Podcasts about GitHub

Hosting service for software projects using Git

  • 3,871PODCASTS
  • 22,176EPISODES
  • 37mAVG DURATION
  • 3DAILY NEW EPISODES
  • Sep 1, 2026LATEST
GitHub

POPULARITY

20192020202120222023202420252026

Categories




    Best podcasts about GitHub

    Show all podcasts related to github

    Latest podcast episodes about GitHub

    Marketing Against The Grain
    Using Codex to build a Research Dashboard/System

    Marketing Against The Grain

    Play Episode Listen Later Sep 1, 2026 33:44


    *Build your AI Research Desk in Codex:* https://clickhubspot.com/inyh Ep. 449 Is informational content on the internet dead? Kipp, Kieran, and guest Matt Wolfe (Future Tools) dive into how you can reclaim hours each week by automating newsletter reading, brand mentions, and industry news updates with your own personal AI system. Learn more on building a custom info dashboard with AI agents, the future of media consumption and creator-business relationships, and how you can leverage open-source tools to create a second brain for your work and life. Mentions Loop: Outlearn. Outmarket. Outgrow https://www.hubspot.com/loop-marketing-book GitHub https://github.com/ Gemini Omni 1.1 Flash https://blog.google/innovation-and-ai/technology/developers-tools/build-with-gemini-omni-1-1-flash/ Codex https://chatgpt.com/codex/ Claude https://claude.ai/ Obsidian https://obsidian.md/ Ask Kipp and Kieran a question! https://form.asana.com/?k=U4n5W_3WC2SkQO1bwK8Xzg&d=8587152060687 Get our guide to build your own Custom GPT: https://clickhubspot.com/customgpt Resource [Free] Steal our favorite AI Prompts featured on the show! Grab them here: https://clickhubspot.com/aip We're on Social Media! Follow us for everyday marketing wisdom straight to your feed YouTube: ​​https://www.youtube.com/@matgpod  Twitter: https://twitter.com/matgpod  TikTok: https://www.tiktok.com/@marketingatg Thank you for tuning into Marketing Against The Grain! Don't forget to hit subscribe and follow us on Apple Podcasts (so you never miss an episode)! https://podcasts.apple.com/us/podcast/marketing-against-the-grain/id1616700934   We really appreciate your support. Host Links: Kipp Bodnar, https://twitter.com/kippbodnar   Kieran Flanagan, https://twitter.com/searchbrat  ‘Marketing Against The Grain' is a HubSpot Original Podcast // Brought to you by Hubspot Media // Produced by Darren Clarke.

    Syntax - Tasty Web Development Treats
    1034: Omarchy Quattro Release

    Syntax - Tasty Web Development Treats

    Play Episode Listen Later Aug 31, 2026 75:47


    Grokbot actually earns its keep, Cursor takes a swing at GitHub with Origin, and Omarchy Quattro ships pre-wired for nine coding agents. Plus: the GitHub outage post-mortem, a compromised Rust crate, native app vibe-coding with Dactyl, and CAD skills for your AI via nurb.dev Show Notes 00:00 Welcome to Syntax! 00:26 Brought to you by Sentry.io 00:37 Grok's New Agentic App: Grokbot 12:51 GitHub's Major Outage and Postmortem 16:42 Cursor's Origin: A GitHub Competitor 22:59 Omarchy: The Linux Distro for Nerds 29:21 CachyOS: Another Arch-Based Alternative 31:12 The $10 Million Omarchy Foundation 34:54 Dactyl: Native iOS and Android Development in the Browser 44:19 Nurb: AI-Powered 3D CAD Design 49:36 Security Stories: Supply Chain Attacks and Model Cheating 49:43 Rust Supply Chain Attack 51:34 Every Model Cheats: AI Benchmark Findings 53:13 Felony Bench: Ranking AI Models by Crimes Committed 54:19 Casio's Smart Dumb Watch 58:43 Everything I Own Is Owned: Reverse Engineering USB Devices with AI 01:08:05 The Mystery 0x Alpha Model 01:13:48 Dactyl Returns Something Hit us up on Socials! Syntax: X Instagram Tiktok LinkedIn Threads Wes: X Instagram Tiktok LinkedIn Threads Scott: X Instagram Tiktok LinkedIn Threads Randy: X Instagram YouTube Threads

    Late Night Linux
    Late Night Linux – Episode 401

    Late Night Linux

    Play Episode Listen Later Aug 31, 2026 26:07


    KDE has a new proper LTS and Joe is very interested, the Steam Frame is (really) nearly here, the Epic Games Store is coming to Linux, Nintendo continues to play whack-a-mole with Switch emulators, and GitHub’s serious scaling issues are getting ridiculous. News/discussion What a real LTS looks like: Kubuntu 26.04 Kubuntu Focus, Techpaladin Software, and KDE e.V. Announce the ‘bullet-proof’ KDE Software Initiative New Frame welcome videos pushed to Steam Store assets Epic Games Store Will Support Linux “Soon” Nintendo Wipes Out 400+ Switch Emulator Repos in Single-Day GitHub Sweep Fairphone 6 + PostmarketOS working main camera! The August 17 GitHub outage, and the work ahead Support us on patreon and get an ad-free RSS feed with some early episodes See our contact page for ways to get in touch. RSS: Subscribe to the RSS feeds here

    Merge Conflict
    530: WinUI Goes Open Source & Mac Mini/Studio Upgrades!

    Merge Conflict

    Play Episode Listen Later Aug 31, 2026 65:58


    This episode kicks off with WinUI's shift to open‑source‑first—what the GitHub‑centric workflow means for Windows devs—and James and Frank's hands‑on tales modernizing apps, CI/CD, and the surprisingly smooth Microsoft Store pipeline. They then deep‑dive into Apple: M6 Mac mini and Mac Studio upgrades for local AI, Rosetta's sunset and Intel‑Mac worries, foldable iPhone rumors, and possible Apple TV Thread/HDMI features—practical insights for choosing platforms and tooling. Note: We had issues with local recordings, so this is a cloud backup processed with Adobe Podcasts Follow Us Frank: Twitter, Blog, GitHub James: Twitter, Blog, GitHub Merge Conflict: Twitter, Facebook, Website, Chat on Discord Music : Amethyst Seer - Citrine by Adventureface ⭐⭐ Review Us ⭐⭐ Machine transcription available on http://mergeconflict.fm

    The Cloudcast
    AI Watermarking: Compliance Theater or Real Provenance Tool

    The Cloudcast

    Play Episode Listen Later Aug 30, 2026 17:30 Transcription Available


    SUMMARY: Brian, Brandon, and Aaron focus on AI watermarking, driven largely by EU transparency requirements, and discuss how approaches like token-selection patterns can be detected but were reportedly cracked quickly with tools that strip watermarks. Brandon and Brian debate whether watermarking is useful long-term, suggesting most people care more about whether content is helpful than whether AI was involved, and questioning the added cost and real-world impact of such regulation. They also explore implications for education policies that ban AI use, changing assessment methods to curb cheating, and potential enterprise and government procurement issues where “no AI” requirements could trigger disputes and lawsuits, while AI review may also level the playing field in contract understanding.SHOW: 1058SHOW TRANSCRIPT: The Enterprise AI Show #1058 TranscriptSHOW VIDEO: https://youtu.be/6zlN_oIR5XcSHOW LINKS:Anthropic WatermarkingClaude Support on WatermarkingSHOW SPONSORS:Nasuni - Activate your data for AI and request a demoTopic: Anthropic recently started invisibly watermarking all Claude-generated text and files (Aug 11), joining Google (SynthID) and ~190 companies that signed the EU's AI Act Transparency Code. Article 50 became enforceable August 2, with fines up to €15M or 3% of global turnover for non-compliance. Within 24 hours of Anthropic's announcement, a free tool to strip Claude's watermark showed up on GitHub.Core question: Is watermarking building durable AI provenance infrastructure, or is it a regulatory checkbox that breaks the moment someone runs a paraphraser?Discussion angles:The cat-and-mouse problem: Watermarks degrade with editing/paraphrasing/translation by design; light edits survive, heavy rewrites don't. Is a signal that vanishes under normal use actually useful, or just plausible deniability for labs?Regulatory arbitrage: EU forces the mandate, but xAI hasn't signed the voluntary Code. What happens to companies operating in the gap, and does the EU rule become a de facto global standard the way GDPR did?What it's actually good for: Not a lie detector, a provenance/tamper flag. Useful for enterprise content authenticity and platform moderation pipelines, much less useful for catching a student or a bad actor who just runs one rewrite pass.FEEDBACK?Email: show @ the enterprise ai show dot comBluesky: @TheEntAIShow.bsky.socialTwitter/X: @TheEntAIShowInstagram: @TheEntAIShow

    Giant Robots Smashing Into Other Giant Robots
    620: My Twin Brother Forced Me To Be His CTO

    Giant Robots Smashing Into Other Giant Robots

    Play Episode Listen Later Aug 27, 2026 43:03


    Would you ever go into business with your family? In this week's episode, our hosts take on Sami's tale of becoming the CTO of his brother's business venture. After the trio get into some excellent running advice, Sami reminds us of the importance of validating the product to make sure the market will actually use what you've built. Will reflects on the importance of a Document of Expectations to weed out potential clients that aren't going to put effort into the development of their ideas (especially if you're doing the work for free), and Chad explains why an idea fizzling out before completion isn't necessarily a bad thing. And make sure to tune in next week, as the team brings in Sami's brother, Doron, to answer some of the questions brought up this episode. — You can find Chad all over social media as @cpytel and Sami through his website. You can also connect with the trio via their LinkedIn pages - Chad - Will - Sami. Don't forget you can now also watch the show over on our YouTube channel! If you would like to support the show, head over to our GitHub page, or check out our website. Got a question or comment about the show? Why not write to our hosts: hosts@giantrobots.fm This has been a thoughtbot podcast. Stay up to date by following us on social media - LinkedIn - Mastodon - Bluesky © 2026 Giant Robots Smashing Into Other Giant Robots Podcast

    The New CISO
    The Player-Coach CISO: Engineering Trust in AI Agents with Open-Source Tools

    The New CISO

    Play Episode Listen Later Aug 27, 2026 49:06


    In this episode of The New CISO, host Steve Moore welcomes Sherri Douville for a conversation that sits outside the show's usual lane — less war story, more blueprint. Sherri works alongside CISOs rather than inside the role, and arrives with a pointed argument about what the job is becoming.She starts with why TTIC exists. IEEE UL 2933 gave healthcare a full-stack standard for clinical IoT device and data interoperability, but a standard on paper does nothing until it is adopted, implemented, and maintained. Getting there in a high-reliability industry means pulling in CIOs, CISOs, physicians, and engineers — and, Sherri admits, negotiating turf wars with bodies who assume you have come for their territory.Then the headline: how to make security cool. Sherri's answer starts with visibility — getting CISOs onto stages, onto podcasts, and into print in front of clinical leadership. Underneath it is a claim about trust. In healthcare, trust is the core of the business rather than an adjacent concern, which makes the CISO its natural steward. With AI pushing trust to the center of every industry, she argues that is the opening to become the rock star of the C-suite.Steve raises a banking CISO's framing of AI as a curious seven-year-old with a gun. Sherri pushes back on the spot: her analogy is the gifted teenager — capable, resource-hungry, and badly in need of direction. That leads to her real thesis. Scarce expertise used to carry economic value, and AI is rapidly compressing the worth of expert analysis. What appreciates instead is judgment, authority, execution, verification, organizational integration, and ownership of the outcome. Executives do not want more reports; they want the security problem to go away without adding coordination burden.The last stretch turns practical. Sherri walks through running Exabeam's open-source Praxen against Medigram's own code — painless to run, with remediation effort scaling to whatever standard you are chasing — and pairs it with Observra for continuous runtime telemetry. She closes on why it matters: when systems go down in a hospital, the real damage is not the outage hour but the fortnight of delays, miscommunications, and pile-up that follows for clinicians and patients.Key TopicsWhy standards bodies stall at adoption, not authorshipMaking security “cool”: visibility, stages, and executive presenceTrust as the core of the business in high-reliability industriesThe gifted teenager vs. the curious seven-year-old with a gunJudgment, authority, execution, verification, integration, ownershipSelective depth and the player-coach executiveRunning Praxen pre-deployment; Observra for runtime telemetryWhat a healthcare outage really costs, 14 to 20 days outGuest BioSherri Douville is CEO and Architect of Medigram and Founder and Chair of the Trustworthy Technology & Innovation Consortium (TTIC). She co-chairs the Trust subgroup of IEEE UL 2933 (TIPPSS), the standard for trust in clinical IoT. Medigram builds and operates Darwin, a governed AI decision platform whose agentic fleet runs in production and writes a sealed governance record at the moment of every agent action — an auditable trail for counsel, courts, insurers, and credit rating agencies. Sherri spent over a decade at Johnson & Johnson across a dozen disease states before physician leaders pulled her into healthcare IT and AI. She calls herself an accidental technologist: a domain expert who got into the code, logging 200 GitHub commits across June and July.GET A DEMO:

    Nintendo Pow Block Podcast
    Gamescom, D23, Final Fantasy Revelation, Kingdom Hearts IV, & More

    Nintendo Pow Block Podcast

    Play Episode Listen Later Aug 26, 2026 185:49


    Hey! Listen! ⁠Email Nintendo Pow Block your questions, topics, and comments⁠! Nintendo is gearing up for a massive fall with new Switch 2 bundles and major game announcements from Gamescom and D23! On this episode of Nintendo Pow Block, ⁠Edward Varnell⁠ and ⁠Corey Dirrig⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ break down the newly announced $529.99 Switch 2 Sports Resort bundle alongside Nintendo's aggressive sweep taking down over 400 emulator repositories on GitHub. They also dive into exciting game reveals coming to Nintendo's next-gen console, including early looks at Stellar Blade: Complete Edition, Kingdom Hearts IV visiting Pixar's Coco, The Witcher 3 Remastered, and Final Fantasy VII Revelation. Plus, they discuss the Call of Duty: Modern Warfare 4 beta heading to Switch 2 and legendary developer Warren Spector retiring from the industry. This and more on Nintendo Pow Block, part of the Boss Rush Network. Join our Communities:Join the ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Boss Rush Network Community Discord⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. Join the ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Boss Rush Network Facebook Group⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠.Follow Nintendo Pow Block on Social Media: Nintendo Pow Block Podcast: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠X/Twitter⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Bluesky⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Instagram,⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Threads⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Facebook⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠YouTube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Twitch.TV⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Follow the Boss Rush Network: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠X/Twitter⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Bluesky⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Instagram⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Threads⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Facebook⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠LinkedIn⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠YouTube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Twitch.TV⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Support Boss Rush Network:Support Boss Rush on ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Patreon⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and buy merch on our ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Store.⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Subscribe to ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Boss Rush on YouTube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and visit our ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠website at BossRush.net⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ for more great content.Thanks for Your Continued Support!Thank you for supporting Nintendo Pow Block! If you're listening on podcast platforms, leave us a five-star rating and a review. If you're watching on YouTube, subscribe, like, comment, and hit the bell so you never miss an episode. Your support means the world—see you next time on Nintendo Pow Block!

    DevZen Podcast
    Сербские пипидастры — Episode 551

    DevZen Podcast

    Play Episode Listen Later Aug 26, 2026 103:24


    В этом выпуске: учим новые слова и проверяем руки мониторов, настраиваем работу с большим количеством агентов, пишем де-эссер на расте, читаем научные статьи и обсуждаем темы слушателей. Шоуноты: [00:00:00] Чему мы научились Dell Pro Single Monitor Arm — MSA20 | Dell UK geoah/go-cctl · GitHub anaflow-ai/cmux: Open source Ghostty-based macOS terminal [00:34:47] Альтернативный деэссинг —… Читать далее →

    Syntax - Tasty Web Development Treats
    1032: Stripe Buys OpenRouter for $7B

    Syntax - Tasty Web Development Treats

    Play Episode Listen Later Aug 24, 2026 67:28


    Scott and CJ break down Stripe's $7B acquisition of OpenRouter, the SvelteKit 3 release candidate, and their first look at TanStack Charts. Plus Zed's new Delta editor, stealing reasoning traces from proprietary LLM APIs, why dark mode toggles only need two states, and all 43 quintillion Rubik's cube states in your browser. Show Notes 00:00 Welcome to Syntax! 02:20 SvelteKit 3 Release Candidate 07:43 Video editor recs Casey Faris 09:58 TanStack Charts First Look TanStack Charts TanStack Charts implementations of every official shadcn/ui chart 14:24 Ponytail AI Tool 17:22 Zed Delta Editor Introducing Delta 23:44 Stripe acquires OpenRouter for $7B+ 29:27 Stealing Reasoning Traces from Proprietary LLM APIs 35:03 First look at Cursor's GitHub killer 42:34 Dark Mode UX Discussion 46:40 Brought to you by Sentry! 48:34 Should AI respond in plain language? 52:57 Swamp Club Automation 01:02:37 Fight AI slop with this anti-slop plugin 01:03:39 Rubik's Cube Permutations 01:05:02 Hackweek Hit us up on Socials! Syntax: X Instagram Tiktok LinkedIn Threads Wes: X Instagram Tiktok LinkedIn Threads Scott: X Instagram Tiktok LinkedIn Threads Randy: X Instagram YouTube Threads

    Soft Skills Engineering
    Episode 527: I lost my job after 10 years and am I too old to switch to a security career?

    Soft Skills Engineering

    Play Episode Listen Later Aug 24, 2026 37:30


    In this episode, Dave and Jamison answer these questions: Hello Dave and Jamison! I'm a longtime listener going back to the early days of the podcast, and I've listened to every episode since. When I started listening, I was beginning my career as a software engineer. Your advice has truly helped shape how I think about work, engineering, leadership, and all the weird human stuff that comes with building software. Now I'm more than 10 years into my career, and I've run into a problem that I suspect many experienced engineers are dealing with right now. In episode 521, you talked about how brutal the current job market is, and the question asker from that episode had been unemployed for a year. I'm thankfully not there yet, but I recently lost my job in a large layoff, and the first couple of months of searching have been pretty discouraging. I'm applying to roughly 10–20 jobs a day. I tailor my resume to each role, ensuring it accurately reflects the skills and terminology in the job description. I usually include a cover letter too; AI gets the privilege of writing the mediocre first draft, and then I rewrite it into something I would actually say. Despite all of that, I've only made it past the resume screen three times so far, one of those was through a referral, and several other referral applications have gone nowhere. The strange part is that I've tried applying across the whole spectrum: Roles that would be a step up, where I think I could do the job but haven't held that exact title before Roles at roughly my current level, where I can honestly check almost every box in the job description Roles that would technically be a step down, but that I'd happily take and feel extremely confident I could do well So my question is: How do you get companies to actually interview you when you're an experienced engineer in a market overwhelmed with qualified candidates? At this point, I'm starting to wonder whether there's such a thing as an awkward career middle age: too experienced for some jobs, not obviously senior enough for others, and competing with hundreds of people for everything in between. If you were in this situation, what would you change? More networking? Fewer but more focused applications? Different positioning? Showing up at the hiring manager's house with a fruit basket and a printed copy of my GitHub profile? Would love to hear how you'd approach it from the other side of the hiring table. Dave and Jamison, Hit me with your dumbest, funniest, most brutally honest advice because I need it. So here's the deal: I'm a software engineer with 30+ year in the industry, a dinosaur who's already reinvented himself like a half-dozen times, network, dev, infra consultant, back to dev. Now I'm having a midlife-ish (okay, late-life) crisis and I've fallen in love with security and compliance. Like, actually excited about compliance, which I'm told is a red flag in itself. Problem is: I'm less than 10 years from retirement and my brain doesn't bounce back from “starting over” the way it used to when I was a spry young whippersnapper. So, am I an idiot for even considering torching my comfy expertise to go be a security newbie this close to the finish line? Or is this exactly the kind of chaotic energy I need before retirement?

    The PowerShell Podcast
    Unit Testing Your Cloud with Mike Soule

    The PowerShell Podcast

    Play Episode Listen Later Aug 24, 2026 41:52


    Mike Soule, Field CTO at Sentinel Technologies, returns to the PowerShell Podcast for the first time in three years to talk identity security, cloud configuration testing, and the evolving role of AI in the Microsoft ecosystem. Andrew and Mike dig into Maester, the open source PowerShell-based test automation framework that applies unit testing concepts to Microsoft 365 security configuration. Mike breaks down how Maester works, how Sentinel uses it with clients, and how the community has grown it into something that spans hundreds of built-in tests covering conditional access, CIS baselines, CISA standards, and more. They also cover EntraOps, the Enterprise Access Model, AI's impact on the MSP world, and why working in managed services is still one of the fastest ways to level up in IT. The episode closes with a strong Brandon Sanderson tangent. Key Takeaways: Maester brings the concept of unit testing to Microsoft 365 security configuration, letting admins continuously validate their cloud settings against known-good baselines with as few as three PowerShell commands. It's built on Pester, is fully open source, and now has over 100 community contributors. AI is changing the MSP landscape fast, but the fundamentals still matter. Mike and Andrew discuss how to think about Copilot licensing complexity, model routing in agent stacks, and why meeting users in their existing interface is often more important than deploying a shiny new tool. MSP experience accelerates learning in a way that internal IT often can't match. When you're working across multiple clients and environments, you accumulate reps quickly, and that breadth is hard to replicate elsewhere. Guest Bio: Mike Soule is the Field CTO at Sentinel Technologies, a large managed service provider focused on identity, cloud, and security strategy. Mike has been working hands-on with PowerShell, Entra ID, and Microsoft 365 security architecture for years and is a regular speaker at identity and security conferences. Resource Links: Maester (open source framework): https://maester.dev Maester on GitHub: https://github.com/maester365/maester Maester Cloud (hosted version by Merill Fernando): https://maester.cloud HIPConf (Hybrid Identity Protection Conference): https://www.hipconf.com EntraOps by Thomas Naunheim: https://github.com/Cloud-Architekt/EntraOps Mike Soule on LinkedIn: https://www.linkedin.com/in/mikesoule The PowerShell Podcast on YouTube: https://youtu.be/EQK693gGWoo  

    The Science Hour
    Fashionably late

    The Science Hour

    Play Episode Listen Later Aug 21, 2026 49:31


    News of an Australian library book finally finding its way home 150 years after it was borrowed has the Unexpected Elements team thinking about things that get forgotten, filed away or simply turn up much later than expected.We start with the story of a meteorite from Mars that spent millions of years travelling through space before ending up in a university drawer. Then, we investigate why scientists believe California may be centuries overdue for a massive earthquake known as "The Big One".Next, Martin Woodward from GitHub joins us to explain how millions of lines of computer code are being preserved deep beneath the Arctic in a vault designed to protect humanity's digital knowledge for generations to come.Plus, we hear about the penguin vaccinators working to protect Australian wildlife from bird flu, discover if smells, tastes and touch can be measured, and explore the dying art of reading a book. All that, plus many more, unexpected elements.Presenter: Marnie Chesterton Producers: Lucy Davies, Ella Hubber, Imy Harper and Robbie Wojciechowski

    Dev Interrupted
    The battle to replace Github, building assembly lines for software, and why no one finishes projects anymore

    Dev Interrupted

    Play Episode Listen Later Aug 21, 2026 24:28


    When an AI can write 90 percent of a codebase in minutes, why is finishing the project harder than ever? This week on the Friday Deploy, Ben and Andrew explore the recent string of GitHub outages and why the surge in autonomous agents is forcing teams to rethink where they host their code. They once again dive into the emerging trend of software factories, breaking down how engineering leaders are turning chaotic AI pull requests into streamlined assembly lines. Finally, they share tactical advice for "landing the plane" and pushing past scope creep to deliver the grueling final fraction of any major initiative. Register: Dev Interrupted Presents: The Software Factory RoundtableFollow the show:Subscribe to our Substack Follow us on LinkedInSubscribe to our YouTube ChannelFollow the hosts:Follow AndrewFollow BenFollow DanFollow today's stories:Incident Report for GitHubCursor launches Origin code hosting platform as GitHub outage exposes opening in AI coding raceAsk HN: Alternatives to GitHubEveryone building a software factory wants the same proofIntroducing Warp FactoriesLanding the planeOFFERSStart Free Trial: Get started with LinearB's AI productivity platform for free.Book a Demo: Learn how you can ship faster, improve DevEx, and lead with confidence in the AI era.LEARN ABOUT LINEARBAI Code Reviews: Automate reviews to catch bugs, security risks, and performance issues before they hit production.AI & Productivity Insights: Go beyond DORA with AI-powered recommendations and dashboards to measure and improve performance.AI-Powered Workflow Automations: Use AI-generated PR descriptions, smart routing, and other automations to reduce developer toil.MCP Server: Interact with your engineering data using natural language to build custom reports and get answers on the fly.

    Security Conversations
    Inside the EncroChat law-enforcement implant, Irregular's AI sandbox failure

    Security Conversations

    Play Episode Listen Later Aug 21, 2026 131:08


    (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 110: We dig into Computer Weekly's scoop on the EncroChat hack and news that the French law enforcement implant was cobbled together from GitHub. Plus, Irregular, the $450M startup running sandboxes for OpenAI, Anthropic and Meta, drones over Romania's gas platforms, OpenAI's two-week training pause, and T-Mobile taking scissors to a cable during Salt Typhoon incident response. Stick around for a UFO segment that somehow involves Dr. Phil. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter; LabsCon speakers announced 9:06 A naval drone reaches the Neptun Deep gas platform 17:38 OpenAI pauses RL training: what "slowing the pace of scaling" costs 24:34 Guardrails vs refusals vs alignment. 33:54 Irregular, formerly Pattern Labs: $80M, $450M valuation, one job 46:11 JAGS on why security needs a new batch of startups right now 1:06:52 EncroChat revealed: a GitHub-sourced implant, IOCs 1:15:12 Law enforcement malware vs intelligence malware 1:21:07 T-Mobile, Salt Typhoon, and cutting the cable with a pair of scissors 1:32:06 Captive Crunch: hotel Wi-Fi, OAuth token theft, and the MSP supply chain 1:47:00 ICE RELIC, UNC6293, and the trouble with subcluster naming 2:00:39 UFO corner: David Grusch, Dr. Phil, and the Skywatcher Project 2:05:44 Shout outs, the Costin Challenge

    Giant Robots Smashing Into Other Giant Robots
    619: Inside Modern Software Engineering with Homebrew's Mike McQuaid

    Giant Robots Smashing Into Other Giant Robots

    Play Episode Listen Later Aug 20, 2026 50:33


    Sami is back this week with Mike McQuaid, CTPO and Homebrew Project Leader, as they take a deep dive into the importance of open source maintainers in modern software engineering. With 18 years of experience reducing developer friction and scaling open source software, Mike discusses the commonalities and differences between open source and proprietary software audiences, impact of large data centres on both the environment and women in the workplace, revealing what drove him to create Homebrew and where they are now, before taking Sami through burnout and why it's important to not be rude to your open source maintainers - you'll be surprised which national entities would fall apart if it weren't for their hard work and time. — Our guest for this episode has been Mike McQuaid. If you'd like to get in touch with Mike, or to keep up to date with his work, you can do so through his website. Also mentioned in today's episode: ‘Open Source Maintainers Owe You Nothing' blog post. Your host for this episode has been Sami Birnbaum. Sami can be found through his website or via LinkedIn. If you would like to support the show, head over to our GitHub page, or check out our website. Got a question or comment about the show? Why not write to our hosts: hosts@giantrobots.fm This has been a thoughtbot podcast. Stay up to date by following us on social media - LinkedIn - Mastodon - YouTube - Bluesky © 2026 Giant Robots Smashing Into Other Giant Robots Podcast

    Game Dev Advice: The Game Developer's Podcast
    Stop Waiting for Perfect, Start Shipping Games | Frank Force

    Game Dev Advice: The Game Developer's Podcast

    Play Episode Listen Later Aug 20, 2026 84:47


    Frank Force joins us to talk about how game developers can ship faster, learn better, and avoid getting trapped by perfectionism. He shares lessons from AAA development at studios like Volition, Midway Games, and others including milestone pressure, polish, crunch, and speedrun-style bug hunting on PsiOps. He also breaks down his current push to release Pyroot, a C++/DirectX Metroidvania he started 6–7 years ago, on Steam Early Access. The conversation dives into why Frank believes browser-based development, JavaScript, game jams, and sharing work early can be powerful ways to build skills and a portfolio. He challenges the idea that web development can't produce “real” games and explains why low-friction tools can make it easier to experiment, iterate, and actually finish projects. Frank also gets into sizecoding and creative programming through JS1K, JS13K and Dwitter, the origins and growth of his open-source LittleJS game engine, procedural audio with ZZFX, and the mindset of removing rather than adding. Plus, he shares how AI is already helping game developers find bugs, prototype ideas, and give small teams more leverage, while also discussing his concerns about sunk-cost thinking, exploitative player psychology, and where the industry may be heading. Topics include: • Breaking into game development • Building a portfolio • Shipping games instead of endlessly polishing • JavaScript and browser-based game development • AAA development lessons • Indie game development • Game jams and rapid iteration • Sizecoding, JS1K, JS13K and Dwitter • LittleJS and open-source development • Procedural audio and ZZFX • AI tools for game developers • Going indie full time━━━━━━ TIMESTAMPS ━━━━━━ 00:00 - Career Advice Myth 00:36 - Meet Frank Force 00:56 - Pyroot Early Access 02:53 - AAA Lessons and Crunch 05:12 - Speedrunning for QA 05:43 - JavaScript Game Dev 09:02 - Ship Fast Share Early 12:03 - Advance Inside Studios 14:36 - Breaking In and Portfolios 18:03 - Sunk Cost Trap 19:27 - AI for Game Development 34:33 - Industry Concerns and Hope 38:57 - Size Coding JS1K 41:44 - Recreational Programming 41:57 - Code Golf vs Sizecoding 43:24 - Demo Scene Culture 44:31 - JavaScript Sizecoding Shift 45:26 - Procedural Assets Challenge 46:13 - Remove Not Add Mindset 48:05 - JS13K Sweet Spot 51:27 - Dwitter Raycasting Magic 54:23 - LittleJS Origin Story 57:10 - Open Source Community Growth 58:47 - Driven Wild and Self Promotion 01:00:48 - ZZFX Sound Without Assets 01:03:03 - Optical Illusion Breakthrough 01:06:25 - Make Stuff and Share It 01:09:11 - Going Indie Full Time 01:13:18 - Generative Art NFT Detour 01:17:12 - Monetizing Web Games 01:20:15 - Advice and AI Tools 01:22:47 - Final Thanks ━━━━━━━━━ ABOUT THE GUEST ━━━━━━━━━ Frank Force has been building real-time interactive software for over 25 years, from AAA titles like DOOM and Red Faction: Guerrilla to LittleJS, his open source game engine with over 4,000 stars on GitHub. He runs Frank Force Games in Austin, Texas, where he works on engines, graphics, games, and tools, and writes an unreasonable number of very tiny programs. ━━━━━━━━━ LINKS & RESOURCES ━━━━━━━━━ https://frankforce.com/ - Frank's website with links to projects and longform writeups https://killedbyapixel.itch.io/dr1v3n-wild - Frank's arcade driving game (started as a 13k game) https://killedbyapixel.github.io/LittleJSArcade/ - 50+ open source games made with LittleJS https://cosmodial.3d2k.com/ - Cosmodial is Frank's newly released open source star atlas https://js13kgames.com/ - JS13k games the 13k size JavaScript coding competition ━━━━━━━━━ GAME DEV ADVICE ━━━━━━━━━ Whether you're a student, aspiring game developer, or industry veteran, you'll find practical takeaways and real stories from inside the world of game development.

    AI Chat: ChatGPT & AI News, Artificial Intelligence, OpenAI, Machine Learning
    Anthropic Hits $65B Run Rate, Cursor Launches Origin

    AI Chat: ChatGPT & AI News, Artificial Intelligence, OpenAI, Machine Learning

    Play Episode Listen Later Aug 19, 2026 13:20 Transcription Available


    In this episode, we discuss Anthropic's remarkable $65 billion revenue run rate in July and how it compares to OpenAI's projections. Additionally, we cover OpenAI's new ChatGPT for teens, Cursor's launch of its GitHub competitor Origin, and the implications of security overhauls in AI model training following recent incidents.Chapters00:00 Introduction02:00 Anthropic's Revenue Surge04:03 ChatGPT for Teens06:40 Cursor Launches Origin09:21 OpenAI's Security Overhaul11:41 Conclusion and Community Announcement Show LinksHow I Grow and Scale My Business with AI: https://www.skool.com/aihustleGet the AI Chat Daily Newsletter: https://www.aichatdaily.com/newsletter

    The CyberWire
    Fake it till you exfiltrate it.

    The CyberWire

    Play Episode Listen Later Aug 18, 2026 28:48


    A fake consultancy fronts an alleged Chinese spy campaign. Meta heads to court over claims it hooked young users. Researchers crack the mystery behind the French EncroChat hack. CISA warns ransomware gangs are exploiting a Windows flaw. Meet C2Looper, a new Rust-based backdoor. A critical WordPress plugin bug threatens hundreds of thousands of sites. MessiahGPT brings generative AI to cybercrime. A lender discloses a breach affecting 1.2 million people. A Ukrainian developer stands trial in Switzerland over alleged ransomware ties. Our guest is Ev Kontsevoy, CEO at Teleport, discussing how AI agents have nondeterministic behavior. The psychology of the endless scroll.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, we are joined by Ev Kontsevoy, CEO at Teleport, discussing how AI agents have nondeterministic behavior. If you enjoyed this conversation, check out the full interview here. Selected Reading A fake website and a deluge of CVs: the Australian firm embroiled in an FBI probe into alleged Chinese espionage (The Guardian) States Seek $200 Billion From Meta Over Child Social Media Addiction Claims (The New York Times) Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network (Computer Weekly) CISA: Windows Task Host flaw now exploited by ransomware gangs (Bleeping Computer) C2Looper Backdoor Uses GitHub for C2 (ThreatLabz) 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw (SecurityWeek) MessiahGPT Criminal AI Service Advertised on BreachForums (HackRead) Heights Finance Data Breach Impacts at Least 1.2 Million Individuals (SecurityWeek) Ukrainian software developer faces 12 years in Swiss ransomware trial (The Record from Recorded Future News) Why Can't We Stop Scrolling? (Psychology Today) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

    The AI Breakdown: Daily Artificial Intelligence News and Discussions
    The AI Engineering Skills Map for Knowledge Workers

    The AI Breakdown: Daily Artificial Intelligence News and Discussions

    Play Episode Listen Later Aug 18, 2026 26:40


    AI is changing what effective knowledge work requires. NLW presents five essential skills for working with agents, building new tools, and recognizing opportunities that were previously impossible—grounded in the domain judgment AI can't replace. In the headlines: Cursor takes on GitHub, Anthropic's revenue surges, and Stripe acquires OpenRouter.AIDB's AI Summer Adventure: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://summeradventure.ai/⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Brought to you by:KPMG – Research from KPMG and the University of Texas at Austin shows the highest-impact AI users treat AI like a reasoning partner — and those skills can be taught at scale. Learn more at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://kpmg.com/us/Sophisticated⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Harbor - Invest in the AI ecosystem. ⁠⁠⁠⁠https://www.harborcapital.com/aidaily⁠⁠⁠⁠Hyperagent - Hire a fleet of always-on agents. New users get $1,000 in inference. ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠hyperagent.com/aidailybrief⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Rackspace Technology- One accountable partner to build, operate and run your full enterprise AI stack ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.rackspace.com/⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Section - Section turns AI investment into workforce transformation and ROI - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.sectionai.com/⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Blitzy - Want to accelerate enterprise software development velocity by 5x? ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://blitzy.com/⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠AssemblyAI - The best way to build Voice AI apps - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.assemblyai.com/brief⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Robots & Pencils - Cloud-native AI solutions that power results ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://robotsandpencils.com/⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠The AI Daily Brief helps you understand the most important news and discussions in AI. Subscribe to the podcast version of The AI Daily Brief wherever you listen: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://pod.link/1680633614⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Our Newsletter is BACK: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://aidailybrief.beehiiv.com/⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Interested in sponsoring the show? sponsors@aidailybrief.ai

    Python Bytes
    #492 Codeberg Puts Head in Sand

    Python Bytes

    Play Episode Listen Later Aug 18, 2026 39:17 Transcription Available


    Topics covered in this episode: Python 3.12.14, 3.11.16, 3.10.21 - security releases Codeberg's AI-code ban tests its role as a GitHub alternative Brett Cannon: what's missing for reproducible builds on PyPI nothing records the source code a distribution came from. direct_url.json captures it when you install from a repo or archive, so the fix is putting the same info in sdist/wheel metadata. recording the build tools. Wheels can already do this via PEP 770 SBOMs in .dist-info/sboms/ - sdists can't, since they're a tarball plus a precalculated PKG-INFO with nowhere to hang extra metadata. Either "don't use sdists" or an sdist v2. Extra extra extra, hear all about it Extras Joke Watch on YouTube Sponsored by Logfire from Pydantic pythonbytes.fm/logfire This episode is brought to you by Pydantic Logfire. It's observability for AI apps from the team behind Pydantic - agents, LLMs, APIs, database, and infrastructure in a single trace, queried with Postgres-compatible SQL. Your coding agent can query it too, through their MCP server. I'll tell you more later. Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Calvin #1: Python 3.12.14, 3.11.16, 3.10.21 - security releases https://blog.python.org/2026/08/python-31214-31116-31021/ Source-only security releases for the three branches now in security-fix-only mode; release team blamed the European solar eclipse for the timing. tarfile hardening. Multiple path-traversal bypasses of the data filter closed, including a symlink escape that bypassed the CVE-2025-4330 fix; extract() now applies the filter to link targets too. Four fresh CVEs: CVE-2026-2297 (SourcelessFileLoader not using io.open_code() for .pyc), CVE-2026-4224 (expat crash on deeply nested content models), CVE-2026-3644 (control chars in http.cookies.Morsel), plus the completed CVE-2021-4189 fix in ftplib.ftpcp. Quadratic-complexity DoS cleanup across the stdlib: HTMLParser, configparser regexes, unicodedata.normalize(), csv.Sniffer.sniff(), and ElementTree XPath index predicates. Header/injection fixes: CR/LF rejected in HTTPConnection.set_tunnel(), control chars blocked in wsgiref.handlers status, and webbrowser now rejects leading dashes (plus a %action prefix bypass). http.client now caps chunked trailer lines and 1xx interim responses at 100 each - a hostile server could previously hang the client forever despite a socket timeout. Memory-safety odds and ends: stale pointers in lzma/bz2/zlib decompressors after MemoryError, a bz2 stack overflow on reuse-after-error, and bundled libexpat bumped to 2.8.3. If you're still on 3.10, 3.11, or 3.12 - and you extract tarballs from anywhere you don't fully control - this one's not optional. Michael #2: Codeberg's AI-code ban tests its role as a GitHub alternative Armin's article “Codeberg Divides” Armin Ronacher argues that Codeberg's new terms, which prohibit projects mostly written with generative AI, create a vague and difficult-to-enforce boundary. His larger concern is that a democratically governed host can still be unpredictable or ideologically narrow, weakening Codeberg's potential as a broad European alternative to GitHub. The strongest question for Python developers is whether repository hosting should judge legal open source by how code was produced, or focus on behavior and resource abuse. “Mostly generated” is hard to measure in modern codebases where developers mix handwritten code, completions, agents, and generated refactors. Ronacher suggests clearer alternatives: ban all LLM involvement, or target autonomous repository spam, abusive resource use, and low-quality generated contributions directly. Codeberg is free to choose a values-driven community, but that may conflict with being predictable, neutral infrastructure and a serious GitHub competitor. Worth discussing: can open-source communities set meaningful AI boundaries without driving maintainers and projects into opposing camps? Very first search for these terms lands on this page. Codeberg looked like a viable alternative. … Unfortunately, the latest update to its terms of service seems to mark a first step in changing one part I moved there for, namely the “freedom” part. Sponsor: Logfire from Pydantic Your AI agent failed at 2am. Was it the model? A tool call? The database? Most observability tools can't tell you, because they only see part of your stack. Pydantic Logfire sees all of it. One trace across your agents, LLMs, APIs, and database. Down to the infrastructure: services, Kubernetes, and hosts. It's built on OpenTelemetry, with SDKs for Python, TypeScript, and Rust, and it works with any OTel-compatible language. Every prompt, token count, and cost, right next to your vector searches and API calls. You query everything with Postgres-compatible SQL. And so can your coding agent, through the Logfire MCP server. Stop guessing. Read the trace. Pydantic Logfire. AI, it's still just engineering. Visit pythonbytes.fm/logfire today and sign up today. Get 10M records free every month, no card required. You can even click “Onboard with your coding agent” to copy a prompt to have claude or codex integrate Logfire into your app. Thanks to Pydantic for supporting the show. Calvin #3: Brett Cannon: what's missing for reproducible builds on PyPI Framing came out of his 2026 Python Packaging Council nomination - the secure-supply-chain gap he found is that Python has no defined way to do reproducible builds at all. Design goal is zero friction: producers uploading to PyPI shouldn't have to do anything. The work lands on build backends and installers. Gap #1: nothing records the source code a distribution came from. direct_url.json captures it when you install from a repo or archive, so the fix is putting the same info in sdist/wheel metadata. Gap #2: recording the build tools. Wheels can already do this via PEP 770 SBOMs in .dist-info/sboms/ - sdists can't, since they're a tarball plus a precalculated PKG-INFO with nowhere to hang extra metadata. Either "don't use sdists" or an sdist v2. The replay mechanism already exists: [build-system] in pyproject.toml is a defined entry point, so if backends recorded their own environment, you could reinstall and re-run the build. Payoff idea: trusted third parties report successful reproductions back to PyPI, which displays "independently reproduced by X" - surfaced in the index API so installers could prefer reproduced files. Explicitly framed as a perk, not a requirement - roughly SLSA build level 1, no shaming projects that don't opt in. Verbal kicker option: "And don't think pure-Python wheels are off the hook. Something built that wheel, and if that something was compromised, so is your wheel. SolarWinds was a build-process attack." Michael #4: Extra extra extra, hear all about it Python 3.14.7 Upgraded the MCP servers to 2026-07-28 v2 protocols (talk python, python bytes) Got agentsview running synced via postgres Talk Python courses, teams trial offering Talk Python courses, government procurement offering Lean TDD audio book is out Extras Calvin: uv now prefers post-quantum key exchange - https://github.com/astral-sh/uv/releases/tag/0.12.4 Joke: Beware of dog

    TechLinked
    OpenAI's New ChatGPT Tracking Feature, Global GitHub Outage Breaks Copilot, Flock CEO Says They Got It Wrong + more!

    TechLinked

    Play Episode Listen Later Aug 18, 2026 7:43


    News Sources: https://lmg.gg/R6kOD Timestamps: 0:00 ChatGPT Computer History 1:25 GitHub outage 2:32 Flock Safety changes 4:12 QUICK BITS INTRO 4:17 Chip shortage warranty woes 4:48 Meta smart glasses harassment 5:13 YouTube view counting change 5:40 Geekom driver virus 6:18 Unitree robot speed claim 6:49 Credits Learn more about your ad choices. Visit megaphone.fm/adchoices

    Paul's Security Weekly
    Secrets, Red Agent, GitHub, evoooo1bot, DecryptAds, Copilot, Aaran Leyland, and More - SWN #608

    Paul's Security Weekly

    Play Episode Listen Later Aug 18, 2026 39:25


    The Secret Word is Meow, Red Agent, GitHub, evoooo1bot, Hatman, DecryptAds, Copilot, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-608

    The Cloud Pod
    368: Push, Pull, and Pray: GitHub Outage Strikes

    The Cloud Pod

    Play Episode Listen Later Aug 18, 2026 75:01


    Welcome to episode 368 of The Cloud Pod, where the forecast is always cloudy! Justin, Matt, and Ryan are in the studio this week, and the major story is the GitHub outage – are you still digging out from that one too? We have MANY thoughts. Plus, we have news from EKS, CloudShell, and some major Microsoft changes to the Copilot ecosystem. There's a lot to cover, so let's get started!  Titles we almost went with this week Amazon Quick Crashes Microsoft’s Copilot Party Bin-Packing Pods Like a Kubernetes Tetris Champ AWS Agents Go GA and Grab Your Wallet AWS Finally Shows You The Money Trends AWS Hands Out Power (User Access) Like Candy AWS Builds Lofts, Developers Build Everything Else Front Door Now Checks IDs Before Letting Traffic In CloudShell Ditches Vim, Editors Rejoice Everywhere AWS Sign-In Gets a Facelift, Scripts Get Nervous Azure Front Door Gets Mutual TLS, Trust Issues Resolved One Copilot to Rule Work and Play GPT-5.6 Sol Hits Warp Speed With Cerebras OpenAI Ditches Overnight Batches for Ultrafast Gratification Ultrafast API Proves Speed and Smarts Aren’t Rivals Terraform Plans Meet Their IAM Autopilot Match AWS Autopilot Now Reads Your Terraform Tea Leaves A big thanks to this week's sponsors: We're sponsorless! Want to get your brand, company, or service in front of a very enthusiastic group of cloud news seekers? You've come to the right place! Send us an email or hit us up on our Slack channel for more info. Follow Up 01:02 Microsoft confirms GitHub is down worldwide GitHub confirmed a widespread Github outage starting at 9:40 AM EDT on August 17, 2026, affecting web, API, Actions, Pull Requests, Issues, Webhooks, and authentication services including SAML, OIDC, and SCIM. As of the 11:42 AM EDT update, GitHub has moved into mitigation mode, but error rates remain unchanged at roughly 20% for web and API traffic and approximately 50% for archive and raw repository content downloads. Copilot was added to the list of affected services at 10:31 AM EDT, extending impact beyond core Git functionality into GitHub’s AI coding tools. Git Operations, Packages, Pages, and Codespaces remain listed as operational, indicating the outage is concentrated in specific service areas rather than the entire platform. GitHub has not disclosed a root cause, and the incident remains under investigation, meaning listeners relying on CI/CD workflows through Actions should expect continued disruption until further updates are posted. Complicating factors that impeded recovery included a number of scraping attacks on codeload endpoints. To prevent recurrence, our follow-up actions include: Correcting autoscaling policies to account for service-mesh sidecar concurrency and capacity. Auditing Istio request, concurrency, and scaling limits across affected services. Reviewing retry limits and backoff behavior across gateways and clients. Addressing the VS Code retry behavior that amplified Copilot token traffic.

    AWS for Software Companies Podcast
    Ep219: Scaling Autonomous Operations with AWS DevOps Agent and ServiceNow

    AWS for Software Companies Podcast

    Play Episode Listen Later Aug 18, 2026 24:14


    ServiceNow and AWS reveal how the DevOps Agent and MCP Server Console are turning incident response into a fast, autonomous, fully governed process. Topics Include:Govind Menon (ServiceNow) and Arun Jacob (AWS) discuss MCP and A2A strategy.ServiceNow understands workflows; partners with AWS to power them with AI.AI Control Tower governs and secures agent access to enterprise data.MCP is the industry standard for how AI agents read and act.Action Fabric spans A2A, REST APIs, and MCP for agentic work.AWS DevOps Agent, built on Bedrock, resolves incidents through sub-agents.Admin and operator access patterns integrate with Dynatrace, Datadog, Slack, GitHub.Demo: ServiceNow incident automatically triggers DevOps Agent investigation and resolution.DevOps Agent writes findings live back into the ServiceNow incident ticket.ServiceNow champions capping MCP servers at 30 tools for performance.MCP Server Console lets teams build scoped, use-case-specific tool servers.NowAssist skills, Knowledge Graph, and REST APIs become MCP tools.Live demo connects a 38-tool custom MCP server to DevOps Agent.Role-based access ensures users only see their permitted MCP tools.ServiceNow's autonomous ITOM agents point toward unsupervised future operations. Participants:Govind Menon – Head of MCP Product, ServiceNow Arunsingh Jeyasingh Jacob – Senior Solution Architect - ISV, Amazon Web Services See how Amazon Web Services gives you the freedom to migrate, innovate, and scale your software company at https://aws.amazon.com/isv/

    Doppelgänger Tech Talk
    Außerbilanzielle Verpflichtungen | Anthropic bald wertvoller als Nvidia? | Google kauft Daten einer Pleite-Airline #589

    Doppelgänger Tech Talk

    Play Episode Listen Later Aug 18, 2026 117:14


    Das Wall Street Journal rechnet vor, dass die großen Techkonzerne rund drei Billionen Dollar an Verpflichtungen tragen, die nicht in ihren Bilanzen stehen, also Kaufzusagen, noch nicht begonnene Leasings, SPV-Konstruktionen und Bürgschaften. Davor geht es um OpenAIs neues Zehn-Gigawatt-Projekt in Ohio, für das Nvidia einen Teil garantiert, und um die Frage, ob GPUs sich wie Flugzeuge oder Schiffe finanzieren lassen. Anthropic soll Ende Juli bei 65 Milliarden annualisiertem Umsatz gelegen haben und peilt für 2028 rund 200 Milliarden an. Stripe kauft OpenRouter für sieben Milliarden. Berkshire erhöht die Alphabet-Position um 83 Prozent, auf Buffetts eigenen Wunsch. Aus China kommen drei Milliarden Qwen-Downloads und ein neues Modell von Z.ai. Google ersteigert für zehn Millionen den Datenbestand einer insolventen Fluglinie. Unterstütze unseren Podcast und entdecke die Angebote unserer Werbepartner auf ⁠⁠⁠⁠⁠⁠⁠doppelgaenger.io/werbung⁠⁠⁠⁠⁠⁠⁠. Vielen Dank!  Philipp Glöckler und Philipp Klöckner sprechen heute über: (00:00:00) Titelsuche (00:01:08) 10 Gigawatt in Ohio (00:02:15) Absatzfinanzierung (00:04:53) Nvidias Bilanz (00:16:05) Die 3 Billionen (00:35:42) Emissionen der Rechenzentren (00:38:19) Misstrauen gegen KI-Chefs (00:40:42) OpenAI-Umsatz (00:42:42) Stripe kauft OpenRouter (00:46:34) Anthropic-IPO (00:55:43) 13F und Berkshire (01:00:46) Qwen-Downloads (01:05:01) GLM 5.3 (01:06:05) Shein fällt weiter (01:06:50) Uber und Zipline (01:12:56) Cursor Origin (01:15:28) YouTube-Views (01:20:35) Google kauft Spirit-Daten (01:29:51) Apple und das Kartellamt (01:31:00) Teickes attuned.world (01:38:43) Thelens Tweet (01:45:22) Grok (01:48:43) Amazon zerschneidet Bücher (01:54:49) Metas COPPA-Prozess Shownotes OpenAI sichert sich 10 Gigawatt in Ohio, Nvidia stützt die Finanzierung - wsj.com Halbleiterkonzerne finanzieren ihre eigenen Kunden - news.crunchbase.com Warum die KI-Ausgaben 3 Billionen höher liegen als ausgewiesen - wsj.com 60 geplante Rechenzentren und ihre CO2-Bilanz - ft.com Junge Menschen misstrauen den KI-Chefs - futurism.com OpenAI-CFO Friar: Enterprise ist jetzt größer als Consumer - cnbc.com Stripe kauft OpenRouter für über 7 Mrd. - bloomberg.com Anthropics IPO-Bewertung hängt an der 2028er Umsatzprognose - reuters.com Anthropics Umsatz vervierzehnfacht sich im zweiten Quartal - bloomberg.com Berkshire erhöht die Alphabet-Position und steigt bei Constellation aus - wsj.com Alibabas Qwen-Modelle kommen auf 3 Milliarden Downloads - bloomberg.com Z.ai bringt GLM-5.3 als offenes Coding-Modell - decrypt.co Shein senkt die IPO-Bewertung auf rund 25 Mrd. - reuters.com Uber und Zipline wollen eine Million Drohnenlieferungen am Tag - wsj.com Cursor startet Origin gegen GitHub - siliconangle.com GitHub war den halben Tag offline - engadget.com YouTube ändert die Zählweise für Views - theverge.com Google ersteigert die Daten von Spirit Airlines für 10 Mio. - news.bloomberglaw.com Apple ändert die Tracking-Abfrage nach dem Verfahren des Bundeskartellamts - reuters.com Julian Teicke kündigt attuned.world an - linkedin.com Klage gegen xAI: 7.000 Missbrauchsbilder aus einem Kinderfoto - washingtonpost.com Amazon zerschneidet seltene Bücher fürs KI-Training - techcrunch.com Meta vor Gericht wegen Suchtdesign und COPPA - engadget.com

    Crazy Wisdom
    Episode #568: AI Is Making Everything More Efficient. What Happens Next?

    Crazy Wisdom

    Play Episode Listen Later Aug 17, 2026 59:35


    Stewart Alsop sits down with Juan Verhook, founder of Tender Market, for a second conversation that ranges from the mechanics of European public tenders to the future of how we organize digital information. They cover how Tender Market helps smaller companies work around barriers like SOC 2 and ISO certification requirements, the surprising scale of public procurement (roughly 20% of GDP), and how AI and machine learning are reshaping the bidding process. From there the conversation opens up into bigger territory: the changing tolerance for being wrong in an AI-saturated information landscape, how language and culture shape perception, the reverse Turing test and the challenge of verifying human versus AI identity online, and Juan's daily workflow running eight or nine MCP servers through Claude Code. They close out talking about whether the folder and file system will survive the shift to AI-native interfaces, tying back to Stewart's own Stewart Squared episodes on the history of the PC. You can visit Tender Market at tendermarket.eu.Timestamps05:00 — Tender Market's origin story and how they help smaller companies work around SOC 2 and ISO certificate barriers.10:00 — Public procurement and its scale, roughly 20% of GDP, plus a look at public-private partnerships.15:00 — Local LLMs on a plane with no Wi-Fi, and comparing local model performance to frontier models.20:00 — Supply versus demand in AI infrastructure and whether hyperscaler token efficiency is quietly improving.25:00 — Whether AI will replace knowledge work tasks, and the shifting reality of what lawyers and other professionals actually do.30:00 — Reverse Turing test, digital identity verification, and the idea of a "pre-AI internet."35:00 — Model poisoning, RLHF, and the difference between pretraining and post-training.40:00 — Interleaved tool calling and how Tender Market ties pricing to task deliverables instead of billable hours.45:00 — RAG versus fine-tuning, prompt engineering, and when context windows actually matter.50:00 — Deterministic programming versus probabilistic agents, and when to build custom tools versus buy existing ones.55:00 — Juan's daily MCP stack (Supabase, GitHub, Calendly, CRM), and whether the folder-and-file system will survive the shift to AI-native interfaces.Key InsightsCertification requirements aren't dead ends—they're routing problems. When smaller companies got rejected from tenders for lacking SOC 2 or ISO certificates, Juan didn't turn them away. He found that EU procurement rules allow bidding as a consortium or subcontracting to a certified partner, turning a disqualifier into a workaround that builds trust with clients.Public procurement is a massive, underexamined market. Roughly 20% of GDP flows through public purchasing of private-sector goods and services, yet most people have no visibility into how tenders work or how governments post and award these contracts.Being wrong has become more socially acceptable. Juan traced this shift to the falling cost of information: in the Stack Overflow era, giving a wrong answer was costly, but now that answers are instant and abundant, both mistakes and corrections happen faster, changing how people learn and communicate.Task-based pricing beats hourly billing for AI-era services. Rather than charging per hour, Tender Market prices around the deliverable, winning a tender, which avoids the perverse incentive of hourly billing to be inefficient and instead rewards actually solving the client's problem.RAG and fine-tuning solve different problems. RAG helps a model reference large documents without hitting context limits, while fine-tuning changes a model's internal weights so it learns new behavior or style. Juan noted that true RAG use cases needing thousands of pages of context are rarer than the hype suggests.Deterministic code should replace repeated LLM calls once a pattern is found. Stewart described his own workflow: solve a task with an LLM a handful of times, then convert the repeated pattern into deterministic software so tokens are no longer spent on it, freeing the model for genuinely new problems.AI agents are never truly autonomous. Both hosts agreed that no matter how many steps an agent chains together, a human operator always initiates the first prompt, meaning accountability and intent trace back to a person even in multi-agent systems.

    The PowerShell Podcast
    What PowerShell taught TJ Turner About IT

    The PowerShell Podcast

    Play Episode Listen Later Aug 17, 2026 37:15


    Andrew Pla sits down with TJ Turner at Microsoft's TechMentor conference @ Microsoft HQ in Redmond, Washington, for a conversation about PowerShell, career growth, and the parts of working in IT that don't show up in the documentation. TJ traces his path from infrastructure through K-12, finance, and retail to his current role as a Cloud Evangelist at TD SYNNEX, along with his early days using PowerShell v2 and v3, competing in the Scripting Games, and helping start the Philadelphia PowerShell User Group. They also dig into real-world automation wins, including a PowerShell workflow that helped validate thousands of systems before a holiday weekend, plus burnout, community, asking for help, and what years of broken demos and IT mistakes can teach you about staying prepared and learning to adapt. Key Takeaways: · What got you here won't get you there. TJ's career moved from hands-on infrastructure into distribution, cloud, and technical evangelism, and none of those moves were necessarily part of the original plan. Staying open to new roles, skills, and opportunities has been a big part of that growth. · PowerShell changes how you think, not just how you work. TJ shares examples of using PowerShell to validate thousands of systems, automate VMware update workflows, and collect detailed system state information. Over time, that automation mindset became part of how he approaches problems, even as his career moved beyond day-to-day infrastructure work. · Community and communication are technical skills too. Whether it's recognizing burnout, asking for help, meeting someone at a conference, or admitting you don't know an answer during a presentation, the ability to connect with other people can have just as much impact on your career as knowing the technology. Guest Bio: TJ Turner is a Cloud Evangelist at TD SYNNEX, one of Microsoft's largest distributors in the CSP and partner channel. His background is in infrastructure, with experience spanning K-12, financial services, retail, and other enterprise environments. TJ got started with PowerShell during the v2 and v3 era, competed in the Scripting Games, and helped found the Philadelphia PowerShell User Group. Today, his work includes Azure, Microsoft 365, security, GitHub, DevOps, and helping partners grow their businesses. Resource Links: · TD SYNNEX Microsoft Partner Programs: https://www.tdsynnex.com/na/us/Microsoft/ · PDQ Connect PowerShell Scanner: https://www.pdq.com/powershell-scanner/ · PDQ PowerShell Scanner Blog Post: https://www.pdq.com/blog/the-powershell-scanner-has-arrived-in-pdq-connect/ · PDQ Community PowerShell Scanners Repository: https://github.com/pdqcom/PowerShell-Scanners · TJ Turner on LinkedIn: https://www.linkedin.com/search/results/people/?keywords=TJ+Turner+TD+SYNNEX The PowerShell Podcast on YouTube: https://youtu.be/ce9vxdkzDbo  

    Hacker Public Radio
    HPR4705: Free Software Is Wasted On You Teens

    Hacker Public Radio

    Play Episode Listen Later Aug 14, 2026


    This show has been flagged as Explicit by the host. Freedom 0–3 (verbatim reference) The four freedoms, GNU/FSF: https://www.gnu.org/philosophy/free-sw.html Richard Stallman: https://www.stallman.org/ Named FOSS figures (freedom 3 list) Linus Torvalds (Linux): https://en.wikipedia.org/wiki/Linus_Torvalds Dries Buytaert (Drupal): https://dri.es Guido van Rossum (Python): https://gvanrossum.github.io Ian Murdock (Debian): https://en.wikipedia.org/wiki/Ian_Murdock Brian Behlendorf (Apache): https://en.wikipedia.org/wiki/Brian_Behlendorf Miguel de Icaza (GNOME/Mono): https://en.wikipedia.org/wiki/Miguel_de_Icaza Infrastructure block (post beer 1) curl / Daniel Stenberg: https://curl.se and https://daniel.haxx.se xkcd 2347 (dependency comic): https://xkcd.com/2347/ xz backdoor, CVE-2024-3094: https://en.wikipedia.org/wiki/XZ_Utils_backdoor Andres Freund's original disclosure: https://www.openwall.com/lists/oss-security/2024/03/29/4 Licensing block (beer 2–3) GPL: https://www.gnu.org/licenses/gpl-3.0.html MIT License: https://opensource.org/license/mit FreeBSD: https://www.freebsd.org macOS/Darwin BSD lineage: https://en.wikipedia.org/wiki/Darwin_(operating_system) PlayStation using FreeBSD (Orbis OS): https://en.wikipedia.org/wiki/Orbis_OS Industry acquisitions (beer 4) Microsoft acquires GitHub, 2018, $7.5B: https://news.microsoft.com/2018/06/04/microsoft-to-acquire-github-for-7-5-billion/ FOSDEM field report (beer 4–5) FOSDEM: https://fosdem.org Ladybird browser / Andreas Kling: https://ladybird.org Godot Engine: https://godotengine.org Home Assistant: https://www.home-assistant.io Redis → Valkey fork: https://valkey.io Terraform → OpenTofu fork: https://opentofu.org Homework block (beer 5) Ollama: https://ollama.com Codeberg: https://codeberg.org LibreOffice: https://www.libreoffice.org Firefox: https://www.mozilla.org/firefox Provide feedback on this episode.

    Giant Robots Smashing Into Other Giant Robots
    618: 22 Years of Bootstrapping with Jesse Mecham

    Giant Robots Smashing Into Other Giant Robots

    Play Episode Listen Later Aug 13, 2026 56:38


    Will is joined this week by personal finance expert, speaker, business leader Jesse Mecham, founder of You Need A Budget (or YNAB if you are very busy and important). In this episode, to celebrate the release of his new book ‘Never Worry About Money Again', Jesse dives into how YNAB came to be, from spreadsheet to the interface it is today, the trials and tribulations the business went through over the years, before going into depth about why people are so scared of money. — Mentioned in the episode: Jesse's brand new book, 'Never Worry About Money Again' out now! Visit the YNAB website Jason Fried's ‘Getting Real' Richard A. Lanham's ‘Revising Prose' Eugene Schwartz's ‘Breakthrough Advertising' Donald A. Norman's ‘The Design of Everyday Things' Clayton Christiansen's ‘Jobs to be Done' Framework Our guest for this episode has been Jesse Mecham. If you'd like to get in touch with Jesse, or to keep up to date with his work, you can visit his website. Your host for this episode has been Will Larry, you can find and connect with Will over on LinkedIn. If you would like to support the show, head over to our GitHub page, or check out our website. Got a question or comment about the show? Why not write to our hosts: hosts@giantrobots.fm This has been a thoughtbot podcast. Stay up to date by following us on social media - LinkedIn - Mastodon - YouTube - Bluesky © 2026 Giant Robots Smashing Into Other Giant Robots Podcast

    Bitcoin Takeover Podcast
    S17 E37: Paul Sztorc on the eCash Three Stage Launch, Free Coins & 12 Drivechains

    Bitcoin Takeover Podcast

    Play Episode Listen Later Aug 13, 2026 28:28


    n August 2026, eCash (ECX) comes out in its alpha phase: leading up to a final complete rollout on October 31st 2026, Bitcoin's 18th birthday. To better explain how this process will take place and why every bitcoiner should try BIP300 this Halloween, Paul Sztorc joins the show for a record-breaking 11th time! Time stamps: 00:01:17 – Welcome: Paul Sztorc for the 11th time, a new record 00:01:42 – Four months since the hard fork announcement 00:02:00 – The three phase rollout: alpha, beta, October 31st mainnet 00:02:25 – Why the launch was delayed: summer, Coldcard hack, BIP 110 00:03:04 – Practice runs: 1,000 test coins convert to 10 real eCash 00:03:55 – Alpha & beta as successors to the drivechain testnet 00:04:25 – How to claim: your Bitcoin private key & splitting transactions 00:04:42 – The fast facts GitHub repo & replay protection 00:05:07 – Why most people should not type in their main keys 00:05:27 – Mining or buying: the other ways to get eCash 00:06:04 – Mining the alpha with SHA-256D hardware 00:06:35 – The 1000:10 conversion threshold explained 00:06:51 – Why old hardware (S9s, Bitaxes) can be profitable again 00:07:17 – The launch difficulty debate: from "difficulty 1" to real data 00:08:14 – Alpha & beta as a glimpse of future price and hash rate 00:09:34 – The other fork's struggles vs planning ahead 00:10:03 – Call to action: withdraw from exchanges, accumulate BTC 00:10:24 – The network only recognizes one owner of the coin 00:10:46 – Self custody advice in a tough summer 00:11:24 – eCash vs BIP 110: honest hard fork vs 100% hash rate claims 00:12:13 – Name picking, PoW changes & the train wreck 00:13:00 – From 5 to 7 to 12 drivechains 00:13:30 – The giveaway announcement & the sponsors 00:16:07 – Thunder: scaling to 8 billion people 00:16:32 – zSide: Zcash Orchard privacy on a drivechain 00:16:48 – BitNames, BitAssets, prediction markets, CoinShift 00:17:17 – Two EVM flavors, an OP_CAT chain & a post-EVM science project 00:18:12 – Elements Plus: Blockstream's own tech, completed by the community 00:19:26 – "How many Lightning implementations at launch?" "Hopefully zero" 00:20:11 – Lightning is a dead project, the evidence is overwhelming 00:20:45 – The giveaway: Paul picks 10, the chat said 77 00:21:17 – Recap: three stages, more drivechains, October 31st 00:22:03 – Try the tech: maximizing what Bitcoin can do 00:22:53 – Rohit wins the prize & the shortest Sztorc interview ever 00:23:59 – The autumn of forks: BIP 110 delays, eCash extends to Halloween 00:24:23 – Bitcoin's 18th birthday on the metzdowd mailing list 00:24:49 – Why drivechains: all fees go to proof of work miners 00:25:38 – Hoping a Bitcoin competitor pushes Bitcoin forward 00:28:02 – Twelve drivechains you can test today

    alphalist.CTO Podcast - For CTOs and Technical Leaders
    #144 Writing Code Is No Longer the Job: Dana Lawson on Trusting AI Agents Like Self-Driving Cars // CTO @ Netlify

    alphalist.CTO Podcast - For CTOs and Technical Leaders

    Play Episode Listen Later Aug 13, 2026 59:46 Transcription Available


    Sponsored by Blocks: Save at least 20% on your AWS costs with AI-powered optimization and enterprise discounts. Get your free Cloud Check at https://blocks.cloud/alphalist?utm_source=alphalist&utm_medium=podcast&utm_campaign=blocks-podcast-2026 Dana Lawson's path into tech started with backup tapes, not a keyboard-in-the-womb origin story. She joined the US Army in the late '90s, automated her way out of manual password resets, and went on to become VP of Product Engineering at GitHub before taking the CTO seat at Netlify. She joins Tobi to make the case that "writing code is no longer the job", an argument from her own New Stack article that lit up Hacker News, and one she doesn't back away from here. The conversation explores why trust in AI agents may eventually become automatic, the same way our trust in cars we can't repair ourselves already has. Dana explains why Netlify is designing for "agent experience" alongside developer experience, and why the engineer's role is shifting from writing every line of code to defining architecture, guardrails, reliability, and safe user experiences. CTOs will walk away with a sharper way to think about where human judgment still matters versus where it's already been commoditized, including the tension between speed and control, whether developers risk becoming the bottleneck, and why the real constraint may be moving from "can we build it?" to "does anyone actually want it?" What's covered: - Dana's path from the US Army to VP of Engineering at GitHub to CTO of Netlify - Why she argues "writing code is no longer the job" and the Hacker News backlash - The self-driving car analogy for trusting AI agents - What "agent experience" means and why Netlify designed for it - Craftsmanship, control, and the shift from writing code to defining guardrails - Whether developers risk becoming the bottleneck in the agentic era - Why the constraint is moving from "can we build it" to "does anyone want it"

    Risky Business
    Risky Business #848 -- OpenAI comes clean

    Risky Business

    Play Episode Listen Later Aug 12, 2026 59:47


    On this week's show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week's news, including: The AI-agent-hacks-stuff saga continues. This week we have one booting gymgoers from full classes to nab its owner a spot Somehow OpenAI's legal team allowed the company to spill all the Hugging Face tea at BlackHat and it's hot and delicious More details emerge about Iran's hacking campaign against US water utilities, but Brad is unimpressed It turns out TeamPCP has been around longer than we thought and predates the AI era Some absolute plonker kept the DEFCON party going on a Delta flight home. No word yet on if they made the plane fly sideways Much, much more This week's show is brought to you by cloud security platform Prowler. Founder and CEO Toni de la Fuente chats about what the company is doing with AI and some of the cool ways customers are using it with Prowler. This episode is also available on YouTube Show notes How a simple request for AI to book a gym class exposed a major threat | Social Signals OK, Well, There Are Even More AI Agent Hacking Incidents | wired.com OpenAI BlackHat talk re Hugging Face incident | OpenAI says Daybreak will expand to offer specialized cyber services | CyberScoop Cyberattacks targeting water systems expand to 12 states as South Dakota, Georgia announce incidents | therecord.media Cyberattack on North Carolina Ports ‘contained' as Coast Guard, state officials investigate | therecord.media Local governments in four states dealing with cyberattacks that have shut down services | The Record Follow-Up Report of the December 2025 Energy Sector Incident | CERT Polska Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says | The Record State Department says Trump raised cyber scam compound issue with Xi | therecord.media Open-source software's archenemy TeamPCP goes back further than anyone thought | CyberScoop A Security Pro Hacked North Korean Hackers. He Found They'd Breached Hundreds of Networks Worldwide | wired.com Srsly Risky Biz: Being a North Korean Hacker Is About to Be Less Fun - Risky Business Media | Chrome adopts what may be the best protection yet against account takeovers | Ars Technica CSS:the bomb inside your inbox | PortSwigger Research Security update available for Metabase - Please upgrade now | Social Signals Canadian man pleads guilty to Snowflake hacks that led to 165 breaches | therecord.media British ‘Com' member who abused more than 100 girls worldwide jailed for two years | therecord.media FBI says cybercriminals are hacking into victims' online accounts to steal their intimate pictures | TechCrunch Security AI is getting better at election facts, but voters shouldn't rely on it | CyberScoop The FTC wants to regulate AI for ideological bias | cyberscoop.com US and South Korea warn of Gunra ransomware targeting govt agencies | BleepingComputer CISA: Microsoft SharePoint flaw now exploited in ransomware attacks | BleepingComputer CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs | BleepingComputer N-able N-central exploitation results in RMM tool deployment | Sophos Delta investigating after someone set up fake Wi-Fi network mid-flight | TechCrunch Security mcp-dashboard-demo/prompt/prowler_dashboard_prompt.md at main · prowler-cloud/mcp-dashboard-demo | GitHub

    The Hidden Curriculum
    E55 - What is Git, Github, and should I use it? With Andrea Moro

    The Hidden Curriculum

    Play Episode Listen Later Aug 12, 2026 52:00


    In this episode we talk with Andrea Moro about Git, GitHub, and version control for researchers. Andrea is an Associate Professor of Economics at Vanderbilt University, where he specializes in labor and political economy. He also serves as Data Editor at the Review of Economic Studies. His research combines theoretical and empirical methods, with current work on jury selection and minority representation. Outside of research, Andrea creates literary concordances for Dante's Divine Comedy and James Joyce's Ulysses.Sebastian Tello-Trillo is an Associate Professor of Public Policy and Economics at the Frank Batten School of Leadership and Public Policy at the University of Virginia. Alex Hollingsworth is an Associate Professor of Economics at the Ohio State University. Henry Morris is our main editor. He is a student at the University of Virginia studying computer science and mathematics.In this episode we discussed:What Git and GitHub are and why they matter for researchersThe difference between version control and file storage (GitHub vs. Dropbox)How to create repositories, commit changes, and manage branchesResolving conflicts when collaborating on shared projectsGitHub's integration with Overleaf for academic writingAndrea's work on jury selection and minority representation

    World of DaaS
    CodeRabbit CEO Harjot Gill on software's new bottleneck and zero to $50m ARR in 2 years

    World of DaaS

    Play Episode Listen Later Aug 11, 2026 55:22 Transcription Available


    Harjot Gill is the co-founder and CEO of CodeRabbit, the AI code review company that became the most installed AI app on GitHub and GitLab. Over about two years, CodeRabbit went from zero to over $50M in ARR and a $1B+ valuation. It is his third startup.In this episode of Summation, Harjot and Auren discuss:Why the bottleneck in software just moved from writing code to reviewing itWhy mature companies now adopt AI firstWhy you should never let a coding agent review its own workThe playbook that took CodeRabbit from zero to $50M+ in two yearsYou can find Auren Hoffman on X at @auren and Harjot Gill on X at @harjotsgill

    Side Project Spotlight
    #117: Assumption One: You're a Hoarder

    Side Project Spotlight

    Play Episode Listen Later Aug 11, 2026 50:53


    The desktop has barely changed in decades, even as we've all become digital hoarders. Scott Jenson's Local-First Conf talk, “How the Desktop UX Needs to Evolve to Keep Up With Local First,” gives The Trio a jumping-off point to explore spatial window management, document context, customizable dashboards, private workflows, and the surprising return of widgets. Kotaro then catches the game development bug and weighs rebuilding Retro Sparkle against the much more ambitious idea of a mobile-first pixel fighting game.## Chapters00:00 Introductions 01:15 Local-First Computing and the Future of Desktop UX 11:16 Widgets, Dashboards, and Personal Workflows 21:58 The Future of Software and AI Automation 38:35 Building Games in the AI Era 50:04 Closing and Community Updates 50:48 Tag ## Show Notes- The discussion begins with Scott Jenson's Local-First Conf talk, shared by Mike Zornek, a former PhillyCocoa organizer and one of its OGs who now works in Elixir.- Overlapping windows made sense on tiny early displays, but modern screens and growing piles of context expose the metaphor's limits.- Scott's prototypes rethink window management, attach research context to documents, and turn desktop history into a navigable timeline.- Brett Terpstra's TerminalWidget lets scripts power personal dashboards for network health, revenue, GitHub activity, and almost anything else.- Apple's old Dashboard sparks nostalgia for web-built widgets, glorious skeuomorphism, and the GPU-powered ripple effect.- Kotaro and Steve imagine desktops that help people assemble private, local workflows without needing to become programmers.- Steve argues that safer abstractions, plug-ins, and focused local models make more sense than asking everyone to generate raw application code.- Kotaro wonders whether the app era is giving way to workflows that connect software, data, and automation at a higher level.- Kotaro weighs rebuilding [RetroSparkle](https://tomatoboy.co/retro) with a pixel-inspired look against making a mobile-first fighting game in Godot.- PhillyCocoa meets in person Thursday, August 13, from 5:45 to 8:00 PM at Vanguard, 2300 Chestnut Street, with talks by Bill Atkins, Kotaro Fujita, and Chris Hiester.## Links**Desktop UX and Local First**How the Desktop UX Needs to Evolve to Keep Up With Local First: https://www.youtube.com/watch?v=-IOLRcFC6OY | Mike Zornek: https://mikezornek.com**Widgets and Personal Workflows**Brett Terpstra's TerminalWidget Dashboard: https://brettterpstra.com/2026/08/10/my-terminalwidget-dashboard/**Kotaro's Project Ideas**Retro Sparkle: https://tomatoboy.co/retro**PhillyCocoa IRL Meetup**Beyond the Simulator: Perspectives on Modern App Development: https://luma.com/mwcqd1cl**PhillyCocoa:** https://phillycocoa.orgIntro music: "When I Hit the Floor", © 2021 Lorne Behrman. Used with permission of the artist.

    Syntax - Tasty Web Development Treats
    1028: Cloudflare Wallets

    Syntax - Tasty Web Development Treats

    Play Episode Listen Later Aug 10, 2026 78:57


    Cloudflare is rolling out crypto wallets with claimable handles as identity, and a real React compiler finally landed for regular hooks-based code. Plus: OpenAI's pricing war, Vue Vapor benchmarks, GitHub's new npm malware scanning, and an active supply chain attack hitting 868 packages. Show Notes 00:00 Welcome to Syntax! 01:02 Shai Hulud is back! New Shai-Hulud announcement Attacked keyv packages 05:27 GitHub scans your npm packages for malware 06:42 Your agent has a wallet now Make your own Cloudflare wallet announcement blog post X402 payments 12:10 Yet another React compiler? Ripple.ts Inferno.js Dominic Gannaway's launch post Octane Native Script Reactivity + Rendering Benchmark 27:19 Scott switched his browser AGAIN! Dia Knock off extension 31:56 AI Mental health survey 32:29 OpenAI models are becoming cheaper? 38:49 GitHub stacked PRs finally arrived 41:48 AI video podcasts HeyGen launch post Hank Green's unhealthy AI usage 48:15 Brought to you by Sentry! 49:28 News from the TC39 meeting ECMAScript news Await dictionary TC39 Process 56:58 Qwen 3.8 01:02:31 Latest and greatest in CSS and UI libraries Foley.dev Morphicons Lucide Nucleo 8bit library CSS radar Impeccable Hit us up on Socials! Syntax: X Instagram Tiktok LinkedIn Threads Wes: X Instagram Tiktok LinkedIn Threads Scott: X Instagram Tiktok LinkedIn Threads Randy: X Instagram YouTube Threads

    Merge Conflict
    527: AI Agents Meet Mobile: GitHub Copilot Canvas Revolution

    Merge Conflict

    Play Episode Listen Later Aug 10, 2026 50:01


    AI agents are revolutionizing mobile development! James and Frank explore GitHub's new Mobile Canvas extension that lets AI agents see and interact with iOS and Android apps in real-time, no matter what framework you're using. They discuss how this tool finally closes the feedback loop for native developers and break down the emerging plugin standard reshaping AI-assisted coding. Link: https://github.com/Redth/mobile-canvas-ghcp Follow Us Frank: Twitter, Blog, GitHub James: Twitter, Blog, GitHub Merge Conflict: Twitter, Facebook, Website, Chat on Discord Music : Amethyst Seer - Citrine by Adventureface ⭐⭐ Review Us ⭐⭐ Machine transcription available on http://mergeconflict.fm

    The PowerShell Podcast
    PSFramework: The Tools for Your Tools with Fred Weinmann

    The PowerShell Podcast

    Play Episode Listen Later Aug 10, 2026 34:54


    Fred Weinmann is back, and this time he's walking us through the PowerShell Framework Collective – his personal answer to the age-old problem of building the tools that build the tools. The core idea is simple but powerful: if you invest in the scaffolding around your code, the actual code you write gets faster, cleaner, and more consistent every time. Fred breaks down four key wins from his framework stack, including PSModuleDevelopment for templating new projects, PSUtil for leveling up your console experience, PSReadLine for predictive history, and PSFramework itself for things like logging, configuration, parameter handling, and protected command execution. If you've ever spent more time wiring up logging and retry logic than solving the actual problem, this episode is going to feel very familiar – and very useful. Key Takeaways: PSModuleDevelopment makes spinning up a new, fully scaffolded PowerShell module a one-liner – complete with tests, GitHub release pipelines, and PowerShell Gallery publishing – so you can focus entirely on the actual functions you need to write. PSFramework handles the infrastructure layer of your code (logging, configuration, tab completion, parameter validation, retry logic) so you stop reinventing the wheel and your projects stay consistent across years and teammates. The real payoff of a shared framework is long-term maintainability: Fred opened a module he hadn't touched in six years and had a bug fixed and released in five minutes because everything was exactly where he expected it to be. Guest Bio: Friedrich "Fred" Weinmann is a Cloud Solution Architect at Microsoft and one of the most recognized PowerShell community contributors working today. He is the creator of PSFramework, which underpins many other modules in the ecosystem, as well as tools like PSModuleDevelopment, PSUtil, and the Active Directory Management Framework. Fred is a frequent conference speaker, a longtime community collaborator, and someone Andrew credits with helping shape his own PowerShell journey. Resource Links: PSFramework Project Home: https://psframework.org/ PSFramework on GitHub: https://github.com/PowershellFrameworkCollective/psframework PSModuleDevelopment on GitHub: https://github.com/PowershellFrameworkCollective/PSModuleDevelopment PSUtil on GitHub: https://github.com/PowershellFrameworkCollective/PSUtil PowerShell Framework Collective on GitHub: https://github.com/PowershellFrameworkCollective/ PDQ Discord – PowerShell Scripting Channel: https://discord.gg/pdq The PowerShell Podcast on YouTube:https://youtu.be/sZQdgBZM75Y

    tools microsoft github powershell weinmann cloud solution architect
    Azure DevOps Podcast
    Jimmy Bogard: AI-Driven Development - Episode 414

    Azure DevOps Podcast

    Play Episode Listen Later Aug 10, 2026 42:06


    https://clearmeasure.com/developers/forums/ Today's guest is a true heavyweight in the .NET open-source world — someone whose work has quietly, but profoundly, shaped the way countless developers build software. Jimmy Bogard is the creator and maintainer of two very popular OSS libraries in the .NET ecosystem: AutoMapper and MediatR. If you've ever tried to simplify object mapping or decouple application logic, chances are you've used his tools. Based in Austin, Texas, Jimmy is an independent software consultant and a 15+ year recipient of the Microsoft Most Valuable Professional award — every year since 2009. AutoMapper alone has been around for 17 years and racked up hundreds of millions of downloads. It started as a personal tool to streamline development for client projects and grew into a global standard for object mapping. Github eShop - https://github.com/jbogard/eShop Jimmy's Github - https://github.com/jbogard AutoMapper Github - https://github.com/AutoMapper/AutoMapper/releases AutoMapper Nuget - https://www.nuget.org/packages/automapper/ MediatR Nuget - https://www.nuget.org/packages/MediatR MediatR Github - https://github.com/jbogard/MediatR/releases Jimmy's Website - https://www.jimmybogard.com/ Jimmy's Website / AutoMapper - https://www.jimmybogard.com/automapper-and-mediatr-licensing-update/ Previous Appearances on the Azure & DevOps Podcast: Episode 356  Episode 264 Episode 98 Episode 11 Want to Learn More?  Visit AzureDevOps.Show for show notes and additional episodes.

    texas development driven github oss microsoft most valuable professional jimmy bogard
    The 8 Bit Files
    037 - Commodore & MiSTer Updates, and John's Japan Experience

    The 8 Bit Files

    Play Episode Listen Later Aug 10, 2026 74:24


    In this episode, Dave leads off on the revived Commodore: the C64C Ultimate and the story of the original 1986 injection molds, and the brand-new "Made For U(ltimate)" software initiative. The block closes on the Callback flip phone, its wildly unstable pricing, and Dave's argument that nobody agrees on what a "dumb phone" actually means. John brings a MiSTer update — DreamSTer, running Dreamcast on a DE10-Nano by putting the PowerVR2 on the FPGA and everything else on the ARM cores, plus MiSTer Monitor, an ESP32 companion display for artwork and system stats. John also unpacks his recent travel experiences to Japan, including Nintendo, Super Potato and other fun places he visited. Dave signs off with the 486 he rescued from his parents' house, and a plea for a keyboard with a five-pin DIN connector.Topics discussed in this episodeCommodore announces the C64C Ultimate using the rediscovered original 1986 injection moldshttps://commodore.net/c-you-soon-commodore-64-ultimate-line-up-expands-with-c64c-edition-later-this-year/Time Extension: the revived Commodore's next FPGA recreation, complete with the original 1986 imperfectionshttps://www.timeextension.com/news/2026/04/the-revived-commodore-just-announced-its-next-fpga-recreation-complete-with-the-original-1986-imperfectionsTime Extension: Commodore celebrates its first birthday with the "Made For U(ltimate)" game initiativehttps://www.timeextension.com/news/2026/08/what-a-year-its-been-commodore-celebrates-its-birthday-with-a-new-game-initiative-for-the-c64-ultimateCommodore gets transparent on the Callback flip phone pricinghttps://commodore.net/commodore-gets-transparent-on-callback-flip-phone/Tom's Hardware: Callback drops to $399 by defaulting to recycled memory chipshttps://www.tomshardware.com/phones/commodore-drops-callback-flip-ohine-to-399-by-defaulting-to-recycled-memory-chipsTime Extension: the "impossible" Dreamcast core comes to MiSTer, but it's very early dayshttps://www.timeextension.com/news/2026/07/the-impossible-dreamcast-core-comes-to-mister-but-its-very-early-daysDreamSTer on GitHub — skmp's Dreamcast project for the DE10-Nanohttps://github.com/skmp/DreamSTerMiSTer Monitor — ESP32 companion display for artwork, system stats and RetroAchievementshttps://github.com/chipster6502/MiSTer_monitorSuper Potato, Akihabarahttps://www.superpotato.com/

    That Real Blind Tech Show
    Episode 211 - Bad app Store connect, Bad app Store connect

    That Real Blind Tech Show

    Play Episode Listen Later Aug 9, 2026 106:20


    It's an all new That Real Blind Tech show with the old school gang of Allison, Brian, Ed, and Jeanine.   Since most of you come to That Real Blind Tech Show for your scientific news, we kick the show off discussing the most interesting and strangest theory on how life on this place called Earth began.   Boy the Japanese sure can innovate as they are now selling human refrigerators because it is so damn hot everywhere.   If there's an app for it, then it must mean the paranoia is real, introducing the Anti-Zuck Bluetooth sniffer app. Some how the old Sham wow infomercial comes up, and if you are like us and wondering what ever happened to the Sham wow Guy watch this YouTube clip about him.   Do we now need a Tick Tock for Dummies, or is that just called Tick Tock? Tick Tock videos are advising people to put their phones in the fridge when they heat up.   Would you take $50 bucks to let an A.I. start up read your mind to train their A.I.?   Jeanine then gives us her recap of this year's ACB Conference.   Then A special quick version of the Blind Feud pops in, asking what is Arizona State the first University in the country to now be offering a major in?   It's then on to Clauding where Brian gets some feedback on his new favorite jingle on the show, and then discusses his experiences with the submission of the That Real Blind Tech show app and App Store Connect. It has not been a good experience.   Allison then discusses the excitement behind launching her first project in to GitHub the Accessible Virtual Machine. She discusses the work behind it, the feedback, and the feeling of empowerment upon launching it all. Sorry for no link to the project as the link Allison provided us did not work, so reach out to her if you want to get it.   Brian then discusses rebuilding his personal website from the ground up. His website had not been updated in 12 years, and he previously had to pay people to update his website for him, you can check out the new site here.   Jeanine then lets us know what she has been up to with Clauding.   And even though Brian claimed he was not going to build until he got past the App Store Connect nightmarish process, he lied to you and himself, as he introduces the latest project he is working on, and of course, he built a little jingle for it as well.   OpenAI announced they will be coming out with a ChatGPT speaker. Which then leads us to discussing what Smart Speakers we are still using.   And it's more of What's Pissing Off Brian Now and Watcha Streaming, Watcha Reading.    

    The Cybersecurity Defenders Podcast
    Intel Chat: Shai-Hulud is back, model pinning & the token spend problem [343]

    The Cybersecurity Defenders Podcast

    Play Episode Listen Later Aug 8, 2026 35:41


    Intel Chat with Matt Bromiley and Chris Luft — recorded in person at Black Hat USA in Las Vegas, day two.No prep doc, no script: just what Matt and Chris were actually hearing on the floor.• Shai-Hulud is back. The self-replicating npm worm returned on August 4, trojanizing the keyv / cacheable family and spreading to 400+ packages within hours. Chris reads through Datadog Security Labs' analysis of the Shai-Hulud 2.0 wave: 796 packages and 1,092 versions, 20M+ weekly downloads, credential harvesting with TruffleHog, GitHub repositories used for both exfiltration and command and control, and a worm that reads its own code to propagate without a C2 server.• The LLM that downloaded the malicious package by itself. A researcher asked a frontier model about a compromised package, and the model decided the best way to help was to go fetch a copy — tripping the SOC's alert and bypassing the company's centralized package clearing house on the way.• Non-human identity as the new perimeter. Every agent you introduce is another identity: who created it, what can it reach, how long should it live?• "Computer says no." Matt's colleague hit a refusal from Opus 5, and the session automatically downgraded to 4.8 and completed the task. Which raises the real question of the episode: do security teams now need model pinning, the way we once needed certificate pinning? And if defenders pin to older models to keep working while adversaries use the newest ones, have we rebuilt the same gap all over again?• AI governance and change control — which models are approved for which tasks, and what happens when a vendor ships a new version or deprecates an old one.• Token spend as a CISO budget line item. Enterprises buying tokens at a scale their vendors can't match and pulling those vendors onto their plan, token burn as an insider-threat vector, and why $100,000 of tokens is not $100,000 of productivity.• Defender takeaways: pin your npm packages, get security off its island and talk to your developers, build approved paths before detections, least privilege and key rotation, and network-gated pushes as a deliberate chokepoint.Stories covered:• https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain• https://research.jfrog.com/post/shai-hulud-is-back-august/• https://securitylabs.datadoghq.com/articles/shai-hulud-2.0-npm-worm/• https://securitylabs.datadoghq.com/articles/npm-worm-compromises-popular-npm-packages/• https://unit42.paloaltonetworks.com/npm-supply-chain-attack/Chapters:0:00 Live from Black Hat, in person for once0:48 How Black Hat has changed4:31 No prep — let's talk about what's actually happening here4:57 Shai-Hulud is back: supply chain compromise6:23 The LLM that downloaded the malicious package7:19 Inside Shai-Hulud 2.010:34 When attackers and defenders use the same tools11:39 Non-human identity is the new perimeter12:13 Opus 5 said no, so the session downgraded itself15:23 Do security teams need model pinning?18:20 Three companies, very nebulous rules18:35 AI governance: which model for which task21:19 Token spend hits the security budget22:58 Is token spend a productivity metric?25:46 Pin your packages26:25 Get security off the island29:17 Least privilege, key rotation, chokepoints32:55 Why it's called Shai-Hulud33:25 Wrapping up at Black HatThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #AIsecurity #supplychainsecurity

    The CyberWire
    AI without adult supervision.

    The CyberWire

    Play Episode Listen Later Aug 6, 2026 25:37


    Meta's AI models join the sandbox escape club. China's telecom footprint in the U.S. may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduce new GitHub risks. ENISA expands its CVE role. A critical Paperclip flaw enables code execution. Crypto wallet fears fuel phishing attacks. Researchers uncover a backdoor in Chinese-made routers. The Snowflake hacker pleads guilty. Our guest is Dustin Childs, Head of Threat Awareness of TrendAI's Zero Day Initiative, discussing the new Patch Tuesday era. AI takes your word for it.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Dustin Childs, Head of Threat Awareness of TrendAI's Zero Day Initiative, discussing the new Patch Tuesday era. Be sure to check Dustin out on the AI Security Briefing podcast. Selected Reading Meta AI Hacked External Systems During Cybersecurity Testing (SecurityWeek) Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says (The Record) Secret White House AI Safety Framework Draws Criticism (BankInfo Security) Few Federal Agencies Trust Their Own AI Agent Security (BankInfo Security) Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows (Hackread) ENISA scales up its role in the CVE Program (enisa) Critical Paperclip Flaw Allowed Admin Access, Code Execution (SecurityWeek) COLDCARD security audit phishing attack installs remote access tool (Bleeping Computer) Chinese-made Zbtlink routers have backdoor, researchers say (Reuters) Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions (US Department of Justice) “I'm Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails (Hackread) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

    Giant Robots Smashing Into Other Giant Robots
    617: Lexxy, Basecamp, and the Joy of Building with Jorge Marubia

    Giant Robots Smashing Into Other Giant Robots

    Play Episode Listen Later Aug 6, 2026 52:23


    Will is back in the host seat this week to chat to Jorge Marubia, Principal Programmer at 37signals, about his previous experience using Lexxy and Basecamp. In this episode, Jorge goes into depth about BaseCamp 5, how his team got through a memory leaking situation after its launch, and Lexxy being open source, before diving into the question on everyone's lips recently - what his thoughts are on AI and how it will affect Junior Developers. — Our guest for this episode has been Jorge Marubia. If you'd like to get in touch with Jorge, or to keep up to date with his work, you can find him via LinkedIn - X - or through his website. Your host for this episode has been Will Larry, you can find and connect with Will over on LinkedIn. If you would like to support the show, head over to our GitHub page, or check out our website. Got a question or comment about the show? Why not write to our hosts: hosts@giantrobots.fm This has been a thoughtbot podcast. Stay up to date by following us on social media - LinkedIn - Mastodon - YouTube - Bluesky © 2026 Giant Robots Smashing Into Other Giant Robots Podcast

    Critical Thinking - Bug Bounty Podcast
    Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?

    Critical Thinking - Bug Bounty Podcast

    Play Episode Listen Later Aug 6, 2026 58:04


    Episode 186: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some Recent Bug Bounty trends and pricing changes, wp2Shell exploits, Sol 5.6, and prompting via the Gauntlet loop.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out Zero Trust Network Access:https://www.criticalthinkingpodcast.io/tl-ztna====== Resources ======Trend of Bug Bounty Programshttps://x.com/iangcarroll/status/2082535987633410540Next chapter: Restructuring GitHub's bug bounty programhttps://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHubhttps://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854Gauntlet Loophttps://x.com/mattshumer_/status/2081830214384886228KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/====== Timestamps ======(00:00:00) Introduction(00:05:40) Bug Bounty Program Trends & Pricing Changes(00:15:52) Wiz Research uncovers RCE in GitHub & Sol 5.6(00:29:06) AI Harnessing, prompting, and the Gauntlet Loop(00:36:58) LHE vs Hackbot(00:43:21) KindaRails2Shell & WP2Shell

    Merge Conflict
    526: GitHub Stacked PRs: Managing Complex Code Changes

    Merge Conflict

    Play Episode Listen Later Aug 3, 2026 43:29


    In this episode, James and Frank dive deep into GitHub's biggest release in years: Stacked Pull Requests. Learn how this long-awaited feature finally solves the challenge of managing massive, complex code changes by breaking them into smaller, independently reviewable chunks while maintaining dependencies—plus discover how Merge Queues work alongside this innovation to streamline workflows in high-velocity projects. Follow Us Frank: Twitter, Blog, GitHub James: Twitter, Blog, GitHub Merge Conflict: Twitter, Facebook, Website, Chat on Discord Music : Amethyst Seer - Citrine by Adventureface ⭐⭐ Review Us ⭐⭐ Machine transcription available on http://mergeconflict.fm

    Talk Python To Me - Python conversations for passionate developers
    #557: Security of everything at PyCon 2026

    Talk Python To Me - Python conversations for passionate developers

    Play Episode Listen Later Aug 2, 2026 68:00 Transcription Available


    Security has always been the vegetables of software. Everyone agrees it matters, and somehow it never quite makes it onto the plate. At PyCon US this year, that changed. For the first time ever, security got its own dedicated, day-long track, one of just two at the whole conference, sitting right next to AI. And the room was packed to the back wall. On this episode, I'm joined by the three people at the center of it. Seth Larson, Security Developer in Residence at the Python Software Foundation and, very recently, a CPython core developer. Juanita Gomez, a PhD researcher at UC Santa Cruz in open source security, who co-chaired the track. And Mike Fiedler, PyPI's Safety and Security Engineer, one of the very few people paid full-time to keep the packages you install safe. We use the arc of the track's talks to take the temperature of Python security right now: supply chain attacks, dependency cooldowns, zero trust, SBOMs, and the push to bring Rust into CPython. And why not one of us thinks security is anywhere close to solved. Turns out that's the good news. It's why the room was full. Episode sponsors Sentry Error Monitoring, Code talkpython26 Talk Python Courses Links from the show Guests Juanita Gomez: linkedin.com Mike Fiedler: miketheman.dev Seth Michael Larson: sethmlarson.dev Trailblazing Python Security: us.pycon.org Everything Security at PyCon US 2026 (PSF blog): pyfound.blogspot.com Dependency Cooldowns: cooldowns.dev Anatomy of a Phishing Campaign (Mike Fiedler) Recording: www.youtube.com FedRAMP: www.gsa.gov Zero Trust in 200ms: Implementing Identity-Per-Transaction with Python & Serverless-Tristan McKinnon: www.youtube.com Rust for CPython project: blog.python.org pre-PEP: discuss.python.org Rust for CPython: Making Python Safer and More Robust for Everyone - Emma Smith: www.youtube.com SBOMit: github.com Asleep at the Wheel: Getting your SBOMs to pay attention... - Sanchit Sahay, Abhishek Reddypalle: www.youtube.com Volatility: volatilityfoundation.org Post Incident Runtime SBOM Generation from Python Memory - Hala Ali: www.youtube.com zizmor: docs.zizmor.sh GitHub Actions security in Python packages (Andrew Nesbitt write-up): nesbitt.io andrew/pycon: data & analysis for the GitHub Actions security talk: github.com GitHub Actions Security in Python Packages - Andrew Nesbitt: www.youtube.com gh-profiler: examine a GitHub user's profile to gauge their contributions: github.com PyCon US YouTube channel: www.youtube.com SBOMit: adding verification to SBOMs (OpenSSF): openssf.org Ecosystems: ecosyste.ms Watch this episode on YouTube: youtube.com Episode #557 deep-dive: talkpython.fm/557 Episode transcripts: talkpython.fm Theme Song: Developer Rap