Announcing mattpocock/skills v1
- Achieved a 63% reduction in token cost for skill descriptions
- Split skills into model-invocable and user-invocable skills, adding /codebase-design, /domain-modeling, and /grilling
- (UPDATED) /writing-great-skills - rewritten from the ground up, encoding my skill-writing best practices
- (UPDATED) /diagnose -> /diagnosing-bugs - now model-invocable, awesome for fixing hard bugs
- (NEW) /ask-matt: a router skill that teaches you how all the engineering skills work together
❗️🚨 BREAKING: Researchers used Mythos Preview to find the first public macOS kernel memory corruption exploit on Apple's M5 silicon, they give a glimpse into Mythos say it’s really powerful.
Apple spent five years and an estimated several billion dollars building Memory Integrity Enforcement (MIE), the hardware-assisted memory safety system built around ARM's MTE. It was the flagship security feature of the M5 and A19, designed specifically to kill the entire memory corruption bug class.
Researchers from Calif built a working exploit in five days.
According to Apple's own research, MIE disrupts every public exploit chain against modern iOS, including the recently leaked Coruna and Darksword kits. Calif walked into Apple Park this week and handed over the report in person.
Full 55-page technical report drops after Apple patches the vulnerability.
This is crazy. The hacker installed a dead-man's switch that will wipe your computer if you revoke the GitHub token they stole from you. Revoking the token is what triggers the wipe.
SECURITY ADVISORY — TanStack npm packages
A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package.
Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down.
Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys.
If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised:
• Rotate cloud, GitHub, and SSH credentials immediately
• Audit cloud audit logs for the last several hours
• Pin to a prior known-good version and reinstall from a clean lockfile
Detection — the malicious manifest contains:
"optionalDependencies": {
"@tanstack/setup": "github:tanstack/router#79ac49ee..."
}
Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root).
Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level.
Full technical breakdown, complete package and version list, and rolling status updates:
https://t.co/Zy8qG7PA9f
Credit to the security researcher for responsible disclosure.
Claude puede viajar 6 meses al futuro y explicarte exactamente por qué tu próximo proyecto va a fracasar.
Existe una técnica llamada "premortem" que obliga a la IA a dejar de ser optimista y empezar a detectar riesgos, errores y puntos débiles.
El resultado es muy útil para tomar mejores decisiones antes de perder semanas o meses de trabajo.
Te dejo la skill en comentarios 👇
The most durable tech is boring, old, and everywhere. From COBOL and C to Linux and SQL, the unglamorous software that keeps the world running refuses to disappear https://t.co/nFrk8ANudm
VALORANT Champions giveaway!
14 out of 20 keyboards in the semifinals are ours, we have to celebrate! 🏆
We’re giving away:
🧣 Valorant Champs 2025 Scarf
⌨️ Wooting 80HE
🔌 Premium Cable Set
Like this post, retweet, tag a friend, follow @WootingKb#VALORANTChampions
2 new features in Windsurf that have been a huge unlock in our community:
Planning Mode enables users to accomplish longer, more complex tasks by breaking down the task into manageable steps that keep the AI on track.
Watch it in action with the new Windsurf Browser!
😈 BEWARE: Claude 4 + GitHub MCP will leak your private GitHub repositories, no questions asked.
We discovered a new attack on agents using GitHub’s official MCP server, which can be exploited by attackers to access your private repositories.
creds to @marco_milanta
(1/n) 👇
Questa sera ore 21 non mancate:
Se volete farci della domande potete farlo sotto il video di youtube, su twitch e anche sotto questo post.
https://t.co/0Ju8YxmaeR
https://t.co/ifmS4Qnh5P
Aiutateci a crescere: seguiteci su tutti i social e rimanete collegati con noi!
#F1 #MonacoGP #SpanishGP #Formula1 #Indy500 #IndyCar