» curated · synthesized
Skip the noise.
Read the signal.
Curated tech news and synthesis for developers and technology professionals.
» Latest posts
357 postsResearchers Lure Lazarus's Fake IT Workers Into a Sham DeFi Startup
Researchers built a fake DeFi startup to hire and monitor North Korea's Famous Chollima IT worker operatives using ANY.RUN sandboxes.
Three.js gets native Gaussian Splatting support
Three.js gains native Gaussian Splatting via PR #33950, with WebGPU/TSL rendering, approximate GPU sorting, and a minimal loader API.
TutorMoments: Testing If AI Tutors Know When to Help or Hold Back
Allen AI's TutorMoments benchmark tests whether LLM tutors know when to scaffold and when to push students toward harder reasoning.
CVE-2026-69243 PoC: aiohttp Request Smuggling via Rejected WebSocket Upgrade
First public PoC for CVE-2026-69243, an aiohttp request smuggling flaw via rejected WebSocket upgrades causing blind handler invocation behind Nginx.
AI Escape Room: Docker CTF Rebuilds the 2026 Hugging Face Breach
A Docker Compose CTF lab recreates the 2026 Hugging Face agent breach, covering SSRF, SSTI, HDF5 exfiltration, and Kubernetes pivoting for security training.
Kakehashi: run macOS ARM64 binaries on Linux aarch64, no JIT
Kakehashi is an experimental userspace layer that runs macOS ARM64 binaries natively on Linux aarch64 without JIT, aimed at cutting CI costs.
SoLo Lets Static musl Binaries Load glibc GPU Drivers
SoLo lets fully static musl Linux binaries dlopen glibc GPU drivers at runtime — no container, no AppImage, one file.
Python Bytecode: The Security Blind Spot Beyond Source Review
Study of over 1M PyPI packages shows Python .pyc bytecode bypasses source-level security review, exposing CPython to crashes and memory-corruption bugs.
MongoDB BSON Symbol Type Bypasses Authorization Check (CVE-2026-18690)
MongoDB CVE-2026-18690: a BSON symbol-typed collection name bypasses authorization checks, letting limited users reach protected system collections.
RovoBlast: One Click Turns Atlassian's AI Assistant Into a Data Leak
Varonis details RovoBlast, a one-click prompt injection flaw in Atlassian's Rovo AI assistant that can expose sensitive enterprise data.