Blog — Page 30
Engineering notes, case studies, and lessons from the field.

Meta Begins Cutting 8,000 Employees and 6,000 Open Roles on May 20 — AI Restructuring at Record Revenue
Meta started notifying employees of layoffs across three global batches today, eliminating 10% of its workforce and cancelling thousands of open roles despite posting $201 billion in full-year revenue. Savings are redirected toward $115–135 billion in AI infrastructure spending.

Drupal Releases Emergency Core Patch Rated 'Highly Critical' — Zero-Auth Exploit Possible Within Hours
Drupal pushed an unscheduled emergency update across all supported branches for a zero-authentication flaw rated 20/25 on its severity scale. Site admins should patch immediately — the security team warned exploits could emerge within hours of disclosure.

AMD EPYC Venice Becomes First HPC Silicon on TSMC N2 — Zen 6 at 2nm With Arizona Production Confirmed
AMD confirmed EPYC Venice (Zen 6) is the first HPC product taped out on TSMC's 2nm-class N2 process, delivering a 10-15% performance uplift over Turin. Simultaneously, AMD confirmed EPYC 9005 volume production at TSMC's Arizona Fab 21, satisfying US CHIPS Act provenance requirements.

Node.js 26 Is Now Current: Temporal API Ships by Default, V8 14.6, and the Date Object Is Obsolete
Node.js 26 landed May 5 as the new Current release line, enabling the Temporal API by default and ending the long reign of JavaScript's broken Date object. V8 jumps to 14.6, Undici to 8.0, and LTS follows in October 2026.

node-ipc Supply Chain Attack: Malicious npm Versions Steal AWS Keys, GitHub Tokens via DNS Exfiltration
Three malicious versions of node-ipc (822K weekly downloads) published May 14 harvested 90+ credential categories from developer machines and CI environments, exfiltrating everything via DNS TXT queries to evade network monitoring. If you ran npm install on May 14, rotate all credentials now.

ShinyHunters Breach Canvas LMS: 275 Million Students Exposed Across 8,800 Universities
ShinyHunters exploited free-teacher account provisioning to steal 3.65TB from Instructure's Canvas LMS, hitting 275 million users at 8,809 institutions. Instructure suffered a second breach just one day after believing the incident was contained — and ultimately paid the ransom.

Take It Down Act Compliance Deadline Is Tomorrow — What Every Platform Must Have Ready by May 19
The TAKE IT DOWN Act's one-year implementation window closes May 19, 2026. Every platform hosting user-generated content must have a working 48-hour takedown system for non-consensual intimate imagery — real or AI-generated deepfakes. FTC penalties reach $53,088 per violation, and enforcement is a White House priority.

"Dirty Frag" Linux LPE (CVE-2026-43284 / CVE-2026-43500) Now Actively Exploited — Patch Your Kernel
The 'Dirty Frag' privilege-escalation pair targeting Linux kernel IPsec and AFS networking modules is now confirmed under active in-the-wild exploitation. Any unprivileged local account — including web shells and container escape footings — can escalate to root. Red Hat, Ubuntu, Amazon Linux, and SUSE have patches; apply them immediately.

Google I/O 2026 Opens Tomorrow: New Gemini Model, Omni Video Generation, and Project Astra on Stage
Google I/O 2026 keynote starts May 19 at Shoreline Amphitheatre. Confirmed on the slate: a new Gemini version, a video-generation model called Gemini Omni, and broad 'Gemini Intelligence' integrations across Android and hardware. Leaked benchmarks suggest the new model lands below Claude Mythos and GPT-5.5.
Page 30 of 61 · 549 articles