Daily notes on AI, testing, and building software.
CVE-2026-68820 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) that allows a locally authenticated attacker with low privileges to escalate to SYSTEM-level access through…
OpenAI's GPT-5.6 Sol introduces state-of-the-art coding intelligence and a new multi-tier model family (Sol, Terra, Luna) that directly affects how AI-assisted test generation, test repair, and automated code review…
New research from ArXiv and a wave of production tooling in 2026 show that LLM-powered autonomous test repair can reduce test maintenance overhead from 40–60% of QA hours to under 5% — but the same research reveals…
CVE-2026-20272 is a Critical-severity command injection vulnerability (CVSS 9.8) in Cisco IOS XE Software that allows an unauthenticated remote attacker to execute arbitrary operating system commands on affected network…
As LLM-powered features ship inside mainstream applications — chatbots, AI summarizers, code assistants, copilots — QA teams are discovering that their entire assertion-based testing playbook breaks down at the model…
The Model Context Protocol (MCP) has consolidated the agentic-Playwright ecosystem around a single standardized bridge, enabling LLMs to drive browsers with full context — replacing brittle selector-based scripts with…
Test oracles — the assertions that define whether a test passes or fails — have always been the hardest part of test automation to scale. New research shows LLMs can now generate high-quality oracles automatically,…
Two actively exploited zero-day vulnerabilities in SonicWall's SMA1000 Series remote access appliances allow an unauthenticated attacker to achieve full root-level code execution by chaining a WebSocket-based SSRF…
Forrester renamed its entire test automation category from "Continuous Automation Testing Platforms" to "Autonomous Testing Platforms" in 2025, and Gartner predicts 40% of enterprise applications will feature AI agents…
CVE-2026-55040 is a critical (CVSS 9.1) JWT token authentication bypass in Microsoft SharePoint Server that allows a remote, unauthenticated attacker to impersonate any user — including site administrators — with no…