News

The x321 Tech Digest — what engineers are talking about, distilled daily.

  • Vulnerability Watch No60

    AWX Archive Extraction Path Traversal • HCL Hive Third-Party Component Vulnerability • GIMP PCX Plugin Memory Corruption Bug • rConfig Authentication Bypass Creates Admin Accounts • NetworkManager WPA-Enterprise Validation Flaw…

    Read digest →

  • Topics Everyone Is Talking About No415

    One Week Using Codex More Than Claude • New Model Context Protocol Roadmap • A Kantian Critique of Justin Biebers Sorry • The Cool Ideas Behind Gleam • PiKVM Adds Webcam Forwarding Support…

    Read digest →

  • Vulnerability Watch No59

    Joomla Fabrik List Controller Allows Unauthorized Data Deletion • Joomla Fabrik Reveals Database Structure to Unauthenticated Users • Joomla Fabrik Allows Unauthenticated Directory Listing • Joomla Fabrik Permits Unauthenticated File Uploads • WordPress WS Form Plugin Exposes Critical PHP Object Injection Flaw…

    Read digest →

  • Vulnerability Watch No58

    LeafWiki Account Update Bug Enables Role Escalation • RaTeX Parser Crash Creates Denial of Service Risk • WordPress Plugin Flaw Enables Privilege Escalation • WeeChat Authentication Timing Bug Exposes Hashes • LeafWiki File Traversal Bug Can Expose Local Data…

    Read digest →

  • Topics Everyone Is Talking About No414

    Bun 1.4: Enhanced Compatibility and Leaner JavaScript Tooling • OpenPubkey SSH: Bringing Single Sign-On to SSH Authentication • Rust Supply Chain Attack Compromises Arrayref Releases • From Rust to Zig: A Systems Developers First Impressions • Aaron Swartz, Data Scraping, and Unequal Tech Accountability…

    Read digest →

  • Framework Release Watch No14

    Bun v1.4.0 release arrives • Rust 1.98.0 adds language and library improvements

    Read digest →

  • Vulnerability Watch No57

    Monkeytype Rate Limit Bypass Enables Abuse • Plate DOCX Conversion Flaw Exposes Internal Services • Link Preview JS DNS Rebinding Bypasses SSRF Protection • dbx Authentication Bypass Enables Database Takeover • NanaZip Archive Parsing Bug Risks Data Exposure…

    Read digest →

  • Tech Layoffs Watch No16

    Starbucks Reshapes Corporate Technology Operations • HR Block Announces Restructuring Job Cuts • General Dynamics Cuts Jobs Amid Demand Pressure • HelloFresh Restructures With Workforce Cuts • Sanofi Reports Merger-Related Layoffs…

    Read digest →

  • Vulnerability Watch No56

    Splunk flaw lets lower-privileged users write arbitrary dispatch metadata • Splunk Monitoring Console link flaw enables unauthorized searches • Splunk authentication weakness can enable forged admin sessions • Splunk SPL2 API issue allows unauthorized module deletion • Splunk Web XML weakness enables operating system command execution…

    Read digest →

  • Tech Layoffs Watch No15

    MaineHealth Announces 83 Job Cuts • Netflix Restructures With 59 Job Cuts • CJ Logistics America Cuts 57 Jobs • Google Reports 52 Job Cuts • Carlex Glass America Cuts 325 Jobs…

    Read digest →