build1 publisherOne report Google's Chrome 155 decodes JPEG XL natively with jxl-rs, the browser's first complete image decoder written in a memory-safe language. Any site can now serve .jxl images to Chrome without plugins or experimental flags, so the format is a production option for Chrome traffic.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives45
- Confidence55
Pwn2Own Ireland teams logged 32 zero-days and over $368,000 in prizes on October 6, breaking LiteLLM, OpenAI Codex and Oracle's AI database. Vendors now have 90 days to ship fixes before the Zero Day Initiative publishes the details.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence62
build1 publisherOne report Google released an official Swift SDK for more than 100 Cloud services, so teams that build Apple apps can write their servers in Swift too. At version 0.4.0 its maintainers still reserve breaking changes before 1.0, and production readiness is for adopters to establish.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence50
build1 publisherOne report D-Link's DIR-822A firmware A_101 has two critical flaws, scored 9.9 and 10.0, with public proof-of-concept code and no fixed release yet. Until D-Link ships a build, owners are left isolating the router from untrusted networks or planning its replacement.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence40
A time-of-check/time-of-use bug in the library many platforms use to run untrusted JavaScript lets guest code reach the host process. Fixes are in 6.2.0 and 7.0.1, and there is still no CVE.
Reality
- Evidence72
- Adoption62
- Hype gap+12
- Incentives
- Insufficient
- Confidence74
The affected releases stretch back to Next.js 13.4, and for Windows self-hosters the only remedy Vercel offers is the version bump. The AVIF bug shipped in the same release at least has a config gate.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence58
build1 publisherOne report Cloudflare pointed Anthropic's Mythos Preview at more than fifty of its own repositories and watched it write, compile and run its own proofs of exploitability. Its refusals on identical code did not repeat.
Reality
- Evidence34
- Adoption26
- Hype gap+18
- Incentives62
- Confidence44
The maintenance release for the 1.6 branch carries seven fixes with GitHub advisory IDs and six that involve memory corruption. It also lets a running IEC 61850 server take a new TLS configuration.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap−25
- Incentives60
- Confidence66
build1 publisherOne report Jarred Sumner's four-month rewrite checked transpiled Rust against a TypeScript suite that does not depend on the implementation language, and reaching a fully passing run cost about $165,000 in tokens.
Reality
- Evidence57
- Adoption62
- Hype gap+22
- Incentives72
- Confidence63
build1 publisherOne report Bun's port from Zig to Rust landed in four months because its test suite was written in TypeScript, independent of the language underneath, and because separate agents wrote the code and reviewed it.
Reality
- Evidence46
- Adoption62
- Hype gap+22
- Incentives74
- Confidence52
The fixes are already upstream, so the work now is confirming your distribution shipped them before someone with a low-privileged shell on a shared host uses the published code to reach root.
Reality
- Evidence62
- Adoption35
- Hype gap−10
- Incentives35
- Confidence60
build1 publisherOne report A practical dev.to guide sets out the low-level and high-level tracks for writing CUDA kernels in Rust, then demonstrates them with a nightly-only kernel whose body dereferences three raw pointers inside an unsafe function.
Reality
- Evidence25
- Adoption
- Insufficient
- Hype gap+40
- Incentives
- Insufficient
- Confidence60
A year on from the CISA and NSA memory-safety report, the adoption evidence is still provider roadmaps and practitioner judgement about C and C++ code that nobody proposes to rewrite wholesale.
Reality
- Evidence45
- Adoption35
- Hype gap+20
- Incentives70
- Confidence50
build1 publisherOne report CrowdStrike's IPC template declared 21 input fields and the integration code supplied 20, a mismatch that compiled cleanly, and the channel file used in testing skipped that field as well.
Reality
- Evidence70
- Adoption84
- Hype gap−6
- Incentives55
- Confidence72
The industry is still shipping the defect classes CISA has flagged for years. The case that AI coding assistants will multiply them comes from two named practitioners, not from the agency's own data.
Reality
- Evidence55
- Adoption30
- Hype gap+35
- Incentives75
- Confidence45
build1 publisherOne report The Dutch NCSC expects mass exploitation attempts on two CVSS 9.8 Check Point VPN flaws that run code before authentication. Both sit in certificate parsing, and one of them reaches the Security Management Server.
Reality
- Evidence46
- Adoption20
- Hype gap+8
- Incentives55
- Confidence44
Onapsis, which found the flaw alongside SAP, rates it CVSS 10.0 and recommends immediate patching. A second kernel note in the same batch reaches every S/4HANA 2025 system and any older release already on a current kernel.
Publishers:onapsis.com
Reality
- Evidence55
- Adoption20
- Hype gap+25
- Incentives75
- Confidence48
build1 publisherOne report V8 says 60% of the Chrome exploits caught in the wild between 2021 and 2023 started in its own code, and that the logic bugs behind them are out of reach of both Rust and memory tagging, so the work went into containment.
Publishers:v8.dev
Reality
- Evidence62
- Adoption35
- Hype gap−10
- Incentives70
- Confidence58
CISA's September 10 advisory says an authenticated user can push Orthanc's image decode past the end of a heap allocation. The stated outcome is a crash, and the only remedy listed is an upgrade to 1.13.0.
Reality
- Evidence66
- Adoption
- Insufficient
- Hype gap−8
- Incentives20
- Confidence58
Google says an exploit exists in the wild for CVE-2026-85046, a type confusion in Chrome's V8 engine, and it is the sixth Chrome zero-day the company has patched under active attack since January.
Perspective Coverage
9 publishers
- Builder
- Builder 25%
- Operator
- Operator 70%
- Investor
- Investor 5%
Reality
- Evidence78
- Adoption52
- Hype gap+8
- Incentives58
- Confidence74