59°F — the cleanest Saturday in the Cascades this weekend. Sunday "Mostly Sunny, 2%," 64°F. Aug 16 WTA report
REGIONAL SNAPSHOT
Snoqualmie / I-90 / North Bend — Trails in good shape throughout the corridor. Snoqualmie Mountain is snow-free and brutally steep (3.63 mi / 3,153' gain, dry with no water after the trailhead).6 Rattlesnake Mountain Grand Prospect is in great condition; some sunny sections need brushing. Note: Exit 38 on the Palouse to Cascades Trail is closed as of Aug 17.6 Saturday brings a 26% rain chance (63°F); Sunday clears to mostly sunny (67°F, 8%).
Mountain Loop Highway — Church Mountain meadows are at peak: wildflowers, ripe berries, smoky views above treeline. Lake 22 is very busy — arrive before 9am to get a regular spot. Cascade Pass and Sahale Arm: nearly full on a Monday, water with filter confirmed at multiple points. Boulder River: no smoke, very few hikers, very potholed access road. Saturday rain risk is 45% — hold for Sunday.
Stevens Pass (US-2) — See weekend pick above for Surprise/Glacier Lakes. Josephine Lake is scenic but has a sketchy post-rockslide section on the approach; mild bug presence (DEET recommended). Bridal Veil Falls: parking lot full by mid-afternoon, waterfall running at late-season levels.
Olympic Peninsula — Clear and cool. Marmot Pass trail is in exceptional shape ("the wilderness equivalent of a golf green," per Aug 17 report), with two good campgrounds below the pass — but the trail runs completely dry above the last camp, so carry or cache water. High Divide / Seven Lakes Basin: no bugs, seven bears seen near Lunch and Heart Lakes Aug 16 — exercise caution in foggy sections where trail visibility is limited.6 Mildred Lakes: biting flies at the lake; navigation is complex (multiple conflicting flagging systems). Weekend weather: Saturday "Slight Chance Light Rain, 24%," 55°F; Sunday 57°F, 15%.
Mt Rainier Area — Access is narrowed. White River and Sunrise are closed for the season due to the Grand Park 2 fire; Nisqually/Paradise entrance lines were 30–40 minutes by 7am on the weekend. The Kautz Creek Trail is open — WTA's website shows a closure, but rangers on the trail Aug 16 confirmed a marked reroute around the washout is navigable.6 Camp Muir is unusually bare this year: snowfields largely melted above 8,000 feet with patches of blue ice.
North Cascades (Hwy 20) — Cascade Pass gravel road (~15 miles) is passable in most cars. Gorgeous views throughout, some smoky haze. Saturday brings a 45% chance of showers and thunderstorms on Hwy 20 — skip this corridor this Saturday; Sunday clears to mostly sunny (75°F, 12%).
PCT — Fire Closures — The Miner's Fire (lightning, Aug 13) continues to close 31 miles of PCT from Mica Lake to Suiattle Pass. Combined with two other active fire closures, roughly 123 miles — about a quarter of Washington's PCT — remain impassable.
Mojo's Compiler Goes Open Source. An AI Found What Copilot Missed.
Modular today open-sourced the Mojo compiler under Apache 2.0, completing the staged handoff that began with the standard library in 2024.1(Vendor-sourced: Modular blog; no independent coverage yet available.) The full compiler, tooling, and build system now live in the modular/modular GitHub repository. Mojo 1.0 shipped last week with source stability guarantees; the compiler source follows immediately. The build is Bazel — a single ./bazelw run --config=build-mojo KGEN:mojo invocation downloads or builds everything and runs a Mojo file from source. Contributions to the compiler are not yet open; the team says that gate opens by end of year. Standard library contributions have been accepted since 2024. The language's core premise — Rust-grade safety for GPU and AI accelerator targets, via LLVM Offload — is validated by an independent arxiv submission from Manuel Drehwald and collaborators: their framework builds a zero-overhead, multi-vendor GPU compilation path natively into rustc and LLVM's Offload backend, using Rust's ownership and noalias guarantees to manage host-device data transfers.2 Evaluation on RAJAPerf shows competitive LLVM IR for GPU kernels against native CUDA and HIP C++ baselines. Two separate teams converging on the same design point — ownership semantics as the key to safe GPU offload — is more signal than either paper alone.
On the model benchmarks: Willison flagged on Aug 17 that Qwen 3.8 27B scored 52 on the Artificial Analysis Intelligence Index, matching GPT-5.6 Luna at max settings and sitting one point behind GLM-5.2 and DeepSeek V4 Pro 0813.3 The GLM is 753B parameters; the DeepSeek is 1.7T. The Qwen is 27B. This paper covered the model's overthinking tendency on Aug 16; the benchmark score confirms the underlying capability is genuine. A 27B model at statistical parity with frontier-scale giants is the hardware efficiency story of the week.
In June, Wiz's Red Agent — an autonomous AI security tool — scanned Snowflake's GitHub organization and found a critical script injection vulnerability in snowflakedb/snowflake-connector-net. (Vendor-sourced: Wiz security research blog, published Aug 17; vulnerability disclosed to Snowflake via HackerOne on June 23.) The injectable code had been live for five days when Red Agent found it.4 The vulnerability was in jira_issue.yml, a GitHub Actions workflow that fires on issues: opened — meaning any unauthenticated user could trigger it by opening a GitHub issue. A PR merged June 18 had replaced a safe env: + jq --arg parsing pattern with direct ${{ github.event.issue.title }} interpolation inside a shell script. The sed escaping ran after GitHub's template expansion, so a single quote in the issue title broke out of echo '...' and allowed arbitrary command execution. The workflow had an if: guard that looked protective; on issues events, github.event.pull_request is always null, making the condition always true.
GitHub Advanced Security scanned the merged PR and didn't flag the injection. GitHub Copilot had co-authored a separate fix within the same PR and marked the overall change clean. Red Agent's first exploit attempt returned a bash syntax error — the # comment character ate the closing ) of TITLE=$(...). Rather than stopping, the agent analyzed the error, switched the payload to ; echo ' to properly close the shell block, and exfiltrated the Jira credentials via out-of-band callback within seconds. The token authenticated as qa@snowflake.net to Snowflake's Atlassian instance, granting read access across engineering, security compliance, and bug bounty tracking projects. Snowflake patched the workflow the same day Wiz reported it. Total exposure window: five days.
The delta that matters is timing. The vulnerability existed for five days before an automated agent found it. Human reviewers, static analysis tools, and an AI coding assistant all passed it. The window between introduction and automated discovery is compressing to days. Short-lived credentials and rapid patch cycles are no longer a best-practice recommendation — they're a minimum viable defense.
DuckDB v2.0 previewed Monday. (Vendor-sourced: DuckDB blog.) The headline: client/server mode via the quack extension graduating to stable, with a CONNECT statement that pushes queries to remote DuckDB, PostgreSQL, or MySQL instances rather than pulling tables over the wire. The recursive CTE engine was rewritten; the authors benchmark a graph reachability query over one million edges at 4.90 seconds in v1.5.4 and 0.12 seconds in v2.0 — a claimed 40× speedup.5 Async I/O lands throughout the engine, including for Parquet, CSV, and DuckDB's own format. A new PEG-based SQL parser replaces the PostgreSQL-derived one, enabling extensions to hook into the grammar itself. The stable C API with versioned YAML spec means extension binaries survive DuckDB version bumps without rebuilds. Full triggers (BEFORE/AFTER, FOR EACH ROW/STATEMENT, transition tables) and APPROX NEAREST joins for vector similarity search round out the feature list. v2.0 is slated for this fall.
Aras Pranckevičius posted Blender VSE tidbits covering Blender 5.1 through 5.3. Two items worth the read: GPU compositor path for strip modifiers (the initial 5.0 implementation used the CPU compositor exclusively, which worked but not quickly), and a shared movie decoder pool landing in 5.3 that eliminates the per-cut ffmpeg context teardown-and-reinit cycle.6 Previously, adjacent strips reading the same input video file each owned a separate decoder object; crossing a cut boundary meant closing one heavy context and opening another, causing frame drops even with prefetching on. The pool selects the least-stale available decoder from a shared cache. Several prior attempts at this fix hadn't landed; this one did. Aras also notes he handed the VSE lead role to John Kiril Swenson.
Cursor began rolling out Origin — a code-hosting service with repos, pull requests, GitHub sync, and integrations with Vercel, Depot, and Buildkite — to all paid plans as of Aug 17.7 It's the first significant product launch since the SpaceX acquisition.8(Vendor-sourced: Cursor changelog.)
Trending today: GitHub is saturated with AI agent harnesses, DeepSeek wrapper forks, and skill-collection repos — no genuine technical novelty cleared the bar.
HERENTALS, Belgium — Wout van Aert launched the decisive move at the Belgian Gravel Championships on Sunday, 22km from home, forcing a split that left only his childhood friend and training partner Daan Soete on his wheel. The two grew up together in Herentals and ride these gravel roads almost daily. They reached the final lap alone, and Van Aert had goosebumps. Then cramps set in. "I wasted a lot of energy along the way, bordering on cramps," he said. "I would have liked to win myself, but there is absolutely no disappointment on my part."1 As pre-Vuelta form checks go, the picture is mixed — but the Vuelta opens in Monaco on Saturday, and the race was never the point.
Visma–Lease a Bike confirmed its eight-man selection for Spain today. Van Aert heads a three-way leadership structure alongside Matthew Brennan and Sepp Kuss, with the team targeting stage wins rather than GC — Jonas Vingegaard is out for the rest of the season. Van Aert should target the opening 9.4km Monaco time trial and the hillier transition stages.2 Brennan, who took two stages at the recent Vuelta a Burgos, handles the flat finishes. Kuss, 31, will try to balance stage hunting with mentoring 21-year-old Norwegian Jørgen Nordhagen, tackling his first Grand Tour after a second at O Gran Camiño and fourth at Tour de Romandie this spring. Also in the eight: Bruno Armirail (another TT contender), Ben Tulett, Christophe Laporte returning after a quadriceps tear, and 39-year-old Steven Kruijswijk riding his final Grand Tour as road captain.
Kuss is racing his third Grand Tour of 2026. He finished 13th at both the Giro and Tour, won Stage 19 of the Giro from a breakaway, and nearly added a Tour stage on Alpe d'Huez before a littering penalty cost him a minute. He calls the Vuelta his home race and hasn't missed it since 2018. The last time Kuss raced all three grand tours in a season was 2023, and that ended with a red jersey.3
Nairo Quintana will not get a Grand Tour farewell. Movistar left the 36-year-old Colombian out of its Vuelta squad, with general manager Eusebio Unzué making the call.4 The spot went to Venezuelan sprinter Orluis Aular; Spanish paper AS reported the decision earlier this week. Quintana had prepared specifically for the race — completing a 10-day training camp — and planned it as his professional send-off. He announced his retirement in March and won a stage and the overall at Vuelta Asturias in April, dedicated to compatriot Cristian Camilo Muñoz who died that week. His Grand Tour palmarès includes the 2014 Giro d'Italia and the 2016 Vuelta a España. A Road Worlds appearance in Montreal in September remains a possibility. Movistar's selection is headed by 23-year-old Cian Uijtdebroeks and four-time Vuelta podium finisher Enric Mas.
Stage 1 of the Tour du Limousin produced a tight uphill sprint in France today, with the first four riders finishing within 10 seconds. It was the kind of stage — 21-year-old Noa Isidore of Decathlon CMA CGM Team at the front of a French domestic-heavy field — that the race calendar exists to give young riders.
In Belgium, the Egmont Cycling Race in Zottegem went to Lidl-Trek, who controlled the 130km race over five laps of a 26km circuit with three climbs and a cobbled sector per lap. The team stayed aggressive throughout, and with 2km remaining, Lucinda Brand led out a teammate through the finishing sprint to take the win ahead of Hélène Hesters (Liv AlUla Jayco).
Mathieu van der Poel returns to mountain bike racing this weekend at the UCI MTB World Cup in Les Gets — XCC on Friday, XCO on Sunday — and then to Val di Sole, Italy, for the MTB world championships on August 30. His Road Worlds target in Montréal sits on September 27, and one bad crash could put it at risk. He's done this before: he cartwheeled off the "Sakura Drop" at Tokyo 2021, crashed out of the 2023 MTB worlds in Scotland less than three minutes in, and fractured his scaphoid at a World Cup in 2025.5 He keeps going back. He has won world titles on road, eight times in cyclocross, and once on gravel; the XCO jersey is missing. This spring, asked what trophy he wants more than anything else: "If I can only choose one, it would be that."5 Two-time defending MTB world champion Alan Hatherly leads the Val di Sole field, alongside World Cup leader Luca Martin and Tom Pidcock.
Groupama-FDJ United announced today that David Gaudu will undergo in-depth medical examinations after a run of form that has left the team without answers. The 2022 Tour de France near-podium finisher — once the team's great GC hope — has produced a string of DNFs since June: French National Championships, Donostia San Sebastian, Stage 5 of the Vuelta a Burgos (the summit finish), and Sunday's La Polynormande. He missed the Tour de France squad for the second year running. "David is currently going through a more difficult period and has not been able to fully regain his form," the team said.6 The medical tests will shape his remaining race schedule.
On helmet safety, CPA president Adam Hansen added a specific new dimension in comments to BBC Sport published Aug 16: the problem isn't only helmet standards, but race traffic management. When the breakaway and main peloton pass a marshal point, civilian vehicles sometimes re-enter the course under the mistaken assumption the race has finished. On mountain stages, Hansen noted, riders still on the road can be 45 minutes behind the front group. "What happened is a bit of a hole in the system," he said.7 The issue has surfaced at previous incidents including Il Lombardia and this year's Tour Auvergne-Rhône-Alpes. As this paper reported Monday, Hansen has spent more than two years pressing inside the SafeR working group for an upgrade to CE EN 1078 — the consumer cycling standard that governs professional race helmets — with no result. The UCI has not responded publicly to either demand.
The Lloyds Tour of Britain Women starts Wednesday, expanded this year from four to five stages.8 Lorena Wiebes, Lotte Kopecky, Kim Le Court Pienaar, and defending champion Ally Wollaston headline the field; Stage 3 finishes atop the Great Orme in Wales, and Stage 4 packs 2,227m of elevation gain over 138km through central Wales.
On the Road Ahead
Updated Aug 18, 2026
Date
Race
Country
Wed–Sun, Aug 19–23
Renewi Tour
Belgium / Netherlands
Sat, Aug 22 – Sun, Sep 13
Vuelta a España (Stages 1–21)
Spain
Sun, Aug 30
Bretagne Classic – CIC
France
Fri, Sep 11
Grand Prix Cycliste de Québec
Canada
Sun, Sep 13
Grand Prix Cycliste de Montréal
Canada
Show Results
BELGIAN GRAVEL CHAMPIONSHIPS (Sunday, Aug 16)
WINNER: Daan Soete (BEL)
PODIUM: 1. Daan Soete, 2. Wout van Aert (Visma–Lease a Bike)
The Code Was Already on the Disc: How id Software's Quake DRM Cracked in 39 Days
The unlock operator at 1-800-ID-GAMES would answer your call, take your credit card number, and read back a string of digits. That string was called a SERIAL. You typed it into the GUI, the software decrypted the game, and you were playing full Quake. The entire system depended on one assumption: that the SERIAL was a secret only the server knew.
It wasn't. The software on the disc could derive the correct SERIAL itself. All it did was compare the number you typed to the one it had already computed locally. Every piece of information needed to unlock every game on that CD — Doom, Doom II, Heretic, Hexen, Final Doom, the full id catalogue — was sitting there in plaintext, waiting.
Fabien Sanglard, whose deep-dives into id Software's code are required reading for anyone who cares how nineties games actually worked, traces the whole episode in a piece dissecting the Quake shareware retail CD. The article is structured like a forensic report: here is the disc, here is how it was supposed to work, here is exactly where it fell apart.
The setup was commercially audacious. By June 1996 id Software had finished Quake, a game that consumed a mere 22 megabytes. A retail CD held 640. So id partnered with a company called TestDrive Corp to pack the remaining capacity with encrypted installers for their back catalogue. A customer could walk into CompUSA, pay $9.95 for the shareware disc, call an 800 number, pay again, receive an unlock code over the phone, and immediately own any game in the id library — no shipping, no waiting, no retailer margin. The disc was announced July 3, 1996 and hit shelves August 30th.1
The hacker group GNOMON released Quakecrk.zip on October 8th. Thirty-nine days.1
TestDrive's protection scheme worked like this. Each game on the disc had its executable "denatured" — the first 32 kilobytes replaced with a stub that refused to run, the original header encrypted and stored separately. To restore the game, you needed a seed derived from the SERIAL. The SERIAL came from the phone operator after you paid. To prevent replay attacks, the GUI generated a fresh 11-digit CHALLENGE number each session, rotating every five minutes. There was no way to reuse a SERIAL from a previous call. On paper this is a serviceable design.
The flaw is that FLOW.EXE, the unlock program that ships on the disc, contains the entire SERIAL derivation pipeline.1 Sanglard traces it in detail: the CHALLENGE encodes a GAME-ID and two parameters, OFFSET and DEPTH. The GAME-ID indexes into a database called SKU.17 to get a codename. The codename retrieves a 512-byte DOC file from a library archive. Mixed with the string "Testdrive Corp." and the codename, the DOC transforms a 508-byte hardcoded table into 254 sixteen-bit values.1 DEPTH and OFFSET walk that table backwards, XOR-ing to produce a value called MEM. The SERIAL follows from a formula involving MEM and the GAME-ID. The whole pipeline runs locally. The phone call proved you paid; it did not provide any secret your machine didn't already possess.
GNOMON's reversal of this pipeline, reconstructed from the crack by researcher rmolina in 2016 and documented by Sanglard now, is a textbook example of security through obscurity collapsing under thirty-nine days of scrutiny.
The secondary failures compound the picture. The encrypted SKU.17 file that maps GAME-IDs to codenames has an unencrypted plaintext twin, SKU.TXT, sitting right next to it in the archive. The library format is unscrambled. The archive contains editor backups, temp files, and an executable called ENCRYPT.EXE that goes unused. Final Doom couldn't be legitimately purchased at all because a typo in SKU.17 — "Final" with a capital F instead of lowercase — caused the SERIAL generator to retrieve the wrong DOC file, producing codes that never validated.1 Paying customers couldn't unlock it; the crack worked fine on it.
The outcome was what David Kushner described in Masters of Doom: distribution chaos, fulfillment spinning out of control, a last-ditch attempt to pull the brakes on retail too late. They were left with almost 150,000 CDs stranded in a warehouse.1
Sanglard's read of the wreckage is unsentimental: "Never attribute to malice what you can attribute to stupidity. And never attribute to stupidity what you can attribute to time pressure."1 The people who built this system were not incompetent — TestDrive Corp was a real company selling a real product, and the challenge-response structure they built would have been sound if the validation had lived on the server. It did not. Whether that was a design error or a shipping deadline nobody is owning up to thirty years later is the one thing Sanglard can't answer, because the disc doesn't say.
What the disc says is everything else. Sanglard built a full filemap of the CD's contents, cross-referenced the encryption formats, pulled the archived Usenet threads from rec.games.computer.quake.misc, bought a physical copy of the retail shareware on eBay, and called 1-800-ID-GAMES to see what picked up. (The number still works. CompUSA closed between 2007 and 2008. You reach an automated message selling products for the elderly.) The result is one of the more complete post-mortems of a nineties DRM scheme you're likely to find — and a clean illustration of why client-side validation has never been a defense against anyone who knows how to read a binary.
The Red Rose in His Lapel, the Letter in His Pocket
By the summer of 1920, 35 states had ratified the 19th Amendment. Thirty-six were required. The remaining states had either already rejected it or would not bring it to a vote that year — Connecticut, Vermont, North Carolina, and Florida all declined.2 Tennessee was the last viable option, and so the entire 70-year American suffrage movement converged on Nashville in August, with Congress's clock running.
The lobbying war that broke out in the statehouse took a name: the War of the Roses. Supporters of suffrage wore yellow roses; the anti-suffragists wore red. Into that legislature walked Harry T. Burn, 24 years old, the youngest member of the Tennessee General Assembly, representing a conservative district in McMinn County.1 He wore a red rose.
On August 18, 1920, the House voted first on a motion to table — to delay — the ratification question. Burn voted yes, to table. It looked like the anti-suffragists had the numbers to bury the amendment for the session. But during the roll call, another representative, Banks Turner, switched sides, leaving the tabling vote deadlocked. The question moved to the floor.
Then, early in the ratification vote, something that stunned the chamber: Burn, red rose on his lapel, said "aye" in a clear voice.
He had a letter in his suit pocket from his mother, Febb E. Burn. She had written asking him to "be a good boy" and vote for the amendment. He later explained his reasoning without apology: "I knew that a mother's advice is always safest for a boy to follow and my mother wanted me to vote for ratification. I appreciated the fact that an opportunity such as seldom comes to a mortal man to free 17 million women from political slavery was mine."2
Turner also voted yes. Tennessee became the 36th state to ratify. American women voted in a federal election for the first time that November.
The story did not end cleanly. Tennessee lawmakers tried to delay official approval of the ratification in the days that followed, and the governor of Louisiana's wife personally pressured Febb Burn to recant her letter — to say it was a fraud. She refused. The official documents arrived in Washington on August 26, 1920, and were signed quietly by the Secretary of State.2
The seven-page letter Febb Burn sent her son still exists in an archive in Knoxville.2
*After Peanuts — on the Quake shareware disc that carried its own unlock formula and gave crackers everything they needed in 39 days. After The Far Side — on the August 18, 1920 moment when the Tennessee legislature's youngest member, red rose in lapel, voted "aye" on women's suffrage because of a letter from his mother.*
DDR5 Memory Up 500% Year-Over-Year — AI hyperscalers have locked up nearly all of the world's DRAM production capacity for 2027, driving a 128GB DDR5 kit from its all-time low of $329 to $3,399 today; SK Hynix's CEO warns 2027 will be the worst year for memory supply in the industry's history. tomshardware.comAug 17, 2026
Engineering Leaders Are Walking Out — The Pragmatic Engineer surveyed nearly 20 CTOs and VPs of Engineering currently on or considering career breaks and found a common pattern: AI-driven "founder mode," demands to cut engineering headcount by 20–50%, worthless equity behind steep preference stacks, and 60,000-line founder PRs landing in production. newsletter.pragmaticengineer.comAug 18, 2026
First Longacres Mile Decided by Disqualification — 32-to-1 underdog Adios Jojo was named winner of the 91st running of the Longacres Mile at Emerald Downs after heavy favorite Touchy was disqualified for interference in the final stretch — the first DQ finish in the race's history. issaquahreporter.comAug 17, 2026
Where to Watch the Vuelta — The Vuelta a España (Aug 22–Sep 13) is on Peacock in the US and NBC Sports, TNT Sports/HBO Max in the UK, FloBikes in Canada, and free-to-air on SBS in Australia, RTVE in Spain, and RTBF/VRT in Belgium. cyclingnews.comAug 18, 2026
Whether an AI coding assistant can catch security vulnerabilities is the wrong question. When Wiz's Red Agent found a critical shell injection in Snowflake's GitHub Actions last June — alive for five days in a PR that GitHub Copilot had co-authored and marked clean — the failure wasn't capability.1 It was position.
As THE LAB reports today, GitHub Advanced Security scanned the merged code and raised no flag. Copilot had contributed a fix inside the same PR and identified the overall change as all-clear.1 It took a different class of AI — one purpose-built for adversarial reasoning rather than collaborative production — to find what collaborative review had missed. The five-day exposure window is the headline, but the structural fact underneath it is more durable: a tool optimized for producing code that passes review is not a tool optimized for catching what it produced.
Today's LONG READ traces an identical failure mode from 1996. An unlock scheme for the Quake shareware CD kept its validation logic client-side, meaning the software meant to guard the secret could derive the secret itself.2 The scheme fell not because attackers were exceptional but because the validator and the thing being validated occupied the same location. Position, not capability.
The question worth carrying today is whether that distinction changes anything in practice. "AI reviews AI" is increasingly the default posture — the same assistant writes the code, reviews the PR, the static analysis scans the result. None of those tools are designed to be adversarial toward their own output. Red Agent's architecture is different: it assumes hostility, not collaboration. The two modes aren't competing; they're complementary — a team running both is genuinely better defended. But a team that runs only the collaborative tier and calls it security review has reproduced the Quake disc's mistake in a new medium. The question isn't whether to trust AI with code. It's whether you've noticed that the thing reviewing your work is the same system that produced it, and whether that means anything to you.