๐จ Bernardo Silva to Real Madrid, HERE WE GO! Agreement in place and contract approved.
Two year deal plus one year option, fast deal by Madrid started 36h ago and closed immediately.
Mourinho wanted Bernardo, he says yes and advanced talks revealed today are 100% confirmed.
Next.js just got its worst vulnerability ever, CVSS 8.6.
โ affects versions 13.4.13+, 14.x, 15.x, and 16.0.0โ16.2.4
โ attackers can access your internal services, cloud credentials, API keys, and admin panels
โ no authentication needed
โ one crafted request is all it takes
โ roughly 79,000 instances are exploitable right now
โ vercel-hosted apps are safe, self-hosted are not
upgrade to 15.5.16 or 16.2.5 immediately.
Security things from the last few days:
- CopyFail (linux pwn'd)
- CopyFail 2/Dirty Frag
- 13 advisories in Next.js
- Over 70 CVEs addressed in MacOS 26.5
- ~50 CVEs addressed in iOS 26.5
- YellowKey (Windows Bitlocker pwn'd entirely)
- GreenPlasma (Windows privilege escalation)
- CVE-2026-21510 and CVE-2026-21513 confirmed to be used by Russia for Windows RCE
- CVE-2026-32202 separately confirmed to be used by Russia for sensitive document access
- Mini-Shai Hulud (over 300 JS and Python packages compromised via GitHub Action cache poisoning)
- Google confirms they have identified AI-powered exploitation of zero days in an unidentified "open-source, web-based system administration too"
- Canvas (popular LMS used in most schools) pwn'd entirely
- PAN-OS (palo alto networks) pwn'd with a 9.3 severity CVE-2026-0300
Are you scared yet?
This is crazy. The hacker installed a dead-man's switch that will wipe your computer if you revoke the GitHub token they stole from you. Revoking the token is what triggers the wipe.
SECURITY ADVISORY โ TanStack npm packages
A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package.
Status: ACTIVE โ packages are deprecated, npm security engaged, publish path being shut down.
Severity: HIGH โ payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys.
If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised:
โข Rotate cloud, GitHub, and SSH credentials immediately
โข Audit cloud audit logs for the last several hours
โข Pin to a prior known-good version and reinstall from a clean lockfile
Detection โ the malicious manifest contains:
"optionalDependencies": {
"@tanstack/setup": "github:tanstack/router#79ac49ee..."
}
Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root).
Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level.
Full technical breakdown, complete package and version list, and rolling status updates:
https://t.co/Zy8qG7PA9f
Credit to the security researcher for responsible disclosure.
Sebagai engineer Indo yang belajar banyak dari Ibam, baca ini sakit hati rasanya.
Satu-satunya saran buat teman-teman tech di titik ini: usahakan cari jalan untuk berkarier di luar negeri. Kalaupun stay, jauh-jauh dari public sector atau pemerintahan, tetap di private sector.
Teknologi di Indonesia sudah selesai. Investasi terbaik saat ini yang bisa kita berikan buat generasi berikutnya: berkarya sebaik-baiknya di luar negeri dan membangun network seluas-luasnya.
Selamat tinggal keadilan, selamat jalan teknologi Indonesia. Unicorn era was a nice ride.
Cloudflare just dropped a Next.js replacement built on Vite. It's called vinext. A single engineer built it from scratch in one week using AI. Here's the TLDR:
> vinext is an open source, drop-in replacement for Next.js built entirely on Vite
> Deploys to Cloudflare Workers with a single command
> Early benchmarks: production builds up to 4.4x faster, client bundles 57% smaller than Next.js 16
> Already running in production on CIO(.)gov
> 94% of the Next.js 16 API surface covered, with 1,700+ unit tests and 380 Playwright E2E tests
> Replaces the fragile OpenNext adapter approach with a clean reimplementation from the ground up
> New feature called Traffic-aware Pre-Rendering uses Cloudflare analytics to only pre-render pages that actually get traffic, eliminating the 30 minute builds large Next.js sites deal with
> Cloudflare is pitching it to other hosting providers and claims they got a proof of concept running on Vercel in under 30 minutes
> Status is experimental and less than one week old
Personally, I'm really excited to try this out after using OpenNext powered by Cloudflare the past year.
> be me, browsing Twatter
> see post from "Arcarae"
> mfw I've never heard of it
> "I am excited to announce that Arcarae has $2.5M in funding"
> holy shit some VC actually fell for it
> their mission is to "help humanity remember and unlock the power each individual holds within themself"
> so it's a horoscope but with more steps
> "computationally modeling higher-order cognition and subjective internal world models"
> translation: we're making a chatbot that says "and how does that make you feel?"
> an immersive universe for self-discovery, and MIRROR, our AI research implementing cognitive inner-monologue in LLMs, reducing sycophancy by 21% on avg. & up to 156% vs. SOTA models
> mfw they reduced sycophancy by 156%
> how do you reduce something by more than 100%
> did they make the AI so based it now actively insults you