News

The x321 Tech Digest — what engineers are talking about, distilled daily.

  • Vulnerability Watch No45

    CrateDB Blob API Bypasses Table Privileges • Malicious Projects Can Trigger Code Execution in Cortex MCP • Recursive Jinja Rendering Enables Command Execution in compliance-trestle • Public Exploit Targets TOTOLINK A800R DHCP Handler • Public Exploit Exposes TOTOLINK A800R IPv6 Stack Overflow…

    Read digest →

  • Vulnerability Watch No44

    Tenda G0 Port Mapping Flaw Enables Remote Buffer Overflow • Tenda G0 Static Route Bug Triggers Remote Stack Overflow • Tenda G0 Port Mirroring Endpoint Hit by Buffer Overflow • Tenda AC1206 Guest Wi-Fi Handler Exposed to Remote Overflow • Tenda AC1206 Device Naming Flaw Enables Remote Buffer Overflow…

    Read digest →

  • Topics Everyone Is Talking About No407

    Codex in ChatGPT desktop app for Linux is now in preview • DeepSeek Harness developer preview • Gloomberb • Gemini 3.7 Flash • Spaghettifying DRAM…

    Read digest →

  • Vulnerability Watch No43

    Biagiotti Core Vulnerable to Unauthenticated Local File Inclusion • Reviewer Subscriber Accounts Can Trigger SQL Injection • Multicluster Engine Tenant Isolation Flaw Enables Cross-Tenant Access • WP Directory Kit Hit by Unauthenticated SQL Injection • Critical Unauthenticated SQL Injection Affects WP Directory Kit…

    Read digest →

  • Framework Release Watch No11

    Angular Language Service vsix-22.1.0 Expands Template Type Checking

    Read digest →

  • Vulnerability Watch No42

    UpSnap Fresh Installs Exposed to Unauthenticated Root RCE • Cedar Express Middleware Flaw Can Bypass Route Authorization • MRBS Vulnerable to Server-Side Request Forgery • OpenStack Designate Flaw Enables Cross-Tenant DNS Hijacking • UpSnap Device Fields Allow Authenticated Command Injection…

    Read digest →

  • Topics Everyone Is Talking About No406

    AI is removing the middle class of software engineering • Grok 4.6 • License plate reader searches should require a warrant • Tailscale Traces Database Corruption to 16yo SQLite WAL-Reset Bug • Im done using AI…

    Read digest →

  • Vulnerability Watch No41

    Critical Microsoft UFO Flaw Exposes ADB-Connected Android Devices • Nagios Notification Macros Enable Authenticated RCE • Nagios NRDP Macro Injection Opens Path to RCE • Nagios CSRF Bypass Can Trigger Commands as Authorized Users • IBM i Navigator Spoofing Flaw Enables Credential Harvesting…

    Read digest →

  • Topics Everyone Is Talking About No405

    No, local models will not win • My Anti AI computer • GNOME Shell Design Dreams • England set to be one of the first countries to eliminate hepatitis C • Stealing Reasoning Traces from Proprietary LLM APIs…

    Read digest →