Dev.to
AI Security Breaches, Vibe Coding Secrets Leak, and OpenAI's $500B Week
AI Security Disasters This Week 🔥 Half a trillion in AI valuations. Eight thousand children's records nicked. Sudo is broken. Everything is on fire and we're shipping vibes. Right. Where to start with this week of AI security breaches and vibe coding gone wrong. A ransomware gang called Radiant (love the branding, lads) hacked a nursery chain called Kido and walked off with personal data on 8,000 children. Children. Not enterprise accounts. Not crypto wallets. Actual kids in actual nurseries. I don't usually get properly miffed about security news because frankly if you're still leaving RDP open to the internet you deserve what's coming. But targeting nurseries? That's a new kind of grim. Meanwhile: OpenAI hit a $500 billion valuation. Half. A. Trillion. We're living in a timeline where AI companies are worth more than most countries' GDP and a nursery chain can't keep toddler data safe. Cool. This is fine. The Hits Keep Coming 💀 It wasn't just the nursery hack. This week was a proper security shambles from top to bottom. Google Ads serving trojans. You search for something legitimate, click an ad at the top of Google, and congratulations, you've just installed malware. Google taking money to distribute malware is chef's kiss levels of ironic. The ad platform that prints money can't vet what it's printing. Fake invoices spreading RATs. Remote Access Trojans shipped via invoice PDFs. Because apparently we still haven't sorted out "don't open random attachments" after twenty-odd years of trying. The sudo exploit (CVE-2025-32463) got added to CISA's Known Exploited Vulnerabilities list. Actively exploited. In the wild. Right now. Sudo. The thing that literally gates root access on every Linux box you've ever touched. If that doesn't make you sweat a bit, you're not paying attention. Tile tracking devices flagged as a stalking risk. The thing you bought to find your keys can apparently be weaponised to find you . Reassuring. UK Co-Op attack costs hit $275 million. Drago
Steven Gonsalvez
2026-07-10 23:43
👁 3
查看原文 →
Dev.to
Multi-Agent Error Cascades: The Double Pendulum Problem Nobody Talks About
Your agents are a chaos machine 🎯 So HumanLayer dropped their Advanced Context Engineering piece last week, and buried in it is this absolute banger of a line: "Bad research -> bad plan -> bad code. A single wrong line in research cascades to widespread errors." That's Dex Horthy describing what happens when you chain AI agents together without checkpoints. And it's the exact same mechanics as a double pendulum. You know the double pendulum, yeah? Simple physics demo. One pendulum hanging from another. The top one swings predictably. The bottom one goes absolutely mental. Tiny changes in the initial swing of the top pendulum produce wildly different trajectories in the bottom one. Chaos theory in action. Looks like it's possessed. Multi-agent AI systems are double pendulums. Your research agent makes a small mistake. Misidentifies which module handles authentication. Gets one import path wrong. Reads an outdated API signature. Tiny error. Barely noticeable in the research output. Your planning agent reads that research and builds a plan around the wrong assumption. The plan isn't obviously wrong. It's coherent. It just starts from a slightly incorrect foundation. The deviation from reality is bigger now but still plausible-looking. Your implementation agent reads that plan and writes hundreds of lines of code. Code that's internally consistent but built on a foundation of sand. The cascade is complete. One wrong line in research became a hundred wrong lines in code. Why more agents makes this worse, not better Here's the bit that does my head in. The whole pitch of multi-agent systems is "more agents = better results." Specialise each agent. Divide the labour. Sounds reasonable. But every agent you add to the chain is another joint in the pendulum. Every handoff is another point where small errors amplify. A three-agent pipeline (research, plan, implement) has two handoff points. A five-agent pipeline has four. Each one is a potential chaos amplification. Sean Moran
Steven Gonsalvez
2026-07-10 23:43
👁 3
查看原文 →
Dev.to
Why Terminal AI Coding Agents Are Beating IDE Extensions
The Headless Takeover 🖥️ IDEs had a good run. Then the terminals learned to think. Here's the thing nobody's saying out loud: terminal-based coding agents are eating headed apps for breakfast. And it's not even close. The Architecture Gap Every IDE-based agent - Cursor, Windsurf, whatever's launching next week - has the same fundamental constraint: IPC . Inter-process communication. The IDE runs here, the AI runs there, and they talk through some protocol layer. Extensions, language servers, message passing. It works, but it's a bottleneck by design. Terminal agents? Direct subprocess execution. No middleware. No protocol translation. You spawn a process, it runs, you get output. Done. 📚 Geek Corner IPC vs Subprocess : IDE extensions typically communicate via JSON-RPC, WebSockets, or custom protocols. Each message serialises, transmits, deserialises. Terminal agents skip all of that - they're just running shell commands as child processes with direct stdin/stdout pipes. The overhead difference is orders of magnitude. The Composability Factor Terminal tools are composable by default . cat file.ts | grep "TODO" | wc -l Thirty years of Unix philosophy baked into every interaction. Pipes. Redirects. Scripts. You can wrap anything - linters, formatters, compilers, test runners, deployment scripts - and the agent just treats them as tools. Try doing that in a GUI. You're clicking buttons. Waiting for panels to load. Fighting with extension APIs that change every release. Terminal agents don't care about your UI framework. They run commands. Commands compose. That's it. The Scaling Play This is where it gets spicy. How do you scale a GUI-based agent? You don't. One human, one screen, one IDE instance. Maybe you run a second window if you're feeling fancy. Terminal agents? Spawn ten of them. Spawn a hundred. Run them in CI. Run them on every PR. Run them overnight while you sleep. They're just processes - orchestrate them however you want. # This is trivial with terminal ag
Steven Gonsalvez
2026-07-10 23:43
👁 3
查看原文 →
Dev.to
GPT-5, Opus 4.1, and Duct-Tape Security: AI's Wildest Week in 2025
The Week That Had Everything 🎪 A 24-year-old lands a $250M AI pay package. Meanwhile, link wrappers are nicking your login credentials. Same industry. Same week. Right, where do I even start with this one. Week 32 was the kind of week where every newsletter hit different. GPT-5 dropped. Opus 4.1 dropped. OpenAI went open-source. Cursor got a CLI and got poisoned. North Korean devs are still out here catfishing hiring managers. And someone, somewhere, is writing a quarter-billion-dollar cheque to a researcher who can't legally rent a car in most US states. Let's crack on. The Money's Gone Absolutely Mental 💰 AI researchers are being recruited like Premier League strikers now. We're talking $250M packages. For a 24-year-old. I don't care how good your transformer architecture paper is, that number should make everyone uncomfortable. The maths works out to roughly "we'd rather overpay by 10x than let a competitor have you." Which, fine, that's how bidding wars work. But it tells you something about the state of things when the talent pool is so thin that a single researcher commands more than most companies are worth . Here's what bothers me though. These packages aren't salary. They're structured as equity, retention bonuses, and golden handcuffs. The researcher doesn't actually get $250M unless the company's valuation holds. And if we've learned anything from the last two decades of tech, valuations are vibes until they're not. Feels like: Paying someone a quarter billion to fix your plumbing while the rest of the house is on fire and nobody's rung the fire brigade. GPT-5: The Main Event (That Got Upstaged) 🎬 OpenAI shipped GPT-5 on Friday. Three variants: Pro, Mini, and Nano. Available to everyone in ChatGPT. Smartest and fastest, they say. And honestly? The reaction was a bit muted. Not because GPT-5 is bad. By all accounts it's proper good. But it landed in a week where everything dropped. Opus 4.1 on Wednesday. GPT-OSS on Wednesday. Gemini coding agent. Cursor CL
Steven Gonsalvez
2026-07-10 23:43
👁 3
查看原文 →
Dev.to
Vibe Coding Peak Hype: Windsurf Acquisition Chaos and the AI IDE Wars
Who Actually Bought Windsurf? 🌀 Three companies walk into a bar. They all claim they bought the same startup. Right. So here's the week in AI coding acquisitions, and I need you to stay with me because it gets properly daft. Monday : OpenAI's $3 billion bid for Windsurf collapses after Anthropic yanks their Claude API access. Brutal move, that. Like cutting off your rival's electricity mid-negotiation. Also Monday : Google DeepMind swoops in and hires Windsurf's CEO Varun Mohan, co-founder Douglas Chen, and the key researchers. Not an acquisition. A reverse acqui-hire. Price tag: $2.4 billion. For the people , mind you. Not the product. Tuesday : Cognition (the Devin lot) scoops up what's left: 250 engineers and $82 million in ARR. So in the space of 48 hours, Windsurf got rejected, stripped for parts, and sold off at a car boot sale. If you're a Windsurf user wondering what's happening to your IDE, the honest answer is: nobody has a clue, least of all Windsurf. Feels like: Watching a pub quiz team implode mid-game, with three other teams fighting over which one gets to adopt the remaining members. Steve Yegge Says What Everyone's Thinking The Pragmatic Engineer ran an interview with Steve Yegge this week, you know, the bloke who's been ranting about platforms since before most current SWEs had GitHub accounts. His take on vibe coding: it's deceptively hard . Not the coding itself (the AI handles that bit). The hard part is knowing whether what the AI produced is any good. He reckons there's an emerging "AI Fixer" role inside companies, someone whose entire job is reviewing and correcting AI-generated code. Which... yeah. That tracks. I've been saying this for months. Vibe coding is mint when you're prototyping or bodging together a script. But the second you need it to work in production, at scale, with actual users? You need someone who understands the code the machine spat out. And right now that someone is still a human. The hot take from the same week, "all mod
Steven Gonsalvez
2026-07-10 23:42
👁 3
查看原文 →
Dev.to
I Benchmarked 42 Compression Formats Spanning Four Decades. Here's What to Actually Use.
I run ezyZip , a browser-based archive tool, so "which format should I use?" is a question I field constantly. The honest answer is usually "it depends," which satisfies nobody. So I stopped hand-waving and measured it. We benchmarked 42 archive and compression formats, spanning four decades, from 1984's Unix compress through today's Zstandard, Brotli, and context-mixing paq8px. Everything ran against the same realistic 55 MB corpus, every archive was round-trip verified byte for byte, and the whole thing reproduces from a single command. Here's what came out of it, and what I'd actually reach for. The setup Most compression benchmarks measure raw codecs on standardized corpora like Silesia. That's the right call for algorithm research and the wrong call for answering "what should I zip my folder with?" I wanted end-user formats, real CLI tools, container overhead and all, on data that looks like an actual folder. So the corpus is deliberately mixed: about 11 MB of text, 15 MB of office documents, 16 MB of images, and 13 MB of video, all public domain so it can be committed and redistributed. That mix matters. Office documents ( .docx , .xlsx , .pptx ) are themselves ZIP containers, so they stress how a tool handles already-compressed data. The JPEG and H.264 media is near-incompressible and sets an honest lower bound. The plain text and uncompressed images are where formats actually separate. Two rules kept it fair and practical: Only two levels per tool: its default, and its one "maximum compression" dial. No method tuning, no dictionary sizes, no thread-count games. That's what a normal person can reach. Everything is round-trip verified. Each archive gets extracted, and every file is hashed with SHA-256 against the original manifest. Exit codes are not trusted. That last rule earned its keep immediately. The verification gotcha On the image category, a 1985-era ARC build produced an archive that its own extractor happily unpacked, while printing a CRC warning an
Andrew Dyster
2026-07-10 23:41
👁 6
查看原文 →
Wired
Hiboy P6 Fat Tire Electric Bike Review: Smooth Sailing
Take on sand, snow, mud, gravel—this is the ebike for all your off-roading adventures.
Kristin Canning
2026-07-10 23:22
👁 8
查看原文 →
InfoQ
Cloudflare Introduces Temporary Accounts for Autonomous Worker Deployment
Cloudflare has recently introduced temporary accounts that let AI agents deploy Cloudflare Workers immediately, without first creating or authenticating with a permanent account. If left unclaimed, the accounts and their deployments expire automatically after 60 minutes. By Renato Losio
Renato Losio
2026-07-10 23:16
👁 7
查看原文 →
The Verge AI
Anker’s 3-in-1 Qi2.2 charging station is $95 off
If you’re looking to declutter your nightstand and quickly charge up to three of your most-used gadgets, Anker’s Prime Wireless Charging Station is an easy way to do both. The station has spots for your MagSafe-ready iPhone, Apple Watch, and AirPods, and right now it’s down to a new all-time low of $134.99 ($95 off) […]
Sheena Vasani
2026-07-10 23:11
👁 8
查看原文 →
HackerNews
AI Cameras on Garbage Trucks to Scan Properties for Code Violations
deadonarrival
2026-07-10 23:09
👁 3
查看原文 →
TechCrunch
Oratomic raises $300M to build a viable quantum computer that needs only 20K qubits
The massive round was co-led by ARCH Venture Partners, Spark Capital, and Khosla Ventures.
Marina Temkin
2026-07-10 23:00
👁 8
查看原文 →
Product Hunt
Claude Overlay
A floating Claude Code chat that sees your screen Discussion | Link
Jason Lin
2026-07-10 22:54
👁 3
查看原文 →
HackerNews
Tell HN: I De-Googled Myself
I really enjoyed the old Google, the nerd Google, the "don’t be evil" Google... Google Reader, Android, GTalk, etc. It made communication with my friends much easier. I had already been moving everything away from the Google ecosystem for about two years, but Google Photos was the hardest part because it contained so many memories that I wouldn’t risk losing. The final straw was when I accidentally subscribed to Google One with AI, which costs much more than simple additional storage. It’s not t
degoogled
2026-07-10 22:29
👁 3
查看原文 →
The Verge AI
I spent a week using the Trump phone — it sucks
The Trump phone was never a serious phone. Not when it was announced last June, in dodgy renders and with an incoherent spec sheet. Nor when Trump Mobile admitted - just two weeks later - that it wouldn't be made in the US. Not even when the company revealed the final phone, first to me […]
Dominic Preston
2026-07-10 22:19
👁 7
查看原文 →
TechCrunch
EU threatens Meta with fines over addictive features on Facebook and Instagram
The tech giant is in breach of the Digital Services Act by focusing on features like infinite scroll, autoplay, push notifications, and the highly personalized recommendation algorithms, the European Commission said.
Aisha Malik
2026-07-10 22:19
👁 8
查看原文 →
TechCrunch
Florida ransomware negotiator convicted for helping ransomware gang extort US companies
A third ransomware negotiator has been jailed for helping a notorious ransomware group extort American victim companies into paying the hackers.
Zack Whittaker
2026-07-10 22:11
👁 7
查看原文 →
Product Hunt
Fudge MCP
Give your AI agents design taste from existing websites Discussion | Link
2026-07-10 22:06
👁 7
查看原文 →
TechCrunch
Hugging Face’s CEO on why companies are done renting their AI
Open source AI is booming, according to Hugging Face CEO Clem Delangue. The company has grown into something like a GitHub for AI in recent years, where AI builders can share and download open models and datasets, now used by roughly half the Fortune 500. Delangue has seen the same story play out again and again: companies start […]
Theresa Loconsolo
2026-07-10 22:00
👁 8
查看原文 →
Ars Technica
VW Group and unions disagree on plan to streamline the automaker
VW's plan calls for half as many models but didn't mention closures or job cuts.
Jonathan M. Gitlin
2026-07-10 21:51
👁 7
查看原文 →
InfoQ
Slack Introduces Agent Driven End-to-End Testing to Improve Resilience in UI Test Automation
Agentic testing is an AI-driven approach to end-to-end test automation introduced by Slack engineering. It uses AI agents that execute workflows based on intent rather than fixed scripts, adapting to UI and system changes at runtime. The approach aims to reduce brittle tests in distributed systems while complementing deterministic unit, integration, and E2E testing strategies. By Leela Kumili
Leela Kumili
2026-07-10 21:48
👁 7
查看原文 →