// tx_log · 50_broadcasts · last 2026.05.08 · 20:30 IST
Engineering signal,
not noise.
Critical cPanel CVE-2026-41940 enables auth bypass. Patch now.
CVE-2026-41940 in cPanel and WHM allows authentication bypass and remote elevated control. Government and MSP networks are being actively targeted. Patch immediately.
Critical Apache HTTP/2 flaw enables RCE. Patch is 2.4.67.
CVE-2026-23918 is a double-free in Apache HTTP Server's HTTP/2 implementation. RCE is plausible. Upgrade to 2.4.67 or disable HTTP/2 until you can.
Next.js 16 makes Turbopack the default. Migration is mostly free.
Next.js 16 ships Turbopack as the default bundler for dev and prod, replaces middleware with proxy.ts, and introduces a Build Adapters API. Six months in, the migration story is calmer than expected.
Anthropic ships Claude 4.7 with 1M-context
Claude 4.7 lands with a million-token context window and modest pricing changes. Five things shipping engineers should care about.
OBLAIDISH NEWS goes live
First broadcast. Daily-cadence tech news with editorial discipline. Engineering signal, not noise.
Panthalassa raises $140M to put AI data centers in the ocean
Oregon-based Panthalassa closes $140M Series B led by Thiel, with Doerr, Benioff, and Levchin on the cap table. The plan: floating compute nodes powered by ocean waves, cooled by ocean water.
EU agrees to simplify the AI Act. The transparency clock now runs faster.
EU Council and Parliament reached political agreement on May 7 to simplify AI Act rules. The headline: a tightened 3-month transparency deadline for synthetic content, plus carveouts for SMEs and small mid-caps.
Vercel raises Series E at $3B valuation
Vercel closes $250M Series E. Pace of platform consolidation continues — and the IPO clock starts.
React 19.2 batches Suspense reveals. Server-render hydration gets quieter.
React 19.2.6 shipped May 6 with type hardening and a notable behaviour change: server-rendered Suspense boundaries are now batched briefly so content reveals together instead of streaming in piecemeal.
China-linked group targeting NATO state, journalists, semiconductor sector
Threat-intel reporting documents UNK_SparkyCarp (GLITTER CARP) targeting academic, political, semiconductor, and legal sector entities across the US, Europe, and Taiwan. Credential phishing is the primary vector.
Anthropic locks in $200B of Google TPU capacity
Anthropic signs a five-year, $200B compute commitment to Google's TPU fleet. The deal reframes the cost basis of frontier model training — and tightens the cloud-vendor knot.
OpenAI ships GPT-5.5 Instant. Anthropic just overtook them on ARR.
OpenAI announced GPT-5.5 Instant on Monday. The same week, Anthropic's ARR ($30B) eclipsed OpenAI's ($24B) for the first time. The model is the headline; the revenue inversion is the story.
ShinyHunters breached Instructure. Canvas covers 41% of US higher ed.
Criminal extortion group ShinyHunters breached Instructure, owner of Canvas LMS. Canvas covers 41% of higher-ed institutions in North America. The pay-or-leak demand is the largest education-sector breach of 2026.
// newsletter_offline · provider_not_configured