Typosquatting bets on your typo. Slopsquatting bets on your AI assistant. When a model invents a...
Every form I ever shipped before React 19 needed the same three pieces of state, and I wired them up...
In my previous article, I argued that AI changes the role of constraints in software...
TL;DR Modern web applications change constantly. Components are re-rendered, generated...
There is a class of people you have never heard of, who have never introduced themselves at a party,...
I timed Dictionary, ImmutableDictionary, and FrozenDictionary on a build-once lookup table. The one I had been using for read-only data came in 7x slower.
Six wrong domains shipped to production in generated code — one of them as an email sender, so those messages could never be delivered. Every reference was syntactically perfect, which is why typecheck, build, tests and deploy all passed. The fix is
This week's releases cluster around two themes: reducing the infrastructure tax on agentic systems,...
If you have ever designed inventory accounting, an ERP system, or billing, you know: calculating...
I used to reach for NextAuth on every project by default. Then I built a few dashboards where I...
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2capsocknewconnectioncb l2capsocknewconnectioncb returned l2cappisk-chan after releasesockparent. Once the parent lock is dropped the newly enqueued child socket sk is reachable via the accep...
Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade t...
In the Linux kernel, the following vulnerability has been resolved: perf/core: Detach event groups during removeonexec perfeventremoveonexec removes events by calling perfeventexitevent. For top-level events, this removes the event from the context with DETACHEXIT only. This can leave inconsistent g...
Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, ...
The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the global scope, included by fvcradminpagehtml function. This makes it possible for unauthenti...
Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix t...
Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10....
Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue...
Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix t...
Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, w...
Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issu...
As reported by Dark Reading, Operation Cronos, a significant international law enforcement effort, successfully dismantled LockBit, once one of the most dominant ransomware-as-a-service (RaaS) operations globally.
Bleeping Computer disclosed that hackers are actively exploiting a critical vulnerability in the FastJson open-source Java library, enabling remote code execution without requiring user interaction or elevated privileges.
Microsoft says tools cost less than competing ones and outperform them, too.
Apple’s technical details on the many security fixes included in today’s operating system updates show how quickly AI tools are becoming part of vulnerability research.