Blog — Page 46
Engineering notes, case studies, and lessons from the field.

Smart Slider 3 Pro Supply Chain Attack Backdoors 900,000 WordPress and Joomla Sites
Attackers compromised Nextend's update server and pushed a weaponized Smart Slider 3 Pro build with four persistence layers, a hidden admin account, and credential exfiltration. Upgrade to 3.5.1.36 immediately.

CVE-2026-39987: Marimo Python Notebook Exposes Pre-Auth RCE — CISA Issues Emergency Patch Deadline
A critical CVSS 9.3 vulnerability in Marimo Python notebook versions ≤ 0.20.4 lets any attacker execute arbitrary code without credentials via an unauthenticated WebSocket endpoint. CISA added it to the Known Exploited Vulnerabilities catalog with an April 11 federal patch deadline.

A2A Protocol Reaches v1.0 — The Open Standard for AI Agent Communication Now Has 150+ Backers
The Agent-to-Agent (A2A) Protocol shipped its stable v1.0 specification on April 9, 2026, one year after its initial launch. The Linux Foundation-hosted standard now counts 150+ organizations including AWS, Google, IBM, Microsoft, and Salesforce, with production SDKs in five languages.

TSMC Breaks Its Own Revenue Record in Q1 2026 — AI Chip Demand Shows No Signs of Slowing
TSMC posted NT$1.13 trillion (~$35.6 billion) in Q1 2026 revenue, a 35% year-over-year jump and a new quarterly record. March alone came in 45.2% above the prior year, the strongest single month in company history.

Meta Launches Muse Spark — Its First Closed-Source AI Model and a Break From the Llama Playbook
Meta Superintelligence Labs ships Muse Spark, a natively multimodal reasoning model that marks the company's first closed-source AI release. The move signals a major strategic shift away from the open-weights Llama family.

North Korea's OtterCookie Malware Hid Inside a Fake Gemini npm Package — Cursor, Claude, and Windsurf Users Targeted
A malicious npm package posing as a Google Gemini token validator silently exfiltrated API keys and source code from directories used by Cursor, Claude, Windsurf, and other AI coding tools. The backdoor is linked with high confidence to North Korea's Contagious Interview campaign.

Perplexity Hits $500M ARR as Autonomous Agent Pivot Doubles Revenue in Under Four Months
Perplexity's annualized recurring revenue has surpassed $500M, more than doubling since year-end 2025 and growing 6x in roughly 16 months. The acceleration traces directly to the company's pivot from AI search to autonomous agent subscriptions.

CVE-2026-34040: Docker Engine AuthZ Bypass Lets Any API Client Gain Host-Level Access — Patch to 29.3.1 Now
A CVSS 8.8 flaw in Docker Engine before 29.3.1 lets attackers silently bypass all AuthZ plugins with a single oversized API request. Successful exploitation can lead to full Kubernetes cluster takeover and SSH access to production hosts.

CISA Joint Advisory: Iran-Linked IRGC Hackers Targeting U.S. Power and Water Networks via Exposed PLCs
The FBI, CISA, NSA, and four other agencies issued advisory AA26-097A after Iranian IRGC-affiliated actors disrupted U.S. energy and water infrastructure through internet-exposed Rockwell PLCs. No CVE involved — attackers abused default credentials.
Page 46 of 61 · 549 articles