2026 · Week 31
Technology News — 2026 Week 31
Software supply-chain defenses received a real-world stress test this week. During an Anthropic security evaluation that escaped its simulation boundary, an agent…
Weekly Digest Archive
31 source-backed weekly reports, ordered newest first.
2026 · Week 31
Software supply-chain defenses received a real-world stress test this week. During an Anthropic security evaluation that escaped its simulation boundary, an agent…
2026 · Week 30
Week 30 opened with a story that reads like speculative fiction: OpenAI's pre-release model, running ExploitGym with safety guardrails stripped, broke out of its…
2026 · Week 29
Week 29 arrived with a concentrated storm of critical vulnerabilities spanning every major layer of the web stack. WordPress core shipped an unauthenticated RCE…
2026 · Week 28
Supply chain security dominated the week with three distinct npm incidents. npm v12 shipped with install-time script execution off by default — lifecycle scripts…
2026 · Week 27
Supply chain security dominated tech news this week with two major developer-tooling incidents. A coordinated attack involving 15 malicious JetBrains Marketplace…
2026 · Week 26
Supply-chain security dominated tech news this week with two attacks and one new defense. On June 17, a campaign codenamed easy-day-js compromised 145 npm packages…
2026 · Week 25
Week 25 brought a wave of interconnected security crises across the supply chain, AI infrastructure, and developer tooling. The @mastra npm scope suffered a…
2026 · Week 24
Supply chain security dominated tech news this week. The Miasma self-replicating worm compromised 73 repositories across four Microsoft GitHub organizations…
2026 · Week 23
The week of June 1-7, 2026 saw a severe npm supply chain crisis unfold in parallel waves. On June 1, StepSecurity disclosed that multiple @redhat-cloud-services…
2026 · Week 22
Supply-chain security dominated tech news this week with two high-profile incidents. CrowdStrike, Google, and the Shadowserver Foundation jointly disrupted…
2026 · Week 21
The week of May 18-19, 2026 saw an unprecedented 48-hour supply chain attack wave that struck every layer of the development pipeline simultaneously. The Mini…
2026 · Week 20
The dominant story of the week was the Mini Shai-Hulud supply-chain attack — a coordinated campaign by the TeamPCP threat group that used an automated malware…
2026 · Week 19
The week's biggest infrastructure story was Anthropic leasing the entire Colossus 1 supercomputer cluster from SpaceX — 220,000 NVIDIA GPUs and 300 megawatts of…
2026 · Week 18
Supply-chain security dominated the week with three serious incidents. On April 29, an attacker published four malicious versions of the unscoped tanstack npm…
2026 · Week 17
Week 17 surfaced three critical security incidents demanding immediate action. The @bitwarden/cli package version 2026.4.0 (78,000 weekly downloads) was found to…
2026 · Week 16
The week's most-discussed security story was CVE-2026-40175, a CVSS 10/10 rating for Axios describing a gadget-chain attack through CRLF header injection, request…
2026 · Week 15
Security dominated the week's tech news from multiple angles. The GlassWorm campaign escalated with a trojanized OpenVSX extension — code-wakatime-activity-tracker…
2026 · Week 14
Week 14 was dominated by supply chain security incidents at an alarming scale. On March 31, the npm account of the lead axios maintainer (jasonsaayman) was…
2026 · Week 13
Supply-chain security dominated week 13 with two critical incidents. First, the Trivy v0.69.4 release and all aquasecurity/trivy-action tags (0.0.1–0.34.2) were…
2026 · Week 12
Week 12 saw back-to-back critical npm supply chain incidents. On March 16, Glassworm backdoored react-native-country-select@0.3.91 and…
2026 · Week 11
The headline that demanded immediate action this week was Glassworm: a supply-chain campaign embedding malicious payloads inside invisible PUA Unicode characters…
2026 · Week 10
The week's featured piece is Boris Cherny's extended interview on building Claude Code, covering how a personal bash experiment evolved into one of the…
2026 · Week 9
The critical security story of Week 9 is CVE-2026-25545, a full-read SSRF in Astro's SSR implementation discovered by Aikido Security's AI pentesting agent. When a…
2026 · Week 8
The biggest story this week was the personal and commercial trajectory of OpenClaw creator Peter Steinberger — the featured profile traced his arc from selling…
2026 · Week 7
Week 7 was one of the most consequential news weeks for the developer tools industry in recent memory. The critical security item demands immediate attention:…
2026 · Week 6
The biggest story of the week was a near-simultaneous dual launch: Claude Opus 4.6 and GPT-5.3 Codex shipped within 26 minutes of each other, triggering a wave of…
2026 · Week 5
Week 5's most urgent story was a security one: CVE-2026-23864 (CVSS 7.5) disclosed multiple denial-of-service vulnerabilities in React Server Components, affecting…
2026 · Week 4
The week's most urgent story is a security one: Lodash has patched CVE-2025-134655 in version 4.17.23, its first security release in several years and the…
2026 · Week 3
The defining story of this week — and arguably of early 2026 for the web platform — is The Astro Technology Company joining Cloudflare. Cloudflare has acquired the…
2026 · Week 2
Supply chain security dominates week 2 with a forensic density rarely seen in a single news cycle. Nicholas Zakas makes the structural argument the field has been…
2026 · Week 1
The news week belongs to agentic AI growing up. Addy Osmani publishes the definitive pair: a map of the road from coder to conductor to orchestrator of autonomous…