// stories

671 stories · editorial analysis with viewpoints and sources

Project Zero's Pixel 10 0-Click Chain: From RCS Message to Root

May 16

▸ Google Project Zero published a full 0-click exploit chain targeting Pixel 10 devices — no user interaction required for complete device compromise.

Hardware / Chips Security / Privacy explainer

Bun Is Rewriting Itself in Rust — and It Already Passes 99.8% of Tests

May 16

▸ Bun's experimental Rust rewrite passes 99.8% of the existing test suite on Linux x64 glibc, signaling the Zig-to-Rust migration is far more than a pro...

Backend / APIs Open Source clear_take

California Says You Can't Just Kill a Game People Paid For

May 16

▸ A California bill would require publishers to release patches enabling offline play — or issue refunds — when shutting down online game servers.

Politics / Regulation Backend / APIs clear_take

Android's VPN Kill Switch Doesn't Kill Everything — GrapheneOS Fixed It

May 16

▸ Android leaks traffic outside VPN tunnels even with 'Always-on VPN' and 'Block connections without VPN' enabled — including connectivity checks and DN...

Open Source Security / Privacy clear_take

Agent Skills: The Standard 35 AI Tools Agreed On While You Weren't Looking

May 16

▸ Anthropic's Agent Skills spec — a folder with a SKILL.md file — has been adopted by Cursor, GitHub Copilot, OpenAI Codex, Gemini CLI, and 30+ other ag...

AI / ML Open Source DevOps / Platform Engineering clear_take

Meta's AI Pivot Has a People Problem Nobody Wants to Talk About

May 16

▸ Meta's all-in AI reorg is reportedly demoralizing employees across non-AI teams as headcount, prestige, and resources shift to generative AI projects.

AI / ML Career / Industry multiple_viewpoints

Your Privacy VPN Is a Tracking Beacon: Mullvad Exit IPs as Fingerprints

May 16

▸ Mullvad's small pool of exit IPs combined with its tiny user base means websites can narrow 'anonymous' VPN users to a remarkably small anonymity set.

Open Source Security / Privacy explainer

The Line Between Vibe Coding and Agentic Engineering Is Dissolving

May 16

▸ Simon Willison argues that agentic engineering workflows are exhibiting the same 'trust the AI, skip the review' patterns that define vibe coding — ju...

Career / Industry AI / ML multiple_viewpoints

GitLab Kills Its Famous CREDIT Values and Cuts Staff in 'Act 2' Reset

May 16

▸ GitLab is retiring its CREDIT values (Collaboration, Results, Efficiency, Diversity Inclusion & Belonging, Iteration, Transparency) — the cultural fra...

Career / Industry DevOps / Platform Engineering clear_take

Turso Kills Its Bug Bounty Program. Blame the AI Slop.

May 16

▸ Turso, the libSQL edge database company, is shutting down its bug bounty program because AI-generated vulnerability reports have made it unsustainable...

Open Source Security / Privacy AI / ML clear_take

84 Malicious TanStack Packages Hit npm Via GitHub Actions Exploit Chain

May 15

▸ An attacker exploited pull_request_target, GitHub Actions cache poisoning, and OIDC token extraction to publish 84 malicious versions across 42 @tanst...

Security / Privacy Open Source breaking

Your AI Calls Don't Need to Leave Your Machine

May 15

▸ A unix.foo post arguing local AI should be the default — not the exception — hit 1,200+ points on HN, the highest signal we've seen on this topic in m...

DevOps / Platform Engineering AI / ML Security / Privacy clear_take

The Senior Dev Communication Trap: Technical Depth Kills Influence

May 15

▸ Senior developers routinely undermine their own influence by defaulting to implementation details when stakeholders need context, tradeoffs, and recom...

Career / Industry Backend / APIs clear_take

A 26M-Parameter Model That Does Tool Calling at 1200 tok/s on Your Phone

May 15

▸ Cactus Compute distilled Gemini's tool-calling capability into Needle, a 26M-parameter model that runs at 6,000 tok/s prefill and 1,200 tok/s decode o...

AI / ML Hardware / Chips Open Source clear_take

Apple-Intel Fab Deal: The Geopolitics of Where Your Silicon Gets Made

May 15

▸ Apple and Intel have reached a preliminary agreement for Intel to manufacture some Apple-designed chips — the first major customer win for Intel's str...

Hardware / Chips Politics / Regulation Career / Industry clear_take

Hardware Attestation Is the New Vendor Lock-In, and It's Working

May 15

▸ Hardware attestation APIs (Play Integrity, App Attest) let apps verify you're running stock OS — effectively banning alternative Android distributions...

Politics / Regulation Open Source Security / Privacy clear_take

The Return of the HTML Monolith: Why AI Agents Prefer No Build Step

May 15

▸ Developers using Claude Code are discovering that single-file HTML apps — inline CSS, vanilla JS, zero dependencies — produce surprisingly polished re...

Frontend / UI AI / ML clear_take

Nginx-Rift: Public Exploit Drops for Nginx Vulnerability

May 15

▸ A new Nginx exploit called 'Nginx-Rift' has been publicly disclosed via GitHub by security research group DepthFirstDisclosures, with a proof-of-conce...

Open Source DevOps / Platform Engineering Security / Privacy breaking

YellowKey Exploit Unlocks BitLocker Drives With a USB Stick

May 15

▸ A zero-day exploit called YellowKey can bypass BitLocker full-disk encryption using only files loaded onto a USB drive — no hardware mods, no solderin...

Security / Privacy Cloud / Infrastructure breaking

A Fields Medalist Stress-Tested ChatGPT 5.5 Pro. The Results Are Telling.

May 14

▸ Timothy Gowers — Fields Medal winner and one of math's sharpest living minds — published a detailed assessment of ChatGPT 5.5 Pro's mathematical reaso...

AI / ML Career / Industry clear_take
← newer page 3 of 34 older →