Internationale Coding News

  • Hackers Are Exploiting Recently Patched WordPress Bugs, Putting Millions of Websites at Risk
    Dienstag 3:30 BeauHD at Slashdot
    An anonymous reader quotes a report from TechCrunch: Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday. Last week, WordPress patched two critical security flaws, urging people who run its software on their websites to update it „immediately.“ The vulnerabilities are so severe that WordPress enabled forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr …
  • New Orleans Cops Published Policy Document Allowing Weaponized Drones
    Montag 23:00 BeauHD at Slashdot
    A draft New Orleans Police Department drone manual briefly published online would have allowed police drones to carry weapons with written approval from the superintendent, according to 404 Media. NOPD says the document was only an early draft and that its current policy (PDF) bans drones from carrying weapons or hazardous materials. 404 Media reports: The current version, live as of July 1, has different language: „The sUAS shall not be equipped with weapons or hazardous materials of any kind,“ referring to small Unmanned Aerial Systems, or drones. According to the NOPD, the operations manual …
  • Longtime Web-Weirdness Site Fark Faces Ad Pinch
    Montag 22:40 BeauHD at Slashdot
    sandbagger writes: Fark.com is ancient in internet terms. It’s not social media. It’s not quite a news site. It’s a holdover from the dot-com era and is invisible to Google, which makes its community great but has necessitated begging. „[W]e won’t survive this year without more TF subscribers,“ wrote founder Drew Curtis in a post on Bluesky. „Spread the word.“ For the unfamiliar, Fark is one of the web’s OG community news sites that features a wonderfully weird mix of user-submitted links, absurd headlines, Photoshop contests and comment-section mayhem. It has also been featured numerous times …
  • China's New AI Model Halts New Subscriptions As Demand Swamps Capacity
    Montag 21:00 BeauHD at Slashdot
    Moonshot AI has temporarily paused new subscriptions for its Kimi K3 model after demand surged beyond the company’s current capacity within days of the launch. The open-source Chinese AI model, described as one of the largest of its kind at 2.8 trillion parameters, has rattled U.S. rivals by beating Anthropic’s Fable 5 and OpenAI’s GPT-5.6 Sol in front-end coding tests. The Associated Press reports: „Kimi K3 has received far more love than we expected,“ Moonshot AI, which is Beijing-based, wrote in a X post late on Sunday. „Over the past 48 hours, demand has pushed close to the limits of our c …
  • Head of US Safety Agency Resigns
    Montag 20:00 BeauHD at Slashdot
    Chris Fall has resigned as director of the U.S. Center for AI Standards and Innovation just three months after being appointed to lead the Commerce Department’s federal AI testing institute. Arvind Raman, who oversees the Commerce office responsible for the institute, will serve temporarily in the role. „The Commerce Department did not provide a reason for Fall’s departure,“ reports Reuters. From the report: Fall’s exit marks the latest change in direction for Trump’s approach to AI. The president upon returning to office in 2025 said the federal government should take a hands-off approach to …
  • Scaling Row-Level Security With ABAC on Databricks Unity Catalog
    Montag 19:00 Sriram Vadlamani at DZone.com Feed
    Onboarding a new table into row-level security should be four lines of metadata. Not two new objects, a code review, and a platform-team ticket. This post describes a tag-driven attribute-based access control (ABAC) pattern built on Databricks Unity Catalog primitives that achieves the objective of one UDF per filter shape, one policy per shape, and a single control table that drives all per-group authorization logic. I work as a solutions architect with large enterprises running hundreds of tables across multiple regions, product lines, and source systems, where row-level security follows a p …
  • AliExpress Hit With Record $625 Million Fine After Failing To Make EU-Ordered Fixes
    Montag 19:00 BeauHD at Slashdot
    The European Commission has fined AliExpress more than $625 million, the largest penalty yet under the Digital Services Act, after finding that the marketplace failed to „diligently assess and mitigate risks relating to the sale of illegal, unsafe, or counterfeit products on its e-commerce platform.“ EU officials said flagged products repeatedly reappeared, sellers could evade safeguards, and AliExpress’s recommendation and ad systems helped amplify dangerous goods. Ars Technica reports: For shady sellers, the risks of detection appeared low. The e-commerce site’s mandatory brand authorization …
  • Agent Sprawl Is Your Next Production Incident: An SRE Response to Datadog's State of AI Engineering 2026
    Montag 18:00 AJAY DEVINENI at DZone.com Feed
    Datadog published the State of AI Engineering 2026 report— real telemetry from over a thousand production environments. Read it. It is the most comprehensive look at AI in production available right now. I want to respond from the reliability engineering perspective, because the data reveals a problem the report names but doesn’t fully resolve: agent sprawl is now a production reliability crisis, and the SRE discipline does not yet have governance frameworks for it.
  • LG Monitors Silently Install Adware-Like App On Windows PCs
    Montag 18:00 BeauHD at Slashdot
    VideoCardz reports that connecting certain LG monitors to Windows PCs can trigger Windows Update to automatically install the LG Monitor App Installer, which runs at startup and repeatedly displays McAfee trial promotions. From the report: Gamers Nexus reproduced the behavior with an LG UltraGear 34GX900A-B after receiving reports from monitor owners. Windows Update first installed LG extension and software component packages. Windows Reliability Monitor showed that LG Monitor App Installer appeared one minute later. The installation did not display a consent prompt or require the user to appr …
  • Hacker Wipes Romania's Entire Land Registry Database
    Montag 17:05 BeauHD at Slashdot
    A hacker reportedly wiped Romania’s entire land registry database after a failed extortion attempt, halting property transactions across the country and preventing notaries from issuing land extracts, authenticating sales, or registering mortgages. „On the dark web, the hacker also boasted to have begun backup copies of stolen data in an attempt to prevent it from being restored,“ reports Cybernews. „However, Romanian officials have managed to at least restore the ANCPI’s website and post a message saying they were rebuilding the agency’s entire network from scratch. It appears that the agency …
  • Green Unit Tests Are a Comfort Blanket
    Montag 17:00 Mikhail Golikov at DZone.com Feed
    My converter has a test suite. It was green. Every example I could think of went in, the right pytest file came out, and I shipped it to PyPI as 1.0. Weeks later it sits there marked Production/Stable. Then I pointed a fuzzer at it, and it stopped being so quiet.
  • SleeperGem RubyGems attack evades CI to hit developer laptops
    Montag 16:39 Ryan Daws at Developer Tech News
    Three malicious RubyGems packages published in July 2026 evaded CI detection by targeting developer laptops directly, researchers say. Security researchers at Aikido Security identified and named the campaign SleeperGem after tracing malicious releases of three RubyGems packages pushed to the public registry between July 18 and July 19, 2026. StepSecurity subsequently ran each compromised version […] The post SleeperGem RubyGems attack evades CI to hit developer laptops appeared first on Developer Tech News.
  • 7 Essential Guardrails for Building AI SRE Agents
    Montag 16:00 Akhilesh Rao Meesala at DZone.com Feed
    AI agents are quickly moving from demos into engineering workflows. For site reliability engineering teams, the appeal is obvious: an agent that can read alerts, inspect dashboards, query logs, correlate deploys, and summarize a likely root cause could reduce the painful first minutes of incident response. But SRE work is different from ordinary automation. A bad suggestion in a chat window is inconvenient. A bad action in production can create an outage, delete data, or make recovery harder.
  • LSU Physicists Create First Room-Temperature Quantum Material
    Montag 16:00 BeauHD at Slashdot
    Researchers at Louisiana State University have created a room-temperature quantum material made from a thin gold film on glass, patterned with microscopic slits that act like artificial atoms. „We call this robust transport. These quantum states carry information,“ says physicist Omar Magana-Loaiza. „Our crystal can distinguish them and move them from one point to another in a robust way without requiring cryogenic cooling. That’s what opens the door to practical quantum technologies.“ ScienceAlert reports: Crucial to the new material’s room-temperature operation is the way it shifts the focus …
  • Fix Circular Dependencies in PostgreSQL Row-Level Security With SECURITY DEFINER Functions
    Montag 15:00 Lex Mulier at DZone.com Feed
    Row-level security in PostgreSQL is one of the more useful features for multi-tenant applications. The idea is straightforward: define a policy on a table that tells PostgreSQL which rows a given user is allowed to see or modify, and the database engine enforces it on every query, regardless of which application code issued the request. The trouble comes when your policies form a cycle. This is more common than it sounds, and it produces one of the more confusing failure modes in PostgreSQL: a query that should return data returns nothing, with no error.
  • LibreOffice Once Again Slams Microsoft For Using 'Lock-In' With Office Files
    Montag 15:00 BeauHD at Slashdot
    An anonymous reader quotes a report from XDA Developers: One of the founding members of The Document Foundation and handler of LibreOffice’s PR and media relations, Italo Vignoli, took to the LibreOffice blog to call out Microsoft’s practices with its Office application. The last time we saw Vignoli take to the stage, we saw him accusing Euro-Office of being just as bad as Microsoft with its practices. Vignoli’s new post focuses entirely on Microsoft’s strategy. He says that „the dominant format for office documents“ is owned by Microsoft Office, particularly the DOCX, XLSX, and PPTX formats. …
  • Security Is a Platform Property, Not a Pipeline Step
    Montag 14:00 Naveen Kalapala at DZone.com Feed
    A few weeks ago, I disabled key authentication on an Azure storage account we used for Terraform state management. It was one of the key security recommendations in Microsoft Defender for Cloud. It made sense to use RBAC-only permissions, enforce PIM approvals for the Infrastructure team, and avoid storing static credentials in config files, where leaks are possible. This is exactly the kind of control you want for state files, which contain the keys to your entire cloud environment. But I missed an important line in the azurerm backend config. If use_azuread_auth = true is not explicitly set, …
  • The Agent Security Split: Tool Layer vs Sandbox Layer
    Montag 13:00 Tosin Akinosho at DZone.com Feed
    When an enterprise asks, „Is your agent platform secure?“, the question is almost always a bundle of two distinct architectural concerns: Tool layer: Can the agent only call the tools we approved? Are the tool inputs and outputs validated? Are credentials kept out of the LLM’s context? Are calls audited? Sandbox layer: When a tool runs code, browses the web, or shells out — is that execution isolated from the host? Can it reach internal networks? Can it write outside its working directory? These look adjacent, but they fail differently. A tool layer fails when an agent calls something it shoul …
  • When Data Quality Checks Pass but the Data Is Still Stale
    Montag 12:00 Vivek Venkatesan at DZone.com Feed
    A pipeline can finish successfully, schemas can match, and null checks can pass, while the business is still looking at yesterday’s truth. Freshness deserves its own quality model. The pipeline succeeded. The schema matched. Required fields were present, ranges were sane, and the dashboard refreshed on schedule. Every quality check was green. The number on the screen was still wrong, because it was built from data that stopped updating two days ago and nobody noticed.
  • Hollywood Sci-fi Studio Lot Now Pitched As Site To Make Real Space-age Weapons
    Montag 11:34 EditorDavid at Slashdot
    James Cameron filmed his Avatar sequels there. Marvel filmed Thor, Iron Man 2, and The Avengers. Manhattan Beach Studios in Los Angeles even handled Star Wars‘ series like Obi-Wan Kenobi and The Mandalorian, which Bloomberg points out is about „a heavily armed bounty hunter in a galaxy far, far away.“ „Now lenders who are selling the property’s $240 million mortgage are promoting the site to potential buyers as a hub for making real space-age weapons.“ „The project is strategically positioned within Los Angeles‘ prominent aerospace and innovation corridor, anchored by industry leaders such as …
  • New Free Speech Concern: When AI Chatbots Won't Criticize Leaders from Repressive Regimes
    Montag 7:34 EditorDavid at Slashdot
    Ask Claude to make a pamphlet critical of China’s leader, Thailand’s king, or Saudi Arabia’s crown prince — and it will decline, reports the Associated Press. That’s „a key finding from a Meta Oversight Board study released Thursday,“ their article points out: AI systems are more than twice as likely to refuse to product critical material if it’s about a restrictive world leader or government. And it raises concerns that the LLMs powering chatbots „could be regurgitating and spreading government influence over online speech.“ The study picked 10 commercial large language models by top tech com …
  • Rust Will Help Linux Succeed and Makes Coding Fun, Says Greg Kroah-Hartman
    Montag 4:20 EditorDavid at Slashdot
    ZDNet reports on June’s Open Source Summit India 2026 in Mumbai, where Linux stable kernel maintainer Greg Kroah-Hartman gave a talk titled „Rust and Linux: How the Rust Language is Going to Help Linux Succeed.“ Kroah-Hartman said in his keynote that „the [Linux] kernel is moving toward Rust. Git is moving toward Rust. Lots of projects are starting to move toward Rust.“ He didn’t always feel that way. Kroah-Hartman added, „A number of years ago, when a friend of mine said, ‚Ah, you got to try this new language. It’s called Rust.‘ I was like, ‚What? No, C is great.‘ His friend continued, „‚No, …
  • As AI Transforms Silicon Valley, Some Tech Workers Face Evaporating Financial Security
    Montag 2:15 EditorDavid at Slashdot
    The Washington Post describes a mid-tier executive at Meta as one of Silicon Valley’s „winners“ whose financial security suddenly „evaporated“ as their workforce „pushed headlong into AI and heavy job cuts,“ creating a transformed job market. „Her ex-husband, a designer at Meta who was laid off in 2020, eventually gave up looking for jobs in his profession. He now lifts boxes at a warehouse.“ Layoffs.fyi, which tracks announced job cuts, counts more than 800,000 tech workers laid off since 2022, including large staff reductions in recent months at Meta, Microsoft, Oracle and Amazon… „There’s …
  • Zilog Z80 8-Bit CPU Turns 50, Open-source Replacement Heads To Drop-in DIP40 Silicon
    Montag 0:50 EditorDavid at Slashdot
    An anonymous reader shared this report from Tom’s Hardware: The Zilog Z80 has just turned 50 years old. This iconic 8-bit processor first went on sale in July 1976 and stayed in production for 48 years until Zilog, now a Littelfuse subsidiary, stopped accepting orders in June 2024. However, there’s an open-source replacement closer than ever to shipping in the chip’s original 40-pin DIP package thanks to community-funded fabrication… The chip powered the ZX Spectrum, TRS-80, MSX machines, Nintendo’s Game Boy, Sega’s Master System, the Pac-Man arcade cabinet, and Texas Instruments‘ graphing c …
  • Observability for AI Agents and Multi-Agent Systems: When Your System Can't Tell You Why It Did That
    Freitag 19:00 Pruthvi Raj Seknametla at DZone.com Feed
    The bug report was received as a customer complaint. An AI agent responsible for managing vendor onboarding had sent a rejection email to a supplier the company had been trying to close for three months. Nobody had authorized it. Nobody had configured it to reject vendors in that category. The agent autonomously made the decision after analyzing a compliance document and cross-referencing it with an internal policy database. By the time the complaint arrived, the reasoning chain that produced the decision had been discarded. The agent had no memory of why it did what it did. The logs showed th …
  • Mitigating Cache Stampedes in Dynamic API Translation Using Java 21 Virtual Threads
    Freitag 18:00 Aniruddha Chatterjee at DZone.com Feed
    The Hidden Cost of API Versioning Hell Continuous API evolution is non-negotiable in contemporary software development, yet maintaining backward compatibility remains an incredibly expensive and labor-intensive hurdle. Core schema mutations frequently force downstream enterprise clients into disruptive and unplanned refactoring cycles, stalling product velocity.   The typical industry fix — maintaining multiple, hard-coded API routes (e.g., /v1, /v2) — inevitably results in severe codebase sprawl, fractured engineering focus, and massive technical debt for the API provider.  
  • Seeding Postgres When Your Schema Has Foreign-Key Cycles
    Freitag 17:00 Mikhail Shytsko at DZone.com Feed
    I have lost more afternoons than I would like to admit on this exact problem: a seed script that ran cleanly yesterday now crashes on its first INSERT, and the error message tells you something you already knew, namely that you have a chicken-and-egg dependency between two tables. SQL   ERROR: insert or update on table „users“ violates foreign key constraint „users_organization_id_fkey“ DETAIL: Key (organization_id)=(1) is not present in table „organizations“. The natural next move is to reorder the inserts, putting organizations first, except that organizations.owner_user_id is NOT NULL REFER …
  • AGENTS.md Makes Your Java Codebase AI-Agent Ready
    Freitag 16:00 Daniel Oh at DZone.com Feed
    The year is 2026, and the way software is built has fundamentally shifted. We are no longer just writing code for other humans to read; we are building systems that AI coding agents, such as Cursor, GitHub Copilot Agent Mode, Claude Code, and autonomous CLI tools, will navigate, debug, and extend. As Java developers, we are blessed with robust tooling. If you are using Quarkus, you already possess a superpower: Supersonic Subatomic Java with an ultra-fast developer loop, continuous testing, and built-in Dev Services.
  • White House launches AI clearinghouse for vulnerability patching
    Freitag 15:04 Ryan Daws at Developer Tech News
    The White House has launched GOLD EAGLE, an AI clearinghouse to coordinate vulnerability patching across infrastructure sectors. The administration says it has “already begun to intake and prioritise” vulnerability data across sectors and coordinate scanning verifications. GOLD EAGLE traces its authority to Executive Order 14409, signed on 2 June 2026 and titled ‘Promoting Advanced Artificial […] The post White House launches AI clearinghouse for vulnerability patching appeared first on Developer Tech News.
  • Every SOC Today Is Answering the Wrong Question
    Freitag 15:00 Igboanugo David Ugochukwu at DZone.com Feed
    Ask most detection engineers what a SOC does, and they’ll say: it finds compromised machines. That’s the wrong question. Attackers stopped compromising machines as the primary objective years ago — machines are just where identities and trust relationships happen to execute. A stolen session token, a federated role assumption, an over-scoped service account: none of those are „a machine got popped.“ They’re a trust relationship quietly doing exactly what it was configured to do, on behalf of someone who shouldn’t have it.
  • Designing Scalable Containerized Backend Services
    Freitag 14:00 Estefanio Fernando at DZone.com Feed
    Modern enterprise software design has fundamentally shifted away from monolithic, single-threaded runtimes toward decoupled, containerized architectures. When building systems that handle high throughput — such as fintech services, automated reporting pipelines, or real-time distributed platforms — engineers must address two core infrastructure vectors: high-concurrency connection management and deterministic relational state execution. A common anti-pattern in backend systems engineering is assuming that containerization automatically scales an application. In reality, wrapping a poorly optim …
  • Your Automation Pipeline Is Not a Source of Truth
    Freitag 13:00 Jeleel Muibi at DZone.com Feed
    A CI/CD pipeline that runs without errors creates a sense of correctness. The job is green. The deployment happened. The infrastructure must reflect what it should. This logic feels sound, and it breaks down in a specific way worth understanding. The pipeline knows what it was told to do at the time it ran. It does not know whether that was the right thing to do. And it cannot tell you whether the state it produced is still aligned with what the organization actually needs, because it has no persistent model of intended state to check against. It ran, it applied, it exited.
  • Anti-Patterns of Microservices Architecture From Real Production Experience
    Freitag 12:00 Ivan Balashov at DZone.com Feed
    Microservices architecture is frequently presented as the natural evolutionary step for scaling modern systems. In presentations and case studies, it appears almost inevitable. Break the monolith into smaller services, deploy independently, scale selectively, and gain resilience through isolation. In practice, the story is more complex. Across long-running production environments, I have seen microservices introduce as many risks as they resolve. The challenges rarely stem from incorrect frameworks or insufficient engineering skill. Instead, they arise from architectural decisions that did not …
  • Fake GitHub repositories exploit developer trust to spread malware
    Freitag 9:00 Muhammad Zulhusni at Developer Tech News
    A campaign involving at least 292 impersonation repositories shows that securing the software supply chain requires developers to verify where tools, binaries, and source code originate. A threat actor created hundreds of fake GitHub organisations and repositories impersonating software companies, security vendors, developer tools, cryptocurrency services, and other technology brands. Arctic Wolf Labs identified at […] The post Fake GitHub repositories exploit developer trust to spread malware appeared first on Developer Tech News.
  • When AI Agents Call Your Microservices: 5 Assumptions That No Longer Hold
    Donnerstag 19:00 Maryna Klochkova at DZone.com Feed
    Microservices were designed around a simple contract: a known caller sends a predictable request, expects a typed response, and moves on. That contract held for years. Then AI agents arrived. An agent doesn’t call your service once. It might call it three times in a single reasoning loop, fan out to five services simultaneously, retry on ambiguous output, or decide mid-flight that a different endpoint is more appropriate. The distributed systems assumptions baked into your architecture rate limiting, idempotency, circuit breakers, auth flows were never built for a non-deterministic, autonomous …
  • Going Stateless: Scaling MCP Servers to Cloud-Native Java and HTTP
    Donnerstag 18:00 Daniel Oh at DZone.com Feed
    The Model Context Protocol (MCP) completely changed how we connect large language models to real-world data and tools. However, early versions of the protocol had a massive bottleneck for enterprise developers: they relied heavily on stateful, long-lived sessions. If you wanted to scale out your AI tools to handle thousands of concurrent agent workflows, you had to deal with sticky sessions, complex load balancing, and heavy memory overhead. The newest updates to the MCP specification solve this problem by introducing a completely stateless HTTP foundation. By removing the traditional initiali …
  • Platform Engineering 2.0: Evolve the Substrate for AI and Agents
    Donnerstag 17:00 Chris Ward at DZone.com Feed
    Al has blindsided cloud native infrastructure management, rendering established platform engineering woefully inadequate. Original platform engineering often suffers from a developer-only focus, but a platform that serves only one persona in a multi-persona organization ultimately delivers a shrinking fraction of its potential enterprise value. Autonomous agents are already beginning to write, review, test, and deploy code or fixes with or without human intervention. This shifts the primary organizational bottleneck from writing code to delivering it safely and quickly.  The gap requires a new …
  • Most Automation Failures Aren’t Bugs — They’re Boundary Problems
    Donnerstag 16:00 Gayathri Bolineni at DZone.com Feed
    When Nothing Is Broken — But the System Still Fails You hit a failure. Tests are failing, or the system behaves in a way that doesn’t make sense. You check the code first. Nothing obvious.  Then logs. Still nothing conclusive. You retry. Same result.
  • Python in 2026: uv vs Poetry vs pip: The Definitive Comparison
    Donnerstag 15:00 Varun Joshi at DZone.com Feed
    Being a Python developer, I have lived through the chaos: setup.py, requirements.txt, virtualenv, pipenv, conda, flit, hatch, poetry — each has promised to fix what came before. In 2026, the dust has settled around these three contenders:
  • Your Agent Trusts That Wiki. Should It?
    Donnerstag 14:00 Abhinav Srivastava at DZone.com Feed
    We were building a DevOps agent to help with on-call remediation. The idea was straightforward: when an incident fires, the agent reads the relevant runbook from our internal wiki, assesses the situation, and executes the appropriate remediation steps. No waiting for an engineer to wake up at 3 am, find the right page, and manually run through a checklist. The agent had the context, the tools, and the access it needed to act. It needed elevated privileges to do the job. Restarting services, scaling resources, in some cases deleting and recreating stacks. That access was intentional. You cannot …