News

  1. GitHub Advanced Security trials for GitHub Team (github.blog)
  2. HydraFusion in VS Code and the GitHub Copilot app (github.blog)
  3. X25519-only TLS ends for GHE.com on October 7 (github.blog)
  4. Cloudflare Impact reaches $100 million in donations (blog.cloudflare.com)
  5. Cut your AI spend with AI Gateway's Auto Router (blog.cloudflare.com)
  6. Detect and send production issues straight to your agent (blog.cloudflare.com)
  7. Simplifying domains for people and agents (blog.cloudflare.com)
  8. Monetization Gateway beta: charge AI agents for consumption with HTTP 402 (blog.cloudflare.com)
  9. Pay Per Use: when AI uses your work, you should get paid (blog.cloudflare.com)
  10. Identify AI model overuse with User Insights (blog.cloudflare.com)
  11. Cloudflare Containers, rebuilt to scale agent sandboxes (blog.cloudflare.com)
  12. The Internet has a second audience (blog.cloudflare.com)
  13. Medela - 423,947 breached accounts (haveibeenpwned.com)
  14. How Etsy gets its mobile apps ready for peak traffic (blog.sentry.io)
  15. What Is Agentic AppSec? (snyk.io)
  16. Evo ADS Govern Agent Behavior Goes GA: Bringing MCP Usage Under Control (snyk.io)
  17. Repository custom runner settings for Dependabot (github.blog)
  18. Bring business context with external custom properties (github.blog)
  19. GPT-6.1 Sol in GitHub Copilot (github.blog)
  20. WSLC Architecture deep dive (devblogs.microsoft.com)
  21. Developer policy update: Transparency, state policy, and what’s ahead (github.blog)
  22. Using AI to chart a course for our post-quantum migration (blog.cloudflare.com)
  23. Building a certificate authority for the whole Internet (blog.cloudflare.com)
  24. Adaptive application security for the AI era: how Cloudflare connects code, traffic, and intelligence to stop attacks (blog.cloudflare.com)
  25. Building a post-quantum certificate authority with Merkle Tree Certificates (blog.cloudflare.com)
  26. We tested our own WAF with frontier AI models. Here’s what we found (blog.cloudflare.com)
  27. Introducing Threat Signals: agentic skills for open-source threat intelligence, free for every Cloudflare account (blog.cloudflare.com)
  28. Is your domain using post-quantum encryption? Now you can see for yourself (blog.cloudflare.com)
  29. Enforce positive security with Cloudflare Application Profiles (blog.cloudflare.com)
  30. Preventing quantum downgrade attacks against IPsec (blog.cloudflare.com)
  31. Big improvements to Seer Agent (blog.sentry.io)
  32. Torchbox Autumn Event 2026 A/V (theorangeone.net)
  33. Self-hosted runner version enforcement date has moved (github.blog)
  34. How we found 24 Android vulnerabilities using our open source AI security agent (github.blog)
  35. Claude Sonnet 5.5 in GitHub Copilot (github.blog)
  36. Highlights from Git 2.56 (github.blog)
  37. Build Agentic UI with the new Blazor AI components (devblogs.microsoft.com)
  38. Introducing cf: the agentic CLI for the entire Cloudflare API (blog.cloudflare.com)
  39. Next.js applications, powered by Vite: introducing Vinext 1.0 (blog.cloudflare.com)
  40. Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway (www.ncsc.gov.uk)
  41. Encouraging learners to think first, prompt second: Using large language models to learn (www.raspberrypi.org)
  42. How DigitalOcean Manages Credentials for Autonomous Agents (www.digitalocean.com)
  43. Weekly Update 523: Live From a Norwegian Fjord (troyhunt.com)
  44. Parametrised tests in Rust with named parameters (alexwlchan.net)
  45. Enterprise managed settings in-product validator (github.blog)
  46. Usage metrics API adds pull request review stages (github.blog)
  47. If we do not stop to help each other, what do we become? (blog.codinghorror.com)
  48. GitHub Copilot app for Beginners: How to build custom workflows with canvases (github.blog)
  49. The agent-first cloud: why we built Managed Agents (www.digitalocean.com)
  50. AG-UI Protocol now has a first-class .NET SDK (devblogs.microsoft.com)
  51. Trading a Cloud Identity for Your Own: Workload Attestation on Managed Compute (netflixtechblog.com)
  52. Improving site performance by shipping more CSS (github.blog)
  53. GDS Local: helping local government buy and use tech better (technology.blog.gov.uk)
  54. When chat is the wrong UI (github.blog)
  55. AI-powered fuzzing with the GitHub Security Lab Taskflow Agent (github.blog)
  56. Multi-Tenant Best Practices Can Backfire (codeopinion.com)
  57. Your Vulnerability Backlog Is No Longer Technical Debt, It’s an Attack Surface (snyk.io)
  58. Bringing Private Processing to Meta AI Glasses (engineering.fb.com)
  59. Measuring the back/forward cache with Application Metrics (blog.sentry.io)
  60. You Own the Outcome: Product Engineering in the Age of AI (kentcdodds.com)
  61. Microsoft is updating its author-signing certificate starting September 23, 2026 (devblogs.microsoft.com)
  62. Rendering huge pull requests in the GitHub Copilot app (github.blog)
  63. Developers want more efficient software. Here’s what over 1,000 GitHub users told us they need. (github.blog)
  64. “We can figure it out”: How one Minnesota teacher uses Experience CS to set the tone for her whole year (www.raspberrypi.org)
  65. Weekly Update 522: Live From Oslo with Scott Helme (troyhunt.com)
  66. Creating a memory dump in C# (devblogs.microsoft.com)
  67. Introducing DigitalOcean Managed Agents: One AI-native stack to power your intelligence (www.digitalocean.com)
  68. Join our new UK study on teaching AI ethics and sustainability in lower secondary school (www.raspberrypi.org)
  69. LimeLeads - 17,838,396 breached accounts (haveibeenpwned.com)
  70. So I asked my agent instead… (snyk.io)
  71. Helix: The internal tool powering our Shopify app's native migration (shopify.engineering)
  72. Open-Sourcing Rebalancer: A Generic, High-Performance Library for Solving Assignment Problems (engineering.fb.com)
  73. Burger King Russia - 3,155,792 breached accounts (haveibeenpwned.com)
  74. Inside Petal: Building the World’s First Petabit-Class Transoceanic Subsea Cable (engineering.fb.com)
  75. One does not simply defend agentically (www.ncsc.gov.uk)
  76. Building Sentry's Laravel AI Integration (blog.sentry.io)
  77. Windows Exploitation Techniques: Dangling COM Object Registrations (googleprojectzero.blogspot.com)
  78. Leave the Class Path in the Rearview Mirror (netflixtechblog.com)
  79. Should you read the code, is RAG dead, and did Skills kill MCP? (github.blog)
  80. There's no point at which turning your brain off will work (danluu.com)
  81. How I Vibed a Proof of Conway’s Conjecture (overreacted.io)
  82. The Next Step for Mission-Critical Workloads: Managed Databases Advanced Edition (www.digitalocean.com)
  83. Adversary simulation: what you need to know (www.ncsc.gov.uk)
  84. Cyber Adversary Simulation (CyAS): scheme documents now available (www.ncsc.gov.uk)
  85. Building a Dashboard for my Fridge (theorangeone.net)
  86. How We Built a Data Warehouse Using ClickHouse (letsencrypt.org)
  87. Build Your Own AI Agent Harness in C#, the MafClaw Live Series (devblogs.microsoft.com)
  88. Avoid API Breaking Changes (codeopinion.com)
  89. Bring AI literacy into every classroom with our new themed resources (www.raspberrypi.org)
  90. Performance Improvements in .NET 11 (devblogs.microsoft.com)
  91. Iranian cyber targeting of dissidents, activists and journalists (www.ncsc.gov.uk)
  92. UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists (www.ncsc.gov.uk)
  93. Abusing ID3 chapters to turn videos into glanceable podcasts (alexwlchan.net)
  94. The AI Hurricane Is Here (snyk.io)
  95. Intelligence is yours. Let's keep it that way. (www.digitalocean.com)
  96. Intelligent Terminal 0.2.2572: Faster, Smoother, and More Reliable (devblogs.microsoft.com)
  97. Share your .NET story with the community (devblogs.microsoft.com)
  98. Launching Astro Pi 2026/27: Code your way to the International Space Station (www.raspberrypi.org)
  99. We are all Product Engineers now (seldo.com)
  100. Chess.com (2026) - 4,653,212 breached accounts (haveibeenpwned.com)
  101. Nobody pays for open source. We can force them to. (seldo.com)
  102. Weekly Update 521: Breach Perception v. Reality (troyhunt.com)
  103. Debugging our AI search assistant with agent tracing (blog.sentry.io)
  104. Use C# unions and closed hierarchies in ASP.NET Core (devblogs.microsoft.com)
  105. Migrating Shop app from React Native to native (shopify.engineering)
  106. Native is now the future of mobile at Shopify (shopify.engineering)
  107. McKesson - 6,404,340 breached accounts (haveibeenpwned.com)
  108. Is prevention essentially a solved problem? (snyk.io)
  109. Home Hardware, Part 2: Width Matters (blog.jessfraz.com)
  110. Built for agents: Omarchy's pipeline moves to DigitalOcean (www.digitalocean.com)
  111. .NET 11 Release Candidate 1 (github.com)
  112. Announcing .NET 11 Release Candidate 1 (devblogs.microsoft.com)
  113. .NET Conf 2026 Community Days Call for Presenters Is Open (devblogs.microsoft.com)
  114. Join the UK Bebras Challenge 2026 (www.raspberrypi.org)
  115. Home Hardware, Part 1: My Control4 Revenge Arc (blog.jessfraz.com)
  116. Introducing Kody: Your Personal Software Factory (kentcdodds.com)
  117. Testing race conditions with memory access tracing and stack-based delay injection (googleprojectzero.blogspot.com)
  118. Experience AI evolves with flexible resources for every classroom (www.raspberrypi.org)
  119. The hidden risks of shadow AI (www.ncsc.gov.uk)
  120. No Hacking Required: The Manchester Airports Group Data Breach (scotthelme.co.uk)
  121. How well do agents use test and verification techniques? (danluu.com)
  122. Weekly Update 520: The Unscripted Edition (troyhunt.com)
  123. Domain Events Are NOT Your Public API (codeopinion.com)
  124. ZGateway: Learnings from Putting a Proxy in Front of ZippyDB (engineering.fb.com)
  125. The book is done! (ericlippert.com)
  126. How River takes security work from a fix to merge (shopify.engineering)
  127. An Organizational Second Brain: Building an AI That Learns From Experts (engineering.fb.com)
  128. Manchester Airports Group - 8,849,657 breached accounts (haveibeenpwned.com)
  129. Weekly Update 519: Breaches & Data Integrity (troyhunt.com)
  130. Application Metrics caught my broken size estimator (blog.sentry.io)
  131. Questel - 1,226,209 breached accounts (haveibeenpwned.com)
  132. Ed Zitron's AI prediction track record (danluu.com)
  133. Let’s Use the Emergent CSS random() Function in all the Browsers (css-tricks.com)
  134. What’s !important #18: , Syntax ::highlight()ing, named-feature(), and More (css-tricks.com)
  135. You Can't "Vibe Code" Love (blog.codinghorror.com)
  136. Bug blindness (danluu.com)
  137. MAPS: Netflix’s Multimodal Asset Personalization at Scale (netflixtechblog.com)
  138. From one switch to a control panel: meet `dataCollection` (blog.sentry.io)
  139. Lightweight architecture for learning at pace  (technology.blog.gov.uk)
  140. Debugging my new network, when 10 Gigabit Ethernet Runs at 300 Megabits (hanselman.com)
  141. Creating Web Widgets Using the Document Picture-in-Picture API (css-tricks.com)
  142. Disruptive cyber activity highlights risk from internet-exposed systems and edge devices (www.ncsc.gov.uk)
  143. animation-trigger (css-tricks.com)
  144. How to evaluate session replay software: a developer's guide (blog.sentry.io)
  145. Why Your AI Application Is Exposed (Even When Your Scans Come Back Clean) (snyk.io)
  146. Introducing v5 Droplets: next-generation performance, sized to your workload (www.digitalocean.com)
  147. A Cautionary Tale About Data Breach Claims, Verification and Carhartt (troyhunt.com)
  148. Carhartt - 12,933,413 breached accounts (haveibeenpwned.com)
  149. Private Preview: DigitalOcean Managed Agents Runtime Services (www.digitalocean.com)
  150. MicroLighter: Syntax Highlighter (css-tricks.com)
  151. PowerToys 0.101 is here: Window Hopper, Insider updates, and Command Palette compact mode (devblogs.microsoft.com)
  152. Supporting a technical AI-focused qualification for young people in England (www.raspberrypi.org)
  153. Patching at Fleet Scale, Twice: How DigitalOcean Closed Januscape and the AMD Safe RET Issue Without Customer Impact (www.digitalocean.com)
  154. MetaRoCE: A New RDMA Transport Built for AI-Scale Ethernet (engineering.fb.com)
  155. MTIA 300: Meta’s First Training Chip with Built-in NICs and Communication-Offloading Engines (engineering.fb.com)
  156. WordPress PHP-Only Block Registration (css-tricks.com)
  157. The ultimate road trip combo: Starlink Mini + UniFi Travel Router (scotthelme.co.uk)
  158. Weekly Update 518: IoT Doorlock Nirvana with UniFi (troyhunt.com)
  159. NIUS - 6,090 breached accounts (haveibeenpwned.com)
  160. Migrating a Synology NAS to a UniFi UNAS Pro 8 with Robocopy, SMB Multichannel, and Surprising Performance Traps (hanselman.com)
  161. Welcoming the Sri Lankan Government to Have I Been Pwned (troyhunt.com)
  162. Golf Canada - 568,972 breached accounts (haveibeenpwned.com)
  163. A Tale of Two Flink Autoscalers (netflixtechblog.com)
  164. Resolved: CSS Class Prefix Selector (css-tricks.com)
  165. Introducing dbsc.dev: Does Your Browser Support DBSC? (scotthelme.co.uk)
  166. There's no reason for software to be slow anymore (danluu.com)
  167. DigitalOcean Inference Router, Now Cache-Aware: Why the Cheapest Model Isn't Always the Best Deal (www.digitalocean.com)
  168. Managing the cyber risk of agentic AI (www.ncsc.gov.uk)
  169. Keep coding when your internet drops: Offline support in the Code Editor (www.raspberrypi.org)
  170. Why can’t you combine .tar.gz files with cat? (alexwlchan.net)
  171. Event Driven Architecture and Coupling: You’re Not as Decoupled as You Think (codeopinion.com)
  172. CSS Navigation Matching, Early Days (css-tricks.com)
  173. Gisting: Compressing LLM Agent context to ↑ throughput and ↓ cost (shopify.engineering)
  174. WordPress.com Student Plan (css-tricks.com)
  175. Oz Hair and Beauty - 1,988,331 breached accounts (haveibeenpwned.com)
  176. Fanlore - 144,520 breached accounts (haveibeenpwned.com)
  177. Remediation Agents, Demystified: Why Fixing Beats Finding (snyk.io)
  178. Benchmarking Secure-and-Functional Remediation and How Snyk Agent Fix Lifts Frontier-Model Fix Rates by over 14% (snyk.io)
  179. Weekly Update 517: Cyber Ransoms (troyhunt.com)
  180. Dark mode toggles: two states are enough (css-tricks.com)
  181. The benchmarkpocalypse (danluu.com)
  182. What's missing to have reproducible builds on PyPI (snarky.ca)
  183. What’s !important #17: Custom Highlight API, CSS Navigation Matching, Fixing text-stroke, and More (css-tricks.com)
  184. How Tailscale tracked down a 16-year-old SQLite bug → (tailscale.com)
  185. How BitLocker PINs help protect your data and devices (www.ncsc.gov.uk)
  186. RingCentral - 1,596,490 breached accounts (haveibeenpwned.com)
  187. How to improve students’ problem-solving skills using subgoal labels (www.raspberrypi.org)
  188. Automated agent triage with Agent Tracing and Claude Routines (blog.sentry.io)
  189. How we raised mobile end-to-end test stability to 98% (shopify.engineering)
  190. Blocked aria-hidden: The Warning is Right, and Every Fix You’ve Found is Wrong (css-tricks.com)
  191. How We’re Building Scam Alert on WhatsApp With End-to-End Encryption and Verifiability Guarantees (engineering.fb.com)
  192. Help shape the future of resilient private 5G (www.ncsc.gov.uk)
  193. Weekly Update 516: Live From Vietnam (troyhunt.com)
  194. The Agent Baseline: 35 Controls, But Where Should You Start? (snyk.io)
  195. .NET 11 Preview 7 (github.com)
  196. Device Bound Session Credentials lands in Chrome on macOS (scotthelme.co.uk)
  197. Water sector example added to the NCSC’s Secure connectivity principles (www.ncsc.gov.uk)
  198. What's new in Sentry Logs: The summer 2026 roundup (blog.sentry.io)
  199. Going Back to Our Roots: A Little Piece of Let's Encrypt History (letsencrypt.org)
  200. My nomination statement for the 2026 Python packaging council (snarky.ca)
  201. Intelligent Terminal 0.2 is here with local model support (devblogs.microsoft.com)
  202. Everything I Learned Shipping Device Bound Session Credentials (scotthelme.co.uk)
  203. Animating CSS border-image (css-tricks.com)
  204. SmashingConf Freiburg 2026, September 7-10 (css-tricks.com)
  205. Show, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS (snyk.io)
  206. Alcon - 218,395 breached accounts (haveibeenpwned.com)
  207. How does programming language affect token efficiency and correctness? (danluu.com)
  208. Brinks Home - 732,162 breached accounts (haveibeenpwned.com)
  209. How and Why Netflix Built a Real-Time Distributed Graph: Part 3 — Querying the graph with gRPC… (netflixtechblog.com)
  210. Using and Styling the Dialog Element (css-tricks.com)
  211. Exact Sciences - 10,869,543 breached accounts (haveibeenpwned.com)
  212. Decoupling in Software Architecture Moves Complexity (codeopinion.com)
  213. How we built an automated debugging workflow at Sentry (blog.sentry.io)
  214. Inter-Con Security - 276,114 breached accounts (haveibeenpwned.com)
  215. From User Sequences to Scaling Laws: A Multi-Stage Architecture for Meta’s Ads Ranking (engineering.fb.com)
  216. Sidekick's continual learning loop (shopify.engineering)
  217. Your OTel spans, our errors: A Sentry love story in one trace (blog.sentry.io)
  218. Continuous Offensive Security & AI Pentesting: 20 FAQs (snyk.io)
  219. NCSC statement in response to recent incidents resulting from frontier AI evaluations (www.ncsc.gov.uk)
  220. Stop The Sprawl Snyk Secrets Now Generally Available (snyk.io)
  221. A First Look at Evo Agentic AppSec: Agentic Remediation and Malicious Code Defense (snyk.io)
  222. Inside the keyv npm Compromise: preinstall Malware, Trusted Provenance, and IDE Hooks (snyk.io)
  223. AI Model Risk Intelligence Know Which Models You Can Trust Before You Deploy (snyk.io)
  224. Evo Continuous Offensive Security Is Here Pentesting Grade Coverage For The 350 Days A Year You Aren't Testing (snyk.io)
  225. Welcoming the Nepalese Government to Have I Been Pwned (troyhunt.com)
  226. Weekly Update 515: Seeking Caffeine Utopia (troyhunt.com)