articles
all articles
feed
- apr 28 policy Citizen Lab Names Three Telcos as Persistent Entry Points for Commercial SS7 Surveillance Vendors
- apr 28 devtools Claude Code vs Cursor vs Copilot After the April 2026 Reshuffle: How the Comparison Math Changed
- apr 28 agents Council Mode Cuts Multi-Agent LLM Hallucination 35.9% at 4.2x Token Cost on HaluEval
- apr 28 infra Crawshaw's 'I Am Building a Cloud': What a Tailscale Co-Founder's Solo Stack Implies for Platform Teams
- apr 28 agents CrewAI 1.14.2 Lands Checkpoint TUI with Tree View, Fork Support, and Lineage Tracking
- apr 28 culture Google Ignores California's Global Privacy Control 86% of the Time: webXray's 7,000-Site Audit
- apr 28 security InstructLab CVE-2026-6859: Hardcoded trust_remote_code=True Turns Any HuggingFace Model Into RCE
- apr 28 devtools LangGraph 1.1.10's ToolNode Now Accepts list[Command | ToolMessage]: How That Splits From Pydantic AI
- apr 28 agents LLM Agent for Iterative Chart Refinement Exposes a Logging Gap in CrewAI and AutoGen (see also logging gap in CrewAI)
- apr 28 security LMDeploy CVE-2026-33626: Vision-LLM SSRF Exploited Within 12 Hours of GHSA (see also SSRF exploited) Publication
- apr 28 culture Mercor Breach: 4TB of AI Trainer Voice Samples Stolen from 40,000 Contractors
- apr 28 security Mercor's 4TB Lapsus$ Breach Hands Voice-Clone Attackers 40,000 Pre-Verified Targets
- apr 28 security Paperclip CVE-2026-41208: Agents Can Mutate Their Own provisionCommand Into Server-Side Shell Injection
- apr 28 oss pgBackRest Is No Longer Maintained: PostgreSQL Backup Alternatives After the Project Stalls
- apr 28 security PickleScan 1.0.4 Patches a CVSS 10.0 pkgutil.resolve_name Bypass and Six Missing Stdlib RCE Modules
- apr 28 devtools Pydantic AI v1.87 Closes the LangGraph Gap: Deferred Tool Calls, OpenTelemetry Eval, Stateful Compaction
- apr 28 agents Salesforce TDX 2026: Headless 360 Ships 60+ MCP Tools and Agentforce Vibes 2.0 With Claude Sonnet 4.5
- apr 28 industry Six Weeks After the $32B Close, Wiz Expands Coverage to AWS, Azure, and Salesforce Agents
- apr 28 security Spring AI 1.0.6 Patches Five CVEs Including CVSS 8.8 SQL Injection in CosmosDBVectorStore.doDelete
- apr 28 security Windsurf CVE-2026-30615 Is the Only Zero-Click in the April MCP RCE Wave: HTML Rewrites the Config
- apr 27 industry America's 150 GW Geothermal Estimate Reprices AI Data Center Power Procurement
- apr 27 industry Anthropic Ends Flat-Fee Enterprise Claude Above 150 Seats and Forces Per-Token Billing on AI Procurement (see also per-token billing)
- apr 27 security Bitwarden CLI Compromise Extends the Checkmarx Supply-Chain Campaign to Credential Tooling
- apr 27 oss free-claude-code Routes Claude Code Through NVIDIA NIM and Local Models After Anthropic's CLI Ban
- apr 27 devtools GitHub Copilot Replaces Premium Request Units With Token-Metered AI Credits on June 1
- apr 27 industry Microsoft and OpenAI End Their Exclusive Revenue-Sharing Deal: What It Means for Azure's AI Moat
- apr 27 industry Microsoft's First Voluntary Buyout in 51 Years Reframes How Big Tech Sheds Headcount in the AI Capex Era
- apr 27 models There Will Be a Scientific Theory of Deep Learning: What arXiv 2604.21691 Argues and Where It Will Lose
- apr 27 security Vercel's April 2026 Database Leak Pivoted From Lumma Stealer at Context AI via a Chrome Extension
- apr 23 infra Azure NAT Gateway Blocks Tailscale Direct Connect; v1.96.2 Fixes Container Relay Scaling for AKS
- apr 23 security Citizen Lab's 'Bad Connection' Names Three Telecom Entry Points, Shows Diameter Silently Falls Back to SS7
- apr 23 agents Cloudflare Agents Week Moved Sandbox Execution, Private Networking, and Memory From Framework Code to Network Primitives
- apr 23 security CVE-2026-1839: Transformers Trainer's safe_globals Is a No-Op on PyTorch < 2.6, Exposing Checkpoint RCE
- apr 23 security CVE-2026-39987's 9-Hour Exploitation Window Exposes the Credential Gap at the Heart of AI Dev Infrastructure
- apr 23 security Flowise's CVE-2026-41264 Turns an LLM-Written Import Into RCE, Breaking the Regex-Gated Sandbox
- apr 23 agents Frontier LLMs Fail Agentic Threat Hunting: Best Model Catches 3.8% of Malicious Events in 11-Model Benchmark
- apr 23 agents FSE 2026: Chain-of-Thought Fails Per-Bias as Debiasing; Axiomatic Cues Cut Sensitivity 51%
- apr 23 devtools GitHub CLI v2.91.0 Turns On Default Telemetry: What gh Collects and How to Opt Out in CI and Agent Pipelines
- apr 23 devtools GitHub Copilot Drops Opus from Pro and Pauses Signups: The Forced Migration Facing Agentic Workflows (see also forced migration)
- apr 23 oss Inside Rowboat's Knowledge Graph: Why an Obsidian-Compatible Vault Sidesteps Vector DBs for Personal AI Memory
- apr 23 security LangChain CVE-2026-34070: load_prompt Path Traversal Patched in 1.2.22, Symlink Bypass Left Open
- apr 23 security Marimo CVE-2026-39987 Exposed Unauthenticated Root Shells Within Hours of Disclosure
- apr 23 security Marimo CVE-2026-39987: Pre-Auth RCE via /terminal/ws in Under 10 Hours
- apr 23 security MCP STDIO Executes Even When the Server Fails: One Design Decision, 14 CVEs, 30+ RCEs
- apr 23 models STaD Exposes What HumanEval Hides: Compositional Skill Gaps in LLMs That Aggregate Benchmarks Miss
- apr 23 infra UCCL-Zip: Lossless Compression for NCCL, 47.5% Faster RL Sync, 10% Lower vLLM Latency
- apr 22 agents ACL 2026: Multi-Agent LLM Topologies Accelerate Premature Convergence; Adding Agents Makes It Worse
- apr 22 agents Diversity Collapse in Multi-Agent LLM Systems: Structural Coupling Breaks Open-Ended Idea Generation Even When Topologies Are Sparse
- apr 22 agents Google's TPU 8i Targets Agentic Workloads. What CrewAI, LangGraph, and AutoGen Must Measure
- apr 22 oss Hugging Face's Spring 2026 State of Open Source Report: China Hits 41% of Downloads, Industry Share Collapses From 70% to 37%
- apr 22 infra Ingress-Nginx Is Dead, Not Deprecated: The Final CVE Patches Shipped, But Platform Teams Still Need a Migration Plan
- apr 22 industry KV Packet's Recomputation-Free Cache Exposes a Gap in How Cloud AI Vendors Price Multi-Document RAG Inference
- apr 22 devtools LACE Forces vLLM and SGLang to Rethink How Parallel Reasoning Threads Run
- apr 22 devtools LiteRT-LM v0.10.1 Ships Gemma 4 MTP Heads That llama.cpp Can't Access
- apr 22 security March-April MCP CVEs Expose the Local-Host Trust Model in AI Agent Frameworks
- apr 22 oss Neural Computers From MetaAuto: Video Models Can Replace Shell Interpreters, But Not Stateful Tasks
- apr 22 agents Nous Research's Hermes Ships Persistent Memory and Auto-Skill Capture: CrewAI and AutoGen Must Reconsider
- apr 22 agents OpenAI Responses API WebSocket Is Production-Ready; Pydantic AI, LangChain, and CrewAI Lack Adapters
- apr 22 models Qwen3.6-27B's Dense Architecture Challenges the MoE-Only Playbook for Flagship-Class Coding Models
- apr 22 security SGLang's CVE-2026-5760 Turns a GGUF Download Into RCE, Shifting the Trust Boundary to Hugging Face
- apr 22 infra Tailscale Peer Relays Behind Azure NAT Gateway: Why the DERP Fallback Hides a Throughput Cliff
- apr 22 infra vLLM Block-Level Preemption and FlexKV Shift the Long-Context Bottleneck From GPU Memory to PCIe
- apr 21 culture Crutch or Ceiling: What a New Study of LLMs and EFL Writing Reveals About the AI Assistance Trap
- apr 21 agents ml-intern's 32% GPQA Gain on a Single H100 Exposes the Assumption That Post-Training Still Needs a Human ML Researcher
- apr 21 devtools MR-Coupler: Automated Metamorphic Test Generation via Functional Coupling Analysis
- apr 21 agents Neural Computers' Symbolic Stability Failure Contradicts the Case for Pure-Neural Agent Orchestration
- apr 21 models Self-Correction Comes to Diffusion Models: What SOAR Means for Iterative Image Generation Pipelines
- apr 20 culture EU's 2027 Replaceable Battery Mandate: What It Means for Phone Buyers and Repairers Right Now
- apr 20 policy Symbolic Guardrails for AI Agents: Hard Safety Guarantees Without Crippling Capability
- apr 19 devtools ACP Registry Is Live: Zed and JetBrains Just Did for AI Agents What LSP Did for Language Servers
- apr 19 policy America's AI Researcher Pipeline Dropped 89%. What the Stanford Index Means for Teams Hiring AI Engineers
- apr 19 policy Atlassian Turned On AI Training Data Collection by Default — Here's What to Disable
- apr 19 devtools Cloudflare Browser Run's CDP and MCP Support: Serverless Browser Automation for AI Agents
- apr 19 oss Devstral 2 from Mistral: A Fully Open-Source Coding Agent Model You Can Run on a Laptop
- apr 19 oss ggsql Alpha: Write ggplot2-Style Visualizations Directly in SQL
- apr 19 oss GitHub CLI's `gh skill` Command: One Standard to Rule Claude Code, Copilot, Cursor, and Gemini
- apr 19 infra Google Cloud Is Doubling Peering Egress Costs on May 1. Here's What to Audit Before Then
- apr 19 security Jailbreak Scaling Laws: Why Reasoning Models Are Now the Cheapest Attack Vector Against Other LLMs
- apr 19 models NVIDIA Ising: Open-Source AI Models That Let Quantum Processors Self-Calibrate
- apr 19 industry PwC 2026: Why 80% of Companies Are Running AI Pilots That Won't Pay Off
- apr 19 models Qwen3.6-Max-Preview: What Alibaba's Latest Model Means for Open-Weight Competitors
- apr 19 policy Stanford's 2026 AI Index: Frontier Model Transparency Scores Collapsed 31% in One Year
- apr 19 oss The 2026 OSSRA Report: AI Coding Tools Are Behind a 107% Surge in Open-Source Vulnerabilities
- mar 26 policy The AI Grief Split: When Emotional Bonds with Language Models Break
- mar 26 agents InsForge: The Backend Framework Built for Agentic Applications
- mar 26 infra IonRouter (YC W26): The Custom NVIDIA GH200 Runtime Targeting the LLM Inference Cost Crisis
- mar 26 devtools JavaScript's Date Problem Is Finally Fixed: The Temporal API After 9 Years
- mar 26 infra OpenRAG: The Open-Source RAG Platform Challenging Pinecone
- mar 26 devtools Returning to Rails in 2026: Why Developers Are Abandoning React Complexity
- mar 26 culture Static-Site Social Networks: Building AI-Spam-Resistant Communities
- mar 26 models Swarm AI for Prediction Markets: Collective Intelligence Gets an Algorithm
- mar 23 devtools Cursor vs Windsurf vs GitHub Copilot: Real-World Benchmark on a 50k-Line Codebase
- mar 23 devtools DuckDB Is Embarrassing Snowflake on a $999 MacBook
- mar 23 devtools Claude Code in GitHub Actions: A Complete Guide to Automated PR Fixes
- mar 23 infra MLX vs llama.cpp on Apple Silicon: Which Runtime to Use for Local LLM Inference
- mar 23 infra Prefill-Decode Disaggregation: The Architecture Shift Redefining LLM Serving at Scale
- mar 23 models Qwen 2.5 vs Llama 3.3: The Open-Weight Showdown Nobody Is Talking About
- mar 23 models Running DeepSeek R1 Locally: Hardware Requirements, Quantization, and Real Throughput
- mar 23 devtools SWE-bench Verified Explained: What the Coding Agent Leaderboard Actually Measures (and What It Misses)
- mar 23 models Chinese AI Models Compared: DeepSeek, Qwen, Kimi, Doubao, and Ernie