developer fueled by coffee and stickers

Sweden
⚠️ Elementor CSRF flaw can create a rogue WordPress admin account when an administrator opens a crafted link. The bug affects 4.3.0 and 4.3.1, bypasses CSRF protection across the site's REST API, and is fixed in 4.3.2. Here's how it works: thehackernews.com/2026/09/el…
5
25
76
33,141
Kim retweeted
Alert: Apple just dropped a new model on Hugging Face. It's a Qwen3.5-9B finetune that turns long documents into small page images to save tokens, then pulls up the full text of only the pages relevant to your question 💡 huggingface.co/apple/LensVLM…
75
278
3,463
278,080
Introducing Gemini 3.8 Flash TTS 📣 for expressive, nuanced voice acting, and 3.8 Flash-Lite TTS ⚡️ for high-volume, cost-efficient scale! Our most expressive, multilingual (100+ languages) speech generation models bring powerful new features for developers and creators alike: • Voice Design: Craft custom voices across languages, dialects, and accents using simple text prompts • 2,000+ Prebuilt Voices: A vast, high-fidelity library covering diverse styles and personas • Voice Replication: Fast, authentic replication with built-in consent verification • Multi-Speaker Dialogue: Seamless, natural pacing between distinct voices Try it now in @GoogleAIStudio 👉 ai.dev/generate-speech
13
10
103
12,802
Introducing Gemini 3.8 Flash and Flash-Lite TTS, our new SOTA text to speech model with: - a new voice design experience - 2,000+ production ready voices - voice replication - support for 100 languages - voice remixing (soon) - #1 spot on Hume AI's voice benchmarks and more!!
372
245
4,528
341,525
Kim retweeted
Agent Runners picks these up along with AI Gateway, so an agent building in Netlify can use them too. The changelog example calls Sol through the Responses API with the model set to gpt-6-sol. netlify.com/changelog/gpt-6-…
4
1
4
2,418
Kim retweeted
Opus 5.5 is available in Agent Runners and AI Gateway, so the agent building your app and the app it builds can both run on the same model. Set the model string to claude-opus-5-5 and use the effort setting on the output config when you want it to work harder on a given request. netlify.com/changelog/claude…
1
4
10
2,714
Let's get the @syntaxfm podcast to 500,000! 🔥 Subscribe if you haven't. It's a great podcast and channel overall. 👇
Should we give away 500,000 of something when we hit 500k subs? (I need 409 people to help me out) piped.video/@syntaxfm?sub_co…
1
1
103
Kim retweeted
Resend Forward ticket drop! Best comment by midnight PT wins.
20
5
49
5,355
Kim retweeted
Today, @washingtonpost covered critical vulnerabilities @depthfirstlabs found in TikTok. These vulnerabilities allowed hackers to access anything on a user’s device that TikTok itself could access, including the camera, microphone, payment information, photos, and the user’s entire TikTok account. Read more in the thread 🧵
14
81
361
101,096
Kim retweeted
Here is the full walkthrough if you want to watch it work. A real support ticket goes in, and Jev comes back with the team that owns it, a frustration score, and a probability that it reads as urgent. The confidence value on each answer decides what gets handled automatically and what a person sees.
1
2
20
10,196
‼️ ALERT - Critical Docker Sandboxes flaw lets malicious guest code escape the shared workspace and read or modify files across a macOS host. CVE-2026-77179 crosses the virtio-fs boundary with the host account’s rights. Read how the escape works → thehackernews.com/2026/09/cr…
13
65
241
50,991
Kim retweeted
TypeSafe's Jev answers typed questions about your program state instead of writing prose. You hand it the state and declare the answers you are willing to accept. A routing question can come back as sales, support, or spam and nothing else, which means you can branch on it directly without parsing anything. netlify.com/changelog/typesa…
6
4
19
4,175
‼️ Critical Unbound DNSSEC validator flaw (CVE-2026-82717) could allow remote code execution. An attacker who controls a malicious zone can trigger the heap overflow by querying a vulnerable resolver. 1.26.0 and earlier are affected. Read details → thehackernews.com/2026/09/cr…
6
45
88
39,412
🚨 Attackers are exploiting a critical WooCommerce Wholesale Lead Capture flaw to plant PHP web shells. Wordfence has blocked over 100,000 exploit attempts since June against CVE-2026-27540, which affects versions through 2.0.3.1. Read: thehackernews.com/2026/09/at…
5
30
108
32,767
1. why do I need to install an app to set up a printer 2. why is that app 400+ MB
21
5
278
9,414
⚠️ Exposed Vite dev servers are being scanned for cloud credentials. Attackers are exploiting a Vite flaw to bypass file restrictions and retrieve .env files, AWS and Azure credentials, and infrastructure state. How the bypass works: thehackernews.com/2026/09/ma…
6
27
82
32,411
Kim retweeted
PHISHING ALERT: Looks like an affiliated account “(Julia)” from @composio unfortunately got hacked and they are sending this DM They changed the account name to “Media Review” and asking to click suspicious links. I almost fell for this but luckily scrolling up on our DM chat history revealed that it’s Julia’s account Beware
7
2
13
2,269
‼️ Google Search is now hiding where its results lead. Links point to google[.]com/goto?, followed by an opaque string only Google can resolve. You can no longer inspect a destination before clicking it, or copy the address out of the page. Every click now travels through Google first.
319
1,000
9,868
1,198,842
Kim retweeted
Laravel Cloud is now ISO 27001 certified! 🎉 That's on top of SOC 2 Type II, GDPR, and HIPAA. Need our compliance certificates? Request them directly from our Trust Center → trust.laravel.com
20
39
326
71,570