Blog
Insights on software development, security, and technology from our team.

A Next.js OG-image bug can run code on your server. Patch to 16.3.6.
Vercel shipped an out-of-band Next.js update on September 22 to fix CVE-2026-94545, a critical remote code execution bug in the Node.js `ImageResponse` from `next/og`, scored CVSS 9.5. It only bites apps that feed visitor-controlled values into dynamic Open Graph images, but that describes most share-card setups. Here is who is exposed, why patching the framework alone may not be enough, and what to check today.

React 19.3 makes View Transitions stable. Turn on Trusted Types while you're there.
React 19.3 shipped on September 9, 2026, promoting View Transitions and Fragment Refs to stable and adding Trusted Types support and a use(browser()) escape hatch. Here's what web, security, and mobile teams should actually do with it.

A PostgreSQL backup account can now run code on your server. Patch CVE-2026-6471.
PostgreSQL patched CVE-2026-6471, a flaw present since 2014 that lets a low-privilege REPLICATION account load arbitrary code and take over the database host. The official severity is 7.2, not critical, because it needs an account that backup tools, replicas and CDC pipelines all use. Here is how to patch, what the new output_plugin_libraries allowlist changes, and which service accounts to audit first.

A polluted prototype can hijack your axios traffic. Upgrade to 1.18.0.
axios just disclosed CVE-2026-67320, a prototype pollution flaw in its Node.js HTTP adapter that can reroute your server's outbound requests through an attacker-controlled proxy and leak credentials over plaintext HTTP. It's a sharp reminder that a dependency you barely configure is still attack surface. Here's what to patch, and what to change beyond the patch.

One POST request now owns a default WordPress site. Patch to 7.0.2 today.
WordPress just patched wp2shell, an unauthenticated remote-code-execution chain in core that turns one crafted request into a full site takeover on a default install. It affects versions 6.8 through 7.0.1, and public exploit code is already circulating. Here's what web and security teams should do this week, and how to check if you were already hit.

A critical PhpSpreadsheet bug walked straight through its own patch
PhpSpreadsheet's fix for a phar deserialization bug got bypassed with a path carrying one extra slash. The new flaw, CVE-2026-45034, is a 9.2 critical: full remote code execution on PHP 7.x and a file-read primitive on PHP 8.x. Here is how the bypass works and what your team should do this week.

Next.js just patched 13 security advisories. Self-hosted teams have the most work.
Vercel shipped a coordinated security release on May 7: 13 Next.js and React Server Components advisories covering DoS, SSRF, cache poisoning, and middleware bypasses in App Router. Self-hosted teams running Node are hit hardest. The deeper takeaway: middleware was never an authorization boundary.

An AI agent nuked a production database in 9 seconds. Here's what went wrong.
A Cursor agent running Claude Opus 4.6 autonomously deleted a startup's entire production database and backups through a single API call. The incident exposes real gaps in how teams hand AI agents the keys to production infrastructure.

4 million developers on AI coding agents. Is anyone checking the output?
OpenAI's Codex hit 4 million weekly developers this month, up from 3 million just two weeks earlier. GPT-5.5 dropped the same week. Meanwhile, security research keeps showing that AI-generated code leaks secrets at double the human rate and nearly half of it contains known flaws. We break down what development teams should actually do about this.

Three Windows zero-days are in the wild. One is patched. Here's what to do about the other two.
A frustrated researcher leaked three Windows privilege escalation exploits, attackers are already using them against enterprise targets, and only one has a patch. We break down what development teams should do right now.

AI is finding your bugs faster than you can patch them
Anthropic's Mythos model found thousands of zero-days in major software this week. A critical Python notebook flaw got exploited in 10 hours. The vulnerability window has collapsed, and most teams aren't ready.

The LiteLLM supply chain attack is a wake-up call for every team running AI tooling
A 40-minute window on PyPI compromised thousands of environments. The Trivy/LiteLLM supply chain attack is the biggest development security story of the week, and it has practical lessons for any team with unpinned Python dependencies.