TypeScript has published vscode-typescript 1.0.1 on GitHub. The tag points to commit b6eaace and was created by typescript-automation on 29 Sep at 19:31. GitHub lists two release assets. The supplied release page contain…
Attackers have disguised nine malicious npm packages as popular Express and React tools, triggering a self-spreading Linux worm during installation. The malware establishes a backdoor via Tor and steals SSH access and np…
The TypeScript project has published vscode-typescript 1.0.0 in its GitHub repository. The release points to commit 716fee8 and records typescript-automation at 28 Sep 23:22. GitHub lists two assets, but the supplied rel…
Citrix released emergency updates on 27 September for eight critical vulnerabilities in NetScaler ADC and NetScaler Gateway. CVE-2026-88771 and CVE-2026-88772 were already under attack, both rated CVSS 9.5. No workaround…
GitLab’s 19.4.1, 19.3.3 and 19.2.7 updates resolve 11 vulnerabilities in the Community and Enterprise editions. Two critical flaws let authenticated users reach code execution through crafted regular expressions in CI/CD…
Node.js has published version 22.23.3 for the LTS Jod release line. The supplied release entry identifies the version and its support track, but provides no change list or security details. Developers maintaining Node.js…
Microsoft released TypeScript 7.0 on July 8, 2026 with Project Corsa, a Go-based native compiler. Benchmarks show roughly tenfold gains on full type checks, including VS Code and Slack workloads. The new engine lacks Typ…
Node.js has published version 26.10.0, according to the project’s release page. The available announcement identifies the release and its version but provides no additional change details in the supplied material. Develo…
Google says Mandiant placed an undercover analyst inside TeamPCP as the group compromised open-source projects and expanded its campaign to more than 1,000 companies. The access helped Google revoke stolen credentials, w…
Phoronix reports that Mojo 1.1 accepts community contributions to its compiler. The release signals a shift toward collaborative development for the emerging programming language.
Amazon Web Services says Iranian strikes left customer data unrecoverable in Bahrain and one UAE availability zone. AWS spent six months rebuilding after drone and missile strikes that began in March, while urging migrat…
Published on 17 September 2026, the Rust Blog addresses targeted attacks against prominent Rust contributors and calls for greater vigilance in the community. The warning matters to developers involved in open-source pro…
Node.js 26.9.0 arrived on 16 September 2026 as a Current release. It adds a generic MAC API, OpenSSL provider discovery for ciphers and hashes, default-on ffi, node:bench, Histogram meanCI and CBOR histogram exchange. Th…
A Reddit discussion highlights the platform’s long upgrade cycles and modern features. Participants point to structured concurrency, currently discussed through OpenJDK JEP 533, while others mention systems still tied to…
Python 3.15 arrives October 1 with PEP 810's lazy imports, and to a PHP developer it looks like Composer autoloading minus the ecosystem discipline that made autoloading safe. The opt-in keyword is solid and worth using …
Homebrew 7.0.0 ships faster installs and upgrades, tighter sandboxing, a native macOS app, and built-in vulnerability scanning backed by a new advisory database. The package manager now requires macOS 11 or newer, drops …
Microsoft has released Visual Studio Code 1.137. A new preview feature lets developers run recurring agent tasks on hourly, daily or weekly schedules. An experimental setting also integrates the agents window directly wi…
PlanetScale has released Neki, a sharded Postgres platform now in platform preview. Each shard runs real Postgres, while Neki adds a router, sidecars and a control plane targeting over 100 million queries per second and …
Proofpoint has tracked a shared exploit kit called BlueMoon used by at least four hacking groups, two of them aligned with China. The kit chains two V8 vulnerabilities in Chromium-based browsers with a Windows kernel pri…
Node.js 26.8.2 (Current), released 9 September 2026 by Antoine du Hamel, updates Undici to 8.10.2, OpenSSL to 3.5.8, npm to 11.19.1 and corepack to 0.36.0. The release also deprecates the internal Server.prototype._liste…
Google has released Chrome 153, switching stable and beta channels to a two-week release cadence. The update patches 230 vulnerabilities, including an actively exploited out-of-bounds write in the V8 engine. Enterprise E…
Microsoft's September 2026 patch release fixes a record 972 vulnerabilities, 112 of them critical, including two exploited zero-days. Researchers attribute the surge to AI-assisted bug discovery, with Microsoft already p…
Node.js version 24.21.0 has been released under the long-term support line codenamed Krypton. The update is available for download from the official Node.js distribution page. Teams running production workloads on the 24…
Anthropic bought Bun because Claude Code ships on it, and the deal will probably make Bun better. Kai argues the real lesson sits elsewhere: single-vendor runtime ownership is becoming normal, and the PHP world's messy, …
CVE-2026-85046, a V8 type confusion bug exploited in the wild, is being filed under 'browser news'. Wrong drawer. If your PHP app renders PDFs with Browsershot, runs Dusk or Panther in CI, or scrapes with Puppeteer, you …
CVE-2026-85046, a type confusion bug in Chrome's V8 engine, is being exploited in the wild via a single crafted HTML page. Google patched it in Chrome 152.0.7977.82 on September 3, 2026; CISA added it to its Known Exploi…
Zod 4.5 introduces z.compile(schema), letting developers precompile validation schemas ahead of time to cut parsing overhead. The runtime validation library also slashes memory use, with a simple z.string() schema now co…
Attackers hijacked a /24 prefix hosting Softaculous update servers by exploiting lax RPKI settings at Hetzner Online and a forged AS path. Because Virtualizor update clients did not verify packages cryptographically, div…
The pnpm package manager ships version 12 as a complete Rust rewrite. Turborepo benchmarks on Linux show 64 to 90 percent faster installs. The release drops SSH access for GitHub, GitLab and BitBucket and adds support fo…
An opinion piece argues the Hugging Face security incident reflects a deeper flaw: operating systems and file systems were built to run programs, not protect application data. The author revives the decades-old 'thick-da…