Daily notes on AI, testing, and building software.
CVE-2026-40575 is a critical authentication bypass vulnerability (CVSS 9.1) in OAuth2 Proxy, one of the most widely-deployed reverse proxy solutions for enforcing OAuth2/OIDC authentication in Kubernetes, cloud-native,…
CVE-2026-27913 is a security feature bypass vulnerability in Windows BitLocker, patched in Microsoft's April 2026 Patch Tuesday, carrying a CVSS score of 7.7. A local attacker — requiring no special privileges or user…
CVE-2025-48700 is a stored Cross-Site Scripting (XSS) vulnerability in the Zimbra Collaboration Suite (ZCS) Classic UI, actively exploited by the Russia-linked threat actor UAC-0233 in targeted attacks against Ukrainian…
Claude Opus 4.7 ships with double-digit improvements specifically in Test Quality — not just code generation at large — and resolves 3x more production tasks than its predecessor. For QA teams drowning in AI-generated…
Anthropic's Claude Mythos is the first widely-publicized frontier model explicitly optimized for computer security tasks — which means the same reasoning power that makes it dangerous in the wrong hands makes it…
Anthropic launched Claude Managed Agents in public beta on April 8, 2026 — a fully managed infrastructure layer for running AI agents with sandboxed execution, scoped permissions, long-running sessions, and end-to-end…
Anthropic's Claude Managed Agents, now in public beta, provide a fully managed infrastructure layer for running autonomous AI agents — including specialized, role-specific agents that can analyze test coverage,…
Agentic AI infrastructure — autonomous agents that plan, observe, and self-correct — is now being deployed directly into testing pipelines, with Anthropic's Claude Managed Agents launching in public beta and GitHub…
CVE-2026-35431 is a perfect-10 CVSS critical Server-Side Request Forgery (SSRF) vulnerability discovered in Microsoft Entra ID Entitlement Management, disclosed on April 23, 2026. An unauthenticated remote attacker can…
OpenAI's GPT-5.3-Codex-Spark delivers over 1,000 tokens per second — fast enough to generate test scaffolding as you type production code, making test-driven development feel like autocomplete. Combined with the…