Attraction
News District
Holographic billboards broadcasting the pulse of tech
Live Broadcast
Billboard Feed
Every screen in the square streams a different slice of the industry. Pick a channel to tune in.
Updated 8/12/2026, 3:37:00 AM
I Gave My Agent One Signed Permission It Couldn’t Mint Itself
Evidence status. The supervised operator run completed on 2026-08-09. An operator-signed job...
Fable 5 Plays Pokémon Sapphire Vision-Only: Notes on a 2,000-Decision Run
This run wasn't designed to discover anything new. It was collecting confirmations on three things:...
How Do You Build an Evaluation Harness for AI Agents?
You have an agent that works. Now someone asks how you know, and the honest answer is that you tried...
The Accidental DDOS: How a Single React Bracket Triggered 100,000 API Requests and Melted Our Database
This is a submission for DEV's Summer Bug Smash: Smash Stories powered by Sentry. Introduction: The...
I Explained My Code While Writing It on Camera. Here’s What Surprised Me
Recently, I decided to start recording my screen while I code. Instead of just sharing the finished...
Choosing Browser Document Storage: CORS Limits in React and Node.js
Use server-mediated uploads when a React application stores private user documents, otherwise reach...
Fixing a Silent Cache Bug in npmx.dev
This is a submission for DEV's Summer Bug Smash: Clear the Lineup. The bug npmx.dev is a...
Stale infrastructure context is worse than none
The bug that isn't a bug On Tuesday you attach a dead-letter queue to orders-queue. On...
How I Smashed a Bug in a Shared Authentication Library
This is a submission for DEV's Summer Bug Smash: Smash Stories powered by Sentry. This happened a...
Three Clouds, Three Native Agents
What is this project trying to do? Three AI agents, each built with a different vendor's...
Three Clouds, Three Native Agents
What is this project trying to do? Three AI agents, each built with a different vendor's...
Optimizing an 18 TB Azure SQL Hyperscale Database — Part 4: Reclaiming Terabytes
Used vs. allocated space, running DBCC SHRINKFILE against a heavily loaded production database, and what it does to backup cost.
Critical supply-chain flaw found in popular CI action
Maintainers urge immediate upgrade after a token-exfiltration vector was disclosed.
Zero-day in widely used VPN gateway under active exploitation
Attackers are already inside networks that haven't patched, teams are being told to assume compromise, not just apply the fix.
Ransomware groups pivot to double extortion as the default playbook
Encrypting data is no longer enough, exfiltration and public pressure tactics are now standard practice.
AI-assisted triage cuts SOC response times industry-wide
New tooling correlates signals across endpoints and cloud in real time, cutting mean time to detect from hours to minutes.
Emergency patch lands for a flaw in a widely embedded SSO library
The bug let an attacker forge valid login assertions without ever touching a password, and researchers found it embedded in dozens of enterprise products.
Linux kernel 7.0 lands with Rust-based driver framework
A major milestone for memory-safe drivers landing in the mainline tree.
Dependency confusion attack slips malicious code into dozens of internal builds
A single typosquatted package name was enough to get past code review at multiple companies before anyone noticed.
A major Linux distribution defaults to a memory-safe coreutils rewrite
Swapping decades-old C utilities for a Rust implementation closes a class of bugs that has quietly caused security advisories for years.
CVE-2026-19383 - saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted upload
A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_exec of the file /app/saipackage/install/upload of the component Plugin Upload Endpoint. The manipulat…
CVE-2026-19384 - SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql injection
A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID…
CVE-2026-19382 - Almico Speedfan MSR Index speedfan.sys KiSystemCall64 memory leak
A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a manipulation can lead to memory leak. The attac…
CVE-2026-19381 - Kingston FURY CTRL RGB Control Software Driver NTIOLib_KSFX.sys privileges management
A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation resu…
CVE-2026-19380 - Mullvad wireguard.sys IOCTL AdapterState reference count
A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of reference count. Local acces…
CVE-2026-19379 - EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection
A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os command injection. The …