News

  1. SplitVPN - 865,336 breached accounts (haveibeenpwned.com)
  2. Gemini 2.5 Pro and Gemini 3 Flash deprecated (github.blog)
  3. Enterprise teams model policy targeting in public preview (github.blog)
  4. Restricting npm bypass-2FA granular access tokens (github.blog)
  5. Modeling Device Capabilities for Analytics (netflixtechblog.com)
  6. Don’t stop early: Case-folding source code at memory speed (github.blog)
  7. From generated code to trusted code with a unit-test agent (devblogs.microsoft.com)
  8. An API for MoQ: provision your own isolated relays (blog.cloudflare.com)
  9. GenRec: Towards LLM-Native Recommendation at Netflix (netflixtechblog.com)
  10. GitHub Models is now retired (github.blog)
  11. Reference same-repository actions with self-repository syntax (github.blog)
  12. Stacked sessions and pull requests in the GitHub Copilot app (github.blog)
  13. Under the Hood: Serving Kimi K3 (www.digitalocean.com)
  14. Stacked pull requests are now in public preview (github.blog)
  15. GitHub Copilot in Visual Studio — July update (github.blog)
  16. Limit remote control to managed devices (github.blog)
  17. Adform compromised to serve crypto stealer via supply chain attack (doublepulsar.com)
  18. Dogfooding at scale: migrating cdnjs to Cloudflare’s Developer Platform (blog.cloudflare.com)
  19. GitHub Copilot in Visual Studio Code, July 2026 releases (github.blog)
  20. Secure at Inception: Announcing the Snyk Studio Integration for Snowflake Cortex Code (snyk.io)
  21. The Attacker Never Sleeps, Neither Can Your Testing (snyk.io)
  22. Copilot code review: Agent skills and MCP now generally available (github.blog)
  23. Tame Dependabot: Group your updates, slow the cadence, keep security fast (github.blog)
  24. Post-quantum authentication to origins is now supported (blog.cloudflare.com)
  25. Making forensic observability the norm for network devices (www.ncsc.gov.uk)
  26. Stadium Summer: The Snyk Connect Fan Zone Tour (snyk.io)
  27. Announcing v2.0 of the official MCP C# SDK (devblogs.microsoft.com)
  28. Disrupting supply chain attacks on npm and GitHub Actions (github.blog)
  29. Natural disasters and government interference: examining Q2 2026’s major Internet disruption events (blog.cloudflare.com)
  30. When cyber attacks happen: helping organisations recover (www.ncsc.gov.uk)
  31. Bringing the global Bebras community together in Cambridge (www.raspberrypi.org)
  32. Houston City College - 831,642 breached accounts (haveibeenpwned.com)
  33. The Generator Can't Be the Validator: What OpenAI's Hugging Face Incident Proves About AI Security (snyk.io)
  34. The harness is all you need (mostly) (github.blog)
  35. Analyze MSBuild Binary Logs with Copilot in VS Code (devblogs.microsoft.com)
  36. GitHub Copilot app for Beginners: Getting started (github.blog)
  37. We’re open-sourcing our privacy proxy CLI (blog.cloudflare.com)
  38. What Is AI Pentesting and How Does It Work? (snyk.io)
  39. Weekly Update 514: This Week in Data Breaches (troyhunt.com)
  40. BGP ORIGIN attribute manipulation and its impact on the Internet (blog.cloudflare.com)
  41. Session Replay for Unreal Engine: see the crash before the crash (blog.sentry.io)
  42. Outperforming Fable 5 at half the price: meet model synthesis, a new server-side tool on DigitalOcean Inference Engine (www.digitalocean.com)
  43. Introducing Cache Response Rules (blog.cloudflare.com)
  44. The case for a cooldown: Why Dependabot now waits before issuing version updates (github.blog)
  45. UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations (www.ncsc.gov.uk)
  46. From 57 bugs to 1, thanks to Seer (blog.sentry.io)
  47. From one club to a global movement: Celebrating 15 years of CoderDojo! (www.raspberrypi.org)
  48. Exercises in benchmarking and evals, part 7: DeepSWE, Senior SWE-Bench, napkin math, and winter tires (danluu.com)
  49. Tails 7.10 (tails.net)
  50. 5 Software Architecture Mistakes That Make Systems Hard to Change (codeopinion.com)
  51. Copilot vs. raw API access: What are you actually paying for? (github.blog)
  52. Next chapter: Restructuring GitHub’s bug bounty program (github.blog)
  53. Post-quantum cryptography (PQC) migration workshop report (www.ncsc.gov.uk)
  54. .NET support for Godot is now generally available (blog.sentry.io)
  55. We Wrote an Academic Paper on Conficker in 2026 (tisiphone.net)
  56. How to build interactive experiences with canvases (github.blog)
  57. How the 2026 World Cup affected Internet traffic (blog.cloudflare.com)
  58. Robots, games, AI, and more at Coolest Projects UK 2026 (www.raspberrypi.org)
  59. How to structure a log (blog.sentry.io)
  60. Weekly Update 513: Clauding The Home Network (troyhunt.com)
  61. Upcoming GPU Pricing Updates (www.digitalocean.com)
  62. Cloudflare Internal DNS is now generally available (blog.cloudflare.com)
  63. Suno - 55,282,226 breached accounts (haveibeenpwned.com)
  64. MongoDB Query Tracing in .NET with Sentry + OTLP (blog.sentry.io)
  65. Sign Commits from Anywhere Without Your Keys Going Anywhere (haacked.com)
  66. Paidwork - 23,272,765 breached accounts (haveibeenpwned.com)
  67. Preventing line breaks in <code> elements (alexwlchan.net)
  68. Fixing a bug with byte order marks (alexwlchan.net)
  69. In-House LLM Serving at Netflix (netflixtechblog.com)
  70. Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities (blog.cloudflare.com)
  71. Announcing .NET Modernization for Beginners (devblogs.microsoft.com)
  72. Your agent should understand what you see (blog.sentry.io)
  73. Building education technology that children can trust (www.raspberrypi.org)
  74. Exploring Hierarchical Interest Representation For Meta Ads Deep Funnel Optimization (engineering.fb.com)
  75. Helping small businesses with free, hands-on cyber consultancy (www.ncsc.gov.uk)
  76. Fluke - 821,100 breached accounts (haveibeenpwned.com)
  77. Goose Creek - 6,574,121 breached accounts (haveibeenpwned.com)
  78. Weekly Update 512: IoT Lockout Fail (troyhunt.com)
  79. .NET and .NET Framework July 2026 servicing releases updates (devblogs.microsoft.com)
  80. CoreCLR Progress and the Mono Timeline for .NET MAUI (devblogs.microsoft.com)
  81. .NET 11 Preview 6 (github.com)
  82. .NET 11 Preview 6 is now available! (devblogs.microsoft.com)
  83. A broken DNSSEC rollover took down .al. Now 1.1.1.1 tells you when validation is bypassed (blog.cloudflare.com)
  84. AI literacy begins with data literacy: An example from healthcare (www.raspberrypi.org)
  85. Building Service Topology at Scale: Architecture, Challenges, and Lessons Learned (netflixtechblog.com)
  86. A Git hook to prevent committing directly to main (alexwlchan.net)
  87. Modernizing the Meta Ads Service With an Open-Source Kernel Scheduler (engineering.fb.com)
  88. Hello World #30 out now: Critical thinking in the age of AI (www.raspberrypi.org)
  89. Introducing Precursor: detecting agentic behavior with continuous client-side signals (blog.cloudflare.com)
  90. UK and Allies urge critical sectors to improve defences against Russian intelligence targeting (www.ncsc.gov.uk)
  91. Mypy 2.3 Released (mypy-lang.org)
  92. Glendale Community College - 793,925 breached accounts (haveibeenpwned.com)
  93. Empowering global AI literacy: Translating Experience AI resources into Croatian (www.raspberrypi.org)
  94. Improving Smart Tiered Cache for Public Cloud Regions (blog.cloudflare.com)
  95. Enhancing your enrichment offer? Code Club is the answer (www.raspberrypi.org)
  96. Scale Faster with Managed Weaviate: Now in Public Preview on DigitalOcean (www.digitalocean.com)
  97. Modernize .NET applications in the GitHub Copilot app (devblogs.microsoft.com)
  98. Why we cannot wait for better post-quantum signature algorithms (blog.cloudflare.com)
  99. Cyber Essentials Pathways: from proof of concept to cyber confidence (www.ncsc.gov.uk)
  100. When and what should I be logging? (blog.sentry.io)
  101. Symlinks Are Still Scary (And Yes, You Can Commit Them to Git) (snyk.io)
  102. Connection Allowlist: a network firewall, built into the browser (scotthelme.co.uk)
  103. Multi-Tenancy Isn’t About Databases (codeopinion.com)
  104. Weekly Update 511: Live from my Riad in Marrakech (troyhunt.com)
  105. Introducing Meerkat: an experiment in global consensus (blog.cloudflare.com)
  106. Mypy 2.2 Released (mypy-lang.org)
  107. How to publish to PyPI using GitHub Actions securely (snarky.ca)
  108. Joy in learning computer science with Experience CS (www.raspberrypi.org)
  109. Cloudflare proudly joins the UK government's Cyber Resilience Pledge (blog.cloudflare.com)
  110. Cyber Shield: The path to an agentic AI future for cyber defence (www.ncsc.gov.uk)
  111. Introducing the Cloud Challenge Book 2026 (technology.blog.gov.uk)
  112. Getting Started with Anchor Positioning (www.joshwcomeau.com)
  113. Your Worker can now have its own cache in front of it (blog.cloudflare.com)
  114. Describing all my photos (alexwlchan.net)
  115. Moody Bible Institute - 2,303,416 breached accounts (haveibeenpwned.com)
  116. I don’t want to repeat repeat myself (alexwlchan.net)
  117. Swimming Pools, Pee, and Trying to Delete Your Data From the Internet (troyhunt.com)
  118. Agentic test processes, LLM benchmarks, and other notes on agentic coding from Galapagos Island (danluu.com)
  119. Process names: The forgotten Observability channel (theorangeone.net)
  120. Connecting government and academia: Responsible AI Through Cloud Technology event (technology.blog.gov.uk)
  121. Built for Mass Scale: Hard-Won Lessons from Teams Running High Volume Inference Workloads in Production (www.digitalocean.com)
  122. Any Apple update can break our app. Here's how we find out first. (blog.sentry.io)
  123. Meta’s AI Storage Blueprint at Scale (engineering.fb.com)
  124. DigitalOcean Evaluations: Production Model and Router Testing for the Inference Stack (www.digitalocean.com)
  125. Making AI search smarter (blog.cloudflare.com)
  126. Your site, your rules: new AI traffic options for all customers (blog.cloudflare.com)
  127. Building more resilient CNI: what industry pen testers told us (www.ncsc.gov.uk)
  128. Top 1 Million Analysis – June 2026: The State of Crypto (scotthelme.co.uk)
  129. Reading the agent traces is how you make the call your eval can't (blog.sentry.io)
  130. Unmasking the crawls with Attribution Business Insights (blog.cloudflare.com)
  131. Tails 7.9.1 (tails.net)
  132. MCP Beyond the Chat Window: Build Diagnostics in CI (devblogs.microsoft.com)
  133. 10 Years of Meta’s Commitment to Python (engineering.fb.com)
  134. Weekly Update 510: Live From Mallorca with Scott Helme (troyhunt.com)
  135. .NET 8 and .NET 9 will reach End of Support on November 10, 2026 (devblogs.microsoft.com)
  136. WSL container is now available for public preview (devblogs.microsoft.com)
  137. Top 1 Million Analysis – June 2026: Ten Years of Web Security (scotthelme.co.uk)
  138. GenPage: Towards End-to-End Generative Homepage Construction at Netflix (netflixtechblog.com)
  139. Next.js already traces your requests. Here's how to export them with OpenTelemetry. (blog.sentry.io)
  140. Rebuilding the computer room (alexwlchan.net)
  141. Snyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice? (snyk.io)
  142. Sysco - 2,691,852 breached accounts (haveibeenpwned.com)
  143. American Tower - 216,601 breached accounts (haveibeenpwned.com)
  144. Privacy-Aware Infrastructure in the AI-Native Era: An Asset Classification Case Study (engineering.fb.com)
  145. Run Codex in the cloud – DigitalOcean for Codex is now available (www.digitalocean.com)
  146. Celebrating over 15,000 young creators at the Coolest Projects 2026 online showcase (www.raspberrypi.org)
  147. NVD in the AI Era: The Case for Multi-Source Vulnerability Intelligence (snyk.io)
  148. Why I wrote PEP 832 -- virtual environment discovery (snarky.ca)
  149. Resilience Patterns Can Make Your System Less Resilient (codeopinion.com)
  150. A dead CDN, a wildcard, and an attack waiting to happen: the netdna-ssl.com takeover (scotthelme.co.uk)
  151. Madison Square Garden Sports - 9,796,738 breached accounts (haveibeenpwned.com)
  152. A Note to Our Customers and Partners (snyk.io)
  153. Weekly Update 509 (troyhunt.com)
  154. How Meta Engineered Ultra-Narrow Batteries for AI Glasses (engineering.fb.com)
  155. The New Security Control Point: Governing AI Agents Inside the Execution Loop (snyk.io)
  156. What nearly 10,000 developer environments reveal about agentic development risk (snyk.io)
  157. Announcing Agentic Development Security (ADS) (snyk.io)
  158. When a vendor's breach becomes yours: lessons from the Klue incident (snyk.io)
  159. Toward More Controllable AI Video Editing: An Early Research Exploration at Netflix (netflixtechblog.com)
  160. Every Choice Changes Everything: The Show (blog.codinghorror.com)
  161. How Netflix Simplified Batch Compute with Kueue (netflixtechblog.com)
  162. Adopting AV1 for Real-Time Communication (RTC) at Scale (engineering.fb.com)
  163. Why No Passkeys? Naming the Top Sites That Still Don't Support Them (scotthelme.co.uk)
  164. The AI shift in cyber risk: why leaders must act now (www.ncsc.gov.uk)
  165. A developer toolkit to make your website agent-ready (developer.chrome.com)
  166. Modern CSS theming with light-dark(), contrast-color(), and style queries (una.im)
  167. What can wonky APIs tell us about the web? (alexwlchan.net)
  168. JCPenney - 368,418 breached accounts (haveibeenpwned.com)
  169. The Data Canary: How Netflix Validates Catalog Metadata (netflixtechblog.com)
  170. Data Projects: Managing Data Assets at Netflix Scale (netflixtechblog.com)
  171. Predicting Risk in Content Launches: How Data-Driven Insights can Transform Launch Planning (netflixtechblog.com)
  172. An update on FortiBleed — what’s happening with victim orgs (doublepulsar.com)
  173. There Are No Instances in atproto (overreacted.io)
  174. Ralph Lauren - 139,903 breached accounts (haveibeenpwned.com)
  175. Operation Endgame 4.0 - 4,348,526 breached accounts (haveibeenpwned.com)
  176. Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways (www.ncsc.gov.uk)
  177. The 'vibe coding spectrum' approach to AI-assisted software development (www.ncsc.gov.uk)
  178. Unlock runtime insights: Introducing third-party developer tools for Chrome DevTools for agents (developer.chrome.com)
  179. The full Snyk AI Security Platform, free for open source maintainers (snyk.io)
  180. CFGI - 248,235 breached accounts (haveibeenpwned.com)
  181. Tails 7.9 (tails.net)
  182. Intelligent Terminal 0.1.1 is here: bash support, new slash commands, and more customization (devblogs.microsoft.com)
  183. Server-Side Tools Are Now Available for DigitalOcean Inference Engine (www.digitalocean.com)
  184. Stop Blaming Event-Driven Architecture (codeopinion.com)
  185. FortiBleed — 75k Fortinet firewalls have admin passwords cracked (doublepulsar.com)
  186. NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK's critical systems (www.ncsc.gov.uk)
  187. What's New in WebGPU (Chrome 149-150) (developer.chrome.com)
  188. A Day in the Life of an AI Engineer in Snyk's Lisbon Office (snyk.io)
  189. A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope (snyk.io)
  190. June 2026 Stealer Logs - 56,278,397 breached accounts (haveibeenpwned.com)
  191. The Instructure Canvas Breach (2026): How XSS in a Support Ticket Compromised 275 Million Students (scotthelme.co.uk)
  192. Weekly Update 508 (troyhunt.com)
  193. Berkadia - 305,216 breached accounts (haveibeenpwned.com)
  194. Infinite Campus - 137,123 breached accounts (haveibeenpwned.com)
  195. The Government Just Banned an AI Model. An Engineer's Perspective. (snyk.io)
  196. When a Government Pulls an AI Model: What the Fable 5 and Mythos 5 Suspension Means for Security Teams (snyk.io)
  197. Better, faster, less wrong: Enhancing issue grouping (blog.sentry.io)
  198. Catch visual regressions with Snapshots, now in beta (blog.sentry.io)
  199. University of Nottingham - 454,635 breached accounts (haveibeenpwned.com)
  200. The Inference Alpha: Maximizing Frontier Models on AMD (www.digitalocean.com)
  201. Solving the ‘God Object’ Problem with Shared Identity (codeopinion.com)
  202. PowerToys 0.100 is here: new Shortcut Guide, Command Palette improvements and much more! (devblogs.microsoft.com)
  203. Weekly Update 507 (troyhunt.com)
  204. What We Learned Hiring 33 Engineers in Two Weeks (www.digitalocean.com)
  205. .NET 11 Preview 5 (github.com)
  206. Join the WebMCP origin trial (developer.chrome.com)
  207. Open-Sourcing dbsc-php: a Server Library for Device Bound Session Credentials in PHP (scotthelme.co.uk)
  208. Works on my machine: how we use AI to reproduce reported bugs (blog.sentry.io)
  209. Using the Screen Capture API to record a browser window (alexwlchan.net)
  210. Baker Distributing - 102,935 breached accounts (haveibeenpwned.com)
  211. DBSC Beta at Report URI (scotthelme.co.uk)
  212. Errors, traces, logs, metrics: when to reach for what (blog.sentry.io)
  213. Using Pytester to test my Playwright fixtures (alexwlchan.net)
  214. Firewalling Docker with nftables (theorangeone.net)
  215. Model Evaluations: Prove Your Routing Policy Actually Works (www.digitalocean.com)
  216. Software supply chain attacks: check your dependencies (www.ncsc.gov.uk)
  217. Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp (snyk.io)
  218. So You Have an AI Security Budget. Now what? (snyk.io)
  219. Type Level Security: The future of secure AI code generation? (snyk.io)
  220. Tails 7.8.1 (tails.net)
  221. The Team Behind Deploy: Shipping AI, the DigitalOcean Way (www.digitalocean.com)
  222. Powering the Inference Era: Inside the DigitalOcean Data & Learning Layer (www.digitalocean.com)
  223. Lights Out, Systems On: Validating Instant Power Loss Readiness (engineering.fb.com)
  224. Seamless PWA origin migration: Change domains without losing users (developer.chrome.com)
  225. Chrome 150 beta (developer.chrome.com)
  226. Welcoming the Philippine Government to Have I Been Pwned (troyhunt.com)
  227. The New Security Risks of the Agentic Development Lifecycle (snyk.io)
  228. Modular Monolith Boundaries Done Wrong (codeopinion.com)
  229. Open by Design: How NVIDIA and DigitalOcean Are Building the Stack for the Always-On Agentic Era (www.digitalocean.com)