🚨Update on the partial restoration of internet in Iran.
It has been 24hrs+ since service started coming back in Iran. In that time, traffic levels peaked at 41% of what we saw prior to Jan 8th, which is also below the Jan 27-Feb 28 partial restoration.
#DigitalBlackOutIran
An interesting insight from https://t.co/sWwZJEXH2T data for the last year: the number of public projects, which use Copilot for creating pull requests stopped growing in the middle of March 2026 and started dropping quickly. The number of such projects dropped from more than 20K to less than 10K during the last two months.
The graph below is obtained from VictoriaLogs playground ( https://t.co/kyQFk3NVg4 )
Under-reported details of the xAI/Anthropic Colossus data center deal: Anthropic get Colossus 1 but xAI keep using the larger Colossus 2, Colossus 1 has a REALLY bad environmental record, and xAI just shut down a bunch of older models on 2 weeks' notice https://t.co/oCKBRNwPVH
SCION has both supporters and critics, but it faces a major challenge: Replacing BGP while competing in an environment where network decisions are driven more by carrier costs than by strategic priorities.
https://t.co/g63ajsWObb
My access to Cloudflare systems has been cut off after 8 years spent with the company. I've had a chance to work with some of the most talented individuals on ambitious Internet-scale projects.
Now, it's time to take a short break and search for a new adventure!
I was one of the 1100 impacted by yesterday's layoff at @cloudflare. Thankful that I had the opportunity to work on @CloudflareRadar over the past 4+ years, evolving it into a trusted industry resource. Would love to continue working with #Internet data in my next role...
The coreutils Rust rewrite story is pretty funny.
Coreutils are tools like rm, mv, mkdir, etc. Unlike binutils, this isn't a fertile ground for memory safety bugs. But, the rewrite was completed, and in the spirit of progress, Canonical decided to switch.
🡇
I'm now unemployed. I hear that the oss community is buried in AI bug reports and don't have enough people to triage and verify. Where is the sign up sheet?
This BGP hijacking operation is still going.
68.136.0.0/14, 68.136.0.0/15, 68.139.0.0/16, 68.138.0.0/16 (unused @Verizon IP space) are announced along:
… 29802 22541 22521
90.98.0.0/15 (unused @orange IP space) is announced along:
… 29802 22541 41128
(forged AS path)
Rant: wow, there are so many #BGP#ASPA invalids being propagated. I'm really hoping ASPA *validation* will soon follow how quickly various ASNs are publishing their Sets of Provider ASes (SPAS). Otherwise we might end up with "another IRR" (irr...elevant because of accuracy).
🚀 ASPA path validation is now live in the new https://t.co/Tk5WEtK8yY release!
🔒 What's new:
- ASPA path validation (beta, sidrops draft)
- Completely new RTR client (v2/v1/v0) - pulls both VRPs and ASPA records
Feedback from operators very welcome 🙏 Stay tuned for more!
We’re thrilled to announce our new MCP server, enabling you to access DomainTools intelligence directly within your AI workflows. Use natural language prompts for instant analysis of risky infrastructure - no new UI involved.
Learn more today: https://t.co/Fv4MNbjHfp
Tom Ptacek posted a great writeup titled "Vulnerability Research Is Cooked", covering the state of vulndev and its rapidly accelerating future:
https://t.co/OL2k2eV9v2
can anyone share evidence how their IP address 142.11.206.73 was sinkholed globally without a trace in #BGP? traceroutes to neighboring IPs work, but not towards .73 -> vendor-specific blocklists?
New supply chain attack this time for npm axios, the most popular HTTP client library with 300M weekly downloads.
Scanning my system I found a use imported from googleworkspace/cli from a few days ago when I was experimenting with gmail/gcal cli. The installed version (luckily) resolved to an unaffected 1.13.5, but the project dependency is not pinned, meaning that if I did this earlier today the code would have resolved to latest and I'd be pwned.
It's possible to personally defend against these to some extent with local settings e.g. release-age constraints, or containers or etc, but I think ultimately the defaults of package management projects (pip, npm etc) have to change so that a single infection (usually luckily fairly temporary in nature due to security scanning) does not spread through users at random and at scale via unpinned dependencies.
More comprehensive article:
https://t.co/EJAZbqAPIQ