Radar Daily Briefings
A clearer signal for WordPress and engineering
/\_/\
(=^.^=)
(")_(")
/\_/\
(=^.^=)
(")_(")
SAFA details CVE-2025-13032 Avast kernel exploit chain
SAFA’s second and final research post describes a full local privilege-escalation exploit for CVE-2025-13032 in Avast’s kernel driver on an up-to-date Windows 11 system. The article says the vulnerability has since been patched.
The exploit races a double-fetch of a user-controlled Unicode string to create a paged-pool overflow. It corrupts an I/O Ring RegBuffers pointer, redirects it to a user-controlled fake buffer entry, and uses I/O operations for arbitrary kernel reads and writes. An MDL exposes an EPROCESS pointer, while additional repairs prevent teardown crashes.
SAFA completes the chain by replacing the current process token with the SYSTEM token. The supplied evidence does not identify the patched Avast version.
UK encryption dispute leaves Apple users with two-tier iCloud protection
A technical article reports that Apple withdrew Advanced Data Protection for new UK users in February 2025 after a reported UK government demand concerning access to strongly encrypted iCloud data. Existing users who enabled the feature remain differently protected.
The article explains that Advanced Data Protection extends end-to-end encryption to categories including iCloud Backup, Photos, Notes, and iCloud Drive. Apple does not hold the decryption keys for that protected data, and its servers reportedly cannot change the setting on a user’s behalf.
The result is uneven encryption coverage among UK customers. The supplied evidence is an opinion article and does not include primary confirmation of the reported notice or tribunal proceedings.
Liquid AI releases experimental LFM2.5-VL-DSpark drafter
Liquid AI has released LFM2.5-VL-DSpark, an experimental DSpark draft model for LFM2.5-VL-3B. It adds a speculative decoding path intended to improve vision-language inference without changing verified output quality.
The drafter uses tapped hidden states from the target model to propose blocks of candidate tokens. It contains approximately 280 million parameters, or 8.9% of the target, and is supported by llama.cpp, MLX-VLM, and SGLang.
Liquid AI reports decoding speedups up to 3.13x on an M5 Max and 2.66x on an H100. Because speculation does not accelerate vision encoding or prefill, end-to-end gains depend on workload and hardware.
NVIDIA article details MJWarp GPU scaling for robotics simulation
NVIDIA’s published article presents a workflow for moving a compatible MuJoCo scene to MuJoCo Warp (MJWarp), using NVIDIA Warp to run batched physics on NVIDIA GPUs. The example scales an SO-101 pick-and-place environment to as many as 2,048 parallel worlds.
The migration preserves MJCF models while replacing CPU stepping with device-resident batched state and mjw.step. The article covers one-world parity validation, contact and constraint capacity sizing, CUDA Graph capture, warm-up, synchronization, and throughput measurement.
The workflow targets aggregate simulation throughput for reinforcement-learning and sampling workloads, not single-world latency. It does not train a policy, and measurements remain dependent on hardware, scene settings, and batch size.
Well-Typed releases Eventlog Live for Haskell telemetry
Well-Typed has released Eventlog Live 0.10.0.0, a program for streaming real-time telemetry from Haskell applications. It analyzes GHC eventlogs and exports data through the OpenTelemetry protocol to platforms such as Grafana Cloud and Prometheus, or to local viewers.
The release supports heap profiles, memory metrics, cost-centre stack profiles, logs, productivity, and thread and capability traces. It runs alongside an application and requires the -threaded and -rtsopts build options; telemetry aggregation and export intervals are configurable.
Eventlog Live has no published built-in viewer yet, and some heap-profile breakdowns need additional support. Its control protocol and REST API are disabled by default behind +control.
WordPress releases Trac MCP server for AI-assisted ticket research
WordPress has announced a public, free Model Context Protocol server for querying WordPress Trac. It connects to Claude, ChatGPT, Claude Code, and other MCP clients without requiring an account or API key.
The server exposes tools including searchTickets, getTicket, getChangeset, getTimeline, and getTracInfo. Results can include ticket discussions, attachments, related changesets, and linked GitHub pull requests with checks and reviews. It supports Core, Meta, Themes, Plugins, bbPress, BuddyPress, GlotPress, and GSoC Tracs.
The announcement includes client connection instructions and links the implementation to WordPress/trac-mcp. It does not provide architecture, performance, adoption, or operational-scale measurements.
Wordfence reports 358 WordPress vulnerabilities for September 14–20
Wordfence’s weekly report covers vulnerabilities disclosed from September 14 through September 20, 2026. It reports 358 vulnerabilities added to the Wordfence Intelligence Vulnerability Database across 243 WordPress plugins and four themes.
The report also says that 184 vulnerability researchers contributed to WordPress security during the week. These figures describe disclosure and research activity at an aggregate level.
The supplied material does not identify individual vulnerabilities, affected versions, severity, exploitability, fixes, or remediation steps. Maintainers and site operators therefore need separate advisories to determine whether a specific installation requires action.
WordPress unifies 2027 flagship event budgets with a live rollup
WordPress has provided four 2027 flagship WordCamp organizing teams with separate budget files connected to a central rollup. The templates are being reviewed by the teams, making the workflow an in-progress first version.
Each file preserves local currency, line items, and working practices while exposing an identical summary tab. The rollup imports actual dollar spending from the accounting ledger, maps budget lines to account names, and uses optional due dates to create a monthly cash calendar across all events.
This gives central oversight of payment timing without requiring teams to re-enter ledger data or change their budgeting process. Results from a full cycle are not yet available.
Datasette 1.0a41 adds OpenTelemetry and shared modal Web Component
Datasette 1.0a41 is presented as a release adding OpenTelemetry support. The update also refactors Datasette’s modal dialogs into a single Web Component.
The release note says this component is documented for other plugins to use, making the modal implementation a shared integration surface for the Datasette plugin ecosystem.
The supplied material does not explain OpenTelemetry configuration, the component’s API, compatibility with existing plugins, or migration requirements. Engineers should consult the project’s detailed documentation before adopting either change.
WordPress 7.0.6 is tagged in the official repository
The official WordPress wordpress-develop repository records version 7.0.6 as a tagged release. The tag was created by johnbillion on September 22, 2026, and points to commit ec455a5.
The supplied release page contains repository metadata and the tag identifier, but no release notes, implementation details, fixes, or migration instructions. It therefore confirms the version-tag event without explaining what changed.
WordPress maintainers and operators can use the tag to track the released core version. Further assessment requires documented change details or commit-level information, which are not included in the supplied evidence.