News

The x321 Tech Digest — what engineers are talking about, distilled daily.

  • Vulnerability Watch No51

    Zephyr Flash Syscall Flaw Enables Kernel Privilege Escalation • Glances Action Templates Can Reconstruct Shell Operators • Malformed Host Header Can Crash WebSocket Servers • Endpoint Privilege Management Tamper Protection Can Be Bypassed • PyCharm Jupyter MCP Tools Expose Unauthenticated Code Execution…

    Read digest →

  • Vulnerability Watch No50

    GL.iNet Routers Hit by Remote NAS Command Injection • Public Exploit Targets Edimax WAN Command Injection • Edimax Access Point Command Injection Exploit Goes Public • Critical ipTIME Authentication Bypass Has Public Exploit • Planet9 File Permissions Enable SYSTEM Privilege Escalation…

    Read digest →

  • Topics Everyone Is Talking About No410

    Claude: System Prompts • Models Are Getting Dumber on Purpose • What happens when an LLM never sees material beyond fifth grade? • I thought I was building a C replacement. I was wrong • Every Fucking Website…

    Read digest →

  • Vulnerability Watch No49

    Scriban Parser Recursion Can Crash Hosting Processes • Circular Objects Trigger Fatal Scriban Stack Exhaustion • Nested Arrays Bypass Scriban Expression Depth Protection • Scriban Template Cache Can Leak Previously Authorized Content • Scriban Cache Flaw Breaks MemberFilter Sandbox Boundaries…

    Read digest →

  • Vulnerability Watch No48

    WordPress Frontend Admin Flaw Enables Administrator Takeover • Royal Elementor Addons SSRF Exposes Internal Services • Podlove File Deletion Flaw Can Lead to Remote Code Execution • ProSolution WP Client Upload Bug Enables Unauthenticated RCE • Autopay WordPress Plugin Allows Unauthenticated Stored XSS…

    Read digest →

  • Topics Everyone Is Talking About No409

    Zig Day Seattle, WA 3 • Why I remain a skeptic • Working with AI Feels More Like Leadership Than Coding • Abdominal fat predicts heart disease risk better than BMI • The First At-Home Test for Infected Ticks Could Improve Lyme Disease Diagnosis…

    Read digest →

  • Vulnerability Watch No47

    Hard-Coded Credentials Expose LB-LINK X-PRO • SQL Injection Hits SourceCodester Timetabling System • Fastify Multipart Flaw Enables Persistent Disk Exhaustion • Fastify Multipart Bug Can Exhaust Disk and Event Loop • Fastify JWT Key Override Breaks Authorization Boundaries…

    Read digest →

  • Vulnerability Watch No46

    Unauthenticated Stored XSS Hits Invisible Anti-Spam WordPress Plugin • Cookie Consent Plugin Exposes WordPress Sites to Stored XSS • MaxUpload Flaw Enables Unauthenticated File Upload and Possible RCE • User Session Synchronizer Bug Allows Full WordPress Account Takeover • Propovoice Manager Accounts Can Escalate to WordPress Administrator…

    Read digest →

  • Topics Everyone Is Talking About No408

    In Australia, a home battery boom has helped cut wholesale power prices • Qwen 3.8 27B • Firefox is now the last major browser that still supports uBlock Origin • Count Binface receives over a quarter of votes in Clacton by-election • Comments in the code vs PR description…

    Read digest →

  • Framework Release Watch No12

    NestJS 11.2.0 adds HTTP QUERY and SSE signals

    Read digest →