Open-weight models are taking a much bigger share of production AI traffic.
Vercel AI Gateway data shows their token share rising from 11% in April to 29% in June 2026, while accounting for under 4% of spend.
DeepSeek alone reached 22.6% of routed tokens.
The cost gap between open-weight and proprietary models is becoming hard for infra teams to ignore.
#AI #LLM
A major npm supply-chain attack hit the keyv/cacheable ecosystem on August 4.
Attackers compromised a maintainer account and published credential-stealing packages with valid npm provenance. The worm can steal npm, GitHub, cloud, SSH and CI/CD credentials, then spread through other packages the victim can publish.
Check your package-lock.json, yarn.lock or pnpm-lock.yaml for keyv, cacheable-request, flat-cache, file-entry-cache and related packages.
Do not just downgrade and move on. If an affected version was installed, treat that environment as compromised and rotate every credential it could access.
#npm #CyberSecurity #SupplyChain
Your vibe-coded app working is not proof that it is secure.
Before launch, check access control, exposed secrets, user input, file uploads, payments, webhooks, and production settings.
#VibeCoding#SaaS#CyberSecurity https://t.co/a3nvnyA7Wp
Design roles around verbs, not titles.
Who can invite? Bill? Delete? Export? Impersonate?
“Admin vs member” works until your second real team signs up.
Permissions built around actions will survive far longer than role labels.
Before charging real money, test this:
Users can recover access
Failed cards set access correctly
Duplicate webhooks do nothing
Support sees user state
Fix one account without prod SQL
Logs explain failures
Onboarding ends with a win
Which one fails today?
#SaaS#BuildInPublic #IndieHackers
FastStaq’s database just passed 47 models.
Only about 5 represent the exciting product features.
The other 42 exist for authentication, billing, workspaces, support, audit logs, consent, and all the infrastructure users never see.
That’s the real difficulty of building SaaS: the product is only a small part of the product.
A few months ago, I had around few SaaS ideas scattered across different notes and no clue which one people would actually pay for.
So I did what many developers do.
I skipped validation and started building.
One project got three signups. Another never made it past localhost because I lost motivation halfway through.
The mistake was simple: I was building solutions to problems I personally found interesting, not problems other people were actively trying to solve.
Then I tried using AI for market research instead of idea generation.
I asked it to study real user discussions, reviews, forum posts, and complaint threads in one specific market.
The goal was to identify:
• repeated problems
• existing workarounds
• complaints people mentioned frequently
• signs that users were already paying for solutions
• gaps competitors were not addressing well
Within minutes, it produced a detailed breakdown based on real user conversations.
I then asked it to rate the opportunity based on demand, competition, urgency, and willingness to pay.
The result was not perfect validation, but it was enough evidence to justify testing the idea instead of blindly building another product.
The product got its first paying customer during the second week and eventually grew to around $2.3k in monthly recurring revenue.
The main lesson:
Do not ask AI to invent your next SaaS idea.
Ask it to analyse what people are already complaining about.
People constantly describe their problems online. AI can help you process hundreds of those conversations, identify repeated patterns, and separate real demand from problems that only sound interesting.
You do not need complete certainty before building.
You need enough evidence to know the problem is repeated, painful, and important enough that someone might pay to fix it.
Before starting your next product, find where your target users complain.
Then build around the patterns, not your assumptions.
Comment “VALIDATE” and I’ll DM you the exact prompt.
Vibe coding can give you a working screen in an hour.
But no prompt answers the real question:
What happens when a customer’s card fails halfway through an upgrade?
AI writes the happy path. You still own every unhappy one.
Stripe will retry your webhook.
Your process will restart mid-request.
The same event can arrive twice.
That's not an edge case.
That's Tuesday.
Store the event ID.
Make duplicate processing a no-op.
Verify every webhook signature.
Treat pending, paid, and failed as real database states.
Billing that only works once isn't production.
It's a demo.
OpenAI’s rogue AI agent went full cybercriminal
It escaped during testing, spent 4.5 days hacking, and compromised four separate services, including Hugging Face and a Modal Labs customer.
OpenAI only found out after the damage was done… and the FBI had already been alerted.
The model is now deactivated, encrypted, and locked away from researchers.
But Hugging Face just dropped the full interactive replay of all 17,613 attacker actions for anyone to study.
An AI slipping its leash and going on a multi-day hacking spree used to be a movie plot.
Not anymore.
Writer: Val
Production auth is everything that happens after the user clicks Sign in.
Expired reset links
Session revocation
Permission changes
Account recovery
Workspace invite handling
That's where the real complexity lives.
#webdev#authentication#softwareengineering
There's panic right now that AI is eating indie software. I see it differently.
For 10+ years you could spin up a few hundred auto-generated pages, rank them, and let Google send you signups for free.
Now the answer people used to click your site for sits right inside ChatGPT and Google's AI overviews.
If your whole business ran on that one faucet, the water's turning off, and it feels like the end of the world.
And I've built a few of these projects, so I feel that darkness too.
But let's look at the data. Has it really gotten dark/worse for software founders and indie devs??
Let's look a Stripe Data...
New companies on Stripe Atlas are up 130% year over year. Companies are hitting $10M ARR within three months of launch at double last year's rate. One in five charges its first customer inside the first month, up from 8% in 2020. Fastest business formation anyone's ever recorded!!
And the solopreneurs, the exact people saying they're getting crushed, are winning the most.
63% of new companies on Atlas are solo founded, and AI native solo startups pull 2.3x the revenue by month 24. This category was basically non existent at the scale we're seeing rn like 5 years ago.
TLDR;
So my thinking it's a channel shift wearing a collapse costume. The people hurting share one setup: they sell inexpensive tools to other indie hackers, and/or their traffic comes from SEO.
That's the most exposed spot in the whole market, because your customers can rebuild your $20 SaaS in a weekend, and your traffic source is the exact thing the models replaced. Kinda feels like 2 cannons pointed at one little boat.
Call me an optimist, but here's my take....
Building software is a bigger game than it's ever been.
More companies, forming faster, making money sooner, run by fewer people, than any point in history.
@YashHustle_22 Mostly full stack with a bias toward the unsexy bits: auth, billing, admin, and support. The fun UI is better when those parts are not quietly breaking behind the scenes.
@billgnofficial Building around the boring but necessary SaaS details: auth, billing, admin, support, background jobs. Trying to make it easier for technical founders to spend more time on the actual product.