Daily notes on AI, testing, and building software.
Shipping a feature powered by an LLM means shipping non-deterministic behavior — and most engineering teams in 2026 are still testing their LLM features less rigorously than their login forms. A structured LLM…
OpenAI's GPT-5.3-Codex — the most capable agentic coding model yet — is accelerating code output by ~25% while shipping with built-in computer use and hosted shell execution, meaning AI is no longer just suggesting code…
CVE-2026-41940 is a pre-authentication remote authentication bypass in cPanel & WHM (CVSS 9.8 / Critical) caused by a CRLF injection flaw in the platform's session-handling subsystem. Attackers exploited it as a…
Anthropic's public beta launch of Claude Managed Agents — a fully managed agent harness with secure sandboxing and built-in tools — hands QA teams a production-grade, cloud-hosted brain they can wire directly into their…
CVE-2026-22557 is a maximum-severity (CVSS 10.0) unauthenticated path traversal vulnerability in Ubiquiti's UniFi Network Application that allows any network-accessible attacker to read and manipulate arbitrary files on…
CVE-2026-41940 is a critical authentication bypass vulnerability (CVSS 9.8) in cPanel & WHM, the web hosting control panel that manages more than 70 million domains worldwide. Exploiting a CRLF injection flaw in the…
CVE-2025-4632 is a critical path traversal vulnerability (CVSS 9.8) in Samsung MagicINFO 9 Server — the content management platform used to push media to digital signage displays worldwide. Unauthenticated remote…
Anthropic's Claude Security — which just launched in public beta for Enterprise customers on May 1, 2026 — doesn't just find vulnerabilities, it reasons about code the way a security researcher does, tracing data flows…
The shift from scripted test automation to goal-driven autonomous QA agents is no longer theoretical — it's the defining transformation of software testing in 2026, with 77.7% of teams already adopting AI-first quality…
CVE-2026-3854 is a critical remote code execution (RCE) vulnerability discovered by Wiz Research in GitHub's internal git infrastructure, affecting both GitHub.com and GitHub Enterprise Server (GHES). Any authenticated…