The journal
Working notes from the workshop.
Posts on AI, software craft, and the things we learn while shipping. Twice a month, sometimes weekly.
Hiring developers? Start with the how-to-hire hub →
Browse by topic
- Web Development 237
- AI Integration 230
- Business 127
- Cybersecurity 119
- Cloud & Infrastructure 90
- Technology 47
- Career 23
- Industry News 22
- AI & ML 8
- Design 8
- Science 7
Or read straight through: page 2 · page 3 · page 4 · page 5 · page 6 · page 7 · page 8 · page 9 · last
Categories
Tags
Showing 12 of 920 articles
Cybersecurity·CVE-2026-87491: Chrome's Second Zero-Day in a Week
Chrome patched a second actively exploited V8 zero-day in five days. Here is what CVE-2026-87491 affects, the fixed version, and how to check your fleet.
CybersecurityCVEChromeBrowser Security
Cybersecurity·CVE-2026-44477: CloudNativePG's Superuser Escalation Bug
CVE-2026-44477 lets any database owner escalate to postgres superuser and run OS commands in CloudNativePG. Here is who is affected and how to patch.
CybersecurityCVEKubernetesPostgreSQL- Career·
How to Hire a Staff Engineer in 2026
A staff engineer is scoped by impact across teams, not seniority. Here is how to screen for that instead of promoting your best senior engineer.
HiringRecruitingCareerEngineering Management
AI Integration·Guardrails AI vs NeMo Guardrails vs Llama Guard in 2026
Guardrails AI validates structured output, NeMo Guardrails controls dialog flow, and Llama Guard classifies safety. Here is which one fits your LLM app.
AIAI IntegrationLLMSecurity
Business·How to Hire a Next.js Developer in 2026
Next.js 16 changed what 'knows Next.js' means: Turbopack, Cache Components, and Server Actions by default. What to screen for, and the questions that reveal real skill.
HiringNext.jsReactFrontend
AI Integration·Fugu Ultra v2: Sakana's Orchestrator Model, Explained
Sakana AI shipped Fugu Ultra v2 on Sept 11, routing every request across a hidden pool of models instead of running one. What that buys you, and what it costs.
AIAI IntegrationLLMDeveloper Tools
Cybersecurity·SonicWall SMA1000's Second Zero-Day Chain: Patch Now
CVE-2026-83548 (SSRF, CVSS 10.0) and CVE-2026-83549 (OS command injection) hit SMA1000 appliances again, seven weeks after the last chain. Affected models and the fix.
CybersecurityCVESecurityInfrastructure
Web Development·WebTransport Explained: A Real WebSocket Alternative Now
WebTransport hit Baseline in March 2026 when Safari 26.4 shipped it. Here's what it actually does, how it differs from WebSockets, and when to reach for it.
Web DevelopmentBackendJavaScriptReal-time
Web Development·CSS :open Is Baseline: One Selector for Toggles
The :open pseudo-class, Baseline since May 2026, styles <details>, <dialog>, and <select> in their expanded state with one selector. No JS classes needed.
CSSFrontendWeb DevelopmentAccessibility
AI Integration·OpenAI's Agents API: The Codex Harness, One Call
OpenAI's Agents API public beta puts session orchestration, context compaction, and sandboxed execution behind one call. What it replaces and what it costs.
AIAI IntegrationLLMDeveloper Tools
Cybersecurity·CISA KEV Deadline: Patch NetScaler and FortiOS Now
CISA gave federal agencies until Sept 12 to patch a Citrix NetScaler auth bypass and a critical FortiOS RCE tied to a live PivotC2 malware campaign.
CybersecurityCVEInfrastructureDevOps
Cybersecurity·CVE-2026-88062: OmniRoute's Unauthenticated RCE
A single unauthenticated request can run code inside OmniRoute, the 58k-star AI gateway. Patch status is contested, so verify your build yourself.
CybersecurityCVEAIOpen Source