JSer.infoの情報源となるサイトをまとめたサイトです。
全てのサイトを一つにまとめたRSSを配信しています

Slackに貼り付けると更新を受け取ることができます

直近1週間の更新

6/13 (土)

記事のアイキャッチ画像
Workflow SDK now runs natively in Nitro v3 ブログのファビコン Vercel News
's native Nitro v3 integration is now in beta. Steps run inside the same bundled runtime as the rest of your app, instead of a separate bundle. Nitro's and other server-side APIs work directly inside functions.Workflow SDKuseStorage()"use step"The Nitro dev server also serves the workflow web UI at . Open it in your browser to inspect, monitor, and debug workflow runs./_workflowWorkflow routes are now bundled by Nitro as part of the app build. Dependencies are traced, and unused code is tree-sha
29分前
記事のアイキャッチ画像
OpenAI WebRTC Audio Session, now with document context Simon Willison's Weblog
<p><strong><a href="https://tools.simonwillison.net/openai-webrtc">OpenAI WebRTC Audio Session, now with document context</a></strong></p>I built the first version of this tool <a href="https://simonwillison.net/2024/Dec/17/openai-webrtc/">in December 2024</a> to try out the then-new OpenAI WebRTC API for interacting with their realtime audio models.</p><p>Last month OpenAI <a href="https://openai.com/index/advancing-voice-intellige...
36分前
記事のアイキャッチ画像
How we made GitHub Copilot CLI more selective about delegation ブログのファビコン The GitHub Blog
Better orchestration, fewer handoffs, faster progress, without a single new knob.The post How we made GitHub Copilot CLI more selective about delegation appeared first on The GitHub Blog.
2時間前
記事のアイキャッチ画像
LLM token theft: how attackers drain your AI startup's bottom line ブログのファビコン WorkOS Blog
A practitioner breakdown of LLM token theft: what it is, how the abuse works, the signals that catch it, and why traditional tools miss it.
3時間前
記事のアイキャッチ画像
Quoting Andrew Singleton Simon Willison's Weblog
<blockquote cite="https://www.mcsweeneys.net/articles/ai-economics-for-dummies"><p>Jenny owns a crematorium. John’s propane company gives her a $20 billion investment in return for 5 percent of her operation. Jenny throws $10 billion into the incinerator, then pays John $10 billion to buy propane to burn that money to ashes. John reports that his AI investments have generated $10 billion in revenue this quarter and that he owns 5 percent of a $100 billion business. A reporter from &...
6時間前
記事のアイキャッチ画像
In-N-Out Animations: Popovers (Part 2/3) ブログのファビコン Frontend Masters Boost RSS Feed
Using our 3, 2, 1 state system, we can make popovers animate on "the way in" and "the way out" just like we did with dialogs in Part 1.
9時間前

6/12 (金)

記事のアイキャッチ画像
エンジニアミートアップのはじめかた ブログのファビコン newmo 技術ブログ
技術情報のキャッチアップは、業務が忙しくなると最初に削られます。意志の問題ではなく、情報収集が時間を細かく、けれど継続的に消費する活動だからだと思っています。newmoでは立派な仕組みを作るより、忙しい週でも続く軽いものとしてエンジニアミートアップを行なっています。 Engineering Meetup とは newmoには「Engineering Meetup」という場があります。週に一度、エンジニアリングに興味のあるメンバーが話題を持ち寄る1時間のランダムトークです。毎週金曜の夕方に、所属や雇用形態を問わず誰でも参加できます。テーマはWebでもモバイルでもクラウドでも自動運転でも、最近読ん…
16時間前
記事のアイキャッチ画像
The Impact Of Humanoid Robots On Humanity ブログのファビコン Articles on Smashing Magazine — For Web Designers And Developers
We have officially moved past the era of humanoid robots as mere public relations stunts. As they become increasingly lifelike, society may soon face profound social, psychological, and ethical challenges. What happens when the boundary between humans and machines becomes almost impossible to distinguish?
16時間前
記事のアイキャッチ画像
ESLint v10.5.0 released ブログのファビコン ESLint Blog
HighlightsFive core rules now highlight smaller ranges of code to avoid shadowing other problems in editors.Rules max-lines-per-function, max-nested-callbacks, and max-statements now highlight only the function header instead of the entire function.Rules max-depth and no-with now highlight only the first keyword.Several errors in the calculations have been corrected in the max-depth and max-nested-callbacks rules. These bug fixes can result in reporting more linting errors in existing code.Featu
1日前
記事のアイキャッチ画像
Unauthenticated file upload in Amasty Order Attributes for Magento ブログのファビコン Sansec - experts in eCommerce security
Amasty Order Attributes, a popular checkout extension for Magento 2 and Adobe Commerce, contains an unauthenticated arbitrary file upload vulnerability. An attacker can upload a file of any type an...
1日前
記事のアイキャッチ画像
AI identity is your next security blind spot ブログのファビコン WorkOS Blog
A practical checklist for platform teams securing agents, MCP servers, and coding assistants before the next credential leak
1日前
記事のアイキャッチ画像
Kimi K2.7 Code now available on AI Gateway ブログのファビコン Vercel News
Kimi K2.7 Code from Moonshot AI is now available on .AI GatewayK2.7 Code is a coding model built for long-horizon programming tasks, generalizing across scenarios including frontend development, DevOps, and performance optimization. The model has a native multimodal architecture that supports text and vision input, and always runs in thinking mode.To use K2.7 Code, set model to in the :moonshotai/kimi-k2.7-codeAI SDKPass an image alongside a prompt to use the model's multimodal input:AI Gateway
1日前
記事のアイキャッチ画像
Program Claude Code, Codex, Pi and other agent harnesses with AI SDK ブログのファビコン Vercel News
introduces , a single API for running established agent harnesses, including Claude Code, Codex, and Pi. AI SDK has always let you switch models without rewriting your agent. Now you can switch the harness the same way.AI SDK 7HarnessAgentWrite the agent once. Use the best harness available.Today. In 3 months. A year from now.Harnesses manage the components above a model call, including skills, sandboxes, sessions, permission flows, compaction, runtime configuration, and sub-agents. The AI SDK n
1日前
記事のアイキャッチ画像
Claude Fable is relentlessly proactive Simon Willison's Weblog
<p>After two days of experience with <a href="https://simonwillison.net/2026/Jun/9/claude-fable-5/">Claude Fable 5</a> I think the best way to describe it is <strong>relentlessly proactive</strong>. It knows a whole lot of tricks and it will deploy pretty much any of them to get to its goal.</p><p>I'll illustrate this with an example. I was hacking on <a href="https://agent.datasette.io/">Datasette Agent</a> today when I noticed a glitch: a ...
1日前
記事のアイキャッチ画像
Web未経験MLエンジニアが社内プロダクト開発でAIコーディングにどハマりするまで ブログのファビコン CyberAgent Developers Blog | サイバーエージェント デベロッパーズブログ
Web未経験MLエンジニアが社内プロダクト開発でAIコーディングにどハマりするまで はじめに こんに ...
1日前
記事のアイキャッチ画像
GitHub availability report: May 2026 ブログのファビコン The GitHub Blog
In May, we experienced nine incidents that resulted in degraded performance across GitHub services.The post GitHub availability report: May 2026 appeared first on The GitHub Blog.
1日前
記事のアイキャッチ画像
Andrew Becherer Joins Socket as Chief Information Security Officer ブログのファビコン Socket
Socket’s first CISO brings deep experience securing high-growth SaaS companies as open source supply chain threats accelerate.
1日前
記事のアイキャッチ画像
Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files ブログのファビコン Step Security Blog
Miasma and Hades worms are spreading across npm and PyPI, running on import and project open. See how Dev Machine Guard's Suspicious Files detects them.
1日前
記事のアイキャッチ画像
Making secret scanning more trustworthy: Reducing false positives at scale ブログのファビコン The GitHub Blog
Alerts are more trustworthy and actionable when noise is reduced. See how we improved the verification step with context-aware LLM reasoning.The post Making secret scanning more trustworthy: Reducing false positives at scale appeared first on The GitHub Blog.
1日前
記事のアイキャッチ画像
datasette 1.0a33 Simon Willison's Weblog
<p><strong>Release:</strong> <a href="https://github.com/simonw/datasette/releases/tag/1.0a33">datasette 1.0a33</a></p> <p>This alpha is a significant step on the road to a stable 1.0, finally extending the <code>?_extra=</code> pattern I introduced <a href="https://docs.datasette.io/en/1.0a3/changelog.html#a3-2023-08-09">in Datasette 1.0a3</a> to cover queries and rows in addition to tables. That pattern is also <a href="http...
1日前
記事のアイキャッチ画像
npm v12 delivers one of the biggest security improvements in years ブログのファビコン Aikido Security's Blog
npm v12 makes install scripts opt-in by default, closing the install-time execution path behind a year of npm supply chain worms from Nx to Red Hat.Category: News
1日前

6/11 (木)

記事のアイキャッチ画像
Aikido x Docker: less noise, more signal in your containers ブログのファビコン Aikido Security's Blog
Aikido now supports Docker Hardened Images with built-in VEX integration, helping teams reduce CVE noise and focus on container vulnerabilities that actually need attention.Category: Product & Company Updates
2日前
記事のアイキャッチ画像
asyncinject 0.7 Simon Willison's Weblog
<p><strong>Release:</strong> <a href="https://github.com/simonw/asyncinject/releases/tag/0.7">asyncinject 0.7</a></p> <p>I built this utility library to support an <code>asyncio</code> dependency injection pattern a few years ago. I was using it with Datasette and Claude Fable 5 spotted some bugs in the dependency which it then fixed for me. It's a very proactive model!</p> <p>Tags: <a href="https://simonwillison.net/tags/asyn...
2日前
記事のアイキャッチ画像
How Okara runs CMO agents for 120,000 companies on Vercel ブログのファビコン Vercel News
Okara on Vercel4 billion tokens processed daily across a multi-provider AI stack on VercelAI CMOs actively managing growth for 120,000+ businessesEight sub-agents handling SEO, GEO, social, content, Reddit, and Hacker NewsNew AI models available to users the same day they shipOkara is an AI CMO that directs a team of specialized sub-agents to drive marketing, so founders don't have to. Give Okara your website URL, and the AI CMO builds a marketing strategy, develops a brand voice, and activates
2日前
記事のアイキャッチ画像
Anthropic Walks Back Policy That Could Have ‘Sabotaged’ AI Researchers Using Claude Simon Willison's Weblog
<p><strong><a href="https://www.wired.com/story/anthropic-responds-to-backlash-on-claudes-secret-sabotage-on-ai-research/">Anthropic Walks Back Policy That Could Have ‘Sabotaged’ AI Researchers Using Claude</a></strong></p>Big scoop for Maxwell Zeff at Wired:</p><blockquote><p>“We’re changing Fable 5’s safeguards for frontier LLM development to make them visible.” Anthropic said in a statement to WIRED. “We made the wrong tradeoff and we apo...
2日前
記事のアイキャッチ画像
Introducing Scoped Blob Storage ブログのファビコン Val Town Blog
Every val gets its own blobs
2日前
記事のアイキャッチ画像
WASI 0.3 Launched ブログのファビコン Bytecode Alliance
WASI 0.3 is official, and async is now native to WebAssembly Components. The WASI Subgroup voted to ratify WASI 0.3.0, rebasing WASI onto the WebAssembly Component Model’s async primitives. The 0.3.0 specification is now stable, and runtime and toolchain support is landing now.
2日前
記事のアイキャッチ画像
Fumadocs OpenAPI v11 ブログのファビコン Fumadocs Blog
Upgrade guide for Fumadocs OpenAPI v11.
2日前
記事のアイキャッチ画像
Why pnpm no longer expands environment variables in a repository's .npmrc ブログのファビコン pnpm Blog
pnpm used to expand $ placeholders everywhere it found them — including in the .npmrc and pnpm-workspace.yaml files that live inside the repository you just cloned. That turned out to be a way for a malicious repository to steal the secrets in your environment. As of v10.34.2 and v11.5.3, pnpm stops expanding environment variables in repository-controlled registry and credential settings.
2日前
記事のアイキャッチ画像
Vercel plugin is now available in Grok Build ブログのファビコン Vercel News
The is now available in Grok Build.Vercel pluginGrok can now draw on Vercel knowledge as you work. Real-time activity, including file edits and terminal commands, dynamically injects the relevant knowledge into context, so answers stay aligned with current platform APIs and recommended patterns.Install it in either of two ways:Learn more about the Vercel plugin in the .documentationRead moreAdd to your prompt and Grok will recommend installing it in chatvercelOpen the Grok Build marketplace with
2日前
記事のアイキャッチ画像
DeepSeek models now available via Azure on AI Gateway ブログのファビコン Vercel News
Azure is now a provider for DeepSeek V4 Pro and V4 Flash on .AI GatewayRequests to either model can route through Azure alongside the existing providers for another failover path. No code changes are required: default routing considers Azure automatically, and if a provider fails the gateway falls back through the remaining list.If you want requests to try Azure first, use in the gateway provider options to prefer Azure while keeping the other providers as fallback for or in the :orderdeepseek/d
2日前
記事のアイキャッチ画像
datasette-agent 0.2a0 Simon Willison's Weblog
<p><strong>Release:</strong> <a href="https://github.com/datasette/datasette-agent/releases/tag/0.2a0">datasette-agent 0.2a0</a></p> <p>Highlights from the release notes:</p><blockquote><ul><li>Tools can now ask the user questions mid-execution. Tools that declare a <code>context</code> parameter receive a <code>ToolContext</code> object, and <code>await context.ask_user(...)</code> can ask a y...
2日前
記事のアイキャッチ画像
DiffusionGemma Simon Willison's Weblog
<p><strong><a href="https://blog.google/innovation-and-ai/technology/developers-tools/diffusion-gemma-faster-text-generation/">DiffusionGemma</a></strong></p>Last May Google briefly released an experimental Gemini Diffusion model. I <a href="https://simonwillison.net/2025/May/21/gemini-diffusion/">tried the preview at the time</a> and recorded it running at 857 tokens/second. It was an exciting model, but Google made no further announcements about...
2日前
記事のアイキャッチ画像
Code is being written everywhere, and the device is the only constant ブログのファビコン Aikido Security's Blog
Developers are coding everywhere. AI agents, Slack bots, and MCP servers have made the developer device the biggest security blindspot.Category: News
2日前
記事のアイキャッチ画像
Socket Partners with Replit to Block Malicious Packages in AI-Powered Development ブログのファビコン Socket
Replit is integrating Socket Firewall into its AI-powered development experience to help protect builders from malicious open source packages.
2日前
記事のアイキャッチ画像
Give GitHub Copilot CLI real code intelligence with language servers ブログのファビコン The GitHub Blog
Install and configure LSP servers for GitHub Copilot CLI, replacing brute-force grep/decompile with real code intelligence. The post Give GitHub Copilot CLI real code intelligence with language servers appeared first on The GitHub Blog.
2日前
記事のアイキャッチ画像
Demystifying the View Transition Pseudo Tree ブログのファビコン Frontend Masters Boost RSS Feed
Each pseudo element plays a distinct role in how the view transition animates. The browser does most of the heavy lifting though, which makes it a little hard to see what’s actually happening under the hood.
2日前
記事のアイキャッチ画像
Quoting Jeremy Howard Simon Willison's Weblog
<blockquote cite="https://twitter.com/jeremyphoward/status/2064595816875217362"><p>Easy solution to slow down recursive AI self improvement:</p><ul><li>The lab with the top-ranked model must agree THEY must not use it for working on frontier AI</li><li>But everyone else should have access to it.</li></ul><p>By definition, this means the frontier doesn't advance.</p><p>It also has the critical benefit of avoiding a dangerous...
2日前
記事のアイキャッチ画像
CSSだけでメイソンリーレイアウト - display: grid-lanesの使い方 ブログのファビコン ICS MEDIA
記事は ics.media へアクセスしてご覧ください。
2日前

6/10 (水)

記事のアイキャッチ画像
SBOMs in 2026: Everyone's generating them, no one's using them ブログのファビコン Aikido Security's Blog
ENISA's 2026 SBOM adoption report covers 334 organizations and surfaces a consistent gap between generating SBOMs and actually using them. Here is what stood out.Category: News
2日前
記事のアイキャッチ画像
Route public traffic to private applications with Cloudflare ブログのファビコン The Cloudflare Blog
Application Services for Private Origins is available now in closed beta. Route public hostnames to private IP origins over your existing IPsec, GRE, CNI, or Cloudflare Mesh paths. No public IPs or extra connector software required.
2日前
記事のアイキャッチ画像
Compromised Rust crate onering performs code exfiltration ブログのファビコン Aikido Security's Blog
The compromised onering Rust crate v1.4.1 on crates.io shipped a malicious build.rs that exfiltrates the diff of your latest commit to a hosted Sentry endpoint every time you build.Category: Vulnerabilities & Threats
3日前
記事のアイキャッチ画像
The Benefits Of Cognitive Inclusion In UX Research ブログのファビコン Articles on Smashing Magazine — For Web Designers And Developers
Findings from an exploratory user research study highlighting the unique insights and practical UX recommendations shared by participants with cognitive disabilities.
3日前
記事のアイキャッチ画像
10 year old critical vulnerability in phpBB affecting tens of millions of users across thousands of forums ブログのファビコン Aikido Security's Blog
Aikido Security discovered a critical unauthenticated authentication bypass in phpBB affecting tens of millions of users. A single HTTP request is all it takes to take over any account — a vulnerability that's been sitting in the codebase since 2014.Category: Vulnerabilities & Threats
3日前
記事のアイキャッチ画像
Introducing the Field Guide to Grid Lanes ブログのファビコン WebKit
This week, we launched the Field Guide to Grid Lanes at gridlanes.webkit.org.
3日前
記事のアイキャッチ画像
Agentic AI Governance: Designing for Accountability and Control ブログのファビコン Company | The JetBrains Blog
Many organizations are already deploying agentic workflows. Some are still experimental, while others are running in production. Once an AI agent can take action on behalf of a business, the question is no longer whether it’s useful, but what happens when something goes wrong. It’s tempting to focus on blame: the AI vendor, the manager, […]
3日前
記事のアイキャッチ画像
ABEMAの多層キャッシュ機構をリアーキテクチャした話 ブログのファビコン CyberAgent Developers Blog | サイバーエージェント デベロッパーズブログ
はじめに はじめまして。東京電機大学大学院修士1年の佐藤聖璃です。 2026年4月の1ヶ月間、株式会 ...
3日前
記事のアイキャッチ画像
AIはQAを代替していない、むしろその可能性を拡張している LINEヤフー Tech Blog (LY Corporation Tech Blog
はじめに:生成AIの登場とQAに投げかけられた問い生成AIが登場した際、多くの職種に対して似たような疑問が投げかけられました。「この仕事はAIに代替されるのか?」「反復的な業務は自動化されるのではない...
3日前
記事のアイキャッチ画像
If Claude Fable stops helping you, you'll never know Simon Willison's Weblog
<p><strong><a href="https://jonready.com/blog/posts/claude-fable5-is-allowed-to-sabotage-your-app-if-youre-a-competitor.html">If Claude Fable stops helping you, you'll never know</a></strong></p>Jonathon Ready highlights one of the more eyebrow-raising details from the <a href="https://www-cdn.anthropic.com/d00db56fa754a1b115b6dd7cb2e3c342ee809620.pdf">319 page system card</a> for Fable 5 and Mythos 5. Here's a longer excerpt, highlights ...
3日前
記事のアイキャッチ画像
Reduce the JS Workload with No- or Lo-JS options ブログのファビコン Frontend Masters Boost RSS Feed
Aaron T. Grogg has a nice page chock full of examples of UI, which used to be the sort of thing that we’d use JavaScript for, but can now be done in HTML & CSS. No hate: I have nothing against JS, but it has better things to do The examples are very modern, like […]
3日前
記事のアイキャッチ画像
Investor Update – May 2026 ブログのファビコン Val Town Blog
Potluck joined the team. Claude became our biggest source of new users
3日前
記事のアイキャッチ画像
How to manage API keys, tokens, and secrets for AI agents ブログのファビコン WorkOS Blog
A practical guide to encrypted storage, OAuth connection management, and session-scoped access for autonomous agents
3日前
記事のアイキャッチ画像
Delegated access for AI agents: The intersection rule explained ブログのファビコン WorkOS Blog
How to scope what an AI agent can do on a user's behalf, and why the answer is never the user's full permission set.
3日前
記事のアイキャッチ画像
The 2026 AI agent auth checklist: 9 things to audit before you ship ブログのファビコン WorkOS Blog
A practical security audit for backend engineers building or inheriting agentic systems, covering identity, token design, delegation, and the patterns that fail in production
3日前
記事のアイキャッチ画像
Threshold billing is now enabled for Pro teams ブログのファビコン Vercel News
Threshold billing now sends Pro teams a partial invoice mid-cycle once on-demand usage reaches a threshold, instead of holding all charges until the end of the billing period. Partial invoices and the end-of-cycle invoice add up to your total usage, so the same usage is never billed twice.Learn more about .partial invoicesRead more
3日前
記事のアイキャッチ画像
Initial impressions of Claude Fable 5 Simon Willison's Weblog
<p>I didn't have early access to today's <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">Claude Fable 5</a> release, but I've spent the past ~5.5 hours putting it through its paces. My initial impressions are that this is something of a <em>beast</em>. It's slow, expensive and has been quite happily churning through everything I've thrown at it so far. As is frequently the case with current frontier models the challenge is finding tasks that it can...
3日前
記事のアイキャッチ画像
初めての新卒SWEインターンを、一緒に取り組んだメンターの視点から振り返る ブログのファビコン LegalOn Technologies Engineering Blog
はじめに LegalOn Technologiesでは、2027年卒からソフトウェアエンジニア(SWE)の新卒採用を本格的にスタートします。 以前公開した「初めての新卒SWEインターンはどう始まったか。プロジェクトメンバーで振り返る」では、新卒採用本格スタートに向けた長期インターンシップの、設計から選考、受入れまでの裏側をお届けしました。今回はその続編として、実際にインターン生を受け入れた各チームのメンターに話を聞きました。 どんなタスクを任せたのか、どんな成長を期待したのか、そしてメンター自身がどんな学びを得たのか。初めてのSWEインターンを現場視点で振り返ります。 今回話を聞いたのは以下の…
3日前
記事のアイキャッチ画像
llm 0.32a3 Simon Willison's Weblog
<p><strong>Release:</strong> <a href="https://github.com/simonw/llm/releases/tag/0.32a3">llm 0.32a3</a></p> <p>Almost entirely written by the new Claude Fable 5, see <a href="https://simonwillison.net/2026/Jun/9/claude-fable-5/#adding-features-to-datasette-agent-and-llm-using-claude-code">my write-up for more details</a>.</p> <p>Tags: <a href="https://simonwillison.net/tags/projects">projects</a>, <a href="https://...
3日前
記事のアイキャッチ画像
Setting a custom price for a model in AgentsView Simon Willison's Weblog
<p><strong>TIL:</strong> <a href="https://til.simonwillison.net/llms/agentsview-custom-model-price">Setting a custom price for a model in AgentsView</a></p> <p>I've been really enjoying <a href="https://agentsview.io/">AgentsView</a> by Wes McKinney as a tool for exploring my token usage across different coding agents running on my laptop.</p><p>Claude Fable 5 came out today and wasn't yet included in the pricing database AgentsV...
3日前
記事のアイキャッチ画像
npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders ブログのファビコン Socket
npm confirmed a tooling bug incorrectly marked several one-character packages as security holders and said it was working on a rollback.
3日前
記事のアイキャッチ画像
New in the Threat Center: Compromised Components, Now Available via API ブログのファビコン Step Security Blog
StepSecurity's new Threat Center API returns the compromised packages for any supply chain incident, so you can automate response and confirm exposure fast.
3日前
記事のアイキャッチ画像
Pythagora-io/gpt-pilot Compromised on GitHub - Shai-Hulud Credential Stealer Blocked by Python Linter ブログのファビコン Step Security Blog
An attacker hijacked a co-founder's GitHub account for gpt-pilot, a 33K-star AI coding tool, and force-pushed a credential-stealing Shai-Hulud payload to the main branch. The ruff Python linter caught formatting and lint violations in the malicious code and blocked the CI build -- twice. The attacker gave up.
3日前
記事のアイキャッチ画像
The Hades Campaign: Graph ML PyPI Packages Deploy Cross-Platform Memory Scrapers, AI Analyst Misdirection, and a Wiper Deterrent ブログのファビコン Step Security Blog
On June 8, 2026, multiple Graph ML PyPI packages in the bioinformatics ecosystem were compromised in the Hades campaign, deploying cross-platform memory scrapers, AI prompt injections to misdirect scanners, and a token-revocation wiper.
3日前
記事のアイキャッチ画像
Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents ブログのファビコン Step Security Blog
On June 5, 2026, the Miasma worm campaign reached Microsoft's Azure GitHub organizations. GitHub disabled 73 repositories across four Microsoft GitHub organizations after a malicious commit was pushed to the Azure/durabletask repository using a previously compromised contributor account. The attack planted configuration files that execute a credential-harvesting payload when a developer opens the repository in Claude Code, Gemini CLI, Cursor, or VS Code.
3日前
記事のアイキャッチ画像
Microsoft's durabletask PyPI Package Compromised in Supply Chain Attack ブログのファビコン Step Security Blog
Three malicious versions of Microsoft's official durabletask Python SDK were published to PyPI on May 19, 2026. The compromised package silently downloads and executes a 28 KB payload that steals credentials from AWS, Azure, GCP, Kubernetes, password managers, and over 90 developer tool configurations, then spreads laterally through cloud infrastructure. The payload skips systems with a Russian locale, a hallmark of Eastern European cybercrime operations. The attack has been linked to the TeamPC
3日前
記事のアイキャッチ画像
Quoting Andrej Karpathy Simon Willison's Weblog
<blockquote cite="https://twitter.com/karpathy/status/2064409694761054332"><p>I feel a lot of things changing as working software increasingly comes out on a tap. The Jevon's paradox kicks in and I feel my own demand for software growing substantially. You can ask for anything - explainers, visualizers, dashboards, bespoke single-use apps (e.g. a full wandb that is hyper-specific just for your project), you can 10X your test suite, auto-optimize code, run giant research projects wit...
3日前
記事のアイキャッチ画像
Discover MapKit JS 6: Rebuilt for Today’s Web Developer ブログのファビコン WebKit
MapKit JS allows you to bring the power and simplicity of Apple Maps to your website or web app.
3日前
記事のアイキャッチ画像
From one-off prompts to workflows: How to use custom agents in GitHub Copilot CLI ブログのファビコン The GitHub Blog
Custom agents let GitHub Copilot CLI understand your stack and team workflows, turning one-off terminal prompts into repeatable, reviewable processes.The post From one-off prompts to workflows: How to use custom agents in GitHub Copilot CLI appeared first on The GitHub Blog.
3日前

6/9 (火)

記事のアイキャッチ画像
Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System ブログのファビコン Aikido Security's Blog
Deep dive into binding.gyp, the often overlooked npm build file that can execute malicious code at install time through shell expansions, sandbox escapes, and compiler hijacking.Category: Vulnerabilities & Threats
3日前
記事のアイキャッチ画像
CA DATA NIGHT #9 〜J1サッカークラブにおけるデータ分析と現場実装の最前線〜 ブログのファビコン CyberAgent Developers Blog | サイバーエージェント デベロッパーズブログ
CA DATA NIGHTは、サイバーエージェントが主催するデータサイエンスに特化した技術者向けの勉 ...
4日前
記事のアイキャッチ画像
Join the WebMCP origin trial ブログのファビコン developer.chrome.com: Blog
Build structured tools for your website, so agents can complete tasks accurately.
4日前
記事のアイキャッチ画像
Claude Fable 5 now available on AI Gateway ブログのファビコン Vercel News
Claude Fable 5 from Anthropic is now available on . A Mythos-class model, Fable 5 is a notable step up over prior Claude models on long-running, ambiguous, multi-step tasks, executing end-to-end on work that previously required frequent human check-ins.AI GatewayThe model sustains productive output across multi-day runs and dependably dispatches parallel sub-agents, and lower effort settings often match what prior Claude models produced at their highest effort. Code review, bug-finding, and repo
4日前
記事のアイキャッチ画像
Defend against frontier cyber models: Cloudflare's architecture as customer zero ブログのファビコン The Cloudflare Blog
In our post about Project Glasswing, we made the argument that the architecture around a vulnerability matters more than the speed of the patch. Here we walk through what that architecture looks like, the threats it defends against, and how we run it ourselves as Cloudflare's customer zero.
4日前
記事のアイキャッチ画像
型安全なGraphQL Fake Server「@newmo/graphql-fake-server」を公開しました ブログのファビコン newmo 技術ブログ
newmoではフロントエンドとバックエンドの通信をGraphQLで行っています。GraphQLのスキーマは、フロントエンドとバックエンドが合意した唯一の正しい定義、いわば「正となる単一の情報源(Single Source of Truth)」です。このスキーマを正として、開発と自動テストの両方をここから組み立てたい。その基盤として@newmo/graphql-fake-serverを自作してOSSとして公開しています。 このライブラリは、スキーマを正としたまま、2つの使い方を1つのサーバで両立します。1つはスキーマに@example* directiveを書くだけで値が返るDeclarativ…
4日前
記事のアイキャッチ画像
2 Martians, greenfield to MVP in 4 weeks: agentic coding on Rails ブログのファビコン Evil Martians
A designer and an engineer shipped a production MVP in four weeks on Rails + Inertia. In this post, we share our agentic coding stack, the skills we built, and why it clicked.
4日前
記事のアイキャッチ画像
Meet Nuxi ブログのファビコン The Nuxt Blog
Today, we're announcing the new Nuxt Agent: Nuxi. We want to make your Nuxt experience less generic and more personalized, with the care that characterizes the Nuxt community.
4日前
記事のアイキャッチ画像
Version 5.0 released Node-RED
Node-RED 5.0 is now available to install. If upgrading, please read the upgrade instructions.
4日前
記事のアイキャッチ画像
Directory sync beyond SCIM: Why "we support SCIM" isn't enough ブログのファビコン WorkOS Blog
What you're actually signing up for when a customer's IdP doesn't speak SCIM.
4日前
記事のアイキャッチ画像
How to handle JWT in .NET ブログのファビコン WorkOS Blog
Everything you need to know to implement and validate JWTs securely in .NET: from token creation and JWKS verification to ASP.NET Core middleware integration, with code examples and best practices throughout.
4日前
記事のアイキャッチ画像
Memory and context poisoning: Don't let attackers rewrite your AI agent's memory ブログのファビコン WorkOS Blog
Prompt injection ends when the session closes. Memory poisoning persists across sessions, activates weeks later, and is nearly invisible to detect.
4日前
記事のアイキャッチ画像
Budgets for API keys on AI Gateway ブログのファビコン Vercel News
AI costs are getting harder to forecast. As teams lean more on coding agents and other token-heavy workflows, a key can burn cost faster than anyone notices:Set a spend cap on any key, and rejects further requests on that key once the limit is exceeded, until the budget resets or you raise it. The cap applies to all AI Gateway providers and models running through the key, making it easier to consolidate and govern AI costs.AI GatewayOn the , click , enable the option, enter a limit in dollars, a
4日前
記事のアイキャッチ画像
Domain Search is now available through the Vercel CLI ブログのファビコン Vercel News
You can now use the Vercel CLI to search domains. Using the command, you can supply a domain name and retrieve availability and price results for all TLDs that Vercel supports. vercel domains searchYou can also filter by TLD, apply sorting, and filter out unavailable domains.Upgrade your Vercel CLI to version to get started.54.10.1Read more
4日前
記事のアイキャッチ画像
Siri AI at WWDC 2026 Simon Willison's Weblog
<p>Given how badly burned anyone who took Apple's <a href="https://simonwillison.net/2024/Jun/10/apple-intelligence/">2024 WWDC Apple Intelligence announcements</a> at face value was, I'm holding to a strict "I'll believe it when I see it" policy for everything <a href="https://www.apple.com/newsroom/2026/06/apple-unveils-next-generation-of-apple-intelligence-siri-ai-and-more/">they announced today</a>. </p><p>The new Siri AI features do at least look f...
4日前
記事のアイキャッチ画像
【イベントレポート】PM Cross Talkを開催しました! ブログのファビコン CyberAgent Developers Blog | サイバーエージェント デベロッパーズブログ
こんにちは!AI事業本部/協業リテールメディアにてPdMをしております三浦です。 先日、CyberA ...
4日前
記事のアイキャッチ画像
Release Notes for Safari Technology Preview 245 ブログのファビコン WebKit
Safari Technology Preview Release 245 is now available for download for macOS Tahoe and macOS Sequoia.
4日前
記事のアイキャッチ画像
Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels ブログのファビコン Socket
Newer packages in this compromise use native extensions and .pth loaders to execute JavaScript stealers in developer environments.
4日前
記事のアイキャッチ画像
GitHub for Beginners: Answers to some common questions ブログのファビコン The GitHub Blog
Find the answers to some of the most common GitHub-related questions.The post GitHub for Beginners: Answers to some common questions appeared first on The GitHub Blog.
4日前
記事のアイキャッチ画像
mTLS Policies in NGINX Ingress Controller ブログのファビコン NGINX Community Blog
NGINX Ingress Controller 5.5 brings full support for mTLS in Ingress objects! This blog post gives a more in-depth overview of our GitHub deployment examples and shows how to configure both our new ingress and egress mTLS Policy CRDs in NGINX Ingress Controller using annotations. Ingress mTLS Ingress mTLS configures how NGINX verifies client certificates […]
4日前

6/8 (月)

記事のアイキャッチ画像
Scrubbable Staggered Animation with CSS @function ブログのファビコン Frontend Masters Boost RSS Feed
Here's a brand new approach to creating staggered animations in CSS using a single progress value, allowing for smooth linkage to various inputs like scrolling. By utilizing a mathematical formula, it enhances control over animated elements without isolating their timelines, making animations more versatile and scrubbable.
4日前
記事のアイキャッチ画像
Turning Cloudflare’s threat indicators into real-time WAF rules ブログのファビコン The Cloudflare Blog
Cloudflare customers can now use Cloudforce One threat intelligence directly within the WAF to block high-risk traffic. By using new cf.intel fields, security teams can automate protection against specific threat actors and targeted industries in real time.
4日前
記事のアイキャッチ画像
AI Turned Every Engineer Into a Tech Lead. Most Don't Know It Yet. ブログのファビコン Nicolas Charpentier's Blog
My Take on AI as of June 2026. Most people say AI kills the creativity and the fun in building. I want to offer the other side: managing agents feels a lot like the tech lead job I already loved.
5日前
記事のアイキャッチ画像
DeepSeek enters the fight for token volume, Anthropic continues to dominate spend ブログのファビコン Vercel News
Every month, routes tens of trillions of tokens between production applications and AI labs, giving us visibility into what AI usage actually looks like, separate from leaderboards and benchmarks. We publish the data monthly in the AI Gateway production index. AI GatewayLast month, headlines about blown token budgets dominated tech news: its annual Claude Code budget shortly after Q1 and Amazon to curb unproductive tokenmaxxing. While runaway cost is a real problem, this month’s report shows tha
5日前
記事のアイキャッチ画像
大規模Androidアプリで、技術をどう現場に適用するか。Yahoo! JAPANアプリで挑む「アジリティとサステナビリティ」の両立
はてなブックマークアイコン 1
LINEヤフー Tech Blog (LY Corporation Tech Blog
大規模なネイティブアプリの開発では、新しい技術を知っているだけでは足りません。難しいのは、それを歴史ある現場へどう適用するかです。ユーザー影響の大きいプロダクトでは、素早く価値を届ける「アジリティ(速...
5日前
記事のアイキャッチ画像
The Road to Component Model 1.0
はてなブックマークアイコン 2
ブログのファビコン Bytecode Alliance
WASI P3 is almost here, bringing native async support to the WebAssembly System Interface (WASI) and Component Model. In this post, we’re looking to the next big milestone: a stable, formally specified Component Model 1.0. At February’s Bytecode Alliance Plumbers Summit, Luke Wagner and Alex Crichton gave a preview of what the path to a stable 1.0 actually looks like. At Wasm I/O 2026 in Barcelona in March, Luke expanded on that vision. So let’s take a look at where the Component Model is headin
5日前
記事のアイキャッチ画像
datasette-agent-edit 0.1a0 Simon Willison's Weblog
<p><strong>Release:</strong> <a href="https://github.com/datasette/datasette-agent-edit/releases/tag/0.1a0">datasette-agent-edit 0.1a0</a></p> <p>I'm planning several plugins for <a href="https://agent.datasette.io/">Datasette Agent</a> which can make edits to existing pieces of text - things like collaborative Markdown editing, updating large SQL queries, and editing SVG files.</p><p>Agentic editing of text is a little tricky to...
5日前
記事のアイキャッチ画像
Reactの状態管理を、ライブラリやコンポーネントではなくモデルから考える ブログのファビコン カミナシ エンジニアブログ
カミナシエンジニアの osuzu です。 「状態管理にどのライブラリを使うか」への違和感 Reactの状態管理の話になると、だいたいライブラリの比較から始まります。少し前なら Redux か Zustand か Jotai か、最近だと TanStack Query と React Hook Form を組み合わせれば残りはわずか、みたいな話が多い印象です。 ただ、読んでいてどこか議論がかみ合わない感じがずっとありました。 理由はたぶんシンプルで、その問いは手前にすべきモデリングを飛ばしているからだと考えてます。 ライブラリ起点・コンポーネント起点はなぜこじれるのか フロントの状態管理でやりが…
5日前

6/7 (日)

記事のアイキャッチ画像
最新コードレビュー事情 ブログのファビコン Object.create(null)
AI もすなるコードレビューといふものを、人間もしてみむとてするなり。 — AI 紀貫之 AI がコードを書くようにはなっても基本的には人間がレビューする生活を続けているので, いま何を考えてどうしているかをスナップショットとして書いておきます. 仕事 メンタルモデルとして AI コーディングエージェントを単なる道具としてみなしていた時代は, 人間(A): タスクに着手, コーディングを AI に指示, 検収 AI: 人間(A)の代わりにコードを書く 人間(B): 人間(A)が書いたコードとしてレビューする というような構造だったんですが, これは人間(A)の検収と人間(B)のレビューが実質的…
6日前
記事のアイキャッチ画像
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave ブログのファビコン Socket
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
6日前
記事のアイキャッチ画像
What is AI SAST? ブログのファビコン Aikido Security's Blog
AI SAST is emerging as a new SAST category, but the meaning is unclear. We clarify the difference between AI-native SAST and AI-assisted SAST, as well as how AI SAST sits in the stack between traditional SAST and AI pentesting.Category: DevSec Tools & Comparisons
6日前

6/6 (土)

記事のアイキャッチ画像
micropython-wasm 0.1a2 Simon Willison's Weblog
<p><strong>Release:</strong> <a href="https://github.com/simonw/micropython-wasm/releases/tag/0.1a2">micropython-wasm 0.1a2</a></p> <p>I added a CLI to <code>micropython-wasm</code> (<a href="https://github.com/simonw/micropython-wasm/issues/7">issue #7</a>), inspired by the first draft of <a href="https://simonwillison.net/2026/Jun/6/micropython-in-a-sandbox/">the blog entry</a> when I realized it would be a great wa...
7日前
記事のアイキャッチ画像
Running Python code in a sandbox with MicroPython and WASM Simon Willison's Weblog
<p>I've been experimenting with different approaches to running code in a sandbox for several years now, but my latest attempt feels like it might finally have all of the characteristics I've been looking for. I've released it as an alpha package called <a href="https://github.com/simonw/micropython-wasm">micropython-wasm</a>, and I'm using it for a code execution sandbox plugin for <a href="https://github.com/datasette/datasette-agent">Datasette Agent</a> called &...
7日前
記事のアイキャッチ画像
`/goal` コマンドの活用例: Vitest の実行時間を 6 倍高速化した話 ブログのファビコン azukiazusa のテックブログ2
Vitest の `isolate: false` オプションを有効にすることで、テストの実行時間を大幅に短縮できましたが、その際に大規模なコードの修正が必要でした。Claude Code の `/goal` コマンドを活用することで、最終的なゴールを達成するために必要なステップを自律的に判断して実行させることができます。この記事ではその経験について紹介します。
7日前