Prva FSD vožnja na posao, nisam znao za opciju da ga ubrzam PEDALOM, pa sam stalno kotačić vrtio :) Odrezao sam ulazak u parkiralište i samo parkiranje zbog privatrnosti. Morat ću negdje drugdje to snimiti. Montaža je potrajala jer je iMovie pucao stalno kod exporta pa sm morao na brzinu naučiti Resolve...
Here is the full video of the descent on Slovenia’s highest road (Mangart Saddle, 2,055 m) 🇸🇮, handled perfectly by Tesla FSD (Supervised), including an impossibly tight squeeze near the end (it really felt that tight in person!).
@teslaeurope@Tesla@elonmusk@TeslaOwnersSLO
The State Of Laravel 2026 survey has started!
You can now participate to identify how the ecosystem changed over the past 12 months! This year with a few AI questions: How are others using AI?
Please RT for reach ❤️
https://t.co/hrhOdgU7ln
Extremely excited to announce that I'm (finally) joining the @laravel team!
Today is my first day as the VP of Marketing and Community. I love this community and I couldn't be more excited to join the team.
This is the era of builders, and Laravel is the best way to build.
Three researchers used Anthropic's Mythos to build a working macOS kernel exploit that bypasses Apple's M5 Memory Integrity Enforcement, a security system Apple spent five years and billions of dollars building.
Bug found April 25. Working exploit May 1. Walked into Apple Park to deliver the report in person.
MIE was the flagship security feature of the M5 and A19, designed to kill the entire memory corruption bug class. According to Apple's own research, it disrupted every known public exploit chain against modern iOS.
Calif didn't break MIE. They walked around it. Data-only attack, no pointer manipulation, standard syscalls from an unprivileged user to root.
The 55-page technical report drops after Apple patches.
This is the story of the year in cybersecurity.
We are honored to announce David Heinemeier Hansson aka @dhh 🇩🇰, creator of Ruby on Rails, on stage at Laravel Live Denmark 2026. A Dane whose framework inspired a generation of developers comes home to Copenhagen this August. Different framework, same craft.
🇭🇷 🚕 Europe's first commercial robotaxi service rolls out in Croatia
A Croatian company has been rolling out what it says is Europe's first robotaxi service on the streets of Zagreb.
Would you be interested if JetBrains releases a totally local AI agent, working 100% on your laptop, using our code insight engine and deeply integrated into the IDE?
Yes, it will be probably 1 month behind the very recent frontier models, but no token blood bath anymore
WDYT?
A tiny piece of code called axios runs inside almost every app on your phone and every website you visit. Developers download it 100 million times a week. A few hours ago, someone poisoned it with malware that hands an attacker full control of your computer.
If you’ve never heard of axios, that’s normal. It does one boring but important job: it lets apps talk to the internet. When a website pulls up your feed or an online checkout processes your card, axios is probably doing the work underneath. Over 173,000 other code packages plug into it. It’s everywhere.
The attacker stole a lead developer’s login for npm (think of it as an app store, but for code that programmers use to build software). Once inside, they swapped the developer’s email to an anonymous ProtonMail account and uploaded the poisoned version by hand. That jumped past every security check the project normally runs before new code goes live.
And this was not some rushed job. The attacker staged the malware at least 18 hours before pulling the trigger. They built separate versions for Windows, Mac, and Linux. They poisoned both the current version and an older one within 39 minutes of each other, casting the widest net possible. Once the malware ran on a machine, it deleted itself to cover its tracks.
The trick was smart. They never touched a single line of code inside axios itself. Instead, they tucked in a fake add-on called plain-crypto-js, built to pass as a well-known, trusted library. It copied the real library’s description and author info, so nothing looked off at a glance. When a developer installed axios, this fake package quietly ran the malware on its own.
When a smaller package called ua-parser-js got hijacked back in 2021 with about 8 million weekly downloads, the security world treated it like a four-alarm fire. Axios has 100 million. Over 12x the exposure, with 173,000+ packages depending on it.
Socket, the security firm that flagged this, caught it in about 6 minutes. That’s fast. But 6 minutes is still plenty of time for automated systems at companies everywhere to pull and install the bad version before anyone can react.
If you or your team runs axios: lock your version to 1.14.0 (or 0.30.3 for the older branch). Change every password, API key, and access token on any machine that installed the compromised update. And check your network logs for connections to sfrclak dot com or the IP address 142.11.206.73.
Codex and I have been building a TUI library called Pat for PHP 🫶
Got the core elements, z-index stacking, diffing, performance all in place. Now need more elements, nicer designs, better DX 👌 One day!