Polaroid announced a new collection of cameras, instant film, and accessories all featuring limited-edition designs to help celebrate the 30th anniversary of Pokémon. The new collection goes a little harder than Fujifilm's Pokémon collaboration from five years ago with the introduction of Polaroid film printed with various characters around the frames, including Pikachu and Snorlax. […]
Rapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to prioritize exposure over severity scores. The post AI-Driven Vulnerability Surge Breaks the Traditional Patching Model appeared first on SecurityWeek .
Minor Changes #15026 6529f0c Thanks @petebacondarwin ! - Allow containers to be attached to a Durable Object from its exports entry A container can now be linked to its Durable Object from the export side, using a new container field that names an entry in the containers array. As a result containers[].class_name is now optional — a container that is referenced this way only needs a name : { "name" : " my-worker " , "main" : " worker.js " , "compatibility_date" : " 2026-07-01 " , "containers" : [ { "name" : " my-container " , "image" : " ./Dockerfile " , "max_instances" : 1 } ], "exports" : { "MyContainerDO" : { "type" : " durable-object " , "storage" : " sqlite " , "container" : " my-container " } } } The existing containers[].class_name direction keeps working and either direction may be used, but the two must agree: a container that names its Durable Object cannot also be claimed by a different one. container is only valid on live durable-object exports ( created and expecting-transfer ) and requires storage: "sqlite" . Wrangler now also reports an error when: a container reference names a container that does not exist two Durable Object exports claim the same container a container and a Durable Object export disagree about which one they are linked to a container ends up linked to no Durable Object at all two containers share a name a container's class_name names a Durable Object whose storage is legacy-kv two containers are attached to the same Durable Object That last case was previously accepted but could never work: workerd attaches a single container per Durable Object namespace, and in local development every container for a class builds into the same image tag, so one silently overwrote the other. If you have two containers on one class_name , give each its own Durable Object class. Patch Changes #15211 bc5726b Thanks @nithin42 ! - Honor access.dev when running Workers with @cloudflare/vitest-pool-workers , so ctx.access.getIdentity() returns the configured identity just as it does with wrangler dev . #14999 ba54f0d Thanks @mittalpk ! - Fix .env loading on Windows leaking stale, differently-cased duplicate keys On Windows, wrangler loads .env values through a case-insensitive Proxy wrapper so lookups like env.PATH and env.Path resolve to the same value, and this object is assigned directly to process.env . When a key was set again under a different casing (e.g. a value in .env.local overriding one from .env with different casing), the previous casing was never removed from the underlying object. env.PATH / env.Path still returned the correct, latest value, but anything that enumerates process.env — Object.keys , for...in , JSON.stringify , object spread, or a spawned subprocess inheriting the environment — would see both the stale and current key. Duplicate entries no longer appear, so environment variables passed to subprocesses and any code that lists the environment now see only the latest value for each variable. #15044 b7422b0 Thanks @stareezy-1 ! - Normalize structural CRLF line endings before sending D1 commands to the remote query API wrangler d1 migrations apply --remote and wrangler d1 execute --remote --command failed with incomplete input: SQLITE_ERROR when the SQL contained CRLF line endings inside a compound statement such as a CREATE TRIGGER ... BEGIN ... END; body. Structural line endings are now normalized to LF before the command is sent to the D1 query API, while CRLF inside quoted values and identifiers remains unchanged. #15046 186339c Thanks @erwinzhang7 ! - Fixes D1 SQL statements not handling lowercase end s correctly wrangler d1 execute and wrangler d1 migrations apply split a SQL file into statements before running them. A BEGIN or CASE block closed with a lowercase end was not recognised as closed, so every statement after it was folded into that block instead of being run on its own. SQLite accepts either case, so a file like this applied only the trigger and silently skipped the table: CREATE TRIGGER IF NOT EXISTS update_trigger AFTER UPDATE ON items begin DELETE FROM updates WHERE item_id = old . id ; end; CREATE TABLE after_the_trigger (id TEXT PRIMARY KEY ); Files written with an uppercase END were unaffected. Both cases now behave the same. #15231 4f922dc Thanks @dependabot ! - Update dependencies of "miniflare", "wrangler" The following dependency versions have been updated: Dependency From To @cloudflare/workers-types ^5.20260811.1 ^5.20260814.1 workerd 1.20260811.1 1.20260814.1 #15248 4d74b8d Thanks @dependabot ! - Update dependencies of "miniflare", "wrangler" The following dependency versions have been updated: Dependency From To @cloudflare/workers-types ^5.20260814.1 ^5.20260815.1 workerd 1.20260814.1 1.20260815.1 #15185 1f79ace Thanks @jamesopstad ! - Resolve --latest to the newest compatibility date supported by the installed runtime wrangler deploy --latest and wrangler versions upload --latest resolved the compatibility date to the current date, and wrangler pages download config did the same for projects configured to always use the latest compatibility date. Both write that date into a configuration file for subsequent commands to use, so a date that the installed workerd did not yet support left the project unable to run wrangler dev . These now resolve to the latest compatibility date supported by this version of Wrangler, which is the release date of the workerd it ships with. #15151 49f73de Thanks @maximilliangrand ! - Fix spurious Trailing comma jsonc(519) warnings for wrangler.jsonc in VS Code 1.131+ Trailing commas in wrangler.jsonc files that reference Wrangler's JSON schema are no longer reported as errors by recent versions of VS Code. Wrangler always accepted these files; only the editor warning was wrong. #14983 7cee278 Thanks @kdelay ! - Respect CLOUDFLARE_ACCOUNT_ID in wrangler pages project list , create and delete These three commands could target a previously used account even when CLOUDFLARE_ACCOUNT_ID was set, failing with Authentication error [code: 10000] in setups with more than one account. They now use the account named by CLOUDFLARE_ACCOUNT_ID , matching the rest of wrangler pages . When the variable is unset, the previously used account is still selected, as before. #15153 265256a Thanks @podonnell-dev ! - Fix wrangler preview base-config commands showing an inherited script positional #15185 1f79ace Thanks @jamesopstad ! - Use a fixed default compatibility date rather than the current date When no compatibility date was set, Wrangler, C3 and the Vitest pool all defaulted to the current date. workerd only accepts a compatibility date up to 7 days beyond its own release, so whenever a workerd release was delayed the default could get ahead of the runtime that had been installed, and local development would fail to start. The default is now fixed at the release date of the workerd version that ships with each release, which leaves a week of headroom and updates as workerd is upgraded. @cloudflare/vite-plugin previously inlined the date at which it was built. It now shares the same default. #15239 f431166 Thanks @jamesopstad ! - Prevent date-enabled Node.js compatibility from adding conflicting globals to generated runtime types Runtime type generation now treats Node.js compatibility enabled by a compatibility date the same way as an explicit nodejs_compat flag. Node.js globals continue to come from @types/node instead of being generated as any declarations that override those types. #15196 8fb2b87 Thanks @skepticfx ! - Use the FedRAMP High managed container registry when Wrangler targets the FedRAMP High compliance region Container builds, pushes, deployments, image commands, and local development now select the corresponding production or staging FedRAMP registry and API from either compliance_region or CLOUDFLARE_COMPLIANCE_REGION . #15082 75cf407 Thanks @penalosa ! - Enable the new configuration format in the cf-wrangler dev delegate Projects started through cf dev now load cloudflare.config.ts and optional wrangler.config.ts , matching the configuration used by the delegate's build path. Updated dependencies [ 1277a72 , 4f922dc , 4d74b8d , 2e0c962 , 8777180 ]: miniflare@5.20260815.0-alpha
Firefighters continue to battle one of the worst wildfires in Belgian history near the German border. Rains and cooler temperatures are helping them bring it to heel after it ravaged an area half the size of Manhattan.
In announcing scaled back joint military drills with South Korea, the US president appears to be moving towards Pyongyang just as North Korea becomes more emboldened.
Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent coding
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services," Ontinue said in a technical report shared with The Hacker News. "Tasking flows through SharePoint Online file
Xpander’s platform uses a universal agent harness that executes AI agents as portable workloads and securely renders interfaces on demand. The post Xpander Raises $7.5 Million for AI Management and Governance appeared first on SecurityWeek .
History suggests valuations will tumble even if they are a fair reflection of the transformative power of AI, according to a European Central Bank analysis.
Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems. The post Fortinet Acquires AI Security Company Virtue AI appeared first on SecurityWeek .
One of the best things my smart home does is help me care for my pets, and security cameras are particularly useful for keeping track of my many critters. But the barrage of notifications they send often means I miss important ones. So, when Google announced its new Pet Memory feature for Gemini for Home, […]
Ah, the relationship between animals and the technology they can’t quite understand. Today, it seems like there’s a high-tech solution to every element of pet ownership, with devices on the market designed to keep pets fed, cleaned, watched over, and entertained. And if you have a pet you know: nothing is too good — or […]
One of the great joys in life is having pets. The unconditional love, the snuggles, the excitement they show when you get home - these things add an emotional fulfillment to daily existence that can't be achieved in another way. I think everyone's life would be better with a pet (or two) in their lives. […]
Creators of chase compilations reject any moral qualms and say they show ‘death is waiting’ for those who join war To many observers they will appear dehumanising and offensive. To many Ukrainians, however, they are a brutal reminder of the fate that awaits Russian soldiers who take part in Vladimir Putin’s invasion, as well as a potent propaganda weapon. Over the past year and a half, videos of kamikaze drones chasing Russian service personnel to their deaths have become a distinctive genre on social media. They are the brainchild of Robert Brovdi , the head of Ukraine’s unmanned systems forces and founder of “Magyar’s Birds” , named after his call sign. Continue reading...
An opinion piece in the medical journal JAMA argues that autonomous AI will soon outperform any doctor-AI team at medical reasoning tasks. The authors warn against writing a doctor's final say into regulation, but concede that almost all the evidence comes from simulations, not real patient care. The article As AI beats doctors, regulators shouldn't force a human into the loop, JAMA piece says appeared first on The Decoder .
The U.S. and Iran missed a deadline to begin peace talks this week. The monthslong war has depleted U.S. resources. And, what to know about Alaska's U.S. Senate seat primary.
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - ubnuler ubnlder ri18nr reaker rakier orakw joxn