Blog — Page 27
Engineering notes, case studies, and lessons from the field.

CVE-2026-42945 (CVSS 9.2): NGINX Rift Heap Overflow Exploited in the Wild — Unauthenticated RCE PoC Now Public
An 18-year-old heap buffer overflow in NGINX's rewrite module is being actively exploited. A public PoC chains an ASLR bypass for unauthenticated RCE on any unpatched instance. Upgrade to 1.30.1 or 1.31.0 now.

CVE-2026-45585 (YellowKey): Unpatched BitLocker Bypass Gives Physical Attacker Full Drive Access — Mitigate Now
Microsoft published manual mitigation steps for CVE-2026-45585, an unpatched zero-day dubbed YellowKey that allows an attacker with brief physical access to bypass BitLocker encryption on Windows 11 and Server 2025 using only a USB drive and native Windows tools. No patch exists yet — switch to TPM+PIN mode immediately.

Vercel Labs Launches Zero: A Systems Language That Emits JSON Errors So AI Agents Can Fix Code Without Human Help
Vercel Labs released Zero (v0.1.2), an experimental systems programming language that replaces human-readable compiler errors with structured JSON objects containing typed repair identifiers. Binaries compile under 10 KiB, and functions must explicitly declare side effects — the language is designed for AI coding agents that need to parse, diagnose, and repair programs autonomously.

Pony AI Q1 2026: Robotaxi Revenue Up 395%, Company Doubles Fleet Target to 3,500 Units
Pony AI reported Q1 2026 results today with total revenue of $34.3M — up 145% year-over-year — driven by a 395% surge in robotaxi services. The company raised its year-end fleet deployment target to 3,500+ units and launched its first commercial robotaxi service in Europe.

Alibaba's Qwen 3.7 Max Sets New Benchmarks for AI Agent Models With 1M-Token Context
Alibaba launched Qwen 3.7 Max, a closed-weight frontier model scoring 60.6 on SWE-Pro and 92.4 on GPQA Diamond, priced at $2.50/$7.50 per million tokens. It executes 1,000+ autonomous tool calls per task and introduces native extended-thinking mode designed for long-horizon agentic workflows.

OpenTofu 1.12: Dynamic prevent_destroy, JSON-to-File Output, and the Feature Terraform Never Shipped in 10 Years
OpenTofu 1.12.0 ships dynamic prevent_destroy — wiring the lifecycle meta-argument to input variables — a feature Terraform users have requested since version 0.7 in 2016. The release also adds parallel provider installation, a -json-into CLI flag for dual-format output, and automatic lock file population on tofu init.

Valkey 9.1: 2.1M Req/s, Database-Level ACLs, and Lua Modularization — Redis Is No Longer the Default
The Linux Foundation's Valkey 9.1 ships a redesigned I/O threading model hitting 2.1 million requests per second, database-level access control, Lua scripting extracted into a loadable module, and new atomic commands including HGETDEL and MSETEX. AWS, GCP, and Aiven now default to Valkey over Redis.

CVE-2026-48172 (CVSS 10.0): LiteSpeed cPanel Plugin Actively Exploited — Any User Can Run Scripts as Root
A maximum-severity privilege escalation in the LiteSpeed User-End cPanel Plugin (versions 2.3–2.4.4) is under active mass exploitation. Any low-privilege cPanel account can execute arbitrary scripts as root via the Redis enable/disable workflow. Patch to LiteSpeed WHM Plugin 5.3.1.0 immediately.

Anthropic Closing $30B+ Round at $900B Valuation — Now More Valuable Than OpenAI
Anthropic is set to close a funding round exceeding $30 billion at a pre-money valuation above $900 billion, surpassing OpenAI's $852B March valuation. Sequoia, Dragoneer, Altimeter, and Greenoaks are co-leading the deal, expected to close the week of May 26.
Page 27 of 61 · 549 articles