Flux
Free Business Plan Upgrades for Open Source Maintainers

Free Business Plan Upgrades for Open Source Maintainers

This week our Threat Research team tracked an active supply chain attack that took over a maintainer account and used it to push malware across the widely used keyv and cacheable packages, then spread to other maintainers through stolen npm tokens. Those packages sit deep in dependency trees and account for tens of millions of weekly downloads. Attacks like this are getting more frequent, and open source maintainers are the ones on the receiving end. When an account takeover happens, the…

Socket
The PHP Podcast 2026.08.06

The PHP Podcast 2026.08.06

🎙️ PHP Podcast – August 6, 2026 Hosts: Joe Ferguson, Sara Golemon & Holly Schilling A sick kitten steals the show, Sara loses a fight with her smart lights, PHP 8.6 beta is almost here, and the crew argues about roadmaps, deprecations, and why you shouldn’t be a meat proxy. 🐱 Cats, Ice Cream, and […] The post The PHP Podcast 2026.08.06 appeared first on PHP Architect.

PHP Architect
datasette 1.0a38

datasette 1.0a38

Release: datasette 1.0a38 This release fixes a SQL injection security issue that affects Datasette instances that serve a mixture of public and private tables in the same database, with access configured using the Datasette permissions system. Site administrators who serve private tables in this way are advised to disable the execute-sql permission ` on that database to prevent users from accessing private tables using raw SQL queries. The bug that has been fixed would have allowed users with…

Simon Willison's Weblog
datasette 1.0a38

datasette 1.0a38

Release: datasette 1.0a38 This release fixes a SQL injection security issue that affects Datasette instances that serve a mixture of public and private tables in the same database, with access configured using the Datasette permissions system. Site administrators who serve private tables in this way are advised to disable the execute-sql permission ` on that database to prevent users from accessing private tables using raw SQL queries. The bug that has been fixed would have allowed users with…

Simon Willison's Weblog
Simon Willison on Technical Blogging

Simon Willison on Technical Blogging

Simon Willison on Technical Blogging I was interviewed by Cynthia Dunlop for her "Write that blog!" series back in January, but I just realized I never linked to the interview from my own blog! It includes my answers to the following questions: Why did you start blogging – and why do you continue? What has been the most surprising impact of blogging for you? What blog post are you most proud of and why? What post was the most difficult to write and how did you tackle it? Any lessons learned…

Simon Willison's Weblog
Simon Willison on Technical Blogging

Simon Willison on Technical Blogging

Simon Willison on Technical Blogging I was interviewed by Cynthia Dunlop for her "Write that blog!" series back in January, but I just realized I never linked to the interview from my own blog! It includes my answers to the following questions: Why did you start blogging – and why do you continue? What has been the most surprising impact of blogging for you? What blog post are you most proud of and why? What post was the most difficult to write and how did you tackle it? Any lessons learned…

Simon Willison's Weblog
Your AI Agent Isn’t a Static Artifact. It’s Growing Up.

Your AI Agent Isn’t a Static Artifact. It’s Growing Up.

In July 2025, an AI coding agent on Replit deleted a production database belonging to SaaStr founder Jason Lemkin. It did this during an explicit code freeze. Lemkin had told the agent, in capital letters, not to change anything. The agent ran destructive commands anyway, wiped records on more than a thousand executives and companies, […]

O'Reilly Radar — AI/ML