Field notes

Blog — Page 46

Engineering notes, case studies, and lessons from the field.

Smart Slider 3 Pro Supply Chain Attack Backdoors 900,000 WordPress and Joomla Sites
Cybersecurity

Smart Slider 3 Pro Supply Chain Attack Backdoors 900,000 WordPress and Joomla Sites

Attackers compromised Nextend's update server and pushed a weaponized Smart Slider 3 Pro build with four persistence layers, a hidden admin account, and credential exfiltration. Upgrade to 3.5.1.36 immediately.

Apr 12, 20265 min read
CVE-2026-39987: Marimo Python Notebook Exposes Pre-Auth RCE — CISA Issues Emergency Patch Deadline
Cybersecurity

CVE-2026-39987: Marimo Python Notebook Exposes Pre-Auth RCE — CISA Issues Emergency Patch Deadline

A critical CVSS 9.3 vulnerability in Marimo Python notebook versions ≤ 0.20.4 lets any attacker execute arbitrary code without credentials via an unauthenticated WebSocket endpoint. CISA added it to the Known Exploited Vulnerabilities catalog with an April 11 federal patch deadline.

Apr 11, 20265 min read
A2A Protocol Reaches v1.0 — The Open Standard for AI Agent Communication Now Has 150+ Backers
Open Source

A2A Protocol Reaches v1.0 — The Open Standard for AI Agent Communication Now Has 150+ Backers

The Agent-to-Agent (A2A) Protocol shipped its stable v1.0 specification on April 9, 2026, one year after its initial launch. The Linux Foundation-hosted standard now counts 150+ organizations including AWS, Google, IBM, Microsoft, and Salesforce, with production SDKs in five languages.

Apr 11, 20265 min read
TSMC Breaks Its Own Revenue Record in Q1 2026 — AI Chip Demand Shows No Signs of Slowing
Hardware

TSMC Breaks Its Own Revenue Record in Q1 2026 — AI Chip Demand Shows No Signs of Slowing

TSMC posted NT$1.13 trillion (~$35.6 billion) in Q1 2026 revenue, a 35% year-over-year jump and a new quarterly record. March alone came in 45.2% above the prior year, the strongest single month in company history.

Apr 11, 20265 min read
Meta Launches Muse Spark — Its First Closed-Source AI Model and a Break From the Llama Playbook
AI Models

Meta Launches Muse Spark — Its First Closed-Source AI Model and a Break From the Llama Playbook

Meta Superintelligence Labs ships Muse Spark, a natively multimodal reasoning model that marks the company's first closed-source AI release. The move signals a major strategic shift away from the open-weights Llama family.

Apr 11, 20265 min read
North Korea's OtterCookie Malware Hid Inside a Fake Gemini npm Package — Cursor, Claude, and Windsurf Users Targeted
Cybersecurity

North Korea's OtterCookie Malware Hid Inside a Fake Gemini npm Package — Cursor, Claude, and Windsurf Users Targeted

A malicious npm package posing as a Google Gemini token validator silently exfiltrated API keys and source code from directories used by Cursor, Claude, Windsurf, and other AI coding tools. The backdoor is linked with high confidence to North Korea's Contagious Interview campaign.

Apr 10, 20265 min read
Perplexity Hits $500M ARR as Autonomous Agent Pivot Doubles Revenue in Under Four Months
AI Tools

Perplexity Hits $500M ARR as Autonomous Agent Pivot Doubles Revenue in Under Four Months

Perplexity's annualized recurring revenue has surpassed $500M, more than doubling since year-end 2025 and growing 6x in roughly 16 months. The acceleration traces directly to the company's pivot from AI search to autonomous agent subscriptions.

Apr 10, 20265 min read
CVE-2026-34040: Docker Engine AuthZ Bypass Lets Any API Client Gain Host-Level Access — Patch to 29.3.1 Now
Cybersecurity

CVE-2026-34040: Docker Engine AuthZ Bypass Lets Any API Client Gain Host-Level Access — Patch to 29.3.1 Now

A CVSS 8.8 flaw in Docker Engine before 29.3.1 lets attackers silently bypass all AuthZ plugins with a single oversized API request. Successful exploitation can lead to full Kubernetes cluster takeover and SSH access to production hosts.

Apr 10, 20265 min read
CISA Joint Advisory: Iran-Linked IRGC Hackers Targeting U.S. Power and Water Networks via Exposed PLCs
Cybersecurity

CISA Joint Advisory: Iran-Linked IRGC Hackers Targeting U.S. Power and Water Networks via Exposed PLCs

The FBI, CISA, NSA, and four other agencies issued advisory AA26-097A after Iranian IRGC-affiliated actors disrupted U.S. energy and water infrastructure through internet-exposed Rockwell PLCs. No CVE involved — attackers abused default credentials.

Apr 10, 20265 min read

Page 46 of 61 · 549 articles