Spotify's Chief Architect just showed how they ship 4,5K deployments /day with Claude at Anthropic stage
27-minutes. free. By #1 music app dev
"More than 99% of our engineers use AI coding tools. Adoption took off after Opus 4.5"
Worth more than any $500 vibe-coding course.
No API keys. No cloud. No per-token cost. Just your Mac. In this video, I show you how to run @arcee_ai Trinity Mini (26B parameters, 3B active) locally on Apple Silicon using MLX, and wire it up to OpenCode as a fully local AI coding assistant. Ideal for air-gapped environments, regulated industries, or anyone who wants a private coding AI.
I cover the full setup: choosing the right quantization for your hardware, benchmarking generation speed across all quantizations, and configuring @opencode to talk to the local model. I also check Trinity's results with @claudeai Code!
YouTube video: "No Cloud, No API Keys: Local Open-Source Coding with Trinity Mini, OpenCode, and MLX" - https://t.co/wE3VfoOnVp
RCE vulnerability in the Yamaha PSR-E433 synthesizer, discovered by Anna Antonenko, allows exploitation through crafted MIDI files that trigger a hidden firmware backdoor with hardcoded password "#0000".
China's biggest cybersecurity company apparently just shipped an AI assistant with its own SSL private key sitting inside the installer. Qihoo 360, think Norton or McAfee, but dominant across the entire Chinese market
It appears that their new AI product, 360安全龙虾 (Security Claw) bundles a wrapper on @OpenClaw. Inside the installer package - accessible to anyone who downloaded it - was a private SSL certificate key for the domain *.myclaw.360.cn. An SSL private key is essentially the master password to a website's encrypted connection. With it, an attacker can impersonate 360's servers, silently intercept user traffic, forge a login page that looks completely legitimate, or possibly take over the AI agent altogether. The cert is valid until April 2027 and covers every subdomain on the platform. It's now public. The founder launched the product with a promise it would "never leak passwords". It did that during release? 461 million users, a $10B valuation, and nobody checked the zip file before shipping. The cert expires April 2027.
🚨 RIP Chrome for AI agents.
Someone built a headless browser from scratch that runs 11x faster and uses 9x less memory.
It's called Lightpanda.
Every AI agent doing web automation right now is running Chrome under the hood. That means you're spinning up a massive desktop application, stripping out the UI, and running hundreds of instances of it on a server. For something that never needs to render a single pixel.
It's like renting a semi-truck to deliver a letter.
Lightpanda is built differently. Not a fork of Chromium, Blink, or WebKit. Written from scratch in Zig with one goal: headless performance, nothing else.
It still runs JavaScript. Still handles Ajax, XHR, Fetch, SPAs, infinite scroll, all of it. Just without dragging along 500MB of browser bloat you'll never use.
And it drops straight into your existing stack:
→ Compatible with Playwright, Puppeteer, and chromedp via CDP
→ One-line Docker install
→ CDP server on port 9222, swap it in for Chrome in 30 seconds
The use cases are obvious: AI web agents, LLM training data scraping, browser automation at scale, testing pipelines. Anything where you're paying for Chrome compute and cringing at the bill.
It's still in beta and Web API coverage is growing. But at 11.8K stars it's clearly hitting a real nerve.
100% Opensource. AGPL-3.0.
Link in comments.
3️⃣ Non-Human Identities Are Reshaping the Enterprise Attack Surface
* Just 0.01% of NHIs control 80% of all cloud permissions, making privileged machine accounts disproportionately powerful.
* Machine identities now outnumber human users 17:1.
* NHIs typically persist indefinitely unless explicitly decommissioned, unlike human users who go through HR-managed offboarding.
💪 @GitGuardian saves the day with secure coding!
See how they do it with the help of Chainguard Images:
🗄️ Eliminated CVEs entirely — by a full 100%
🔎 Reduced container image size by 33%
🧠 Allowed devs to focus on innovation
Read the full case study: https://t.co/p7RM0SNsX0
I am no advertising expert but a mere mortal, so all of the subtle nuances of these files you will need to research. Just know that the https://t.co/BG21GjJbJI website let's you run domain and other searches where you can discover advertisers, publishers and intermediaries.
2/n
Do people prefer content written by ChatGPT or Bard?
We had ChatGPT create 1000 articles on various topics.
We then gave Bard the same instructions on the same topics.
In total, we created 2000 pieces of content with AI.
1000 from ChatGPT. 1000 from Bard.
When then paid people to read the articles (we didn’t tell them they were written by AI) based on their interests.
In total 249 articles were read from ChatGPT and the 249 counterpart versions from Bard.
We then asked which one they preferred.
Here are the results.
75.51% of the time people prefer Bard articles.
24.49% of the time people preferred the articles written by ChatGPT.