DeveloperLand
Back to the park map

Attraction

Developer Observatory

A living globe of trends, adoption, and alerts

Mission Control

Signals from across the park

A synthesised live view of what the developer world is building, adopting, breaking, and shipping.

Live

Trending Technologies

  • TypeScript78%
  • Rust34%
  • WebAssembly22%
  • Go41%
  • Bun19%
  • Edge Functions27%
  • Docker68%
  • Kubernetes52%
  • Tailwind CSS61%
  • GraphQL37%
  • AI Agents44%
  • tRPC23%
  • Svelte21%
  • Deno16%
  • Zig12%
  • WebGPU9%

Global developer activity

Framework Adoption

  • Next.js46%
  • Astro18%
  • SvelteKit14%
  • Remix12%
  • Nuxt10%

GitHub Activity

vercel/next.js, 342 commits today

microsoft/typescript, 118 commits today

rust-lang/rust, 96 commits today

torvalds/linux, 271 commits today

facebook/react, 84 commits today

denoland/deno, 57 commits today

oven-sh/bun, 63 commits today

kubernetes/kubernetes, 129 commits today

vercel/next.js, 342 commits today

microsoft/typescript, 118 commits today

rust-lang/rust, 96 commits today

torvalds/linux, 271 commits today

facebook/react, 84 commits today

denoland/deno, 57 commits today

oven-sh/bun, 63 commits today

kubernetes/kubernetes, 129 commits today

Security Alerts

  • Critical supply-chain flaw found in popular CI action

    Maintainers urge immediate upgrade after a token-exfiltration vector was disclosed.

    CVE Feed · 2026-06-30

  • Zero-day in widely used VPN gateway under active exploitation

    Attackers are already inside networks that haven't patched, teams are being told to assume compromise, not just apply the fix.

    CISA · 2026-07-05

  • Ransomware groups pivot to double extortion as the default playbook

    Encrypting data is no longer enough, exfiltration and public pressure tactics are now standard practice.

    Recorded Future · 2026-06-20

  • AI-assisted triage cuts SOC response times industry-wide

    New tooling correlates signals across endpoints and cloud in real time, cutting mean time to detect from hours to minutes.

    Dark Reading · 2026-07-03

  • Emergency patch lands for a flaw in a widely embedded SSO library

    The bug let an attacker forge valid login assertions without ever touching a password, and researchers found it embedded in dozens of enterprise products.

    The Hacker News · 2026-07-06

  • CVE-2026-19383 - saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted upload

    A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_exec of the file /app/saipackage/install/upload of the component Plugin Upload Endpoint. The manipulat…

    CVE Feed · 2026-08-10T02:16:43.000Z

  • CVE-2026-19384 - SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql injection

    A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID…

    CVE Feed · 2026-08-10T01:30:11.000Z

  • CVE-2026-19382 - Almico Speedfan MSR Index speedfan.sys KiSystemCall64 memory leak

    A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a manipulation can lead to memory leak. The attac…

    CVE Feed · 2026-08-10T01:16:48.000Z

  • CVE-2026-19381 - Kingston FURY CTRL RGB Control Software Driver NTIOLib_KSFX.sys privileges management

    A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation resu…

    CVE Feed · 2026-08-10T01:16:48.000Z

  • CVE-2026-19380 - Mullvad wireguard.sys IOCTL AdapterState reference count

    A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of reference count. Local acces…

    CVE Feed · 2026-08-10T01:16:48.000Z

  • CVE-2026-19379 - EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection

    A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os command injection. The …

    CVE Feed · 2026-08-10T01:16:47.000Z

Open Source Trends

  • Linux kernel 7.0 lands with Rust-based driver framework

    A major milestone for memory-safe drivers landing in the mainline tree.

    LWN · 2026-06-10

  • Dependency confusion attack slips malicious code into dozens of internal builds

    A single typosquatted package name was enough to get past code review at multiple companies before anyone noticed.

    Sonatype · 2026-06-12

  • A major Linux distribution defaults to a memory-safe coreutils rewrite

    Swapping decades-old C utilities for a Rust implementation closes a class of bugs that has quietly caused security advisories for years.

    Phoronix · 2026-06-25

Breaking News

AI

I Gave My Agent One Signed Permission It Couldn’t Mint Itself

React

The Accidental DDOS: How a Single React Bracket Triggered 100,000 API Requests and Melted Our Database

TypeScript

Fixing a Silent Cache Bug in npmx.dev

Cloud

Three Clouds, Three Native Agents

Cybersecurity

Critical supply-chain flaw found in popular CI action

Cybersecurity

Zero-day in widely used VPN gateway under active exploitation

Cybersecurity

Ransomware groups pivot to double extortion as the default playbook

Cybersecurity

Emergency patch lands for a flaw in a widely embedded SSO library

Cybersecurity

CVE-2026-19381 - Kingston FURY CTRL RGB Control Software Driver NTIOLib_KSFX.sys privileges management

Cybersecurity

CVE-2026-19379 - EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection