Tech News
← Home  ·  All topics

Code

171 GoKawiil briefs on this topic

Microsoft leads takedown of EvilTokens phishing service, two UK men arrested

Microsoft's Digital Crimes Unit, working with Health-ISAC, law enforcement, and SpyCloud, dismantled the infrastructure behind EvilTokens, a phishing-as-a-service platform that had compromised over 12,000 Microsoft accounts across more than 10,000 organizations. The UK's Metropolitan Police arrested two men, aged 32 and 38, suspected of administering the site, following raids in Canary Wharf and Nine Elms; both were released on bail.

Sublime Text updates internal Python engine to version 3.14

Sublime Text, the cross-platform code editor, has upgraded its embedded Python runtime to version 3.14, keeping the plugin API current with the latest language release. The editor remains a lightweight alternative to full IDEs, offering a single license for use across Windows, Mac, and Linux systems.

Engineer says Claude Code has turned coding into 12-hour 'press enter' drudgery

An anonymous software engineer posting on X as 'voxium' says his employer now uses Anthropic's Claude Code to generate specs, tests, tickets and reports, leaving staff to work 12-13 hour days largely just approving AI output. He says engineers of all seniority levels are reduced to prompting the AI, with little time to review code or fix bugs, and calls the job 'soul-sucking.'

Carson Gross argues Markdown files are becoming software's true source code

In an essay, Montana State University professor and consultant Carson Gross describes a shift he has observed in client organizations adopting agentic coding: Markdown documents are increasingly the source of truth for systems, with LLM-generated code treated as a derived, low-level artifact. He cites Hartley Brody's earlier essay 'Markdown is the new source code' to support the observation, and argues that Markdown specs should be checked into /src alongside the code and tests they generate, rather than living only in transient prompt sessions.

Foremerge open-sources Git-based tool to flag intent conflicts among AI coding agents

Foremerge is a new open-source coordination protocol that sits on top of Git to let multiple AI coding agents, such as Claude Code, Codex, or Cursor, share their intended changes before writing code. Each agent registers what function or component it plans to modify in a shared SQLite-backed list stored inside the project's .git folder, so overlapping or contradictory plans can be flagged before they merge. The current release, version 0.5.0, is a local-first, pre-1.0 MVP with a working CLI, JSON API, MCP server, and conflict detector, though it doesn't yet support coordination across multiple machines.

WordPress patches 'Click2Shell' CSRF flaw enabling remote code execution

Researcher Paulos Yibelo of pwn.ai disclosed a WordPress Core vulnerability, called Click2Shell, that chains a cross-site request forgery bug with the theme Customizer preview to achieve remote PHP execution. The flaw lets an attacker trick a logged-in administrator into visiting a malicious link, silently installing a theme from the WordPress.org catalog and running arbitrary PHP through the Customizer preview even before activation. WordPress fixed the issue in version 7.1.1 after it was reported in late August.

Developer Jared White launches 'We Write Code by Hand' pledge site

Portland-based developer and writer Jared White created a website where programmers can publicly sign their names to affirm they still write software manually, without relying on AI code generation tools. The list has already drawn dozens of signatories from independent developers and freelancers around the world. White also runs a web studio, Whitefusion, that markets itself to clients seeking human-crafted development work.

Gmail adds one-tap 'Copy code' button for 2FA emails on mobile

Google is rolling out a new 'Copy code' shortcut in Gmail that appears beneath the subject line of verification emails, letting users copy a 2FA code straight to their clipboard without opening the message. The feature is live on Gmail for Android version 2026.09.07.x and iOS version 6.0.260907, though it hasn't reached the web version yet.

Developer argues MCP protocol has outlived its usefulness as LLMs advance

A developer who attended an MCP-focused industry event says the Model Context Protocol, released by Anthropic in November 2024 and later handed to the Linux Foundation's Agentic AI Foundation, was designed for weaker, less agentic models than exist today. As adoption exploded, users began overloading context windows by connecting many MCP servers at once, prompting platforms like Composio, MintMCP, and Pipedream to build workaround tools that centralize credentials and trim tool lists.

Microsoft rewrites GitHub Copilot's runtime from TypeScript to Rust using AI agents

Microsoft used AI agents to convert the Copilot runtime's 430,000 lines of TypeScript into 800,000 lines of Rust, a project that took about 14.5 weeks, over 135 releases, roughly $120,000 in AI token costs, and three weeks of human developer oversight to fix dozens of regressions. The Rust version now powers Copilot across VS Code, Visual Studio, the CLI, SDK, and Office apps like Excel and Outlook.

Essay Argues AI Will 'Teleoperate' Humans for Physical-World Work

A new essay argues that the fastest near-term impact of AI on the physical world won't come from robots, but from AI systems directing human workers step-by-step, similar to how GPS navigation already tells drivers what to do. The author calls this 'teleoperation,' where AI handles strategy and broad awareness while humans execute the physical actions AI can't yet perform itself. The piece uses driving and GPS as an early, already-normalized example of this pattern.

OpenAI Codex sandbox flaws let attackers execute code on developer machines

Security researchers at Accomplish AI discovered two ways to break out of the sandbox that isolates OpenAI's Codex coding agent from a user's system. The worse of the two, dubbed Heapjack, let a malicious repository trigger unsandboxed code execution on a victim's machine simply by having Codex answer a question about that repo's code, with no approval prompt or visible warning. Both bugs were reported to OpenAI on August 12 and patched within eight days.