Patch Tuesday used to be manageable. A hundred fixes, maybe a hundred and forty on a heavy month.
If you run Ray — even locally on your laptop for training experiments — stop reading this and run pip install -U "ray>=2.52.
Snowflake's .NET connector repo on GitHub had a workflow that turned issues into Jira tickets.
On June 18, a pull request landed in Snowflake's snowflake-connector-net repository.
On July 4, 2026, OpenAI's internal Artifactory instance went down for maintenance.
Last month, someone drained 1,082 Bitcoin from Coldcard hardware wallets in forty-one minutes. The firmware had compiled without a single warning.
On August 4, someone compromised a single GitHub account.
Late last month, security researchers at Pillar Security proved that anyone with a GitHub account could file an issue on Google's Agent Development Kit...
Twenty-nine years. That's how long a single missing null check sat in Squid's FTP parser, leaking heap memory into HTTP responses.
The vLLM v0.24.
Vercel shipped Next.js's first-ever scheduled security release on Monday.
Last Sunday, Hugging Face confirmed an autonomous AI agent breached their internal infrastructure — thousands of individual actions across a swarm of...
Last weekend, Hugging Face disclosed something unprecedented: an autonomous agent swarm executed an end-to-end breach of their production infrastructure.
Hugging Face disclosed a breach this week.
On July 8, npm v12 did something no major package manager had ever done: it told every dependency in the JavaScript ecosystem, "You no longer get to run...
Three days ago, someone pushed a Rust infostealer into jscrambler — a JavaScript obfuscation tool with 15,800 weekly downloads.
Dell's support website broke last month.
Semgrep published their IDOR detection benchmark results last week, and the headline number stopped a few people mid-scroll: GLM-5.
Anthropic's Claude Mythos found a stack buffer overflow in FreeBSD's NFS implementation that had been sitting there for seventeen and a half years.