News
The x321 Tech Digest — what engineers are talking about, distilled daily.
-
Framework Release Watch No10
Laravel 13.25.0 Expands Image and Queue APIs • Laravel 12.66.0 Hardens Cloud Integrations
-
Vulnerability Watch No39
Windows DHCP Client Heap Overflow Enables Privilege Escalation • Browserslist Cache Exhaustion Can Crash Processes • Browserslist Stats Parsing Opens Door to Crashes and Prototype Changes • Nanoid Integer Bug Can Make Security Tokens Predictable • Windows CLFS Race Condition Enables Local Privilege Escalation…
-
Tech Layoffs Watch No12
Nutanix Cuts 390 Jobs in Restructuring • Imperial Brands Cuts 2000 Jobs in Cost Push • Mercer International Cuts 350 Jobs • SF Pretrial Diversion Project Cuts 82 Jobs
-
Topics Everyone Is Talking About No404
A domain can now say it is for sale, in DNS • The Nixpkgs core team has disbanded • Hardware backdoors in some x86 CPUs • Code was never the hard part is an insult to all programmers • They dont make em like Sublime Text anymore
-
Vulnerability Watch No35
MingSoft MCMS SQL Injection Exposes Remote Attack Surface • node-sql-query SQL Injection Fixed in 0.1.29 • Aitemi M300 Command Injection Enables Remote Attacks • Tenda CH22 Command Injection Disclosed Publicly • Task Management System Hit by SQL Injection…
-
Vulnerability Watch No34
lollms Path Traversal Exposes Arbitrary Server Files • MSI Radix AXE6600 OpenVPN Flaw Enables Root Command Execution • MSI Radix AXE6600 Mac Filter Bug Allows Root Commands • MSI Router Telnet Configuration Flaw Leads to Root Access • MSI Router SSH Configuration Flaw Enables Root Command Injection…
-
Vulnerability Watch No33
Bouncy Castle FIPS Key Zeroisation Can Fall Behind on Newer JVMs • Bouncy Castle FIPS Entropy Failure Can Hang Applications • Klever-Go REST APIs Exposed to Slow-Header Denial of Service • Klever-Go Peer Can Trigger Unbounded Goroutine Creation • Tiny Malformed Transaction Can Crash Klever-Go Nodes…