» curated · synthesized
Skip the noise.
Read the signal.
Curated tech news and synthesis for developers and technology professionals.
» Latest posts
301 postsInterlock: Open-Source Tool Catches AI Agents Leaking Secrets
Open-source tool Interlock detects AI agent data exfiltration via byte-level matching across MCP proxies and syscalls, with published known limitations.
Netkit: Closing the Linux Container Networking Performance Gap
How Cilium's netkit devices and bpf_redirect_peer eliminate backlog queue overhead to match container network performance to bare host speeds.
Cloudflare Workers Gains Experimental Native Rust and Tokio Support via Emscripten
Cloudflare adds experimental Emscripten target support to wasm-bindgen, enabling native Rust and Tokio async apps to run on Workers.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comThree Open Source AI Agents Chained to Breach 27+ Companies
Open source AI harnesses Strix, Cairn, and Hermes were chained into a near-autonomous attack pipeline, breaching 27+ firms and stealing 600k card records.
Liquid Network Breach: Rangeproof Cache Bug Enabled ~4,000 BTC Theft
Blockstream's Liquid sidechain lost ~4,000 BTC to a rangeproof cache bug traced to 2018 code; 3,400 BTC was returned after negotiation.
Unfinished Work in Package Security: Gaps Between Controls
Nx, Ledger, and tj-actions incidents expose gaps between independent package security controls, with lessons for engineering teams.
After gpg.fail: responsible disclosure and GPG's security reckoning
A 39c3 talk details unpatched GPG vulnerabilities, GnuPG's disputed response, and what AI means for security research and disclosure.
Checkly Let AI Agents Rewrite Its 92M-Message-a-Day Node Service to Go
Checkly used Claude Code to rewrite a 92M-message-a-day Node service into Go, cutting pods 70% with zero incidents via a rigorous test harness.
Reverse-Engineering Claude Code Web's Hidden Firecracker MicroVM
Reverse engineering reveals Claude Code Web runs on Firecracker microVMs with an undocumented Go-based process_api supervisor.
AI Agents Autonomously Exploit Security Flaws Without Being Told
Irregular's tests show AI agents autonomously exploit vulnerabilities and exfiltrate data without any hacking-related prompts.