open-source Git repository host
POPULARITY
Categories
In the security news this week: UK government rolls out passkeys to 20 million users Phishing-resistant authentication and replay resistance Passkey adoption, device security, and user acceptance EU Cyber Resilience Act guidance, scope, and compliance CRA vulnerability disclosure and reporting requirements The real cost of cyberattacks and cybersecurity spending Cyber insurance and improving organizational security Nightmare Eclipse and the release of Windows zero-days Check Point VPN vulnerabilities and perimeter security GitLab security updates and shadow IT Discovering unmanaged GitLab instances Cyberattacks against oil tankers and insider threats VPN patching and implied rules Zero-downtime GitLab updates and version management Running Windows ARM on Apple Silicon with VMware and Parallels Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-944
In the security news this week: UK government rolls out passkeys to 20 million users Phishing-resistant authentication and replay resistance Passkey adoption, device security, and user acceptance EU Cyber Resilience Act guidance, scope, and compliance CRA vulnerability disclosure and reporting requirements The real cost of cyberattacks and cybersecurity spending Cyber insurance and improving organizational security Nightmare Eclipse and the release of Windows zero-days Check Point VPN vulnerabilities and perimeter security GitLab security updates and shadow IT Discovering unmanaged GitLab instances Cyberattacks against oil tankers and insider threats VPN patching and implied rules Zero-downtime GitLab updates and version management Running Windows ARM on Apple Silicon with VMware and Parallels Show Notes: https://securityweekly.com/psw-944
In the security news this week: UK government rolls out passkeys to 20 million users Phishing-resistant authentication and replay resistance Passkey adoption, device security, and user acceptance EU Cyber Resilience Act guidance, scope, and compliance CRA vulnerability disclosure and reporting requirements The real cost of cyberattacks and cybersecurity spending Cyber insurance and improving organizational security Nightmare Eclipse and the release of Windows zero-days Check Point VPN vulnerabilities and perimeter security GitLab security updates and shadow IT Discovering unmanaged GitLab instances Cyberattacks against oil tankers and insider threats VPN patching and implied rules Zero-downtime GitLab updates and version management Running Windows ARM on Apple Silicon with VMware and Parallels Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-944
In the security news this week: UK government rolls out passkeys to 20 million users Phishing-resistant authentication and replay resistance Passkey adoption, device security, and user acceptance EU Cyber Resilience Act guidance, scope, and compliance CRA vulnerability disclosure and reporting requirements The real cost of cyberattacks and cybersecurity spending Cyber insurance and improving organizational security Nightmare Eclipse and the release of Windows zero-days Check Point VPN vulnerabilities and perimeter security GitLab security updates and shadow IT Discovering unmanaged GitLab instances Cyberattacks against oil tankers and insider threats VPN patching and implied rules Zero-downtime GitLab updates and version management Running Windows ARM on Apple Silicon with VMware and Parallels Show Notes: https://securityweekly.com/psw-944
NSA preps a major restructuring. Anthropic's CEO calls for an AI slowdown. China acknowledges AI risks. RubyGems got swarmed by AI agents. A maximum-severity GitLab vulnerability is under active exploitation. Direct Send abuse makes phishing emails appear legit. A British fintech firm leaks sensitive customer info. LinkedIn wins a legal dispute over browser extension scanning. Monday business briefing. Our guest is Tim Starks, senior reporter at CyberScoop, sharing government leaders' outlook for cybersecurity and AI at the Billington Cybersecurity Summit. Finding Bigfoot in the neural network. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest We are joined by Tim Starks, senior reporter at CyberScoop, sharing government leaders' outlook for cybersecurity and AI at the Billington Cybersecurity Summit. You can read Tim's coverage here. Selected Reading National Security Agency launches historic restructuring (The Washington Post) Anthropic CEO Calls for an AI Slowdown. Is It Possible? (SecurityAffairs) China's spy agency warns of AI risk to national security (Financial Times) OpenAI Agent Swarm Hacks RubyGems Package Manager (Infosecurity Magazine) CISA: Hackers now exploit max severity GitLab flaw in attacks (Bleeping Computer) Direct Send: How Attackers Weaponize Your Infrastructure Against You (KnowBe4) Revolut discloses data breach exposing financial info, passports (Bleeping Computer) LinkedIn beats "BrowserGate" lawsuits over scanning users' Chrome extensions (Ars Technica) NVIDIA to acquire Hugging Face for $12.9 billion. (N2K Pro Business Briefing) Sentient AI's Bigfoot Era Could Arrive at Any Moment (Gizmodo) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Andrew welcomes back Constantin Hager, a senior systems engineer, PowerShell User Group organizer, and brand new Microsoft MVP. They open by revisiting Constantin's infamous "size of a finger" intro from his first appearance, then dig into his talks at PSConfEU this year on dev containers with GitHub Codespaces and on Maester, the testing framework for M365 and on-prem AD. A quick detour into the GitHub vs. GitLab vs. Codeberg debate leads into the main event: a deep breakdown of Microsoft365DSC, what it actually does, how it treats M365 tenant settings like Intune, Entra, and Exchange as idempotent, drift-monitored code, and how the M365DSC Workshop wraps the notoriously painful setup process into a lab folder anyone can run. They cover the workshop's multi-tenant design, its DSC Community roots, and the honest limitations, like settings that still aren't exposed through public APIs. Constantin also shares his organic path to becoming an MVP, updates on his user group's shift to English-language talks, and a heads up on an upcoming blog series diving deeper into M365DSC. They close with news on the free PSConfEU MiniCon, happening October 13th with the CFP open until September 25th. Key Takeaways: Microsoft365DSC turns M365 tenant configuration into idempotent, drift-monitored code, and the M365DSC Workshop exists specifically to make the notoriously painful setup process approachable through a ready-to-run lab folder instead of a hundred-page whitepaper. Not everything in M365 is automatable yet. Settings without a public API (some Copilot controls, for example) still require manual portal fixes or an interactive token, so full automation has real gaps today. Constantin's MVP award grew out of years of showing up, organizing his user group, speaking at conferences, and opening GitHub issues, not out of being the loudest voice in the room. Guest Bio: Constantin Hager is a senior systems engineer based in Germany, organizer of the PowerShell User Group Inn-Salzach, and a newly awarded Microsoft MVP. A returning guest of the podcast, he's known for his enthusiasm around dev containers, PSFramework, and now Microsoft365DSC. Resource Links: Constantin Hager on LinkedIn https://www.linkedin.com/in/constantin-hager/ Constantin's blog, The IT Guide https://the-itguide.de Andrew's blog: https://andrewpla.tech PowerShell User Group Inn-Salzach (Meetup) https://www.meetup.com/de-DE/powershell-usergroup-inn-salzach/ Maester (M365 and Entra security testing framework) https://maester.dev/ Microsoft365DSC official site https://microsoft365dsc.com Microsoft365DSC on GitHub https://github.com/microsoft/Microsoft365DSC M365DSC whitepaper and CI/CD pipeline scripts https://github.com/ykuijs/M365DSC_CICD DSC Community https://dsccommunity.org PSConfEU https://psconf.eu PSConfEU MiniCon Call for Papers (Sessionize) https://sessionize.com/psconfeu-minicon/ PDQ Discord https://discord.gg/PDQ The PowerShell Podcast on YouTube: https://youtu.be/Vy4kaayGT2M
What do you do when everything goes wrong...and everyone is looking to you for answers?Chaim Mazal knows that feeling.As Chief Information Security Officer at GitLab, he operates in a world where one alert can suddenly mean it's “all hands on deck.”In this episode of Lead The Team, Chaim shares the story of a major cybersecurity incident at a previous company where sensitive customer data was exposed. At one point, the potential impact appeared to include more than 3,000 customers.Teams worked nights and weekends, the clock was ticking, and, as Chaim describes it, everyone was “collectively freaking out.”His job as a leader was to remain the voice of reason.His lesson: “It's not what happens, it's how you deal with it.”Chaim and Ben also explore:• Why resilience matters more than perfection• How to stay calm when your team is under intense pressure• Chaim's daily practice of “positive projection”• Why great leaders hire talented people and then trust them• The three leadership traits he believes matter most in the AI era• How Brazilian jiu-jitsu, running, and physical challenges build mental resilience• The COVID realization that changed how he manages stress• Why becoming a better leader starts with investing in yourself as a human beingChaim's career requires him to prepare for things to go wrong. Yet his leadership philosophy is rooted in optimism, trust, curiosity, and the belief that his team can find a way forward.Whether you're leading through a crisis, managing an ambitious team, or simply dealing with the everyday uncertainty of leadership, this conversation offers a practical reminder: you can't control everything that happens, but you can control how you show up when it does.-----Connect with the Host, #1 bestselling author Ben FanningSpeaking and Training inquiresSubscribe to my Youtube channelLinkedInInstagramTwitter
WeWorm has China's attention. Calls for an AI slowdown continue. OpenAI calls for mandatory AI regulation. Anthropic disrupts Russian cyberespionage. The EU's 24 hour reporting requirement goes into effect. GitLab and Check Point patch critical vulnerabilities. IDScan confirms theft of IDs. Microsoft tracks a cloud intrusion campaign. Our guest is Kevin E. Greene, Chief Cybersecurity Technologist, Public Sector at BeyondTrust, discussing the role of privilege disruption in cyber resiliency. Watch what you say. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Kevin E Greene, Chief Cybersecurity Technologist, Public Sector at BeyondTrust, discussing the role of privilege disruption in cyber resiliency. Selected Reading For China, a Mock A.I. Attack on WeChat Signals a Dangerous New Era (The New York Times) This Is Really Bad (The New York Times) OpenAI Calls for Mandatory National AI Safety Rules (BankInfo Security) Anthropic caught Russia-linked spies using Claude in hacking operations (The Record) EU's Cyber Resilience Act starts the 24-hour vulnerability clock (The Register) GitLab urges users to patch max severity path traversal flaw (Bleeping Computer) Check Point Patches Critical VPN Vulnerabilities (SecurityWeek) ID verification giant IDScan confirms data breach with more than 150 million driver's licenses stolen (TechCrunch) Passkey-themed social engineering leads to identity and cloud compromise (Microsoft Security Blog) Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Webflow just scanned 2,000 real websites and gave them a report card on how ready they are for AI search. The median score? A 2 out of 5. And the reason companies are failing isn't the reason LinkedIn keeps telling you.Dave Steer — CMO of Webflow, with prior stops at Twitter, Facebook, eBay, PayPal, Cloudflare, and GitLab — joins Stephanie Postles to unpack what the data actually says: the failure point isn't content volume, it's the technical basics of your website. Broken internal links. Missing schema. No bylines. Stale content. Fix those four things and you'll pull ahead of a category that's failing them all.Then Dave goes deeper — why AEO breaks the siloed marketing org, why hiring an 'integrated marketer' won't fix your silos, and why the teams that know how to fight well are the ones that are going to win.What you'll learn• Why the median website scores a 2 out of 5 on AI discovery readiness — and what that actually looks like under the hood• The 4 technical fixes (internal links, schema, bylines, content freshness) that will move you up the AEO maturity index this week• Why AEO can't be one person's job — and what a cross-functional weekly cadence actually looks like (the Reddit task force story)• Why hiring an 'integrated marketer' doesn't create an integrated team — and what an 'orchestrator' role does instead• The Tuckman model of high-performing teams, and why 'silos exist because of conflict aversion' — not because of org design• The 3 expertise sets every modern CMO needs — and why nobody is world-class at all threeConnectDave Steer on LinkedInWebflowMarketing TrendsChapters• 0:00 Introduction• 2:22 The biggest shift Dave has seen in two decades of marketing• 3:24 CMO 1.0 vs CMO 2.0 — from campaigns to systems• 5:34 What's actually working (and not) across millions of websites• 8:28 'AI has fundamentally rewritten the buyer journey — under our feet'• 9:42 The 4 pillars of AEO maturity (and why it's a team sport)• 12:14 'What we learned shocked us' — the 2,000-site scan• 13:54 Why 'just make more content' is making the internet worse• 16:15 The 4 technical fixes: links, schema, bylines, freshness• 18:29 Can AI help do these basic checks?• 20:47 The Reddit task force — what cross-functional AEO actually looks like• 26:58 Building high-performing teams (Tuckman model + conflict)• 31:26 The integrated marketing hire that didn't integrate anything• 36:03 'The teams that know how to do this will beat the teams that don't'• 37:52 Trust is the highest-order bit — your name is your guarantee• 39:37 Is the CMO role dying? The 2.0 answer.• 41:01 The one skill every CMO needs to unlearn• 42:46 Lightning round ----Mission.org is a media studio producing content alongside world-class clients. Learn more at mission.org. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
In this episode, Ray Cochrane records from the Michigan studio on the one year anniversary of losing the show’s original host, Todd Cochrane. The featured story is Anthropic’s $5 million grant program, which pays outside researchers to measure whether AI is actually good for the people using it. Ray also covers Anthropic’s Enterprise Frontier Safeguards, Google’s Fairwind cyber defense program, Meta’s organizational second brain, sixteen green AI projects across Asia-Pacific, an Oklahoma Bitcoin mine condemned after leaking 3.8 million gallons of water, BepiColombo closing in on Mercury, and the 2026 Ig Nobel Prizes. – Want to start a podcast? Its easy to get started! Sign-up at Blubrry – Thinking of buying a Starlink? Use my link to support the show. Subscribe to the Newsletter. Email Ray if you want to get in touch! Like and Follow Geek News Central’s Facebook Page. Support my Show Sponsor: Best Godaddy Promo Codes Get 1Password Full Summary Cochrane opens from the studio in Michigan, recording on the one year anniversary of the show losing its original host, Todd Cochrane, his father. The family has gathered for the occasion. He also plans to record several episodes throughout the week as a commemorative run, so listeners should expect a heavier release schedule than usual. He also shares where things stand. He and Delaney have gone back and forth on relocating to Michigan, but the family is pushing, and the plan is firming up for the coming month or so. Part of the draw is getting his dad’s studio cleaned up and running the way it used to. Finally, he passes along an update on the Zuvers, a story long-time listeners will recognize. The father of the three children is due out of jail soon, though he now faces retrial for the murder of the three boys. Cochrane notes that the original prison term related to their return rather than the murders themselves. The family’s expectation, he says, is that this time the sentence will be permanent. Anthropic Puts $5 Million Behind Measuring AI’s Effect on You The featured story asks a question the industry has mostly avoided. Not whether a model is smart, but whether you are better off after using it. Anthropic is funding independent research to find out, and the structure is the interesting part. The money creates what the field calls evaluations: standardized tests for AI models. Hundreds already exist for coding, math, and reasoning. However, almost none measure whether the tool is good for the human on the other end. Crucially, Anthropic is not building these tests in-house. Grantees receive funding, model access and technical support, then work fully independently. Everything they produce must be published open source, so any developer at any company can run it. As Cochrane puts it, Anthropic is paying to create a ruler other people will use to measure Anthropic. The example Anthropic leads with is deliberately uncomfortable. Claude might offer diet and workout advice to someone asking about weight loss. But if that user has a history of disordered eating, the same response becomes actively harmful. Cochrane connects this to sycophancy, a topic the show has returned to before, and notes that models carry no real memory of who you are unless you tell them. That is exactly why the problem has gone unmeasured. Code compiles or it doesn’t. Math checks out or it doesn’t. Wellbeing has no answer key, because the identical response can help one person and harm the next. The Five Things Anthropic Wants These Tests to Do Cochrane walks through all five criteria, since each targets a specific way this research usually fails. First, state plainly what you are measuring. It is easy to measure something adjacent, such as how often a model uses warm language, then publish numbers about a proxy while claiming insight into loneliness itself. Second, involve clinicians and subject-matter experts in designing and validating the tests. A capable engineer may simply not know what the warning signs of an eating disorder look like in text. Without those people in the room, the test measures what engineers imagine the harm looks like. Third, count overcompliance and overrefusal as harms. Overcompliance is the obvious failure. Overrefusal is the model becoming so cautious it turns useless, or shutting down someone who had nowhere else to ask. Cochrane adds that overrefusal is far harder to spot, because you often cannot tell it is degrading until it has degraded. Fourth, reflect real multi-turn usage. Most safety testing throws one nasty question at a model and checks for refusal. Meanwhile, actual harm builds across a long conversation where every individual message reads as fine. Fifth, validate the automated graders against real experts. Scoring thousands of conversations means an AI grades the AI. Consequently, a subtly wrong grader skews every downstream number in the same direction, and nothing in the process flags it. Cochrane expects this to be the hardest criterion to satisfy, since psychiatric and medical specialists do not come cheap by the hour. Applications close September 21st, and shortlisted applicants will be notified by October 5th. Notably, the announcement names no individual researcher or executive. Sponsor: GoDaddy Economy hosting $6.99/month, WordPress hosting $12.99/month, domains $11.99. Website builder trial available. Use codes at geeknewscentral.com/godaddy to support the show. Anthropic’s Enterprise Frontier Safeguards Keep Your Logs in Your Vault Anthropic’s second announcement targets a completely different audience. Catching misuse across many sessions requires keeping logs. However, banks and hospitals cannot hand that data to an outside vendor, because regulators will not allow it. Safety monitoring and compliance were in direct conflict. The fix moves where the data lives. Activity logs go into the customer’s own cloud bucket at Amazon, Microsoft or Google, locked with keys the customer controls. Automated systems scan a rolling window for serious abuse such as credential theft, and alerts route straight to the customer’s own security team. No human at Anthropic reads it, and Anthropic does not charge for the feature. The backstory explains the urgency. Anthropic had begun retaining thirty days of data with its Fable 5 model, specifically to catch patterns that only appear across multiple sessions. Regulated customers had to walk away immediately. Over a hundred organizations helped shape the result, including a quarter of the Fortune 100 and every US globally systemically important bank. It works across Claude Code, Claude Enterprise, Amazon Bedrock, and Microsoft Foundry. Wells Fargo’s security team put it simply, saying their logs stay in a Wells-managed environment under Wells-managed keys. Cochrane adds a personal note on the same retention change. Because transcripts now persist thirty days after last touch, he can keep Claude Code threads open far longer and lean on clear without losing context. Google’s Fairwind Program Hands Patching to the Machines Google is running the same play from the defensive side. Normally, a human engineer must reproduce a security flaw, understand it, write a fix, then prove the fix broke nothing else. That can stretch to weeks, and attackers live in exactly that gap. Fairwind pairs two systems to close it. Gemini 3.8 Flash Cyber is a model tuned for security work. CodeMender hunts for flaws and writes the patches. Together, Google says they produce verified, deployment-ready patches in minutes, running inside the customer’s own environment. Access is deliberately restricted to three groups: national cyber authorities; critical infrastructure operators in healthcare, telecom, energy, and finance; and major technology platform providers. More than 650 partners are involved. Cochrane’s take centers on logging quality. Systems that emit specific, unique errors rather than generic ones let these tools find real issues almost immediately. Furthermore, he sees value in purpose-tuned models over general ones, since different training data and methodology surface gaps a single familiar model would miss. Meta Built an AI That Learns From Its Own Experts Every organization has two or three people who actually understand the hard systems. When they are busy, everyone waits. When they leave, the knowledge leaves too. Most AI assistants address this with retrieval, searching documents when you ask. Meta went the other way. A long-running offline process digests the source material ahead of time into more than 200 structured knowledge files, so the thinking happens before anyone asks. On top sit what Meta calls recipes, step-by-step procedures mirroring how a specialist actually works a problem. The reported numbers are concrete. Restructuring cut tokens consumed per turn by 80 percent. Assessments that took days now take minutes. The team built the whole system in six weeks across three sprints. Cochrane focuses on the feedback loop. Normally, an expert corrects an assistant in chat; the answer improves once, then the system forgets. Meta’s version compiles corrections into knowledge files and regression-tests them, so fixes stick without retraining the model. However, he raises two real caveats from his own attempts. Building those knowledge files is token-heavy, and codebases change. If the offline process does not rerun, the documentation drifts away from the code it describes. He also predicts this will become a service offered by AWS, GitHub, or GitLab rather than something each company builds alone. Sixteen Green AI Projects Across Asia-Pacific Google DeepMind named the first cohort of its Accelerator: AI for the Planet program. Sixteen organizations span New Zealand, Singapore, South Korea, Indonesia, Thailand, India, Australia and Japan, receiving three months of access to Google’s AI stack plus mentorship and a Singapore bootcamp. Several stand out. A New Zealand outfit called 800 Trust uses bioacoustics, monitoring an ecosystem by listening to it and running AI over continuous audio to track biodiversity. Wildlife.ai builds open-source AI camera traps. Australia’s X-Centric replaced the soil lab with a handheld X-ray reader that answers a farmer standing in the field. In India, Climitra Carbon verifies invasive species removal and converts the biomass into biochar. Access matters more than money, as Cochrane points out. A six-person conservation nonprofit cannot run frontier models, because the compute bill alone would consume its operating budget. The organizations closest to these problems have always been furthest from the tooling. An Oklahoma Bitcoin Mine Condemned After Leaking 3.8 Million Gallons Cochrane corrects the figure up front. Many outlets report three million gallons, but El Reno city officials put it at 3.8 million. A Bitcoin mining operation on West Jensen Road leaked water and dropped pressure badly enough to close El Reno Public Schools, the Canadian County Courthouse, and other city and county offices. It happened during a month with 24 days above 100 degrees, in a region under severe to extreme drought. The leak is not the damning part. The city issued a stop-work order on the site back in 2023 for electrical, construction, and fire safety violations, then never followed up. The facility ran roughly three years under an order nobody enforced. Interim city manager Ken Brown did not dodge it, saying simply, “We failed.” The site is now posted as condemned with a ten-day removal notice, and a hearing with operator Athlon BT is set for September 14th. Reaching the company has proven difficult, with a website stuck on a maintenance notice and an unanswered California phone number. Cochrane draws one distinction that the coverage keeps blurring. This is a Bitcoin mining rig, not a hyperscale AI data center. The residents who lost pressure absorbed the cost, and nobody billed the operator for the aquifer. BepiColombo Closes In on Mercury After Eight Years Reaching the closest planet to the Sun took nearly eight years, which sounds backward until you understand the physics. Falling toward the Sun means gaining enormous speed, and a spacecraft arriving too fast simply sails past. So the mission spent those years shedding velocity across nine gravity-assist flybys: one at Earth, two at Venus, and six at Mercury itself. On September 3rd, the transfer module separated and was discarded more than 200 million kilometers from Earth. Mission control marked the moment with “Roll call completed, GO for separation.” Importantly, the spacecraft has not arrived yet. Orbit insertion is November 21st, the two science orbiters separate around December 9th and 10th, and science operations begin in April 2027. That November date is revised, having slipped from an earlier plan. Two orbiters fly because they do different jobs. Europe’s Mercury Planetary Orbiter studies the planet and what lies beneath its surface. Japan’s Mio studies the magnetosphere. Mercury having a magnetic field at all is genuinely odd, since a planet that small should have cooled and lost it long ago. The mission honors Giuseppe “Bepi” Colombo, the Italian mathematician who worked out how to slingshot a spacecraft to Mercury in the first place. NASA Builds a Rocket Engine Talk You Can Hear NASA hosts a webinar on Friday, October 2nd at 2 pm Eastern, titled “The RS-25 Engine and the Future of Artemis Missions.” It runs about two hours, is open to anyone, and RSVPs close September 25th. The RS-25 is not new hardware. It is the Space Shuttle main engine, the same design that flew 135 shuttle missions across three decades, now bolted four at a time into the SLS core stage. Together they produce roughly 2.2 million pounds of thrust at 111 percent of their original shuttle rating. Throwing them away is the strange part. These are precision engines built to fly repeatedly, yet Artemis expends four on every launch. NASA got a proven engine and skipped a decade of development, and that is the trade. The accessibility work is the real story. The event includes an audio-described video of an engine test firing, a live Q&A with an Artemis engineer, and a panel on accessibility in space and science. A test firing normally sells entirely on spectacle. Conveying that, and the engineering underneath it, without the visuals is a genuine design problem NASA built the whole event around solving. Buried Underwear Wins a 2026 Ig Nobel The 2026 Ig Nobel Prizes were awarded September 3rd in Zurich. Marc Abrahams launched them in 1991 at the satirical magazine Annals of Improbable Research, and what began as a roast is now something researchers actively want. The soil science prize went to a team that buried 1,000 pairs of underwear across more than 25 countries and dug them up two months later. Measuring how much cotton rotted turns out to be a cheap, surprisingly good proxy for how biologically alive the soil is. The biomechanics prize recognized a precise, cross-species definition of kissing that works for animals and excludes passing food. By that definition, polar bears kiss, some birds kiss, and so do ants. Nature reports the behavior traces back roughly 21.5 million years to the ancestor of all large apes, meaning ancient humans very likely kissed Neanderthals. Cochrane’s favorite was the physics prize, awarded for a splash-free urinal design that reportedly cuts spray to 1.4 percent of normal. Cochrane closes by pointing listeners to the GNC Insider program, the newsletter, and podcastapps.com for a modern podcast app. Feedback on the show’s format is explicitly welcome at geeknews@gmail.com, where either Ray or Chris will read it. The post Anthropic’s $5 Million Push to Measure AI’s Effect on Wellbeing #1876 appeared first on Geek News Central.
Plus: Oil continues to move higher. And cybersecurity stocks fall after Palo Alto Networks posts quarterly loss. Imani Moise hosts. Sign up for WSJ's free What's News newsletter. An artificial-intelligence tool assisted in the making of this episode by creating summaries that were based on Wall Street Journal reporting and reviewed and adapted by an editor. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
In der heutigen Folge sprechen die Finanzjournalisten Lea Oetjen und Holger Zschäpitz über den gruseligen September-Auftakt, Kracherzahlen von Dell und eine Enzym-Aktie, die fremde Blockbuster in eigene Erlöse verwandelt. Außerdem geht es um SAP, CrowdStrike, Cloudflare, RWE, Merck, Apple, Credo Technology, MongoDB, GitLab, Palo Alto Networks, Nvidia, Broadcom, Shein, H&M, Fast Retailing, Next, Inditex, Associated British Foods (ABF), Gap, Roche, Johnson & Johnson, Merck & Co., Halozyme Therapeutics, Bristol-Myers Squibb, Pfizer, Eli Lilly, Alteogen, Schott Pharma, Gerresheimer, Ypsomed, West Pharmaceutical Services, Husqvarna, Toro, KraneShares Global Humanoid and Embodied Intelligence ETF (WKN: A41PZ8) und iShares Automation & Robotics ETF (WKN: A2ANH0). Am 2. Oktober findet unser „Alles auf Aktien“-Summit in Berlin statt. Mit dem Code „AAAFRIENDS“ sparst du 50 Prozent auf dein Ticket – aber nur unter folgendem Link: https://veranstaltung.businessinsider.de/event/financesummit26/summary?rp=c6dc55d6-6f4f-4fb4-b75f-3… Wir freuen uns an Feedback über aaa@welt.de. Noch mehr "Alles auf Aktien" findet Ihr bei WELTplus und Apple Podcasts – inklusive aller Artikel der Hosts. Hier bei WELT: https://www.welt.de/podcasts/alles-auf-aktien/plus247399208/Boersen-Podcast-AAA-Bonus-Folgen-Jede-Woche-noch-mehr-Antworten-auf-Eure-Boersen-Fragen.html. Hier könnt ihr den AAA-Newsletter abonnieren: https://www.welt.de/newsletter/article232797673/Alles-auf-Aktien-Der-taegliche-Boersen-Newsletter-fuer-WELTplus-Abonnenten.html Und – ganz neu: AAA gibt es jetzt auch auf Instagram: https://www.instagram.com/alles_auf_aktien/ Disclaimer: Die im Podcast besprochenen Aktien und Fonds stellen keine spezifischen Kauf- oder Anlage-Empfehlungen dar. Die Moderatoren und der Verlag haften nicht für etwaige Verluste, die aufgrund der Umsetzung der Gedanken oder Ideen entstehen. Hörtipps: Für alle, die noch mehr wissen wollen: Holger Zschäpitz können Sie jede Woche im Finanz- und Wirtschaftspodcast "Deffner&Zschäpitz" hören. +++ Werbung +++ Du möchtest mehr über unsere Werbepartner erfahren? Hier findest du alle Infos & Rabatte! https://linktr.ee/alles_auf_aktien Anzeige: Eight Sleep: Der Pod 5 reguliert die Temperatur im Bett automatisch, trackt Schlaf- und Gesundheitswerte ohne Wearable und kann so zu besserem Schlaf beitragen. Mit dem Code ALLESAUFAKTIEN erhaltet ihr auf https://www.eightsleep.com/allesaufaktien bis zu 350 Euro Rabatt. Impressum: https://www.welt.de/services/article7893735/Impressum.html Datenschutz: https://www.welt.de/services/article157550705/Datenschutzerklaerung-WELT-DIGITAL.html
Der DAX verliert am dritten Tag in Folge 0,5 % und schließt bei 25.839,33 Punkten, dem tiefsten Stand seit Anfang August. Steigende Kapitalmarktzinsen und Brent-Öl bei rund 96 USD sorgen für Nervosität. Etwas Entlastung bringen schwache ADP-Daten: In der US-Privatwirtschaft entstehen im August nur 38.000 Stellen. Am Abend folgen die Zahlen von KI-Schwergewicht Broadcom. Adidas führt nach einer Barclays-Hochstufung den DAX an, Zalando und GEA verlieren. Ryanair senkt wegen hoher Kerosinkosten die Passagierprognose auf 214 Mio. Passagiere. Uber streicht weltweit 3.300 Stellen. An der Wall Street springen Dell um mehr als 12 % und GitLab um 12,6 %. HyImpulse erhält mehr als 50 Mio. Euro. OpenAI begrenzt den Zugang zu Astra wegen hoher Cyberrisiken. Börsenweisheit des Tages: "Der Wunsch nach ständiger Aktivität, unabhängig von den Rahmenbedingungen, ist selbst bei Profis für viele Verluste an der Wall Street verantwortlich." Gerald M. Loeb
Today we are talking about Security, Vulnerabilities, and how to avoid exposure with guest Dave Welch. We'll also cover Security Scanner as our module of the week. For show notes visit: https://www.talkingDrupal.com/567 Topics What Are CVEs CVE Lifecycle and Disclosure AI Era Security Challenges What CVE Program Excludes Patch Fast Reality Global Security Signals CVE Timing Judgment KEV Flags Explained CVE Updates Link Rot Who Decides CVE Sneaky Patch Dangers ADP Program Fixes Small Team Triage Vulnerability Tsunami AI Autonomous Security Future Legal Pressure Budgets Resources Psalm PHP Static Analysis Tool SARIF format PHP ecosystem Council of roots How AI Broke Open Source Security: End-of-Life Software Is the Most Exposed CVE podcast Vulncon PSIRT Guests David Welch - github: dwelch2344 dwelch2344 Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi JD Flynn - dorficus MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever wanted a fast way to catch the security mistakes that slip into custom Drupal code — especially the code your AI assistant just wrote — before it ships? There's a module for that. Module name/project name: Security Scanner Brief history How old: created in July 2026 by Mayank Gupta (mayankguptadotcom) of Acquia Versions available: 1.0.0, which works with Drupal 10.3 and 11 Maintainership Actively maintained — created and shipped its first stable this summer, with steady development right through late July Security coverage Test coverage — and it's strong: unit and kernel tests, including a regression corpus built from real Drupal core advisories Documentation? In-depth README with a full check table and CI recipes, plus a CHANGELOG Number of open issues: 1 issue, not a bug Usage stats: 2 sites (it's brand new) Module features and usage Provide a Drush command, has no UI — you point drush security:scan at a module or any path, it reads the code statically, and prints a prioritized, OWASP-mapped list of things to review It's built for the age of AI-written code — the checks target the classes AI assistants keep reintroducing: routes with no access check, #markup and |raw XSS, missing CSRF tokens, unserialize() on untrusted data, hardcoded secrets Then there's an optional deep pass: with the Psalm static analysis scanning engine installed, it'll trace untrusted input across functions and files to catch cross-function issues. And it's honest about state — the report always says whether that deep pass ran, was skipped, or failed, so a failure never gets mistaken for a clean scan One nice detail under the hood: a tokenizer-backed "code map" that knows whether a match is real code, a comment, or a string — so it won't flag the word "unserialize" sitting in a doc comment. That kills the single biggest source of false positives The checks are regression-tested against real Drupal advisories (Drupalgeddon, Drupalgeddon2, the 2019 unserialize bug, etc) so a pattern that caused an actual CVE can't quietly come back in your custom code Output comes in three flavors: a readable table, JSON for CI and AI agents, and SARIF — which means findings show up as annotations right on your GitHub or GitLab merge-request diff instead of buried in a job log For adopting it on an existing codebase there's a baseline file — you fingerprint the findings you've reviewed, with a required reason on each, and they stop failing the build but never go invisible; every run still counts them It exits non-zero on error-level findings, so it drops straight into CI or a pre-commit hook And it's extensible — checks are Drupal plugins with a #[SecurityCheck] attribute, so any module can add its own or alter the ones that ship Big caveat, and the module says this itself: a finding means "review this," not "this is broken." Static analysis has false positives, and a clean scan doesn't prove the code is secure — access-control logic especially still needs human review I first heard about this module over beverages at Drupalcamp Asheville, so I know that this module was largely vibe-coded, after having an AI agent ingest every single Drupal security team CVE. So I like to think of this module as security pattern recognition tool, but of course it does even more
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting! https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272 Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays https://isc.sans.edu/diary/Even%20MOAR%20Powershell%2C%20looking%20at%20Entra%20logins%20-%20the%20good%2C%20the%20bad%20and%20the%20password%20sprays/33268 Microsoft Entra ID Remote Code Execution Vulnerability CVE-2026-69836 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836 GitLab Critical Patch Release CVE-2026-19478 CVE-2026-19650 https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/ GTA 6 Leak File with Malware https://x.com/Aidas29506493/status/2091194667073204624 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Faster AI code generation is increasing the need for governance, security and control across the software-development life cycle, says Bill Staples, GitLab's CEO. Staples joins Bloomberg Intelligence analyst Mandeep Singh on this episode of the Tech Disruptors podcast to discuss GitLab's position as a cloud- and model-neutral orchestration layer for coding agents, as well as the shift from seat-based subscriptions toward a hybrid model that includes consumption pricing for agentic workloads.
PHP Podcast – August 20, 2026 Hosts: Joe Ferguson, Sara Golemon & Holly Schilling Shirley MacLaine is the answer — but what’s the question? RAM prices went up 500%, GitHub fell over for eight hours, and the crew figured out how you can actually contribute to PHP. Glasses optional. Shirley MacLaine, Green Room Shade, and the Show’s New Normal The episode opens with Joe flustered — not because it’s a “flustered day,” but because there’s shade being thrown in the green room backstage chat. Rather than spoil the drama, the crew turns a mysterious green-room answer into a running bit: “Shirley MacLaine” is the answer, and listeners are invited to submit what the question was. It’s declared the first round of PHP Architect’s Jeopardy, complete with its own Easter egg sound cue. Joe also lays out where the show is heading. Eric and John took over the podcast the previous week to relive their glory days, and the plan is for the old guys to step back to roughly one episode a month. Joe and Sara are working on something to fill one slot, another mystery show is in the works pending signed contracts, and Alive and Kicking is confirmed still alive and kicking after a great recent episode with Derek. Joe also plugs the PHP 8.6 Beta 1 tag and Scott Keck-Warren’s PHP Community Podcast interview with release managers Daniel Scherzer and Matteo Bacotti. The RAM Apocalypse: 500% in Twelve Months The big topic of the week is the ongoing memory and chip crisis. Memory prices have climbed 500% in twelve months, and the crew commiserates about the parts they wish they’d bought bigger. Sara explains the brutal math: you can’t build a semiconductor fab fast enough — two or three years minimum — and by the time one comes online nobody knows if we’ll have overproduction or a burst bubble. Worse, Sara notes that essentially every RAM stick through the end of 2027 is already accounted for and sold to vendors. The ripple effects are everywhere. Console prices are going up instead of down late in their cycle, with next-gen consoles projected to start at $1,000 or more. The hobbyist single-board computer market is getting crushed — Pine64 announced they’re stepping back from making hardware, and a Raspberry Pi 5 that debuted cheap now runs over 100 pounds. Holly’s new PC, bought at the start of 2025, ended up shipped 3,000 kilometers the wrong way to California and is stuck awaiting import paperwork, leaving her leaning on a laptop and some now-precious Raspberry Pi zeros. The nostalgia gets thick as the crew reminisces about DIP chips, EDO RAM, Pentiums, Epson 486s, Tandy 1000s, and the TRS-80. Special venom is reserved for Packard Bell (“utter freaking trash”) and Gateway 2000’s cow-pattern branding — which Sara confirms sold better in Wisconsin than anywhere, though hay bales in a Berkeley storefront still boggle the mind. A chat comment about technicians de-soldering and reballing BGA RAM chips becoming economically viable gets a hearty “absolutely.” Memory-Aware Development and Why PHP 7 Doubled Down Bringing the RAM crisis back to PHP, Joe wishes more developers were aware of how their applications consume and release memory — a lesson he credits to learning enough C back in the day, where you have to manage memory yourself. He connects sloppy memory awareness to the N+1 query problems web developers keep tripping over. Sara drops a great deep dive: a significant reason PHP 7 was roughly twice as fast as PHP 5 was changes in the memory layout. Every variable became referenced by one fewer pointer, and while eight bytes sounds trivial, every level of indirection adds time across every single instruction and access. Sara adds the CPU-level detail — one layer of indirection can be a single instruction on most architectures, but adding a second layer can push a lookup from one instruction to three. That leads into a warm tangent about learning C to become game developers. Sara’s evergreen joke: “I’m going to be a game developer” is the programmer’s version of “I’m going to buy a bar.” Great people, brutal hours, endless competition, and the reality of hitting spacebar 400 times to figure out why you can phase through a wall. The cat-reading-the-paper “I should buy a boat” meme makes an appearance to seal it. The GitHub Outage and the Monoculture Problem Monday’s eight-hour GitHub outage hit the crew directly. Holly couldn’t use a site that only offered “log in with GitHub,” and Joe got kicked out of his CLI auth session mid-PR with no way to re-authenticate. To GitHub’s credit, they published an incident update and a follow-up blog post: a service auto-scaled so aggressively to handle network traffic that the sidecar and supporting services couldn’t keep up, bringing the whole thing down. The conversation turns to whether this is self-inflicted. Joe recalls GitHub’s pre-Microsoft, gold-standard reliability and wonders aloud how much the decline lines up with Copilot’s arrival and internal AI adoption, with uptime reportedly slipping below a single nine at points. Sara defends them somewhat — the number of actions, CPU cores, and pull requests has genuinely hockey-sticked, partly because AI has emboldened people who previously wouldn’t have opened a PR. But as Joe puts it, the call is coming from inside the house, since GitHub itself has been pushing AI. On alternatives, Joe says the least-jarring migration for PHP Architect’s clients would be self-hosting GitLab, since GitHub Actions and GitLab runners are nearly identical in syntax — Atlassian’s Bitbucket, by contrast, is a bridge too far, mostly because the entire ecosystem assumes you’re on GitHub. Sara names this the core problem: monoculture. The crew discusses package mirrors, local caches, 12-factor thinking, and Composer’s support for custom mirrors, all while remembering the PHP repo intrusion years ago that came from an unmaintained self-hosted Git server. The takeaway: owning your pipeline end-to-end is the only way an outage can’t stop you — and Joe teases spinning up a self-hosted GitLab now that “the boss” (Sara) has signed off. How to Contribute to PHP (and Handling Security Reports) The crew highlights two PHP Foundation blog posts. First, Matt Stauffer’s “How to Contribute to PHP,” adapted from a talk he gave at Atlanta PHP. It goes well beyond “learn C,” clearly separating the PHP project, the PHP ecosystem, and the Foundation, and lays out approachable on-ramps: testing pre-releases (PHP 8.6 Beta 1 is out, Beta 2 lands next week), improving documentation, and writing tests — which, spoiler, are written in PHP, not C, using PHP’s own test format that’s simple enough to learn from any single example. Other contribution paths include triaging and reviewing issues across PHP repositories — invaluable work that frees core developers from wading through AI-generated slop bug reports — and participating in internals via the well-documented mailing list process, up to and including running for release manager (8.7 managers will be needed before you know it). Sara points folks to discord.phpc.chat for the PHP Discord, with dedicated Internals and Foundation channels for anyone the mailing list intimidates. Second, Sebastian Bergmann’s “So you received a security report. Now what?” is a jump-around reference for application developers rather than a front-to-back read, walking through roughly ten steps to triage, validate, and resolve reported issues the right way. Sara shares a real-world example from mobile: a flagged package that was only exploitable on a rooted device with an actively hostile package installed alongside it — a very different risk profile than a SQL injection on an API endpoint. Cue reminiscing about writing SQL against Access databases over ODBC from PHP (and Perl) back in the 90s, and Joe’s advice for handling any security report: don’t panic, and always know where your towel is. Links from the show: PHP Tek 2027 — April 27–29, 2027 in Chicago; early bird tickets & hotel available now PHP Tek 2027 CFP Audio versions of the podcast at phparch.com Join us live on Discord at discord.phparch.com PHP Discord — discord.phpc.chat Community Corner Podcast: PHP 8.5 + 8.6 Release Manager Daniel Scherzer Memory prices climb 500% in 12 months So You Received a Security Report. Now What? How to Contribute to PHP Shirley MacLaine Host: Joe Ferguson Mastodon: @joepferguson@phpc.social PHPArch.me: @svpernova09 Sara Golemon Mastodon: @pollita@phpc.social Holly Schilling Mastodon: @TheCodeLorax@tech.lgbt Streams: Youtube Channel Twitch Connect & Hire PHP Architect Website Twitter/X Mastodon Hire PHP Developers Looking to hire PHP developers? Email support@phparch.com – Joe and the team are available for consulting, infrastructure work, Ansible playbooks, and code review. Partner This podcast is made a little better thanks to our partners Displace Infrastructure Management, Simplified Automate Kubernetes deployments across any cloud provider or bare metal with a single command. Deploy, manage, and scale your infrastructure with ease. https://displace.tech/ OurCVEs Your security posture, on autopilot with OurCVEs CodeRabbit Cut code review time & bugs in half instantly with CodeRabbit. PHP Architect Consulting Your PHP codebase deserves a partner, not a contractor PHP Architect provides long-term technical partnerships for organizations that need senior-level PHP expertise that you can depend on https://www.phparch.com/consulting/ Music Provided by Epidemic Sound https://www.epidemicsound.com/ Join Us Live Next Week Youtube Channel Got feedback? Join us on Discord at discord.phparch.com The post The PHP Podcast 2026.08.20 appeared first on PHP Architect.
How do entrepreneurs turn daily headaches into solutions that benefit an entire industry? In the world of angel investing, even the most tech-savvy find themselves wrangling gruesome spreadsheets and chasing down lost documents—begging the question: why are investors, of all people, stuck managing chaos with outdated tools? This episode features Zach Holman, one of GitHub's earliest team members and a prolific angel investor. After years of advising top startups and investing in hundreds of companies, Zach found himself wrestling with the same messy tracking problems plaguing countless others. Drawing on his unique background at the intersection of engineering, advising, and investing, he set out to build Signed—a modern platform purpose-built for angel investors to organize, analyze, and make sense of their portfolios. Listeners will hear firsthand how frustration with the status quo inspired Zach to create a tool he originally built just for himself, and which is now helping the broader investing community. From tracking investments and importing documents to handling the perennial headaches of taxes and K1s, the conversation dives into the nuts and bolts of managing a dynamic investment portfolio. This episode is a must-listen for anyone interested in the evolution of angel investing, practical founder stories, and the tangible ways entrepreneurship can transform pain points into much-needed innovation. To get the latest from Zach Holman, you can follow him below! https://www.linkedin.com/in/zachholman/ https://signed.com/ Sign up for Marcia's newsletter to receive tips and the latest on Angel Investing! Website: www.marciadawood.com Learn more about the documentary Show Her the Money: www.showherthemoneymovie.com And don't forget to follow us wherever you are! Apple Podcasts: https://pod.link/1586445642.apple Spotify: https://pod.link/1586445642.spotify LinkedIn: https://www.linkedin.com/company/angel-next-door-podcast/ Instagram: https://www.instagram.com/theangelnextdoorpodcast/ TikTok: https://www.tiktok.com/@marciadawood
90 % der Entwickler nutzen bereits KI beim Coden. Aber was passiert eigentlich danach? Wenn wir mit AI deutlich schneller und mehr Code produzieren, müssen Code Reviews, Security Scans, Pipelines, Deployments, Governance und Compliance mit dieser Geschwindigkeit mithalten. Und genau da wird es spannend. In dieser Folge von Devs On Tape sprechen Caro und ich mit André Braun von GitLab, der seit über 35 Jahren in der IT unterwegs ist und heute die Organisation von GitLab in Zentraleuropa verantwortet. Wir starten bei der Frage, was GitLab heute eigentlich noch mit einem klassischen Git-Repository zu tun hat – und landen ziemlich schnell bei einer viel größeren Frage: Wie sieht Softwareentwicklung aus, wenn nicht mehr nur Menschen, sondern ganze Flotten von AI Agents daran beteiligt sind? Wir sprechen darüber, warum AI-generierter Code nur der Anfang ist, weshalb der Kontext einer Entwicklungsplattform für Agents so wertvoll wird und warum Unternehmen ihre bestehenden Prozesse nicht einfach mit KI automatisieren sollten. Denn vielleicht müssen wir Softwareentwicklung nicht nur schneller machen. Vielleicht müssen wir einige unserer Prozesse komplett neu denken.
This week we talk about when is it appropriate to fix problems, and when is it scope creep. Plus, the second installment of our new SteveScale segment! -- During The Show -- 00:45 Intro Rabbit holes 02:30 Comodore phone - Charlie Flip phone Sailfish OS Commodore Phone 04:37 Cameras - Tyler Agara (AQARA?) Hub Camera flood light combo AQARA to homekit Honeywell Vista 20P Panel Eyezon EVL4(https://www.eyezon.com/envisalink_evl4_smart_alarm_dsc_honeywell_no_monthly_fees.html) Silicon Lab CP210 Alarm Relay 12:50 News Wire Postgres 18.6 - postgresql.org GIMP 3.4 - phoronix.com Rsync 3.5 - lwn.net QEMU 11.1 - phoronix.com Linux 7.2 - phoronix.com KDE Frameworks 6.29 - kde.org Linux Mint HWE 22.3 - linuxmint.com Sparklinux 8.4 - sparkylinux.org Manjaro 26.1 - daily.dev Meta Glimmer 30b - huggingface.co LTX 2.5 - huggingface.co Qwen3.8-2.4T-A95B - huggingface.co DeepSeek-V4-Pro - huggingface.co Qwen3.8-27B - huggingface.co Debian Turns 33 - bits.debian.org 14:35 Church Tech Church "Tech Booth" Stripped everything down Built a tech both Traced and labeled all the lines Plugged everything back in Re-Configured the mixer Beringer XR18 with X Air Edit FreeShow OBS Streamdeck with BitFocus Companion Angry Audio interface 21:30 Oven's Data Center Let us know if you want to hear about storage and backup Laying down infrastructure Local git Forgejo GitHub vs GitLab vs Others Secret Management Ansible Vault KeePass Hashicorp Vault OpenBao Running into problems RLIMIT_MEMLOCK Docker registry Comfy UI MiniMax H3 Thunder Compute Fish Audio -- The Extra Credit Section -- For links to the articles and material referenced in this week's episode check out this week's page from our podcast dashboard! This Episode's Podcast Dashboard Phone Systems for Ask Noah provided by Voxtelesys Join us in our dedicated chatroom #GeekLab:linuxdelta.com on Matrix -- Stay In Touch -- Find all the resources for this show on the Ask Noah Dashboard Ask Noah Dashboard Need more help than a radio show can offer? Altispeed provides commercial IT services and they're excited to offer you a great deal for listening to the Ask Noah Show. Call today and ask about the discount for listeners of the Ask Noah Show! Altispeed Technologies Contact Noah live [at] asknoahshow.com -- Twitter -- Noah - Kernellinux Ask Noah Show Altispeed Technologies
Harjot Gill is the co-founder and CEO of CodeRabbit, the AI code review company that became the most installed AI app on GitHub and GitLab. Over about two years, CodeRabbit went from zero to over $50M in ARR and a $1B+ valuation. It is his third startup.In this episode of Summation, Harjot and Auren discuss:Why the bottleneck in software just moved from writing code to reviewing itWhy mature companies now adopt AI firstWhy you should never let a coding agent review its own workThe playbook that took CodeRabbit from zero to $50M+ in two yearsYou can find Auren Hoffman on X at @auren and Harjot Gill on X at @harjotsgill
Jaleh Rezaei, Co-founder and CEO of Mutiny, joins Sam Jacobs, AJ Bruno, and Asad Zaman to explain how she deprecated a thriving 8-figure SaaS business in November 2025, shipped a private preview in February, and GA'd an AI-native product in April that is now used by more than 3,500 organizations including Snowflake, Rippling, Uber, and GitLab. Topics include why running a scaled SaaS business and a zero-to-one AI bet at the same time proved impossible, how to price and defend AI credit consumption when a $5,000 design project now costs 50 credits, and the shift from sales-led outbound to product-led growth for enterprise go-to-market. Plus, why brand is one of the few remaining moats in B2B, an AI raccoon launch video that fooled (some of) the panel, and a bulls-versus-bears debate on quota attainment, AI note-takers, and whether salespeople will ever spend 85% of their time selling. Key Takeaways: - Make the hard decisions FAST. As Jaleh Rezaei, CEO and Co-founder of Mutiny, put it: "I definitely would've said the job of the CEO is you have to make the hard calls. But what I learned in that experience is that it's actually about making the hard calls really fast, which means that you're getting there before everybody else on your team is there." Her test for founders weighing a similar bet is a single question: "is there one really hard decision, maybe one that scares the hell out of you that you don't want to do, that you can make that would make 50 subsequent downstream decisions a lot easier for your company?" - AI budgets get cut because vendors let buyers anchor on the credit bill. Instead, they need to help buyers see the value of the work the credits replace. Jaleh Rezaei, CEO and Co-founder of Mutiny, reframed it with her own before-and-after: "I used to have a designer that I paid $5,000 to, and it would take 2 weeks of back and forth, and I paid $5,000 to get to something that I was pretty happy with. But end to end took a month. Now in 6, 7 hours, I can build that in Mutiny, and maybe that does cost me 50 credits. That's really freaking cheap relative to what I used to pay that designer." She argues the vendor has to build the ROI case for the customer, per rep, or budget conversations default to minimizing every AI bill. - Brand is a durable moat in B2B mostly because so few companies are willing to pay for it in risk. According to Jaleh Rezaei, CEO and Co-founder of Mutiny: "great brand comes when you marry deep customer knowledge and a willingness to take risk … a lot of times people that own brand they don't necessarily either have the deep customer knowledge or they don't have the ability to take that kind of risk inside of the company." Her internal standard is blunt: "anything we do on marketing, like, if it's not different, just stop doing it. It's just not going to matter." - Quota attainment is snapping back hard, and the data has not caught up to the narrative. AJ Bruno, CEO of QuotaPath, brought Q2 numbers to the bulls-versus-bears round: "I just looked at Q2 numbers and they're trending wildly back up. We're actually, the average quota attainment for a QuotaPath customer was 76% in Q2." Asad Zaman pushed back that a jump from roughly 40% to 76% in a single quarter reads more like a bubble signal than a sudden improvement in selling, and AJ offered to run a comp study with Pavilion on the data. Connect with the Hosts & Guests: Host: Sam Jacobs, CEO at Pavilion - https://www.linkedin.com/in/samfjacobs/ Host: AJ Bruno, CEO at QuotaPath - https://www.linkedin.com/in/ajbruno3/ Host: Asad Zaman, CEO at STA - https://www.linkedin.com/in/azaman1/ Guest: Jaleh Rezaei, CEO & Co-founder at Mutiny - https://www.linkedin.com/in/jalehr/ Topline is more than a YouTube Channel: Subscribe to Topline Newsletter: https://toplinemedia.substack.com/ Tune into Topline Podcast, the #1 podcast for founders, operators, and investors in B2B tech: https://www.joinpavilion.com/topline-podcast Join the free Topline Slack channel to connect with 600+ revenue leaders to keep the conversation going beyond the podcast: https://www.joinpavilion.com/topline-slack Chapters: 00:00 Introducing Jaleh Rezaei 04:00 Can SaaS Era Companies Go AI Native? 05:01 From Gusto To Founding Mutiny 07:00 When AI Became A Reasoning Engine 11:28 Why Running Two Products Was Impossible 13:32 Shutting Down An 8-Figure Business 16:18 Winning Formula: Speed, No Backup Plan 20:17 The Hard Months After Deprecation 24:47 Acute Pain Versus Chronic Pain 29:17 CEO Has To Be The Bad Guy (Sometimes) 37:17 AI Margins And Credit-Based Pricing 40:10 A $5,000 Deck Versus 50 Credits 47:03 Sales-Led To PLG For Enterprise 50:37 Brand As The Remaining Moat 1:00:34 Bulls and Bears
Federal Tech Podcast: Listen and learn how successful companies get federal contracts
For decades, software was "bespoke." Each application was carefully crafted to solve a specific problem. When this was applied to the federal government, they discovered that this process was slow and unpredictable. The solution: a software factory. From custom-built software to software that could be created in an organization that had a "bubble" that could standardize on federal security guidelines. From there, they could deliver safer, higher-quality software much faster. Today, we sit down with Jorge Lopez, Vice President of Security Operations and Trust and Safety at GitLab, to discuss the concept of software factories in the federal government. Lopez admits the importance of visibility, collaboration, and compliance in these factories. However, during the interview, he notes that gaps in DevSecOps often stem from organizational issues, such as miscommunication between security and development teams. He emphasizes the need for proper monitoring, incident response, and managing secrets to mitigate risks. Digging deeper, he states that if a federal organization does not have monitoring in place, they will only discover a problem after it happens. One approach is to go to the people responsible for defending the software. Lopez has seen success when security operations teams and software factory teams talk to each other. Lopes also discusses the impact of AI on code production and the importance of proactive measures to ensure software factory security.
Sandra und Daniel berichten über DNS-Probleme, Camping im Garten sowie darüber, dass man auch im hohen Alter mathematische Probleme lösen kann.
Most enterprises rolling out AI are quietly optimizing for the wrong thing: speed, volume, lines of code shipped. Manu Narayan, CIO of GitLab, argues that efficiency gains alone are about to drive companies straight into a productivity ceiling they can't engineer their way out of. The reason is simple and uncomfortable—a faster version of a pre-AI workflow is still a pre-AI workflow. The real unlock isn't speeding up what you already do; it's rebuilding it from first principles.In this episode of Talking AI, Matt Paige sits down with Manu Narayan, GitLab's first-ever CIO, who owns the company's internal AI strategy, enterprise technology, and data infrastructure—in effect, putting GitLab to work inside GitLab. Manu makes the case for moving beyond incremental AI adoption toward a genuine operating model for enterprise AI.The conversation covers GitLab's hub-and-spoke operating model and its embedded "AI transformation owners," why the team measures adoption against business KPIs instead of token counts, how "human in the loop" is evolving into an orchestration role, and why context and traceability—not raw speed—are the new differentiators in software development.In this episode, you'll hear about:Why efficiency gains alone lead straight into a productivity ceilingThe gap between AI "haves and have-nots" and how to close itGitLab's hub-and-spoke (really hub-spoke-hub) operating modelWhat an "AI transformation owner" does inside each division"Full stack" people: stretching roles end-to-end across a life cycleThe difference between a skill and an agent—and why it mattersBuilding an internal skill library with governance built inWhy token maxing is the wrong scoreboard, and what to measure insteadHow human-in-the-loop shifts to a higher level of abstractionWhat "loops" mean and the move to being a manager of agentsWhy context and traceability beat commoditized speedLocal vs. repo-side development and where guardrails belongHandling shadow AI with a genuine "happy path to production"The first move for a CIO stuck optimizing the old workflowKey Moments00:03:11 — The AI "haves and have-nots" inside every enterprise00:04:30 — The hub-and-spoke operating model and "AI transformation owners"00:07:00 — "Full stack" people: stretching roles across the whole life cycle00:09:06 — Skills vs. agents — human-invoked versus autonomous00:12:00 — The daily to-do skill that briefs Manu every morning00:12:58 — Building an internal skill library with a review-and-promote pipeline00:16:13 — Why GitLab doesn't ascribe to "token maxing"00:18:02 — Measuring adoption by role — beyond lines of code and MRs00:24:30 — Local vs. repo side: where governance and guardrails actually live00:27:39 — How "human in the loop" is evolving as agents outpace review00:30:49 — What "loops" really are, and the manager-of-agents shift00:33:52 — Why context and traceability are the new differentiators00:37:29 — The maintainability fear and the bottleneck that moved to review00:39:55 — SaaSpocalypse, agent sprawl, and the limits of MCP00:42:51 — Shadow AI and the "happy path to production"00:45:29 — The first move Monday morning: executive alignment on scope00:47:33 — Advice to his pre-AI self: stay nimble, it's okay to pivotKey LinksGitLabConnect with Manu on LinkedInMentioned in this episode:AI Opportunity FinderFeeling overwhelmed by all the AI noise out there? The AI Opportunity Finder from HatchWorks cuts through the hype and gives you a clear starting point. In less than 5 minutes, you'll get tailored, high-impact AI use cases specific to your business—scored by ROI so you know exactly where to start. Whether you're looking to cut costs, automate tasks, or grow faster, this free tool gives you a personalized roadmap built for action.
About This Episode Remote work has matured far beyond simply allowing employees to work from home. As organizations embrace distributed teams and artificial intelligence, the conversation is no longer about location—it's about designing systems that enable people to work effectively from anywhere. In this episode of the Future of Work® Podcast, Frank Cottle welcomes Darren Murph, recognized by CNBC as an "oracle of remote work" and former workplace strategy leader at GitLab. Together, they examine why successful distributed organizations don't happen by accident. They discuss the importance of intentional workplace design, operational discipline, documentation, knowledge management, AI readiness, asynchronous collaboration, and the rise of small, globally connected companies. The conversation also explores the future of entrepreneurship, the "manager of one" philosophy, coworking as an extension of remote work, operational fit, and why AI makes organizational knowledge more valuable than ever. Whether you're building a startup, leading a distributed team, or preparing your organization for AI, this episode offers practical insights into creating resilient, scalable organizations.
Six years on from the great work‑from‑home experiment, the conversation about remote work in Ireland has gone strangely quiet. Roughly 15% of Irish companies now hire fully remotely and 45% are hybrid, but the change is, in Tracy Keogh's words: “stitchy, not systemic.” Headlines focus on big multinationals pulling people back to the office, while a whole category of globally distributed employers passes Ireland by.In this episode of The HRLocker Room, HRLocker's CEO, Crystel Robbins Rynne, sits down with Tracy Keogh, Co‑founder of Grow Remote, to unpack where Ireland has actually landed on remote working, and what it would take to turn dispersed progress into a genuine national advantage.Grow Remote was founded pre‑pandemic to solve the practical problems of remote work and maximise its benefits for people, places and employers. Today it runs Europe's largest training programmes for remote workers, managers and adopting organisations, and operates the world's largest offline community of remote employees, with local meet‑ups across Ireland growing by 120%.Tracy makes the economic case in stark numbers: for every 1,000 remote jobs landed into Ireland, the country gains approximately €10 million in tax revenue and €20 million in GDP, and proper PRSI/PAYE employment, dispersed across towns from Mullingar to West Cork. She also doesn't shy away from the harder truths, saying: there is real, organised pushback against remote work in parts of Ireland, the “right to request” legislation isn't moving the needle, and not every company should go remote…and that's fine.Tune in for a candid, practical conversation about defining what remote work actually means, why the IDA / Enterprise Ireland model needs a location‑agnostic equivalent, and the surprising story of an Irish AI team that landed roles a multinational couldn't fill in the US.Key topics we exploreThe state of remote work in Ireland: 15% fully remote, 45% hybrid, and why the progress is “stitchy, not systemic”Why the “right to request remote work” legislation isn't shifting the dialThe missing category: global remote‑first employers (Automattic, GitLab, Zapier) and how to win them into the Irish marketThe economic case: €10M in tax revenue and €20M in GDP for every 1,000 remote jobs landedDefining “remote work”: from one‑day‑a‑week hybrid to fully nomadic, and why location‑agnostic employment is the sweet spotThe talent gap: why Irish candidates and global remote employers aren't finding each otherLocal pushback against remote work and why blocking it isn't an optionWhat an “IDA for remote work” could look like in practiceWhy some organisations should stay office‑first, and how to know which camp you're inWould you like to know how HRLocker can help you with your people management in 2024? Click here to get in touch today!
Chris Ronzio, Jonathan Ronzio, and Sasha Robinson trade hot takes on the workforce headlines everyone's arguing about. Are companies really cutting jobs because of AI, or just using it as cover for bad decisions and overhiring? Is the war on middle management (à la GitLab's three-layer flattening) a smart move or a morale killer? And with engagement at an 11-year low and "quiet stayers" replacing quiet quitters, how much turnover is actually healthy?Then things get personal: Chris and Jonathan go head-to-head on remote vs. hybrid work—data, digital-nomad nostalgia, and all—while Sasha referees and lays out where Trainual actually lands today. Plus, why your manager shouldn't be your "guidance counselor," the case for an employee "aspiration index," and how AI is letting great managers handle 15 reports instead of 5.(The performance management deep-dive? Bumped to next week—this one ran away from us.)
JDK 26 optimise la JVM dans ses moindres recoins, le SDK Java d'Agent2Agent passe en 1.0, Micronaut 5 est là. Côté terrain, un retour d'expérience après 40 jours à coder avec 100 % d'IA : génie ou junior, Alzheimer numérique et dette technique invisible. Pendant ce temps, GitLab restructure, Microsoft suspend ses licences Claude Code, et un développeur injecte un prompt destructeur dans sa lib JUnit. La révolution IA a un coût et les boites commencent à s'en rendre compte. Enregistré le 12 juin 2026 Téléchargement de l'épisode LesCastCodeurs-Episode-341.mp3 ou en vidéo sur YouTube. News Langages Les améliorations de performance dans le JDK 26 https://inside.java/2026/06/09/jdk-26-performance-improvements/ Côté bibliothèques, l'API LazyConstant (anciennement StableValue) fait son entrée en prévisualisation pour permettre une initialisation paresseuse, sécurisée pour les threads et optimisée par le mécanisme de constant-folding de la JVM. L'extraction de chaînes de caractères via MemorySegment::getString a été revue pour réduire considérablement les allocations intermédiaires et les copies en mémoire off-heap, accélérant fortement les traitements sur les chemins critiques (hot paths). La méthode générée automatiquement hashCode() pour les classes de type record a été optimisée par la JVM pour atteindre un niveau de performance équivalent à une implémentation écrite manuellement. Le ramasse-miettes G1 bénéficie du JEP 522 qui redessine sa table de cartes (card-table) afin de réduire les coûts de synchronisation des barrières d'écriture, offrant un gain de débit de 5 % à 15 % sur les applications manipulant énormément de références d'objets. Grâce au JEP 516 (Project Leyden), le cache d'objets Ahead-of-Time (AOT) adopte un format de flux agnostique, ce qui lui permet d'être compatible avec n'importe quel Garbage Collector, y compris le ramasse-miettes à très faible latence ZGC. Le démarrage de la JVM s'accélère par défaut lorsqu'aucune taille de tas n'est configurée, car HotSpot n'applique plus de pourcentage initial (InitialRAMPercentage) mais démarre directement avec la taille minimale (MinHeapSize) pour éviter d'allouer des métadonnées inutiles. Les threads virtuels gagnent en robustesse en étant désormais capables de céder la main (yield) pendant les phases d'initialisation des classes, éliminant ainsi le risque de famine des threads porteurs (carrier threads). Le compilateur C2 JIT améliore son modèle de coût pour la vectorisation des boucles (SIMD) et se montre maintenant capable de compiler et d'optimiser des méthodes dotées de listes de paramètres extrêmement longues. Librairies Release candidate du A2A Java SDK supportant versions 0.3 et 1.0 en même temps https://medium.com/google-cloud/a2a-java-sdk-1-0-0-cr1-released-f0c651ec9139 Dernière étape avant la GA : Toutes les fonctionnalités prévues pour la version 1.0 sont finalisées. Migration simplifiée depuis la Beta1. Compatibilité v0.3 : Ajout d'une couche de compatibilité permettant aux agents v1.0 de communiquer avec les systèmes v0.3 (via JSON-RPC, gRPC ou REST). Support natif pour Android (nouvel AndroidHttpClient). Uniformisation des clients HTTP pour garantir une cohérence entre les versions. Nouveau parseur SSE (Server-Sent Events) conforme aux spécifications. Ça y est, le SDK Java de l'Agent 2 Agent Protocol est sorti en version 1.0 finale ! (avec compatibilité v0.3 et v1.0) https://medium.com/google-cloud/a2a-java-sdk-1-0-0-final-released-10c05b6aee34 Lancement officiel : Sortie de A2A Java SDK 1.0.0.Final, la première version stable (GA) du protocole Agent2Agent. Objectif du protocole : Standard ouvert (Linux Foundation) permettant aux agents IA de communiquer, déléguer des tâches et collaborer, indépendamment du langage ou du framework. Interopérabilité : Introduction de l'Integration Test Kit (ITK) pour valider la compatibilité entre les SDK (Java, Python, TypeScript, etc.). Transports supportés : Support complet et équivalent pour JSON-RPC, gRPC et HTTP+JSON/REST. Alignement total avec la spécification A2A 1.0.0. Passage aux Java records pour l'immutabilité et moins de code répétitif. Architecture interne basée sur un MainEventBus pour garantir la persistance et éviter les conditions de concurrence. Intégration d'OpenTelemetry pour le suivi et la surveillance. Support d'Android et compatibilité descendante avec la version 0.3. Installation : Gestion des dépendances via Maven BOM (org.a2aproject.sdk). Sortie de Micronaut 5.0 https://micronaut.io/2026/05/20/micronaut-framework-5-0-0-released/ Lancement majeur : Disponibilité générale de Micronaut 5, incluant une refonte de plus de 70 modules et la plateforme BOM. Baselines techniques : Support de Java 25, Groovy 5, Kotlin 2.3 et GraalVM 25.0.3. Optimisations internes : Amélioration significative des performances au démarrage et réduction de la surcharge à l'exécution via une refonte du conteneur IoC et du traitement à la compilation. Architecture HTTP : Support stable de HTTP/3, nouvelle API de formulaires (multipart) et annotations de nullabilité (JSpecify) pour une meilleure interopérabilité Kotlin/IDE. Configuration : Nouveau système d'importation de configuration (remplaçant le Bootstrap Configuration) et validateur de schéma JSON intégré. Fiabilité : Nouvelles API programmatiques pour les politiques de retry et circuit breaker. Sécurité & Outils : Mise à jour majeure des dépendances (Jackson 3, Ktor 3), rafraîchissement du Panneau de contrôle et diagnostics AOT améliorés. Écosystème : Mises à jour complètes pour les bases de données (Data, SQL, R2DBC, MongoDB, Redis), le cloud (AWS, Azure, GCP, OCI) et les tests (JUnit 6, Testcontainers 2.0). Évolutions notables : Intégration HTMX dans Micronaut Views, retrait du support RxJava 2 et migration de divers processeurs d'annotations vers des modules dédiés. Comment rajouter un agent IA dans une app Android, avec le tout nouveau framework ADK pour Kotlin https://glaforge.dev/posts/2026/05/21/wiring-adk-kotlin-agents-in-an-android-application/ Guillaume a participé au développement et au lancement du nouveau runtime ADK pour Kotlin et Android https://developers.googleblog.com/adk-kotlin-android-building-ai-agents/ Tutoriel sur comment intégrer un agent ADK dans une app Dépendances : Ajout du noyau ADK (google-adk-kotlin-core) et du processeur KSP dans build.gradle.kts. Sécurité API : Utilisation de local.properties pour stocker la clé API Gemini et l'exposer via BuildConfig afin d'éviter le hardcoding. Définition de l'agent : Création d'un objet LlmAgent configuré avec le modèle Gemini, des instructions spécifiques et des outils (ex: GoogleSearchTool). Utilisation de InMemoryRunner pour gérer automatiquement le contexte et l'historique de la session. Implémentation de runAsync avec StreamingMode.SSE pour un retour en temps réel dans l'interface. Threading : Exécution des requêtes réseau sur Dispatchers.IO et mise à jour de l'état de l'interface utilisateur sur Dispatchers.Main. Comment développer et hoster des agents IA sur la plateforme d'agents managés de DeepMind https://glaforge.dev/posts/2026/05/21/managed-agents-with-the-gemini-interactions-java-sdk/ L'équipe DeepMind de Google a lancé une plateforme d'agents managés sur son API Gemini Interactions https://blog.google/innovation-and-ai/technology/developers-tools/managed-agents-gemini-api/ Guillaume a implémenté un SDK Java pour utiliser cette API Gemini Interactions, qui donne entre autre accès à tous les modèles mais aussi à cette plateforme managée d'agents IA Agents managés : Permet d'exécuter des agents autonomes qui raisonnent, planifient et exécutent du code dans des environnements isolés (sandboxes), sans gestion d'infrastructure par le développeur. Environnement distant : Utilise des espaces de travail Linux éphémères dans le cloud via le paramètre remote, permettant l'accès réseau et la persistance des fichiers sur plusieurs appels. Agents prédéfinis : Accès immédiat à des agents spécialisés comme deep-research-pro (recherche multi-étapes) ou antigravity (tâches de codage généralistes). Agents personnalisés : Possibilité de configurer ses propres agents avec des instructions système dédiées, des outils spécifiques (exécution de code, recherche Google) et des règles réseau (egress) personnalisées. Architecture basée sur les étapes (Steps) : Utilise une structure de données typée (Step, Content) pour suivre le raisonnement de l'agent, ses appels de fonctions et ses résultats en temps réel. Outils et Schémas : Inclut des utilitaires pour générer des schémas JSON complexes via une interface fluide (DSL), par réflexion Java ou par parsing JSON. Streaming réactif : Support natif des événements en temps réel (SSE) pour suivre la progression de l'agent et recevoir les deltas de contenu au fur et à mesure de la génération. Flexibilité : Fournit un gestionnaire de routage (InteractionsHandler) pour créer facilement des serveurs proxy ou des backends intermédiaires traitant les interactions Gemini. Spring Boot 4.1 https://github.com/spring-projects/spring-boot/wiki/Spring-Boot-4.1-Release-Notes Support natif pour Spring gRPC permettant de créer et tester facilement des applications clientes et serveurs basées sur Netty ou des Servlets via HTTP/2 Introduction du lazy fetching pour les connexions JDBC via la propriété spring.datasource.connection-fetch=lazy afin de ne prendre une connexion du pool que lorsqu'un Statement est réellement exécuté Amélioration de l'auto-configuration de Jackson permettant de définir globalement les contraintes de lecture/écriture pour les formats JSON, XML et CBOR via des propriétés de configuration Sécurisation des clients HTTP bloquants et réactifs face aux attaques SSRF grâce à l'introduction d'un InetAddressFilter bloquant les requêtes sortantes vers des adresses spécifiques Améliorations majeures autour d'OpenTelemetry avec le support complet des variables d'environnement OTel, la possibilité de désactiver le SDK via une propriété globale et l'ajout du support SSL sur les exporters OTLP Ajout de l'auto-configuration pour l'utilisation de Spring Batch avec MongoDB incluant un nouveau starter dédié spring-boot-batch-data-mongo Auto-configuration des endpoints @RedisListener sans nécessiter la déclaration manuelle d'un RedisMessageListenerContainer Dépréciation du support de Apache Derby (projet arrêté), suppression définitive du mode layertools du JAR et réintroduction du support de Spock 2.4 (avec Groovy 5) Upgrade des dépendances majeures de l'écosystème avec notamment Spring Framework 7.0.8, Spring Security 7.1.0 et Micrometer 1.17.0 Outillage Vous êtes plutôt endive ou chicorée ? La librairie Chicory qui permet d'exécuter du code WASM à partir de son application Java est forkée et rejointe la Bytecode Alliance pour continuer son développement https://bytecodealliance.org/articles/endive-and-the-next-chapter-of-webassembly-on-the-jvm Annonce d'Endive : Nouveau projet hébergé par la Bytecode Alliance ; fork de Chicory (moteur WebAssembly pur Java, sans dépendance native). Objectif principal : Permettre aux développeurs Java d'intégrer, charger et déployer des modules Wasm nativement via les workflows Java habituels. Compilateur "Redline" : Intégration à venir de Redline (basé sur Cranelift) pour compiler le Wasm en code machine natif ; performances comparables à Rust/Wasmtime. Zéro dépendance (Java 25+) : Grâce à l'API standard Foreign Function & Memory (Project Panama), l'exécution à vitesse native se fait sans composants externes. Modèle de Composants (Component Model) : Support futur prévu pour consommer des composants (Rust, Go, JS, etc.) via des interfaces typées et sécurisées directement dans la JVM. Prochaines étapes : Fusion de Redline, conformité stricte aux specs Wasm (dont WasmGC) et amélioration du support WASI. Un visualisateur de sessions de travail avec Antigravity https://glaforge.dev/posts/2026/06/11/antigravity-brain-visualizer/ Un projet open source construit avec Micronaut, LangChain4j et GraalVM pour analyser les sessions de travail avec l'outil de développement agentique Antigravity (de Google) Analyse toutes les étapes, les requêtes utilisateur, les outils utilisés, les erreurs rencontrées, les réponses du modèle Gemini fait une analyse pour comprendre les moments clés de cette session de travail Outil buildé avec l'aide d'Antigravity lui-même SBX-Kits : des environnements de développement simplifiés pour les débutants (et les autres) https://k33g.org/20260501-sbx-kits.html Philippe Charrière (:whale: ) présente SBX-Kits (Sandbox Kits), une initiative personnelle visant à simplifier radicalement la mise en place d'environnements de développement pour les débutants, en éliminant la complexité d'installation des outils traditionnels. Chaque "kit" est une archive prête à l'emploi contenant un outil de développement spécifique (comme un langage, un framework ou une base de données) configuré pour s'exécuter de manière isolée et portable. La philosophie du projet repose sur le principe de "zéro configuration" et "zéro dépendance globale", permettant de tester une technologie ou de commencer à coder immédiatement sans polluer son système d'exploitation. L'approche technique s'appuie sur des scripts légers et des binaires portables pré-packagés, offrant une alternative plus simple et moins gourmande en ressources que les conteneurs Docker ou les configurations d'IDE complexes pour l'apprentissage. L'objectif à terme est de proposer un catalogue de kits couvrant les technologies courantes (JavaScript, Python, petites bases de données) pour faciliter les ateliers de programmation et le prototypage rapide. De nombreux kits sont disponibles sur https://github.com/docker/sbx-kits-contrib ghui: une interface utilisateur en ligne de commande (TUI) interactive pour GitHub https://github.com/kitlangton/ghui ghui est un outil en ligne de commande (TUI) écrit en Rust qui fournit une interface visuelle, interactive et rapide directement dans le terminal pour interagir avec GitHub. Il permet de gérer ses pull requests, ses issues et ses notifications sans avoir à ouvrir son navigateur web ou à taper de longues commandes avec la CLI officielle de GitHub. L'outil propose une navigation fluide au clavier, des raccourcis efficaces, et permet de réaliser des actions courantes comme valider une PR, ajouter des commentaires, attribuer des reviewers ou inspecter les logs des GitHub Actions. Conçu pour être extrêmement réactif, ghui s'intègre naturellement dans le flux de travail des développeurs adeptes du terminal et du mode "sans souris". Sortie de Homebrew 6.0.0 https://brew.sh/2026/06/11/homebrew-6.0.0/ Introduction du mécanisme de sécurité Tap Trust : comme les dépôts tiers (taps) peuvent exécuter du code Ruby arbitraire non sandboxé sur la machine, Homebrew demande désormais une confiance explicite de l'utilisateur avant d'évaluer ou d'exécuter leur code. L'API JSON interne devient le choix par défaut, offrant un système plus léger et beaucoup plus rapide pour les développeurs. Sécurisation renforcée de l'environnement avec l'implémentation du sandboxing sur Linux. Évolution des comportements par défaut basés sur un sondage utilisateur : le mode "ask" est activé par défaut pour les développeurs, affichant un résumé des dépendances et une demande de confirmation avant toute action de brew install ou brew upgrade. Améliorations notables des performances globales, notamment un boost de ~30 % sur la vitesse de la commande brew leaves et la parallélisation de la récupération des bottles (binaires) lors des mises à jour. Ajout du support initial pour la prochaine version d'Apple, macOS 27 (Golden Gate). Multiples optimisations pour brew bundle, incluant une gestion plus sécurisée des installations de paquets npm. Méthodologies Retour d'expérience très détaillé et 100% humain sur 40 jours avec une équipe 100% AI hormis le superviseur https://www.linkedin.com/pulse/jai-vir%C3%A9-mon-%C3%A9quipe-de-dev-pour-une-100-ia-pendant-40-luc-bonnin-jlgjf/ Voici le résumé en bullet points : Expérimentation de 40 jours : remplacer une équipe de dev par 100% IA agentique (Cursor) sur un vrai projet en production (playthatsheet.com, 200k lignes de code legacy) Chiffres bruts : 2,3 milliards de tokens consommés, 1 477 prompts, 260 564 lignes ajoutées (+145%), 59% du code final produit par l'IA ROI vertigineux à court terme : 9 mois de travail humain livrés en 40 jours, coût total 260$ d'abonnement + 15 jours de supervision, ROI x18 Profil psy de l'IA : Alzheimer (oublis de contexte), schizophrène (change de méthodo), ado de 12 ans (refait les mêmes erreurs), oscille entre génie et junior sans prévenir Effet iceberg : la dette technique ne disparaît pas, elle se camoufle et s'accélère ; hallucinations = bombes à retardement détectables uniquement par relecture humaine ligne par ligne Paradoxe du bateau de Thésée : perte de paternité et de maîtrise fine du code, baisse de l'autonomie du dev humain qui valide sans avoir construit Arnaque du "monkey money" : consommation de tokens opaque, non corrélée à la complexité (écart de 350% sur des prompts identiques), facturation imprévisible donc impossible à budgéter Syndrome du bazooka : les devs utilisent l'IA même pour changer une couleur CSS, atrophie progressive des compétences et coût écologique délirant Risque stratégique : dépendance irréversible aux vendeurs de tokens (Nvidia, Anthropic, OpenAI), business non rentable qui devra augmenter ses prix Conseil final : approche Pareto, garder 20% du temps en code "fait main", nommer un responsable stratégie IA, l'humain senior reste irremplaçable pour superviser Une libraries de test JUnit cache un prompt qui demande aux coding agents d'effacer les tests https://arstechnica.com/security/2026/05/fed-up-with-vibe-coders-dev-sneaks-data-nuking-prompt-injection-into-their-code/ Agacé par les « vibe coders », un développeur introduit une injection de prompt destructrice dans son code Le développeur de jqwik (un moteur de tests pour JUnit 5) a volontairement inséré une injection de prompt dans la version 1.10.0 de sa bibliothèque Java pour saboter le travail des agents d'IA. L'instruction injectée via la sortie standard (stdout) ordonne textuellement aux LLM d'ignorer les consignes précédentes et de supprimer l'intégralité du code et des tests jqwik du projet. Pour dissimuler cette action aux yeux des développeurs humains, le mainteneur a utilisé des séquences d'échappement ANSI qui effacent la ligne d'injection dans les émulateurs de terminaux interactifs. La modification a été découverte par un utilisateur qui a pointé du doigt les risques majeurs et disproportionnés pour les machines des utilisateurs, bien que certains outils comme Claude d'Anthropic aient détecté et bloqué la consigne malveillante. Face aux critiques de la communauté et aux accusations de comportement infantile ou potentiellement illégal, le développeur a mis à jour ses notes de version pour documenter explicitement son opposition à l'usage de son outil par des IA, avant de refuser tout commentaire supplémentaire sur conseil de son avocat. La réalité du rôle de Principal Engineer https://leaddev.com/career-development/reality-being-principal-engineer Le passage au rôle de Principal Engineer marque une transition majeure où les compétences techniques ne suffisent plus, l'impact se mesurant désormais à travers l'influence, la stratégie et la capacité à aligner la technique avec les objectifs business. Contrairement aux attentes, le quotidien est souvent marqué par une forme d'isolement, car le poste se situe à l'intersection de la direction (qui attend des solutions) et des équipes techniques (qui attendent des directives), sans appartenance directe à un groupe précis. Le rôle exige d'accepter une grande part d'ambiguïté et l'absence de retours immédiats, les projets et les décisions stratégiques mettant parfois des mois ou des années à porter leurs fruits. La gestion du temps devient un défi critique, nécessitant de savoir naviguer entre les sollicitations constantes, la présence en réunion et le besoin de préserver des moments de réflexion approfondie pour concevoir des visions à long terme. La réussite à ce niveau repose sur le développement de compétences humaines pointues (soft skills), notamment la négociation, la communication vulgarisée auprès des profils non techniques, et la capacité à faire grandir les autres ingénieurs par le mentorat. Sécurité Une attaque de la chaîne d'approvisionnement npm utilise binding.gyp pour compromettre des dizaines de paquets https://cybersecuritynews.com/binding-gyp-supply-chain-attack-compromises-dozens-of-npm-packages/ Une nouvelle variante du ver auto-propageable "Shai-Hulud", baptisée "Miasma", cible l'écosystème npm (et PyPI sous le nom de "Hades") en dissimulant son exécution dans le fichier binding.gyp au lieu des scripts classiques preinstall ou postinstall. La technique, surnommée "Phantom Gyp", exploite le fait que npm lance automatiquement node-gyp rebuild dès qu'un fichier binding.gyp est présent à la racine d'un paquet pour compiler des modules natifs C/C++, exécutant ainsi le code malveillant dès la commande npm install. L'attaque contourne la plupart des outils de sécurité traditionnels car l'injection s'appuie sur l'évaluation récursive de commandes (via la syntaxe ) ou directement sur la fonction eval() de Python sous-jacente à GYP, cachée sous n'importe quelle clé du fichier. Le script malveillant télécharge un runtime alternatif (Bun) pour échapper aux détections comportementales de Node.js, puis moissonne les identifiants et secrets des développeurs et des environnements CI/CD (npm, GitHub, AWS, GCP, Azure, Kubernetes, HashiCorp Vault). Plus de 57 paquets npm (dont le SDK serveur de Vapi ou des outils liés à l'IA) et des dizaines de paquets PyPI ont été infectés via des comptes de mainteneurs compromis, le ver republiant automatiquement de nouvelles versions vérolées en utilisant les jetons volés. Loi, société et organisation Restructuration chez Gitlab https://about.gitlab.com/blog/gitlab-act-2/ GitLab entame une restructuration majeure pour s'adapter à l'ère de l'intelligence artificielle agentique, incluant une réduction d'effectifs planifiée de manière transparente et ouverte. L'entreprise prévoit de réduire de 30 % le nombre de pays où elle maintient de petites équipes, d'aplatir sa hiérarchie en supprimant jusqu'à trois niveaux de gestion, et de réorganiser la R&D en une soixantaine d'équipes plus petites et autonomes. Les processus internes vont être revus en intégrant des agents d'IA pour automatiser les revues, les approbations et les passages de relais afin d'accélérer le rythme de travail. La stratégie repose sur la conviction que le logiciel sera bientôt écrit par des machines et dirigé par des humains, ce qui va multiplier la demande de logiciels et transformer le rôle des ingénieurs vers la résolution de problèmes complexes. Sur le plan technique, GitLab reconstruit son infrastructure sous-jacente (notamment Git) pour supporter la charge massive générée par les agents d'IA, tout en misant sur l'orchestration du cycle de vie, la centralisation du contexte des données et une gouvernance intégrée. Le modèle économique évolue vers un système hybride combinant les abonnements classiques et une tarification à la consommation pour le travail effectué par les agents d'IA. Un LLM local sur un mac pourrait coûter plus cher en électricité qu'un modèle hébergé sur OpenRouter dans le cloud https://www.williamangel.net/blog/2026/05/17/offline-llm-energy-use.html Conclusion : L'inférence locale sur Mac M5 Max est 3x plus chère et 2x plus lente que le cloud (OpenRouter). Électricité : Négligeable (~0,02 $/heure pour 50-100W). Matériel (Le vrai coût) : Achat du Mac à 4 299 $; l'amortissement sur 3 à 5 ans plombe la rentabilité horaire. Coût au million de tokens (Gemma 4 31b) : Mac M5 Max : 0,40 à4, 79 (pour 10-40 tokens/s). OpenRouter : 0,38 à0, 50 (pour 60-70 tokens/s). Verdict pro : Le temps humain perdu à cause de la lenteur locale coûte infiniment plus cher que les tokens cloud. Privilégier les API (Anthropic, OpenRouter). Ai didn't kill your junior pipeline https://andrewmurphy.io/blog/ai-didnt-kill-your-junior-pipeline-you-did L'IA n'a pas tué le recrutement des juniors, les entreprises l'ont fait elles-mêmes, par effet de mode. Sans juniors, pas de futurs seniors : on retire l'échelle qui nous a tous fait monter. Tout le monde pêche dans le même bassin de seniors sans le réapprovisionner, pénurie garantie dans 3-5 ans. Une équipe 100% senior + IA est fragile : un départ et tout le savoir tacite s'évapore. Les juniors posent les "pourquoi ?" qui révèlent les bugs et processus absurdes ; l'IA, elle, exécute sans questionner. Les seniors s'atrophient aussi en déléguant leur réflexion à l'IA, pince à double effet sur les compétences. Dépendre des outils IA, c'est sous-traiter sa stratégie talents à des fournisseurs dont les prix vont tripler. Solution : redéfinir le rôle junior (revue de code IA + mentorat), pas le supprimer. Les rapports internes de Microsoft révèlent la crise des coûts de l'IA : les agents coûtent plus cher que les employés humains https://fortune.com/2026/05/22/microsoft-ai-cost-problem-tokens-agents/ Des données et rapports internes chez Microsoft et d'autres géants de la tech ébranlent la promesse de rentabilité de l'IA, révélant que le déploiement d'agents autonomes à l'échelle de l'entreprise revient souvent plus cher que de payer des humains pour le même travail. Le modèle de tarification à l'usage (basé sur les tokens) se heurte à la nature même des architectures agentiques : contrairement à un simple chatbot, un agent boucle, enchaîne les appels d'outils, crée des sous-agents et auto-évalue son code, ce qui multiplie la consommation de tokens par un facteur de 5 à 30, voire jusqu'à 1 000 fois pour des tâches de programmation complexes. L'impact financier sur les budgets de calcul cloud est immédiat ; par exemple, Uber a entièrement épuisé l'intégralité de son budget annuel 2026 dédié au codage par IA en l'espace de seulement quatre mois. Face à cette explosion des coûts, des retours en arrière drastiques sont observés : Microsoft a ainsi commencé à suspendre une grande partie de ses licences internes Claude Code pour rediriger d'urgence ses milliers de développeurs vers sa propre solution moins onéreuse, GitHub Copilot CLI. Les directeurs techniques (CTO) et acheteurs de solutions logicielles qui ont signé des contrats pluriannuels basés sur des projections de réduction de masse salariale se retrouvent pris au piège, les gains réels de productivité ne parvenant pas à compenser les factures d'infrastructure exorbitantes. Conférences La liste des conférences provenant de Developers Conferences Agenda/List par Aurélie Vache et contributeurs : 11-12 juin 2026 : DevQuest Niort - Niort (France) 11-12 juin 2026 : DevLille 2026 - Lille (France) 12 juin 2026 : Tech F'Est 2026 - Nancy (France) 15 juin 2026 : Jupyter Workshops: Demystifying MyST Markdown in Education - Orsay (France) 16 juin 2026 : Mobilis In Mobile 2026 - Nantes (France) 17-19 juin 2026 : Devoxx Poland - Krakow (Poland) 17-20 juin 2026 : VivaTech - Paris (France) 18 juin 2026 : Tech'Work - Lyon (France) 22-26 juin 2026 : Galaxy Community Conference - Clermont-Ferrand (France) 23-24 juin 2026 : MWCP 2026 - Paris (France) 24-25 juin 2026 : Agi'Lille 2026 - Lille (France) 24-26 juin 2026 : BreizhCamp 2026 - Rennes (France) 26-27 juin 2026 : LeHACK - Paris (France) 27 juin 2026 : Asynconf - Paris (France) 2 juillet 2026 : Azur Tech Summer 2026 - Valbonne (France) 2 juillet 2026 : MCP Connect Travel Edition - Paris (France) 2-3 juillet 2026 : Sunny Tech - Montpellier (France) 3 juillet 2026 : Agile Lyon 2026 - Lyon (France) 6-8 juillet 2026 : Riviera Dev - Sophia Antipolis (France) 28-30 août 2026 : State of the Map - Champs-sur-Marne (France) 4 septembre 2026 : JUG Summer Camp 2026 - La Rochelle (France) 10-11 septembre 2026 : Nantes Craft - Nantes (France) 17 septembre 2026 : dotAI - Paris (France) 17-18 septembre 2026 : API Platform Conference 2026 - Lille (France) 18 septembre 2026 : WordCamp Bretagne - Rennes (France) 18 septembre 2026 : dotJS - Paris (France) 18 septembre 2026 : WordCamp Bretagne - Rennes (France) 22 septembre 2026 : Salon Data 2026 - Nantes (France) 22-23 septembre 2026 : Agile en Seine & IA 2026 - Paris (France) 24 septembre 2026 : OWASP AppSec Days France 2026 - Paris (France) 24 septembre 2026 : PlatformCon Paris - Paris (France) 24 septembre 2026 : React Native Connection 2026 - Paris (France) 24-26 septembre 2026 : Paris Web 2026 - Paris (France) 25 septembre 2026 : SAP Inside Track Paris 2026 - Paris (France) 28-29 septembre 2026 : 4th Tech Summit on AI & Robotics - Paris (France) & Online 1 octobre 2026 : WAX 2026 - Marseille (France) 1-2 octobre 2026 : Volcamp - Clermont-Ferrand (France) 2 octobre 2026 : DevFest Perros-Guirec 2026 - Perros-Guirec (France) 5-9 octobre 2026 : Devoxx Belgium - Antwerp (Belgium) 8-9 octobre 2026 : Forum PHP 2026 - Marne-la-Vallée (France) 12 octobre 2026 : Dev With AI - Paris (France) 22-23 octobre 2026 : Agile Tour Bordeaux 2026 - Bordeaux (France) 26 octobre 2026 : Agile Tour Montpellier - Montpellier (France) 27-29 octobre 2026 : Directions EMEA 2026 - Paris (France) 29-30 octobre 2026 : BDX I/O 2026 - Bordeaux (France) 29-30 octobre 2026 : Agile Tour Nantais 2026 - Nantes (France) 29 octobre 2026-1 novembre 2026 : Pycon FR - Biarritz (France) 30 octobre 2026 : Cloud Nord 2026 - Lille (France) 4-5 novembre 2026 : Devoxx Morocco - Casablanca (Morocco) 14-15 novembre 2026 : Capitole du Libre - Toulouse (France) 19 novembre 2026 : DevFest Toulouse 2026 - Toulouse (France) 19 novembre 2026 : Agile Laval 2026 - Laval (France) 19 novembre 2026 : OVHcloud Summit - Paris (France) 19 novembre 2026 : Codeurs en Seine - Rouen (France) 27 novembre 2026 : DevFest Paris 2026 - Paris (France) 1-3 décembre 2026 : Apidays Paris - Paris (France) 2-3 décembre 2026 : Cloud Native AI Summit Europe - Paris (France) 4 décembre 2026 : DevFest Lyon 2026 - Lyon (France) 4 décembre 2026 : DevFest Dijon 2026 - Dijon (France) 9-10 décembre 2026 : OpenSource Expérience - Paris (France) 9-10 décembre 2026 : DevOps REX - Paris (France) 10 décembre 2026 : KCD Provence - Aix-en-Provence (France) 7-9 avril 2027 : Devoxx France 2027 - Paris (France) 3 juin 2027 : Cloud Native Days France 2027 - Paris (France) Nous contacter Pour réagir à cet épisode, venez discuter sur le groupe Google https://groups.google.com/group/lescastcodeurs Contactez-nous via X/twitter https://twitter.com/lescastcodeurs ou Bluesky https://bsky.app/profile/lescastcodeurs.com Faire un crowdcast ou une crowdquestion Soutenez Les Cast Codeurs sur Patreon https://www.patreon.com/LesCastCodeurs Tous les épisodes et toutes les infos sur https://lescastcodeurs.com/
NuNet is building a decentralised compute and orchestration network where people can contribute spare CPU, GPU, RAM and other resources, while developers and organisations can deploy workloads across available infrastructure. In this episode, Peter talks with Jennifer from NuNet about the new NuNet Appliance and why it matters for making decentralised compute more practical for everyday users.The conversation covers how NuNet matches the right compute to the right job, how the Appliance lowers the barrier to onboarding devices, and why use cases like n8n automations, private AI agents, edge AI, Cardano SPO infrastructure and web deployment workflows are a natural fit for the network. Jennifer also explains NuNet's zero-trust security model, pricing approach, organisations, ensembles, deployment templates, and how NTX fits into orchestration fees.If you have spare compute, want to run private AI workloads, or are building in the DePIN and Cardano ecosystem, this episode gives a practical look at how NuNet is moving from concept to usable infrastructure.Key Takeaways:- NuNet is a decentralised compute and orchestration platform that lets people contribute spare compute and lets workloads find suitable resources automatically.- The NuNet Appliance is designed to make onboarding CPUs, GPUs, RAM and other compute resources much easier for non-expert users.- NuNet can support broad workloads, including n8n automation, private AI agents, Qwen-based LLM deployments, edge AI, web builds and Cardano SPO infrastructure.- The network uses a zero-trust model where machines are cryptographically identified and verified at each interaction.- Compute pricing is designed around stable currency values, with automatic conversion into NTX rather than forcing users to price workloads directly in a volatile token.- NuNet organisations can let other DePIN projects bring their own communities and native tokens while still using NuNet's orchestration layer.- Ensembles and templates are intended to simplify deployments so users do not need to manually understand every YAML configuration detail.- NuNet is open source, with docs, GitLab, Discord, Medium and X available for people who want to try the network or contribute.Links & References:- NuNet — Compute Orchestration for a Decentralized World: https://link.learncardano.io/eGKGuZ- What is NuNet? | NuNet Documentation: https://link.learncardano.io/rHu2E4- x.com: https://link.learncardano.io/NIhPKR- https://link.learncardano.io/Tlu7wNWebsite: https://link.learncardano.io/bQ68RcX/Twitter: https://link.learncardano.io/3a1QtvDisclaimer: This content is for educational purposes only. Nothing constitutes financial advice.DISCLAIMER: This content is for informational and educational purposes only and is not financial, investment, or legal advice. I am not affiliated with, nor compensated by, the project discussed—no tokens, payments, or incentives received. I do not hold a stake in the project, including private or future allocations. All views are my own, based on public information. Always do your own research and consult a licensed advisor before investing. Crypto investments carry high risk, and past performance is no guarantee of future results. I am not responsible for any decisions you make based on this content.
We found the best way for a Linux user to manage Windows: keep it remote, keep it contained, and touch the desktop as little as possible.Sponsored By:Webroot: Webroot is cloud-based antivirus, engineered to stay out of your way. For a limited time, you can save sixty percent.Jupiter Party Annual Membership: Put your support on automatic with our annual plan, and get one month of membership for free!Managed Nebula: Meet Managed Nebula from Defined Networking. A decentralized VPN built on the open-source Nebula platform that we love.Support LINUX UnpluggedLinks:
This week on The Audit Podcast, Danielle Ritter, VP and Head of Internal Audit at GitLab and former CAE at Instacart, joins the show to share lessons from her leadership journey and practical advice for audit professionals at every stage of their careers. Drawing from her experience leading audit functions across multiple organizations, Danielle discusses what matters most during a CAE's first 100 days, how to build credibility with stakeholders, and why strong relationships are essential to an effective audit function. She also shares how her team is embracing AI, developing new skills, and preparing for the future of the profession. 2:06 – Using AI in work and everyday life 5:16 – Where CAEs should focus: insights vs. efficiency 6:46 – Day One: listening and learning 10:11 – Navigating the CAE interview process 13:09 – How to define and demonstrate value 16:40 – What information belongs in the boardroom 19:00 – A practical approach to building strong relationships 22:45 – AI and the future of job security 27:55 – Making time for self-directed learning 30:07 – Final thoughts: your career does not define you Be sure to connect with Danielle on LinkedIn. Also, be sure to follow us on our social media accounts on LinkedIn, Instagram, and TikTok. Also be sure to sign up for The Audit Podcast newsletter and to check the full video interview on The Audit Podcast YouTube channel. This podcast is brought to you by Greenskies Analytics, the services firm that helps auditors leap-frog up the analytics maturity model. Their approach for launching audit analytics programs with a series of proven quick-win analytics will guarantee the results worthy of the analytics hype. Whether your audit team needs a data strategy, methodology, governance, literacy, or anything else related to audit and analytics, schedule.
In this episode of Elixir Wizards, hosts Charles Suggs and Emma Whamond sit down with Marek Šuppa, creator of the Missing GitHub Status page, a project that reconstructs GitHub's historical uptime data and reveals discrepancies between official status reporting and the platform's actual reliability. Marek tells us about his dev journey from open source contributor at DuckDuckGo to machine learning engineer at Cisco-acquired Slido. Then, we discuss GitHub's evolution from a hosted Git service into a critical developer tool. We cover reliability, transparency, AI-driven platform growth, developer workflows, and the challenges of balancing convenience with resilience. Along the way, we cover alternative platforms, self-hosted solutions, and whether recent outages are changing how developers think about ownership, dependency, and the future of software collaboration. Topics Discussed in this Episode: Why did Mr. Shu create the Missing GitHub Status Page? GitHub's reported uptime versus developer experiences How open source contributions shaped Marek's career The evolution of GitHub from tool to critical infrastructure Centralization risks in modern software development Git's distributed roots and today's platform-centric workflows Developer reactions to GitHub outages Transparency and accountability in status reporting AI's impact on developer platforms and infrastructure demands Microsoft's stewardship of GitHub Forgejo, Codeberg, and alternative Git hosting platforms Self-hosted Git solutions and tradeoffs Network effects and platform lock-in The social side of software collaboration Building resilience into developer workflows What GitHub outages teach us about infrastructure dependency Links Mentioned: The Missing GitHub Status Page https://mrshu.github.io/github-statuses/ Slido https://www.slido.com/ https://duckduckgo.com/ The official GitHub Status Page https://www.githubstatus.com/ Statuspage.iohttps://www.atlassian.com/software/statuspage Zig Leaves GitHub https://ziglang.org/news/migrating-from-github-to-codeberg/ Ghostty Leaves GitHub https://mitchellh.com/writing/ghostty-leaving-github GitLab https://about.gitlab.com/ Codeberg https://codeberg.org/ https://git.kernel.org/ Forgejo Lightweight Self-Hosting https://forgejo.org/ Former GitHub CEO Thomas Dohmke launches Entire https://entire.io/news/former-github-ceo-thomas-dohmke-raises-60-million-seed-round Update on Spain and LALIGA blocks of the internet https://vercel.com/blog/update-on-spain-and-laliga-blocks-of-the-internet
Bom dia Tech! Tudo bem? Meu nome é Arthur Givigir e hoje é quinta-feira, dia 04 de junho de 2026 e trago para vc as principais notícias de tecnologia, vamos lá?Quer patrocinar ou fazer uma parceria com o Bom dia Tech? Mande um e-mail para contato@bomdia.teche vamos conversar!Apoio03:48: Promoções do 6.6 da Amazon - Diversos ProdutosNotícias00:00: ☀️ Bom dia Tech!00:23:
George Tsilis discusses Wednesday's top moving stocks right after the opening bell. He highlights GitLab's (GLTB) earnings beat and job cut announcements. George turns to Macy's (M) Ulta Beauty's (ULTA) earnings and what they mean for the retail space. ======== Schwab Network ========Empowering every investor and trader, every market day.Subscribe to the Market Minute newsletter - https://schwabnetwork.com/subscribeDownload the iOS app - https://apps.apple.com/us/app/schwab-network/id1460719185Download the Amazon Fire Tv App - https://www.amazon.com/TD-Ameritrade-Network/dp/B07KRD76C7Watch on Sling - https://watch.sling.com/1/asset/191928615bd8d47686f94682aefaa007/watchWatch on Vizio - https://www.vizio.com/en/watchfreeplus-exploreWatch on DistroTV - https://www.distro.tv/live/schwab-network/Follow us on X – https://twitter.com/schwabnetworkFollow us on Facebook – https://www.facebook.com/schwabnetworkFollow us on LinkedIn - https://www.linkedin.com/company/schwab-network/ About Schwab Network - https://schwabnetwork.com/about
Markets are facing a conundrum of overbought technicals, says Tom White when analyzing the price action on Wall Street. He urges caution for traders in the short term. That's not stopping earnings from muscling strength, seen in Palo Alto Networks' (PANW) beat despite a pullback in shares. Tom also notes GitLab's (GTLB) earnings beat and announcement of job cuts. Macy's (M) posts a strong quarter that adds confidence in the retail sector. ======== Schwab Network ========Empowering every investor and trader, every market day.Subscribe to the Market Minute newsletter - https://schwabnetwork.com/subscribeDownload the iOS app - https://apps.apple.com/us/app/schwab-network/id1460719185Download the Amazon Fire Tv App - https://www.amazon.com/TD-Ameritrade-Network/dp/B07KRD76C7Watch on Sling - https://watch.sling.com/1/asset/191928615bd8d47686f94682aefaa007/watchWatch on Vizio - https://www.vizio.com/en/watchfreeplus-exploreWatch on DistroTV - https://www.distro.tv/live/schwab-network/Follow us on X – https://twitter.com/schwabnetworkFollow us on Facebook – https://www.facebook.com/schwabnetworkFollow us on LinkedIn - https://www.linkedin.com/company/schwab-network/ About Schwab Network - https://schwabnetwork.com/about
In der heutigen Folge sprechen die Finanzjournalisten Daniel Eckert und Holger Zschäpitz über Infineons historischen Rekord, die Disruptionsangst bei den Börsenbetreibern und warum die Börsenrallye in 2 Wochen abrupt enden könnte. Außerdem geht es um Nvidia, Hewlett Packard Enterprise, Broadcom, Applied Materials, Lumentum, Coherent, Qualcomm, ON Semiconductor, Lattice Semiconductor, Alphabet, Amazon, Microsoft, CoreWeave, Nebius, Salesforce, ServiceNow, Intuit, Workday, The Trade Desk, Palo Alto Networks, GitLab, Ulta Beauty, Infineon, Suss Microtec, Siemens, SAP, Bayer, Deutsche Börse, Cboe Global Markets, CME Group, Nasdaq, CrowdStrike, C3.ai, Five Below, Macy's, Medtronic, Rent the Runway, Inditex, Micron Technology, SK Hynix, AT&S, Ibiden, Unimicron, ING, Spotify, Amundi FTSE All World GDP-Weighted (WKN: ETF345). Wir freuen uns an Feedback über aaa@welt.de. Noch mehr "Alles auf Aktien" findet Ihr bei WELTplus und Apple Podcasts – inklusive aller Artikel der Hosts. Hier bei WELT: https://www.welt.de/podcasts/alles-auf-aktien/plus247399208/Boersen-Podcast-AAA-Bonus-Folgen-Jede-Woche-noch-mehr-Antworten-auf-Eure-Boersen-Fragen.html. Hier könnt ihr den AAA-Newsletter abonnieren: https://www.welt.de/newsletter/article232797673/Alles-auf-Aktien-Der-taegliche-Boersen-Newsletter-fuer-WELTplus-Abonnenten.html Und - ganz neu: AAA gibt es jetzt auch auf Instagram: https://www.instagram.com/alles_auf_aktien/ Disclaimer: Die im Podcast besprochenen Aktien und Fonds stellen keine spezifischen Kauf- oder Anlage-Empfehlungen dar. Die Moderatoren und der Verlag haften nicht für etwaige Verluste, die aufgrund der Umsetzung der Gedanken oder Ideen entstehen. Hörtipps: Für alle, die noch mehr wissen wollen: Holger Zschäpitz können Sie jede Woche im Finanz- und Wirtschaftspodcast "Deffner&Zschäpitz" hören. +++ Werbung +++ Du möchtest mehr über unsere Werbepartner erfahren? Hier findest du alle Infos & Rabatte! https://linktr.ee/alles_auf_aktien Impressum: https://www.welt.de/services/article7893735/Impressum.html Datenschutz: https://www.welt.de/services/article157550705/Datenschutzerklaerung-WELT-DIGITAL.html
Investors digest cybersecurity earnings, AI developments and shifting risk appetite. Mandy Xu of Cboe explains how options traders are positioning and where speculative activity is building. Palo Alto Networks headlines earnings. Saket Kalia of Barclays breaks down the results and what they signal for cybersecurity spending, enterprise demand and the broader software landscape. Ulta and GitLab add fresh reads on the consumer and technology spending. A major conversation on AI in healthcare: our Kate Rooney sits down with Microsoft AI CEO Mustafa Suleyman and Mayo Clinic CEO Dr. Gianrico Farrugia to discuss how artificial intelligence is transforming medicine, research and patient care. Sunhaina Sinha of Raymond James discusses the capital raising environment and whether funding conditions are improving for companies and investors. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Today we are talking about AI, How to stay up to date with it, and if it will really take our jobs with guests Angie Byron & Amber Matz. We'll also cover AI Best Practices for Drupal as our module of the week. For show notes visit: https://www.talkingDrupal.com/555 Topics What Is AI Learners Club Amber Defines the Club Origin Story and DrupalCon AI Debate and Community Tensions Issue Queue Conduct and Moderation Thread Tone vs Substance AI Adoption Outside Drupal Conflict Mediation Playbook Maintainer Burnout and Flood Safe Space Learners Club How the Club Started Picking Topics and Demos AI Taking Our Jobs Future of Learners Club Resources Context Control Center AI Learners Club Initiative page Event calendar YouTube Playlist Session Recaps Next session (Claude Design) Slack: #ai-learners Most wanted topics What Angie's working on these days Guests Amber Matz - tugboatqa.com amber-himes-matz Angie Byron - ai_best_practices webchick Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi Scott Falconer - managing-ai.com scott-falconer MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Do you want to start using AI tools for Drupal development, in the most efficient way possible? There's a composer plugin for that! Module name/project name: AI Best Practices for Drupal Brief history How old: created in Mar 2026 by Angie Byron (webchick), one, of today's guests, a long-time Drupalist, one-time Acquian, and a fellow Canadian Versions available: dev version only, which doesn't seem directly opinionated about what version of Drupal you're using, though it does have minimum versions of PHP and Symfony libraries that suggest Drupal 10 is functionally your minimum Maintainership It is officially seeking co-maintainers Test coverage Documentation - an in-depth README, or you can ask an AI model! (like I did for this segment) 54 open "Work Items" on Gitlab, so lots of active discussion already Module features and usage AI Best Practices for Drupal aims to be the opinionated starter experience for AI-assisted Drupal development You can think of it as a single Composer install that makes any AI coding agent "speak Drupal": following community standards, preferring contrib over custom code, and avoiding framework-naive mistakes. It replaces scattered, tool-specific CLAUDE.md files and Cursor rules that some Drupal developers currently maintain individually, with one canonical, community-governed package that works across Claude Code, Cursor, Copilot, and more. With contributions by a variety of Drupal luminaries including Marcus Johansson, Christoph Briedert, and Scott Falconer, it's the Drupal equivalent of Laravel Boost: stop explaining Drupal to your AI every session and just get writing code. After install or update, it will create an AGENTS.md file from a provided template if there isn't one already, or it will update a specifically marked "ai-best-practices" section of an existing file You will also have a directory of provided skills, and guidance for creating new Drupal agent skills Also included is a set of evals, meant to automatically identify when AI models go off course and provide feedback AI Best Practices for Drupal is meant to provide guidance that will be particularly useful for AI agents, so it's ideal for Drupal developers getting started with AI tools, or for AI developers who want to get started with Drupal
The power of choice is in full effect! How you can leverage GitLab to publish your next Quarto document online, how to bring key R functional paradigms to a Python session, and adding a larger safety net with your unit tests with {mutagen} 0.2.0. Episode Links This week's curator: Jon Carroll - @jonocarroll@fosstodon.org (Mastodon) & @jonocarroll.fosstodon.org.ap.brid.gy (Bluesky) & @carroll_jono (X/Twitter)Deploying Quarto documents with GitLabFunctions over Idioms - Writing R in Python with rfunsmuttest 0.2.0: More Mutators, Better Reporting, and Parallel ExecutionEntire issue available at rweekly.org/2026-W22Supplement ResourcesData Science at the Command Line https://datascienceatthecommandline.com/DevOps for Data Science https://do4ds.com/{pak} System Requirements https://pak.r-lib.org/reference/sysreqs.htmlSupporting the showUse the contact page at https://serve.podhome.fm/custompage/r-weekly-highlights/contact to send us your feedbackR-Weekly Highlights on the Podcastindex.org - You can send a boost into the show directly in the Podcast Index. First, top-up with Alby, and then head over to the R-Weekly Highlights podcast entry on the index.A new way to think about value: https://value4value.infoGet in touch with us on social mediaEric Nantz: @rpodcast@podcastindex.social (Mastodon), @rpodcast.bsky.social (BlueSky) and @theRcast (X/Twitter)Mike Thomas: @mike_thomas@fosstodon.org (Mastodon), @mike-thomas.bsky.social (BlueSky), and @mike_ketchbrook (X/Twitter) Music credits powered by OCRemix Wrestling with Double Bass - Street Fighter II - Malcos - https://ocremix.org/remix/OCR01270A Simple Flip can Change Fate - Final Fantasy VI - Level 99 - https://ocremix.org/remix/OCR02692
У свіжому дайджесті DOU News обговорюємо реліз в Україні: Мінцифра додала ШІ-асистента в застосунок «Дія». У глобальному тек-секторі черговий парадокс — корпорація Cisco звільняє 4000 співробітників на тлі рекордних прибутків, а GitLab повністю перекроює структуру заради ери ШІ-агентів. Також у випуску нова жорстка reCAPTCHA від Google та свіжа аналітика ринку праці 2026 року. Дивіться ці та інші новини українського та світового тек-сектору. Таймкоди 00:00 Інтро 01:07 Як айтівці шукають роботу в 2026 році 05:55 На скільки зростає зарплата айтівців при зміні роботи 06:54 ШІ-асистента додали у мобільний застосунок «Дія» 08:16 На війні загинув QA-спеціаліст, переможець Премії DOU Геннадій Міщевський 09:07 Головні фічі нової Android 17 12:14 Cisco звільняє 4000 співробітників попри надприбутки 13:44 GitLab проводить масштабну реструктуризацію заради ери ШІ-агентів 17:19 Anthropic повернула OpenClaw та використання сторонніх агентів 20:12 Anthropic знову обійшла OpenAI за кількістю бізнес-клієнтів 22:29 Нова reCAPTCHA від Google блокує доступ до сайтів 24:16 Батьки звинувачують ChatGPT у загибелі сина через погану пораду 26:44 Що рекомендує Женя: статтю про вайб-кодинг та агентну інженерію та канал «AI Engineer»
Take the 2026 AI Engineering Survey and get >$2k in credits and AIE WF tickets!On the product side, everyone is getting Computer - Perplexity, Manus, Cursor, and so on. Meanwhile on the research side, agentic evals like TerminalBench and GDPVal are also assuming computer (Harbor). On both ends, the consolidating LLM OS stack has become a standard toolkit, and Daytona is one of a small set of AI Infra companies that are booming because of it.“The end of localhost” has been Ivan Burazin's obsession for more than a decade.Something that is all too familiar…Long before agents became the default way people talked about software development, Ivan was already chasing the idea that development should not depend on a fragile local machine. CodeAnywhere, one of the first browser-based IDEs, was an early attempt at that future: move the development environment into the cloud, make setup reproducible, and free developers from the endless “works on my machine” tax.The thesis was directionally right, but the market wasn't ready yet.However, agents changed that. They do not care about a laptop, desk setup, or favorite editor. They need a computer they can access through an API: something stateful enough to keep working, fast enough to spin up instantly, flexible enough to resize, isolated enough to be safe, and composable enough to run the messy real-world workflows that real software engineering actually requires.Daytona isn't just selling “sandboxes” in the narrow code-execution sense. It is the latest version of Ivan's original localhost thesis.In this episode, Daytona's CEO joins swyx to explain why AI agents need more than code execution boxes: they need composable computers, stateful sandboxes, instant startup, dynamic resources, and infrastructure that can survive workloads going from zero to 100,000 CPUs.We go deep on the new agent compute market: Daytona's hard pivot from human dev environments to AI sandboxes, the New Year's Eve MVP that customers begged for, why Daytona runs on bare metal with its own scheduler, how one customer runs almost 850,000 sandboxes a day, and why RL/eval workloads went from 0% to roughly 50% of usage in just months. Ivan also explains why agents need Windows and macOS machines, why CLI may matter more than MCP, why Kubernetes is painful for this workload, and why the future AI cloud may look more like Stripe than AWS.We discuss:* How Daytona grew out of CodeAnywhere, Shift, and the “end of localhost” thesis* Why Daytona pivoted from human dev environments to AI sandboxes* Why agents need composable computers instead of disposable code execution boxes* The New Year's Eve MVP that customers chased API keys for* Why Daytona chose bare metal, stateful snapshots, and its own scheduler* How Daytona spins up one sandbox in ~60ms and 50,000 sandboxes in ~75 seconds* Why Daytona's biggest customer runs ~850,000 sandboxes a day* How RL/eval workloads create zero-to-100,000 CPU spikes* Why RL workloads went from 0% to roughly 50% of Daytona usage* Why customers compare Daytona against EKS/GKS and say they're “never going back”* Why every AI agent may need a computer, including Windows and macOS environments* The Apple licensing constraints that make macOS sandboxes hard* Why CLI gives agents more power than MCP* How open source helps agents integrate Daytona* Why agent-generated PRs may break today's CI/CD assumptions* Why AI SaaS companies reselling tokens may face a cold shower* Why the AI cloud may look more like Stripe than AWSIvan Burazin* LinkedIn: https://www.linkedin.com/in/ivanburazin* X: https://x.com/ivanburazinDaytona* Website: https://www.daytona.io* X: https://x.com/daytonaioTimestamps* 00:00:00 Hook* 00:01:12 Introduction* 00:03:15 CodeAnywhere, Shift, and the end of localhost* 00:05:58 What Daytona is: composable computers for AI agents* 00:08:07 The pivot from dev environments to AI sandboxes* 00:10:17 The New Year's Eve MVP and customers begging for API keys* 00:12:56 Bare metal, stateful sandboxes, and Daytona's scheduler* 00:17:28 60ms startup, 50,000 sandboxes, and 850K daily runs* 00:21:53 Spiky RL/eval workloads and the new agent infra problem* 00:28:12 RL workloads, Kubernetes pain, and dynamic resizing* 00:33:31 Why every AI agent needs a computer* 00:38:48 macOS sandboxes and Apple's licensing problem* 00:44:28 Why CLI may matter more than MCP* 00:48:11 Open source, GitHub stars, and agent integration* 00:53:11 Git, CI/CD, and agent collaboration bottlenecks* 00:58:15 Founder life and building a 25-person infra company* 01:02:44 AI SaaS, token resale, and API-first business models* 01:06:10 GPU sandboxes, data centers, and compute growth* 01:09:48 Why the AI cloud may look more like Stripe than AWS* 01:11:26 Closing thoughtsTranscriptIntroduction: Daytona, CodeAnywhere, and the End of LocalhostSwyx [00:00:02]: Okay, we're in the studio with Ivan Burazin, CEO of Daytona. Welcome.Ivan [00:00:07]: Thanks for having me, man.Swyx [00:00:08]: Ivan, you and I go back.Ivan [00:00:10]: Way back.Swyx [00:00:11]: How I don't even know how, you found, did you reach out or, for Shift.Ivan [00:00:17]: I reached out to you. The reason was you - we were just - we were thinking about I was one of the co-founders of CodeAnywhere, the first browser-based IDE, and so we were thinking a long time of, localhost should die. And you had this article.Swyx [00:00:29]: End of localhost.Ivan [00:00:30]: Then I reached out to you because of that, and then we talked, and I was actually at a different job and learning about I was the head of, developer experience, and you were quite well-versed in that, and I actually reached out to you, among other people, how do we go about that? What are the key things and whatnot at this point in time? And you were nice enough to take the call, and I remember I was late on your call with you.Swyx [00:00:51]: I don't remember.Ivan [00:00:52]: I remember because I was with my then I'm thinking of a girlfriend or wife at that point in time, I'm not sure. It's the same person, so that's great, and I was late ‘cause we were, in, Italy on, vacation, and then I was late for something. I felt so bad, and you were so nice to be, good about.Swyx [00:01:10]: The reason I'm nice is because I'm also late to other people, so it's like, who's, who's without sin here, yeah, so I have to, for those who don't know, InfoBip Shift, there's this whole thing that, you did in the past, and, and that was basically one of the inspirations for me starting AI Engineer, which is like, I have to thank you for giving me that push to be like, “Oh, you can, you can build and sell conferences?”Ivan [00:01:34]: I remember you asked you asked me at the beginning to give me advisory shares, and I was so focused on what we were doing, I said no, and I should've took the advisory shares. So I'm sorry, dude. But anyway.Swyx [00:01:43]: We're not, we're not venture backed.Ivan [00:01:44]: No, it doesn't matter.Swyx [00:01:45]: It's Yeah, anyway, so I think what's impressive about you is that CodeAnywhere is the thing that you've been trying to build, and, you kind of put it on hold and then came back after InfoBip. Just give us the story, do you - the story and the origin story, going into Daytona.From CodeAnywhere and Shift to DaytonaIvan [00:02:05]: Sure. Like, really way back, me and my co-founder have been together. I say this, I've said this multiple times, it's like we were married and divorced and married. Some people actually ask me is my co-founder my partner. they thought it literally. It's not literally, but we have done multiple companies together, and to your point, we had this shift where we went from the CodeAnywhere to the conference called Shift, and then back to, Daytona. We originally started stacking servers, doing like virtualization in the early 2000s and, routers and doing basically all these things, at a foundational level, and that was a services company which we sold to focus on what my co-founder actually invented, which was the very first browser-based IDE, right, I say the first. Before us was actually Heroku. They did it for a very short time until they became Heroku. But outside of them, we were the only one, and it was called.Swyx [00:02:55]: There was Cloud9.Ivan [00:02:57]: Cloud9 came out slightly after us. There was Replit, which came out when we stopped doing it, Replit came out, and they have been successful since then, which is great. There was Nitrous.io. There was quite a few that existed at the time, but it was like too early. But the interesting part is that we, at that point in time, because there was no VS Code, there was no Kubernetes, and Docker had just started when we Or I'm not sure if it was even public at that point in time. And so we had to build everything to the whole stack ourselves and that was the key learning that we brought into and that we've been using in Daytona today. So it was super early. There's about 3 million people used CodeAnywhere. It was slightly, it was angel-backed more than venture-backed. We ended up paying everyone back because it didn't have that sort of scale. But, three years ago, we started something similar with Daytona, which is not what we are today, but it was automating dev environments for human engineers, the basically the underlying stack of CodeAnywhere. And then we did a hard pivot last January to sandboxes. And so here we are.Swyx [00:04:01]: Historic pivot, yeah, and, it's one of those things where, I had independently invested in CodeAnywhere, but also in E2B, and then both of you pivoted into the same thing, and I'm like, “F**k.”Ivan [00:04:12]: You invested, you invested in Daytona. You invested in Daytona. But you were the first If we had not got your check, we wouldn't have done it.Swyx [00:04:18]: No way.Ivan [00:04:19]: No, it was like, “We have to get him on board first,” and you were that kicker that we, that got us off the ground.Swyx [00:04:23]: No, because you were putting me on your pitch deck, man. I was like, “Man, this is like a good trip if I don't invest.”Ivan [00:04:29]: That's because it was your quote. It's like we.Swyx [00:04:30]: Yeah. It's the end of localhost.Ivan [00:04:31]: Did a bunch of research about end of localhost and who was interested in that,.Swyx [00:04:34]: No, that's like, I put, I wrote that blog post, and every single company in that field reached out to me, and then every VC who was receiving those pitches then also had to call me and, talk it, talk through it with me.Ivan [00:04:47]: It's finally happening though.Swyx [00:04:48]: It was really super interesting.Ivan [00:04:48]: It's finally happening.Swyx [00:04:49]: It's finally happening.Ivan [00:04:49]: Yeah, it's finally.Swyx [00:04:49]: It's finally happening, with maybe sort of non-human users. Yeah, so what is Daytona today? Let's get like a quick description. I'm wearing the shirt.What Daytona Is Today: Composable Computers for AI AgentsIvan [00:04:58]: You're wearing the shirt. Yes,.Swyx [00:04:59]: It says, I think your branding is very good. Like, it's very consistent. It runs AI code. Like, it cannot be simpler.Ivan [00:05:05]: Exactly, but we're gonna probably have to change that.Swyx [00:05:07]: Oh, s**t.Ivan [00:05:07]: It's also a subset of what we do. Unfortunately, we really love this, Run AI Code is super simple. People interpret it different ways. I think we've given out 5,000, 6,000 of these shirts. People wear them with pride because it doesn't really market about us.Swyx [00:05:21]: Yeah, Daytona's on the back.Ivan [00:05:22]: It markets the back. It markets to the person itself, so I think we did a really good job on that one. But it is also a subset of what we do, because people, when they think about Run AI Code, they just think about these small, let's call it isolates, code execution boxes that, you send some code, you get an output. Whereas what Daytona is today is essentially composable computers for AI agents. It is, the market calls them sandboxes which can be misleading.Swyx [00:05:44]: All these things. All these things on.Ivan [00:05:45]: Yeah, exactly, ‘cause it can be misleading ‘cause people usually think about sandboxes as a demo or a test environment versus a production-grade environment. But what Daytona does, if you think of the laptop that you have in front of you or the computer that's over there, or, my wife is an architect, so she has like a Windows with a 3D graphics card inside to do 3D rendering. Like, as humans, we have different computers or different compositions of computers. And our belief is strongly that agents today and going forward will need all these different compositions of computers to do different types of tasks. And so we offer that basically through an API.Swyx [00:06:19]: Yeah, to give people - I'm trying to sort of front-load all the aha moments or the wow moments so that people can, stay engaged and click like and subscribe. the market is exploding, right? Like, you have been reporting 74% month-on-month growth, and it also, it's just been growing for a while. Like, it's been going like this. And every single - It's not just you guys. It's every single.Ivan [00:06:41]: Everyone, yeah.Swyx [00:06:42]: Sort of, compute provider. I don't know if you agree with me saying compute provider or not.Ivan [00:06:48]: It's fine.Swyx [00:06:48]: Yeah. So like organically PLG-driven growth, but also enterprise is doing super well, I think I wanna rewind to January of last year when you did the pivot. Like, so you obviously called this market early, and you were positioned for it, and you are now one of the market leaders. But what was the insight that made you do the pivot?The Pivot: From Human Dev Environments to Agent SandboxesIvan [00:07:06]: The insight that made us do this pivot is the quarter before that, so end of 2024, when we had - Basically, we did a demo with - I don't I think we discussed this as well, Devin was not public. You actually gave me access to Devin at that time. So Devin.Swyx [00:07:25]: I did?Ivan [00:07:26]: Yeah, you gave me access.Swyx [00:07:26]: I don't think I was supposed.Ivan [00:07:27]: Yeah, exactly.Swyx [00:07:28]: Yeah, I.Ivan [00:07:28]: So it doesn't matter. You.Swyx [00:07:29]: Yeah. I gave like three friends access.Ivan [00:07:31]: Yeah, or it was a call and you showed it to me. It doesn't matter. but OpenDevin was available, which is now called OpenHands. And so we're like, “Oh, this seems to be a thing. This is not public. Let's take our for human automation of dev environments and take, OpenDevin and launch that as a SaaS.” And we did that. Not very many people signed up and used it, but a lot of people reached out that were building agents, and they were like, “Hey, my agent needs a compute sandbox runtime,” whatever you wanna call it. I forgot what it was called at that point. And then we were like, “Oh, amazing. This is a new market. Here is our infrastructure. Here's our product, and go.” And what we found really fast, soon, was that people did not like what we had built. It didn't work. And I remember talking to people at the beginning when we're doing this, the sandbox we're building for agents. People were like, “Oh, why is it different? It's the same thing. We have like EC2, we have VMs, we have all these things.” But we saw that everyone we gave it to, it was like 20, 30 people, they all said, “No.” Like, “This is not what we need. This sort of breaks.” And basically, me and my co-founder not knowing a lot about - ‘cause we're infra people. We're not AI people. So I basically took it upon myself to like watch every single podcast that exists, including all of, all of these and all that, and sort of get up to date, read all the blogs, like get, understand what's going on.Swyx [00:08:45]: Do you wanna shout out who else was useful, just in case people are also looking.Ivan [00:08:49]: Generally we -, I looked at There's a few of podcast, different segments and different types. So there's you guys, No Priors, Bill Gurley's was great while.Swyx [00:09:04]: VG2, yeah.Ivan [00:09:05]: Yeah, while it was around. So there's a few. 20VC is interesting from a different dynamic, and some are different dynamic. But there was, also Red Points.Swyx [00:09:14]: We're not really about the compute market.Ivan [00:09:15]: It was also already - Sorry?Swyx [00:09:16]: You're, you want - You're looking at the agent infra market.Ivan [00:09:19]: I was looking at the agent market and the AI market in general and sort of understanding who are the players, what the perception, and how that goes. And like obviously you complement this with like going to conferences, going to events, going to meetups, reading white papers, like doing all the things that you have to do to understand what's happening. And so when we figured, when we sort of had an idea of what we had to build, literally over the New Year's Eve, literally on New Year's Eve, I half vibe coded the first MVP, first minimal viable product of what Daytona is today. And I went to sleep at like 3:00 AM or something like that. I was doing - I just put my like baby daughter and wife to sleep and, Happy New Year's, and go back to just, doing this. And I sent it to my co-founder, my CTO, and he saw it in the morning. He's like, “This is absolute garbage.” “Do not show this to anybody at all, but the idea is good.” And so he took two weeks, and he rebuilt it.Swyx [00:10:09]: Did it like look like that? Listen, I - It was rough idea.Ivan [00:10:12]: Oh, not even, not even close. Like it was it was way worse. But it was like a very - It was a simplistic view of what it should be. Like, it worked, but it was not ideal. And so he went, we went down the whole, which is his job as CTO, to go, and he came back with this version. We then called all the people that had said like, “This is garbage,” a quarter ago. And we set up these calls, and we gave it to - We just demoed it to everyone. And all the calls went long, every single one. They were 15-minute calls, and they all went to like 25, 30 minutes or whatnot. And everyone said, “We need, we want access.” There was no login, just an API key, ‘cause it was just a beta or an alpha. And they said, “Oh, we want access.” And we're like, “Sure, yeah. Okay, thank you very much.” But after like the next day, if we'd not send it, every single one, like every call that we did, everyone came back, “Where is my API key?” Like everyone wanted it. We're like, “S**t.” Like this is it. Like I've never felt So one, the understanding to your point was like most people thought it was the same infrastructure for humans and agents. We understood a quarter ago it's not. We just didn't know what was the right primitive. And then when we came, and we can talk about what that is, and we gave it to these people, I've never seen, I've never experienced - I've done multiple companies in my life. I've never experienced this, that people literally call you if you do not give them access. Like they want access right now. And so it's like, okay, they don't want this. the thing that they want doesn't seem to exist, or they have not found it, and they really want what we want. And then when we understood that we're onto something, and then when you think about the size of the market, like the market for human engineers and enterprise is a very large market, so think GitLab or whatnot. But the market for every single agent that will exist ever in the future is just like, what is that market? How big is that? And we're like, “We are all in on this.” And so that is where we made sort of the cut between the old product and the new one.Bare Metal, Stateful Sandboxes, and the Lambda + EC2 ModelSwyx [00:12:02]: Yeah. But it wasn't composable at the time?Ivan [00:12:05]: It was very - It was basically just a Linux box that you could change, that you could define number of CPUs, disk, and RAM. Like that is what you could do, but you couldn't have multiple operating systems, you couldn't resize it on the fly, you couldn't add a GPU, you couldn't do like all the things. It was just the, just the first sort of variation of that, yeah.Swyx [00:12:22]: Was it bare metal from the start?Ivan [00:12:24]: It was bare metal from the start. And so the interesting thing that we thought about right away, so our.Swyx [00:12:29]: Which, give people the background, what is the normal path?Ivan [00:12:32]: Yeah, so, basically most providers run this on top of VMs. And also.Swyx [00:12:37]: Firecracker.Ivan [00:12:38]: Yeah, they run on Firecracker and VM. And so we also fire - We can get - We have multiple isolation layers and we can do that. But the common way to do it is that they, one, that the state of the machine, or the hard disk is not part of the sandbox itself. And the other thing is they're not meant to last forever. So most of them are preemptible, like they can There's a time that they can live. And so our thought was when we were going into this is, agents will be like humans in the sense of you don't want your laptop to be shut down until you're done with work. Like, and you want to close the lid and open the lid, it's the same state. So you - Agents would want that, like the pause and come back. They want those two things. But also agents really want speed, right? Can they get it? So when we thought about it's like we need something insanely fast, how to make it fast, how to make it long-running, and stateful. And so those two things, it's like combining a Lambda and an EC2, right? Those two things together. And so we didn't have an idea how others did it, ‘cause we didn't know too that there was a market around this. It was more like, okay, this is what we need, what they need. And we looked at Kubernetes, it wasn't wasn't good enough for that. We looked at Nomad, it didn't enable that. And so our history in rewriting our own scheduler at CodeAnywhere is basically what my CTO came up with. Like, he's like, “Oh, the learnings from there,” and he brought it. And the funny thing is, our third co-founder, when he saw it, he's like, “Dude, what is this? This is like 2008.” Like, we went back in time, and he's like, “Exactly.” And so the reason why Daytona is like super fast, and you see this on benchmarks, is we essentially, we run on bare metal. We have our own scheduler, we use the underlying, disk, CPU, and RAM of the underlying machine, which means your IOPS are insanely fast because there's no, there's no network between an EBS or something like that. But also the snapshot, the point in time, the templates, are also preloaded on the bare metal machines. So when you fire off a sandbox from a template or a snapshot, you're essentially directed to the bare metal machine where that snapshot is based on that NVMe drive, and then it literally just turns on that machine, and it's local. There's no network latency, anything on there. And so that is sort of the specificities that we, when we're thinking from first principles, what a computer would look like for an agent, that is what we came up with, and that's what we created.Benchmarks, 60ms Startup, and 50,000 SandboxesSwyx [00:15:02]: Yeah. I should maybe, I don't know if you endorse this, but there's someone that does compute SDK, you guys do very well on there, with like the TTI, right? I. is this a, is this a is this a relevant benchmark for you guys? I don't know.Ivan [00:15:16]: I don't know, and it changes every day. So today RKL is.Swyx [00:15:18]: I don't know what RKL is. Never heard of it.Ivan [00:15:20]: Yeah. RK, yeah, so it is there.Swyx [00:15:22]: You are, at least a third of the next tier of performance, and then, there's a lot of other better-known names that are very slow to start.Ivan [00:15:31]: Yeah. We've been the number one by far for a long time, and now there's different, there's different definitions also of sandboxes, different isolation patterns, different other things. So RKL runs it literally on the S3, the data, so it's very different, and they spin up a sandbox, spin up a container for that, so it's a different type of thing. So the definition of a sandbox is something that we can all, we all need to get along with. But yeah, we're insanely fast on getting these things, up and running. And so you can see even there that it's a zero point 0.10 to 0.11, so.Swyx [00:16:03]: Close enough. Yeah. what else do you need, right?Ivan [00:16:05]: Yeah. So the benchmarks itself, so, in this, in I don't think the benchmarks equate to market ownership or revenue or anything like that. and I've seen this with multiple benchmarks, not just in sandboxes, but in general benchmarks around.Swyx [00:16:20]: It's table stakes. It's just like.Ivan [00:16:21]: Exactly. But it doesn't hurt.Swyx [00:16:22]: Just roughly check.Ivan [00:16:22]: Like you definitely have to be up there and you have to be competing so that people know that, oh, this is definitely one of the top. Because this is only one dimension of what customers look for. There's other things like how many can you spin up consecutively? There's a feature set, there's support, there's like all different things that people look at, but you definitely have to be there, on the benchmarks.Swyx [00:16:40]: How many people do people spin up consecutively?Ivan [00:16:43]: So we have.Swyx [00:16:43]: Or concurrently, is the Concurrency, right?Ivan [00:16:45]: There's three metrics that we look at. And so one is like time to spin up one, and so our time to spin up one is 60 milliseconds with network latency. So request, spin up, reply, 60, the whole thing, 60 milliseconds. That is one. But if you wanna spin up 50,000 at once, we are now at about 75 seconds. So it takes about 75 seconds to spin up concurrently 50,000. Some others, there's public data around this, like take 2,000 seconds, which is 30 minutes. Like there's different variations of that. And then there is the so it is speed of one, speed of like multiple, and then how many can you consistently have up and running. And so we basically have right now no limit to how much we can add because we basically own our own metal. But the biggest customer of ours does like about 850,000 every single day is sort of where they're, where they're just shy of a million every single day that they're running, we do have a request for half a million concurrent, which is literally half a million CPUs somewhere running. So that's an interesting.Swyx [00:17:44]: They pay by like vCPU seconds.Ivan [00:17:47]: By seconds, yeah.Swyx [00:17:47]: Or whatever. Yeah. Okay, and so and then, and the other thing is, the sleeping and the resuming, ‘cause it's all the stateful resumption of all these things, how, what kind of workload are people putting through this, right? Like how is it Do we measure by gigabytes in memory, gigabytes in storage? I don't In like network attached storage. I, what are the costly ones of, out of all these features?Workload Economics: CPU, RAM, Network, and StorageIvan [00:18:15]: The most expensive thing are CPU.Swyx [00:18:18]: Okay. Yeah, of course.Ivan [00:18:18]: The second one, yeah Then it's RAM, then it's disk. We actually don't charge.Swyx [00:18:22]: Which is snapshotting, right?Ivan [00:18:23]: No, it's actually the, snapshotting's part of it, but basically the size of your hard disk, of your machine. So do you have 10 gigabytes, do you have 20, do you have 50, do you have whatever? And then the transference of that. Right now, currently we don't charge for, network at all at Polychron.Swyx [00:18:37]: Oh, you gotta, yeah, you gotta fix.Ivan [00:18:38]: Yeah. It is very much a it's a larger and larger part of our bill, so we're working around, that part there. Obviously, that is the least, expensive, so the hard disk is the least expensive, so it's basically CPU, RAM, for us network, ‘cause we don't charge the customer, and then hard disk, is how it's split up. But there's also different types of workloads, so we basically split it up into two types of workloads in Daytona. One is what we call background agents or long-running agents. and the other is, basically RLs and evals, which I put sort of together. And so they have very different patterns of usage, and if you look at the usage of a background And I'll just name names of companies, not specifically.Background Agents vs. RL/Evals: Two Usage ShapesSwyx [00:19:21]: Yeah, open, all hands.Ivan [00:19:23]: Yeah. So like a background agent's a Cognition, a Lovable, a like all these things are Harvey. These are all long-running, background agents. And so if you look at their usage patterns, their usage patterns are similar to human, which is like follow the sun. Basically, the usage patterns of that is like noon is probably the highest, and the midnight is the lowest, and then weekends are lower. weekday is higher.Swyx [00:19:42]: Yeah, that's a fun question. How global is it? Is it very US-centric or?Ivan [00:19:46]: The US is a large part, but we have currently, we have Asia, Europe, and the US regions.Swyx [00:19:52]: So it's quite global.Ivan [00:19:53]: Yeah, it's quite global. We have it all over. It's interesting that our I talked to you a bit about this. Our number one city by user.Swyx [00:20:01]: Hmm.Ivan [00:20:02]: Is Singapore.Swyx [00:20:04]: Oh, wow. Amazing.Ivan [00:20:05]: Which is an interesting one, right? Not by revenue, just by just like by individual head count.Swyx [00:20:09]: Really?Ivan [00:20:09]: Just like an interesting thing.Swyx [00:20:10]: Singapore is, Singapore is weirdly high in the adoption charts of AI for the population. It's like an, seven, eight million population. And it's like keeps showing up.Ivan [00:20:20]: No, it's quite interesting. We were quite shocked, and I was like, “Oh, this is interesting.” And also one that's up there.Swyx [00:20:24]: There's a reason I'm doing AI using Singapore. it's because I'm from there.Ivan [00:20:27]: We're there. We're gonna, we're gonna be there as well. and it's interesting that Japan is in the top or like Tokyo's in the top, which is in all the tech cycles it has never been. It has never been, so it's quite interesting that they're.Swyx [00:20:39]: I think the Japanese just love AI. Yeah. It's that, and then it's Brazil. That's it.Ivan [00:20:44]: Brazil has always been in.Swyx [00:20:45]: I think.Ivan [00:20:46]: Even when I look, if you look at like GitHub's data and ask historically with CodeAnywhere, it was always like US, Western Europe, and then you'd have like India, Brazil, China, like that would be there. But like Singapore was not in, specifically Japan was never in sort of that top, that top.Swyx [00:21:01]: Yeah. Weird pockets.Ivan [00:21:01]: Weird. Yeah, so it's very global.Swyx [00:21:02]: Okay, so actually that, but that's helps you to distribute your load through, all time?Ivan [00:21:08]: The interesting thing is like we have those kind of loads, but if you look at the researcher loads, they're quite different. So what they are is like if you give them concurrency of 10,000 or 50,000 or 100,000 CPUs at ARMb, when they fire off a run, it's just 100%. And then it just runs, and then it stops. So it's very, the usage pattern is squares basically, right? And it's also not follow the sun, because people will fire it off at midnight before they go to sleep but then wake up and so it's very unpredictable, so you don't know where that is. So the shapes of the usage are quite different than we have had before. And also what's interesting is when it's sort of a follow the sun, even if you have a high growth company, you can sort of predict your usage patterns and have enough capacity for that, because it's sort of, it grows in a, in a way you can project. When you have companies doing sort of like evals and RL, they're super spiky. So they're gonna come in, it's like, “We're gonna use nothing, then can we have 100,000?” Right? And then go back down. And then 100,000, go back down. So it's very different, right? And.Swyx [00:22:09]: Do you want to lock them into commits so.Ivan [00:22:11]: Yeah, we do.Swyx [00:22:12]: Yeah, okay.Ivan [00:22:12]: We so we have to lock them into some sort of commits to have that capacity, because we have to have, basically we have to have the capacity for peak. Right? And so right now, Daytona's mean utilization is 15%, 1-5.Swyx [00:22:25]: Oh my God.Ivan [00:22:26]: So it's very low.Swyx [00:22:27]: Because it's very spiky.Ivan [00:22:27]: It's very spiky, but we get up to 90%. so we have these things. And so what we're, what we're looking at right now as a company is similar to Cloudflare where you can like geo move things around, but that works really well for basically the background agent where it's follow the sun. But this, it's not. Like it's a very different shape. Obviously with scale you figure these things out, but that's an interesting new problem that we have, as a compute provider in the agent space. And when we were doing the conference recently, and so we talked to like Nikita from Neon and.Swyx [00:22:57]: I should bring it up.Ivan [00:22:58]: Parag from Parallel and whatnot, everyone has the same problem. Whereas the usage is super spiky, and this is something that has not happened before, that you have these types of like it was always, it the amplitudes were not this high, right? So it's quite interesting use case and problem solve.Compute Conference and Spiky Agent InfrastructureSwyx [00:23:12]: Yeah, I don't know if we're gonna bring this up again, but let's just talk about the conference, you had like 1,000 something people at the Warriors game, at the Sorry, where is it? What's.Ivan [00:23:22]: Chase Center.Swyx [00:23:23]: Chase Center.Ivan [00:23:23]: Chase Center.Swyx [00:23:24]: I went. It was, it was very impressive. Obviously, you can, how to throw a conference, what did you learn? you put, you pulled together all these impressive names.Ivan [00:23:33]: What I.Swyx [00:23:34]: What were you looking for?Ivan [00:23:35]: My thesis behind the Compute Conference was let's bring together people that are building infrastructure for AI agents. Because when I think of what we're building, it is the agent is the primary user, what are the ergonomics and usage patterns of agents, and so we can do that. And what I found, this was a theory, it wasn't proven, is that we all have these problems, as I touched onto. And I was, as I was talking on stage, it was like we all have the same underlying infra problems, which is this spiky workloads, unpredictable workloads that we've never had before, in human, compute or human infrastructure. And it's, again, it's the same when I was talking to Parag or when I was talking.Swyx [00:24:20]: Lynn. Nikita.Ivan [00:24:21]: Lynn, Nikita. Lynn especially, I was talking to her the other day as well. Like the It is a very interesting type of problem to solve because I can touch on Cloudflare because there's a lot of like talk about that recently as to how they solve that, which is they have a bunch of geos, and basically, as users work in different places, and depending on your tier, they can move you around the geos. And so that how, that's how they get the higher utilization. But you can sort of predict these, and it's If it's something in You'll rarely get a spike that is 10 orders of magnitude. Like you'll get a like let's say one of your customers has some like an exponential curve. What is that to I'm using Cloudflare as an example. 10%, 20%, whatever it is. I don't, I don't have this data, I'm just assessing. It's surely not 10x, right? It's surely not something there. And so how do you go out and solve this problem? And we're all solving this in different ways. So we have.Swyx [00:25:11]: She also has the same thing.Ivan [00:25:12]: Yeah, I know specifically that like Neon had that issue as well. Like how are we solving these spiky loads and things like that ‘cause we talked about it. And so the interesting thing for me to actually internalize was, yes, everyone that's building for agents first is going through this, and we're all solving similar problems, which is quite.Swyx [00:25:28]: Let me let me double-click on this. Okay. So for example, Neon, I happen to know that they're very sort of S3 oriented, right? so they're just like fully bet on S3. And you get to benefit from S3's distribution and infrastructure. So I would imagine that Neon doesn't have to care, whereas Lynn maybe has to care a bit more because obviously she's doing GPU inference. And, for listeners, we did an episode with her, one and a half years ago. And you have to care. But like, right?Ivan [00:25:54]: Parag cares for sure, and Nikita.Swyx [00:25:58]: And Parag is C of, Parallel.Ivan [00:25:59]: Parallel, yeah.Swyx [00:26:00]: Former CTO of Twitter.Ivan [00:26:01]: Twitter, yeah.Swyx [00:26:02]: They are the search.Ivan [00:26:03]: Yeah, they're search, yeah.Swyx [00:26:03]: I You and I know but the listeners don't know.Ivan [00:26:08]: Yeah, we can put it down in the screen, and so ‘cause we, when we were talking.Swyx [00:26:11]: I'll put it up on the, on the screen.Ivan [00:26:12]: Yeah, right.Swyx [00:26:12]: People can look it up if they need.Ivan [00:26:14]: Look it up. And, yes, but they still have CPU and RAM, allocation that you have to have up and running. And so CPU and RAM, you have to allocate that and have that ready. And so there's basically two ways to do it. One is you either over-provision and you can handle the bursts, or two, you basically have, I don't know if this is a term, just-in-time compute, which is like as your load becomes, as your usage comes in, you can fire off requests for VMs or bare metals at other cloud providers and then get them up and running.Swyx [00:26:43]: This is if you go above 100%, right?Ivan [00:26:45]: Yeah, this is.Swyx [00:26:46]: Like your overflow.Ivan [00:26:46]: If your overflow, like spillage or whatever you do.Swyx [00:26:48]: You probably lose money on it, but it doesn't matter, right?Ivan [00:26:50]: It, not Well, you might, you might not That is a more cost-effective way to do it but it's a slower way to do it. Because basically what you have to do is you have to like queue your requests, spin up these just-in-time compute, get it all ready, provision it, and then get your workload there. And so if the time isn't important that much, that's fine, and you can do that. But if your customer, and especially for, let's say, the RL training runs, the reason why a lot of people come to us is because GPUs are more expensive than CPUs, right? So you want your GPU running at, what, 100% the entire time. And so when you're running runs on CPUs, when the when the CPU cycle is like down and spinning up the next one, you want that to be instantaneous so that your GPU doesn't go down, right? And if you then have to like go out and provision machines, you're essentially telling the GPU that it has to wait, and that's incurring our cost. So there's things that you have to try to solve for there.RL Workloads, Declarative Images, and Kubernetes ReplacementSwyx [00:27:43]: Yeah, let's talk about the different workload, right? You said that, what was it? A few months ago, you had zero RL workload and now it's 50%.Ivan [00:27:52]: It will be this one, 50%, yeah.Swyx [00:27:54]: Let's talk about how different it is, right? Like I imagine, for example, a lot less dynamic code generation of like arbitrary code. Like here, it's probably all the same code. You're just doing parallel runs or something, I don't know.Ivan [00:28:05]: Yeah. So you'll have multiple Depends on the like for each run, you'll have a snapshot. And they, for the most part, they actually do use our declarative image builder, which is like, “Oh, we, the agent wants these dependencies, these env vars.”Swyx [00:28:17]: These ones, yeah.Ivan [00:28:18]: Yeah, the declarative image builder, it.Swyx [00:28:20]: Which is a very modal like thing that they.Ivan [00:28:22]: Yeah. And so we build it on the fly and then we propagate that snapshot, and you can spin up as many sandboxes as you want against that snapshot. And then if you have to do changes, the model can, or like it could be also be automated. It's like, “Oh, now for the next run, we need to install these things or remove these things or whatever to get, a task done,” and then it goes off and runs that. So yes, that is something that it seems that they prefer. The number one reason I found, or should I say, let's take a step back. What we are competing against in that environment is essentially managed Kubernetes. So EKS, GKE, whatever. That is what the vast majority run on. And anyone that has tried Daytona versus GKE, EKS is like, “I'm never going back.” That has always been. There's a few reasons. One is the ergonomics. So if you have, if you're using Kubernetes to spin that up, you have to essentially manage the interface interactions with that. Daytona, although as a compute provider, it's more akin to a Twilio and Stripe from a consumption perspective than it is an AWS. Like you have an API, an SDK, it's quite like easy and seamless to get these things up and running, that's one. The other is the speed to which we spin up, which we mentioned earlier, which is much faster, and the scale to which we can go to. We haven't got into features, but an interesting feature is that it's very hard to OOM, or out of memory, our sandboxes, because we can dynamically on the fly.Swyx [00:29:48]: Resize.Ivan [00:29:49]: Resize, which is like impossible on almost any other thing. There are some technologies that enable you to do that, but it's like a very hard thing. And so we actually saw this when, the Terminal Revenge team is, brought us actually. So thank you, Alex and the team, that brought us into this whole space.Swyx [00:30:05]: It's just very rare that, a framework would just say, “Guys, just use Daytona.”Ivan [00:30:11]: Yeah, I think it says it somewhere. Yeah.Swyx [00:30:13]: Yeah. I was like, “What is this?”Ivan [00:30:15]: There's all, there's multiple there, but they also mention a few other places. and so Daytona specifically-We have, the, just jumping on themes here We, I don't know where it says Data Center.Swyx [00:30:27]: I, there.Ivan [00:30:27]: Doesn't matter.Swyx [00:30:28]: There's a very strong recommendation, which is, very unusual. Which is, it's.Ivan [00:30:33]: We do not pay them for this, just.Swyx [00:30:34]: I know, yeah. They just like you.Ivan [00:30:35]: Yeah, they like us. yeah, and also a thing, so, Data Center has multiple isolation sets underneath. The customer doesn't have to know what they are. But basically we have Docker, which is a container, that's hardened with Sysbox. So it's Docker's, isolation that is a security equivalent to a VM, but it's still a container. And that is the default, and they, especially in these training workloads, really like that as an interface to be able to use just a basic Docker container, and we enable Docker and Docker. Which for these RL runs, if you need to do a Docker compose or Kubernetes, you can spin up a K3S inside of these things, which unlocks a huge amount of workloads that you can do that you cannot do on other providers. So just on that part is much more interesting. And so we went that, through that. We showed them that we could do that, and they enjoyed that quite a bit. They being the general venture people.Swyx [00:31:28]: Those people, yeah.Ivan [00:31:29]: And Harbor people.Swyx [00:31:29]: Harbor people, do are they, are they a company yet?Ivan [00:31:33]: As far, I do not know.Customer Pull, Slack Connect, and the Computer Use BetSwyx [00:31:35]: Okay. All right. Yeah. It's like super obvious that like, there's a lot of excitement and success around these things, okay, so yeah, tell us more, right? Like, this is an exploding workload, Harbor adopted you, which helped speed things along. But what are you learning as this new workload comes online?Ivan [00:31:53]: There's a couple things that we learned, which we chat about in the beginning. We, and this has led our story, as we mentioned, we like talked to a lot of customers along the way, and we add more features and more tool sets as we talk to customers. And it's interesting that And I think it's that the ecosystem is so small and/or the models get smarter, where when we see one user come with a request, we know it goes on a roadmap if like three to five customers come with the same request in that week. It's like very bizarre. It happens so many times, which is.Swyx [00:32:27]: Because they're all friends.Ivan [00:32:28]: Sorry?Swyx [00:32:28]: They all, they're all friends. They're all in the same group chat.Ivan [00:32:30]: Yeah, probably, yeah. ‘Cause and they're like, “Oh, can you do this?” And I'm like, “Okay, this is interesting. We'll put it on a feature request.” And then the next one's like, “Oh, can you do this?” “Okay.” It's all the same, right? It's always the same. And so what we try to do, and I personally try to do, I try to be on as many call, quote-unquote “sales calls” I can. I'm in every Slack channel. We literally have about 1,000 Slack Connect channels, something like that. It's an interesting, there's so many interesting things you find out when you have all the Slack channels. You can also see where people, transfer between companies. You see leave Slack channel, enter Slack channel. It's an interesting thing. Also, just I digress, I feel that Slack Connect is literally LinkedIn what it should be. You have a list.Swyx [00:33:08]: LinkedIn charges you to, use your own connections, but Slack doesn't, right? Slack is like, do it for free. It's more lock-in. It's great.Ivan [00:33:15]: Yeah. It's amazing. Yeah. It's one of the reasons.Swyx [00:33:17]: You're gonna pay Slack for life.Ivan [00:33:18]: Exactly. You're there for life. So that's interesting. And so one of the things, the newer things we were talking about earlier is we made a big bet and put a lot of investment on computer use. that is not seen publicly the light of day. We haven't GA'd that yet, but we have.Swyx [00:33:32]: Is there a thing I can pull up?Ivan [00:33:33]: There is computer use there. It's right up a bit.Swyx [00:33:36]: Oh, yeah. Okay.Ivan [00:33:38]: What we have, what we talked about and what we've seen publicly is there's this theme now about, the human emulator where And Elon from XAI has talked about this publicly, and if you think about the models today, they're actually quite sophisticated and they can do a lot of work, but they still don't have access to all the tools. Like, I'm a strong believer that the most efficient way for an agent to work is essentially headless or through, terminal or whatnot. But if we, if we look at knowledge work in general, there's about 100 million knowledge workers in the US, about a billion in the world, and knowledge workers, and the salaries of them aggregate to 10 trillion in the US 50 trillion worldwide.Swyx [00:34:24]: Wow.Ivan [00:34:25]: Something like that. And if we look at, the five most important sectors of that, so like healthcare and government and financial services and whatnot, that's about 56% of that. So let's say it's about half of that. So in the US it's about 25 trillion, and most of them, most of that work is actually still locked into legacy apps inside of Windows, which is not going anywhere for a very long time. Like, people just won't invest in that. How much of it? our assumption is the following: if, in the RPA market, which is similar market, well, not the same 25% of, these white collar, workers', work is automated. If an agent is more sophisticated, can go through more runs, figure stuff out, let's say it's, 40%, right? And so if you take 40% of that, you get to essentially, $10 trillion a year.Swyx [00:35:17]: That's a TAM.Ivan [00:35:18]: That is a that is a TAM. So that's the TAM of the models, right? That's not our, essentially ours. But you get to that size, and to be able to do that, you essentially have to give agents these computers with the legacy. So computer use, either Mac or Windows or Linux. Linux we also obviously have and others have. But Windows specifically is something very new, and the only option right now is an EC2 with, Windows or on Azure. Both of them take anywhere from three to five minutes to spin up. We've created an actual sandbox, so it's a second instead of milliseconds, but you have, point in time snapshots, you have, forking, you have all the things that you have from a sandbox, but essentially enables you to hopefully unlock all this value. And so that's been our big push and bet, but we've sort of, kept our ear to the ground. What is sort of the next things in the market?RPA Returns: Why Agents Still Need ComputersSwyx [00:36:06]: Yeah, knowledge work, and building, and sort of RPA, the next wave of RPA. I got very excited about RPA kind of during COVID times. The UI path was IPO-ing. And it was, a very hot Isn't it, Eastern European?Ivan [00:36:20]: It is, Romanian.Swyx [00:36:21]: Romanian?Yeah, it might be the only Romanian, big unicorn okay, yeah. This I don't I don't, I don't have like a I think there's, I think there's a stage being set for the resurgence of RPA, ‘cause everyone understands that, yeah, no one wants to deal with these shitty apps and no one's gonna rewrite them. Like, you just have to do, a remote operation and programmatic operation of them.Ivan [00:36:45]: If you wanna unlock it, my own setup was basically the following. So I was doing a board deck recently, last month, whatever, and I'm like, “Okay, let's just, let's just do automated.” So, all our data's in, ClickHouse and PostHog and QuickBooks, where everyone else's is, and I'm basically, connected that all to, my Cloud code, like go off and go Cloud code whatever. Go off and, here's the integrations, go do that. It pulled out the first report, which was great. It connected to Brex and all these things, pulled it, which was great, and then I say, “Okay, now pull out this, and this,” and I kept getting, really well McKinsey-style design reports, but the data said partial data. all the missing data, partial data. Like, it can't access all the things, and I got so frustrated, and so I got, I got, my Mac Mini virtual sandbox with OpenClaw. I gave it its own account in our company, and then I went to all these services and created a read-only account, so literally like an intern in your company. And so I would say, “Now go and do this report,” and it would get the same, or like, “I can't via the MCP or the API or whatever. I can't get all the information.” I'm like, “Go log in.” And it will log into the website, then go in, export the data. It'll export the data and do the thing end to end. So even for things that have today APIs, not all of it is exposed, and I to get value, I get immense value right now, but it has to be a computer usage, unfortunately, and so I spend a bunch of tokens just on that, but I get the job done. And so if even a startup like ours, and using all the hottest tools, still needs a computer agent what hope does, Goldman have to have a headless, right?Swyx [00:38:22]: Yeah, what a - Why isn't Microsoft doing this?Ivan [00:38:27]: I'm pretty sure, Satya had a post yesterday.Swyx [00:38:29]: Oh, okay. I see.Ivan [00:38:29]: Which was like, “Every agent needs a computer.”Swyx [00:38:31]: I see, I see.Ivan [00:38:32]: So they have launched something recently.Swyx [00:38:34]: Yeah, they have Microsoft Power Automate, I'm sure, I'm sure, they're gonna have their version.macOS Sandboxes, Apple Constraints, and the Windows OpportunityIvan [00:38:39]: Version of that, yeah.Swyx [00:38:39]: You're gonna try to do yours, and it - I always know there's always demand for Mac, but I know it's, tricky to host, macOS sandboxes.Ivan [00:38:49]: We will have macOS sandboxes fairly soon. The problem with macOS, OS sandboxes is, I'm deep in this, I don't know how much interesting is.Swyx [00:38:55]: No, it's.Ivan [00:38:56]: MacOS has this problem.Swyx [00:38:57]: It's a licensing thing, right?Ivan [00:38:58]: Licensing thing. So one, you're allowed to run only two parallel VMs per machine, so that's one. Two, you can only license to a different user every 24 hours. So if you come in and theoretically, if I wanna charge you per second and I charge you one second, I have to have it idle for the rest of the day. I can't have anyone else doing that. So the pricing will be different in the sense that I will have to - we would have to charge for 24 hours, and that's not even, that's not even the most difficult thing. But the, thing above that is, from a security perspective, they enable you to do memory snapshot, pause, resume, but only on the same physical drive, physical machine. And so what you can do in, Windows world or Linux world is that I can move in the background, your snapshot from one to the other and manage load, right? Here, if you wanna do that, you essentially have to have your.Swyx [00:39:49]: Yeah, snapshots. Yeah.Ivan [00:39:50]: Your.Swyx [00:39:51]: It's like.Ivan [00:39:51]: Physical machine.Swyx [00:39:52]: You can't break it up.Ivan [00:39:53]: You can't, you can't move things around that, and all of that is, that part is, from a security standpoint, if it is written. Like, I understand the security aspect of that, but it disables you from doing these agentic, like really scalable agentic workloads.Swyx [00:40:08]: You need to do a vibe-coded, clean room implementation on macOS that you can then - That's like Clean OS or something. I don't know.Ivan [00:40:17]: So. We have.Swyx [00:40:18]: ‘cause like Linux was originally like a clean room rewrite of Unix.Ivan [00:40:21]: Okay. Yeah.Swyx [00:40:21]: Or something like that, right? Like same thing to macOS. Someone needs to do it.Ivan [00:40:25]: Someone will do that, and someone will have some long-running agents for a few days to figure this stuff out. But yeah. So definitely we - we're really close to offering something ‘cause people do want it, but the pricing will be different, and the feature set will be sort of stringent.Swyx [00:40:38]: Yeah, nobody's gonna use this. like, the labs, the labs will because they want to automate macOS.Ivan [00:40:42]: They have to do RL. They have to do RL again. But even if you The - So the point is with the RL part, if you, if you do RL on macOS, then the next iteration of the model comes out, it will be able to use these tools significantly. Then you actually need to run those, that somewhere. So you're gonna have to have that, later on. And from, if anyone at Apple is listening, I very much feel that they are shooting themselves in the foot of the scale of the revenue of compute or licensing they could get if they would just enable a concurrency model similar to what you can get on a Windows and a, and Linux.Swyx [00:41:17]: Yeah. Yeah. And I'm sure they've heard this before. They just don't care. Yeah, it's And maybe they will change their mind with the new CEO.Ivan [00:41:24]: Yeah. We'll see.Swyx [00:41:25]: We'll see.Ivan [00:41:25]: High hopes.Swyx [00:41:26]: High hopes.Ivan [00:41:26]: High hopes.Swyx [00:41:27]: Okay. But I, it's very clear the market opportunity is huge in Windows, and you can go for a long time on just Windows, but your customers are gonna want both. and I think, it is interesting to me that, this is the sort of God application of agents, right? Like, I don't It was - How big was OpenClaw for you guys? Like, was it, was there, a significant bump.OpenClaw, Agent Labs, and the B2B2C Sandbox MarketIvan [00:41:54]: Not for us because we.Swyx [00:41:54]: Because you already.Ivan [00:41:55]: We're kind of positioned differently. Whereas although it's completely PLG and we have individual developers that use it, most of the users that use Daytona are sort of a B2B2C. Sort of it's either B2B or B2B2C. So, in the researcher world, it's B2B, so you're selling to, labs and neo labs and things like that. But on the long-running agents, it's mostly, from a scale revenue perspective, it's mostly B2B2C, where you have a app layer agent that uses you at a big scale.Swyx [00:42:26]: Like a Manus. Yeah.Ivan [00:42:28]: Like a Manus Lovable type of thing.Swyx [00:42:31]: Yeah. I think that's the question of, well how, um-Uh, yeah, B2B to C is basically to me what I've been calling an agent lab, which is kind of like you're not in a model lab, but you're making a very good wrapper that is a platform that other people can sign up so they don't have to code those things. Yeah, it sound, it sounds like a much better market than the direct OpenClaw market.Ivan [00:42:56]: I've like - We I've done multiple things. So the CodeAnywhere's part of our career path R in the calendar, was very much an end user developer product. And so that is great. It You can get a lot of developer love, and I feel that we do as a company have a bunch of developer love. But it's a different type, where it's people building these things. Again, it's more akin to a Twilio because you don't really run - As a person, you wouldn't run Twilio. I don't know how many people remember. It was like ask your developer billboard and whatnot. And people really love Twilio, but they only used it inside of like, “Oh, I'm building this app or service for thing.” And so we're very much directly to that. And you also know that I used to work for a competitor for Twilio, so it's kind of ingrained, in my DNA.Swyx [00:43:35]: People don't know InfoBip is that big.Ivan [00:43:38]: Yeah, it's.Swyx [00:43:39]: Because.Ivan [00:43:40]: It's a billion euro.Swyx [00:43:40]: They're all American. They're like, “Whatever's in Europe doesn't matter to me.” But like it's the, it's the same size or bigger? Same size?Ivan [00:43:46]: It's about half the size.Swyx [00:43:47]: Half the size?Ivan [00:43:48]: Yeah, about half the size.Swyx [00:43:48]: It's like, yeah.Ivan [00:43:48]: Still huge. Multiple billions a year. Yes.Swyx [00:43:51]: That's crazy.Ivan [00:43:51]: Exactly, and so that - These are like really interesting and large revenue-generating, very sticky businesses. Whereas when you're selling to the - When your focus is the end developer, it is a very hard sell because they're very price sensitive, very price conscious, very around that. And there's very It's very hard to scale. Your cap is the number of people that are willing to spin up - First of all, wanna spin that up, and then spin up multiple of these. Whereas if you're in the enterprise one, like we know everyone's talking about like how many tokens they're spending, I'm spending. Like a lot of companies today are like, “If this is our company, spend as much as you can.” Like basically that is where we're going. And so if you think about that paradigm, where you're selling to companies that say, “Spend as much as you can to generate, productivity,” versus, “Oh, I'm a single person. I have this much budget, and I'm doing this thing because it's fun or it's helping me out or whatever.” Like it is a different, it's a different go-to-market, I think, strategy.MCP, CLIs, and Sandboxes as the Agent RuntimeSwyx [00:44:50]: Yeah, there's a lot of discussion. I'm just kind of going through like the mental list of things that are in your favor, which is, for example, MCP versus CLI. Like obviously you want CLI. It's been very good for you. I feel like it's maybe a drop in the bucket or maybe it's huge. I'm just checking whether it's like these are big trends.Ivan [00:45:10]: Those things you - work well in our favor, to your point just because every.Swyx [00:45:13]: They're kind of drop in the bucket, right?Ivan [00:45:15]: I think it's like sort of all the things come together. And so there's so many things that impact that. To your point, like OpenClaw wasn't huge for us, but like having the agent SDK, from Anthropic, so or Cloud Claude Code was very interesting. The reason why it was interesting is that a lot of, let's call them app I don't know what to call them, app layer agent companies, essentially they are like, “Oh, I can create this new app, this new agent. All I need, I just use Claude Code, and I throw it into a sandbox, and then I have my interface to the human to that.” And so that enabled so many more companies to actually offer this, and then they would pull on sandbox. So that was, that was interesting. And to your point, like MCP, versus the CLI, the MCP is an interface against an API, whereas the CLI is like you can actually go do things. Like this is it. The difference between integrations and actually running scripts or data or analysis against a thing. So being able to use a CLI very well enables the agent to do more things, and it's because that people will invoke a sandbox, they'll run it in the CLI, and but it'll do anal-analysis on that data and then give you an actual result versus just, pulling data from an API source.Swyx [00:46:29]: Yeah, it's a layer of indirection basically, it's the same thing as agentic search versus RAG, which where you're.Ivan [00:46:34]: Exactly, yeah.Swyx [00:46:34]: Just like you just win whenever people put more agents into their workflow. And so like it doesn't really matter, but I'm just kinda teasing out like what else have people heard about that like it's sort of, “Oh yeah, this is another sandbox use case. Oh yeah, that's another one.” Am I, am I missing any big ones?Ivan [00:46:51]: The thing, the thing that people, which is the computer use stuff, which I think is probably the most interesting one, is, and to your point, we've talked to so many people over the last year. It's like, “Oh, like why do you need a sandbox? Why do you need this? Why this?” And to your point, it's like, “Oh, I need sandbox for this. I need sandbox for that. I need sandbox-” It's like, “Oh, I need it for every single thing.” And so basically what I, what I - and it sounds like a broken record, it's like you use a laptop every single day, right? And you are n of one. It's just you. But now imagine how And by the way, the laptop, the computer PC market, the PC market is about equal to the cloud market in total. So it's about 150, 180 billion a year. Something like that. It's about roughly the three cloud hyperscalers is about equal to like Apple, HP, Lenovo, whatever, It's a little bit less, but it's sort of like that. And now imagine And that's just like, so how big is the addressable market? What, how many people are there in the world now? What's the last data?Swyx [00:47:45]: Let's call it eight billion.Ivan [00:47:46]: Eight billion. And so let's say you can have two computer, like you have one personal and one business, whatever. Like so it's double that, right? and so that's 16 billion, right? How many agents are gonna be running in two years, in 10 years, in 100 years? Like And for every single task, they will need one of these. And so how big is that? That market is essentially quote unquote “infinite”. You will get to the point, and Dylan Patel was at the conference talking about, from SemiAnalysis, that talks usually about GPUs, was also talking about how CPUs will now be a bottleneck because it will be the constraint. You won't be able to grow, or we won't be able to have enough of these because there won't be enough CPUs to basically do.Swyx [00:48:23]: Yeah. Well, I actually had a really good podcast with Doug Oliphant, who, which was his president at SemiAnalysis, where they've basically been like, yeah, it's been a GPU shortage first, but then it's cascaded down to memory and now to CPUs.Ivan [00:48:35]: CPU, yeah.Swyx [00:48:35]: It-What's next? So networking. So, networking actually has been in shortage for a while if you're looking at, just GPU networking. But, yeah, it's really crazy the amount of computer use that's going on, yeah, cool. I, other questions are, just the one very big part is the open sourceness which you didn't have to do, your competitors don't do, like it's not, a lot of people are worried about keeping their projects open source because some competitor can just slot fork it. I don't know if there's any reflections on just being an open source company.Open Source, Trust, and Enterprise ProcurementIvan [00:49:15]: Yeah. There's a bunch. So we the original product that we did was open source.Swyx [00:49:19]: Yeah. CodeAnywhere.Ivan [00:49:20]: So doing that was actually very good for us. There's basically a saying of, What's the saying? Like, companies that are, that are doing really well, measure themselves against, free cashflow, that are kinda okay, it's EBITDA, then, it's, it goes all the way down.Swyx [00:49:36]: The worst is like GitHub stars.Ivan [00:49:37]: GitHub stars. GitHub stars are the worst, yeah. So you go all the way down to GitHub stars. And so our original one was GitHub stars. That's what we talked about, we're at the point we're talking about revenue, so we're we've gone up the stack on that. And so we started.Swyx [00:49:47]: No, profit.Ivan [00:49:48]: Yeah. We haven't, we're, we'll get there. We'll get there. But basically at that point we did stars and GitHub and it was useful, and the original variation that we did, it we split the core into its own repo and it was Apache 2.0, so very, permissive. And then we basically would bundl
What if faster coding is actually slowing your software delivery down? Most teams are pouring AI into the coding phase, but the real bottleneck is everywhere else.In this episode, Andrew Haschka, Field CTO at GitLab for Asia Pacific and Japan, explains why most AI strategies in software engineering are failing and what it takes to fix them. He introduces the AI paradox: teams invest heavily in AI-assisted coding, yet coding accounts for less than 20% of the software delivery lifecycle, leaving the biggest bottlenecks untouched.Andrew makes the case for intelligent orchestration — moving from isolated AI interactions to governed, end-to-end agentic flows that span planning, coding, testing, security, compliance, and release. He shares how a unified system of record forms the foundation for high-quality AI outcomes, and why fragmented tools and siloed context actively limit what AI can deliver. Drawing on real customer examples — including Ericsson's 50% faster deployments and 130,000 hours saved in six months — he shows what a holistic approach actually looks like in practice.The conversation also covers how tech leads, developers, and junior engineers need to evolve their skills in a world where AI handles routine implementation. Andrew closes with a compelling argument: in the agentic era, governance isn't just a compliance burden, it's the primary source of competitive advantage.Timestamps:(02:30) What Are the Key Responsibilities of a Field CTO at GitLab?(03:26) Why Should Organizations Govern AI Strategy Rather Than Chase the Latest Features?(06:41) Why Is an End-to-End Agentic Flow More Valuable Than Individual AI Tools?(09:39) What Is the AI Paradox and How Does Intelligent Orchestration Solve It?(14:47) How Does Shifting Focus to Requirements Quality Transform Software Delivery Outcomes?(18:19) How Has GitLab Evolved Beyond CI/CD Into a Full End-to-End Delivery Platform?(20:20) What Should Software Teams Prioritize Beyond Coding in the AI Era?(24:14) How Do Organizational Silos Create a Capability Threshold for AI Adoption?(27:49) What Practical Strategies Can Organizations Use to Break Down Internal Silos?(30:58) How Did Ericsson Achieve 50% Faster Deployments and Save 130,000 Hours With GitLab?(33:07) How Should Software Developers Evolve in the Age of AI Agents?(36:26) How Is the Tech Lead Role Evolving in a Hybrid Human-AI Team?(39:22) How Can Junior Developers Keep Up With the Rapid Shift in Industry Expectations?(42:40) Why Do 79% of Singapore DevSecOps Practitioners Believe AI Will Create More Jobs?(45:27) Why Are Companies Reducing Staff Despite the Growing Demand for Software?(48:34) What Are the Most Common Pitfalls When Implementing Agentic Workflows?(52:29) What Practical Steps Should Engineering Leaders Take to Govern AI Responsibly?(55:13) Why Should Engineering Leaders Build an AI Strategy Before Choosing Technology?(57:15) 3 Tech Lead Wisdom_____Andrew Haschka's BioAndrew Haschka serves as Field CTO for Asia Pacific & Japan at GitLab, where he acts as a trusted strategic advisor to enterprise customers and partners navigating complex technology transformation. With over 20 years of experience spanning software delivery, cybersecurity, cloud infrastructure, and organisational transformation, Andrew brings a rare combination of technical depth and executive-level counsel to the organisations he works with.Prior to GitLab, Andrew held senior leadership roles across APAC at Google and VMware, and has led large-scale digital transformation programmes for organisations including Downer, IBM, Jones Lang LaSalle, Thomson Reuters, Optus, and across the Fiji and Pacific Islands.Follow Andrew:LinkedIn – linkedin.com/in/andrewhaschkaLike this episode?Show notes & transcript: techleadjournal.dev/episodes/258.Follow @techleadjournal on LinkedIn, Twitter, and Instagram.Buy me a coffee or become a patron.
In der heutigen Folge sprechen die Finanzjournalisten Philipp Vetter und Holger Zschäpitz über einen kleinen Realitätscheck an den Börsen, die Orbitpläne von Space X und Google sowie eine veritable Enttäuschung bei der Munich Re. Außerdem geht es um Bayer, Munich Re, Siemens Energy, Thyssenkrupp, Zalando, Under Armour, Hims & Hers Health, ZoomInfo, GitLab, CME Group, Alphabet, Rackspace Technology, AMD, eBay, GameStop, Allianz, Micron, Meta, Tesla, Apple, Qualcomm, Volkswagen, BMW, Mercedes-Benz Group, Airbus, Saudi Aramco, Equinor, ConocoPhillips, AppLovin, Nvidia, Investor AB, Welltower, Altria Group, CNOOC, SAP, Global X China Electric Vehicle and Battery ETF (WKN: A3C5S0), UBS MSCI China A SF UCITS ETF (WKN: A2PRV8), Xtrackers CSI300 Swap UCITS ETF (WKN: DBX0M2), HSBC MSCI China A UCITS ETF (WKN: A2N390), KraneShares CSI China Internet UCITS ETF (WKN: A2PBU9), HSBC Hang Seng Tech UCITS ETF (WKN: A2QHV0), iShares Dow Jones China Offshore 50 ETF (WKN: A0F5UE). Wir freuen uns an Feedback über aaa@welt.de. Noch mehr "Alles auf Aktien" findet Ihr bei WELTplus und Apple Podcasts – inklusive aller Artikel der Hosts. Hier bei WELT: https://www.welt.de/podcasts/alles-auf-aktien/plus247399208/Boersen-Podcast-AAA-Bonus-Folgen-Jede-Woche-noch-mehr-Antworten-auf-Eure-Boersen-Fragen.html. Hier könnt ihr den AAA-Newsletter abonnieren: https://www.welt.de/newsletter/article232797673/Alles-auf-Aktien-Der-taegliche-Boersen-Newsletter-fuer-WELTplus-Abonnenten.html Und - ganz neu: AAA gibt es jetzt auch auf Instagram: https://www.instagram.com/alles_auf_aktien/ Disclaimer: Die im Podcast besprochenen Aktien und Fonds stellen keine spezifischen Kauf- oder Anlage-Empfehlungen dar. Die Moderatoren und der Verlag haften nicht für etwaige Verluste, die aufgrund der Umsetzung der Gedanken oder Ideen entstehen. Hörtipps: Für alle, die noch mehr wissen wollen: Holger Zschäpitz können Sie jede Woche im Finanz- und Wirtschaftspodcast "Deffner&Zschäpitz" hören. +++ Werbung +++ Du möchtest mehr über unsere Werbepartner erfahren? Hier findest du alle Infos & Rabatte! https://linktr.ee/alles_auf_aktien Impressum: https://www.welt.de/services/article7893735/Impressum.html Datenschutz: https://www.welt.de/services/article157550705/Datenschutzerklaerung-WELT-DIGITAL.html
This is a recap of the top 10 posts on Hacker News on May 11, 2026. This podcast was generated by wondercraft.ai (00:30): I'm going back to writing code by handOriginal post: https://news.ycombinator.com/item?id=48090029&utm_source=wondercraft_ai(01:57): Postmortem: TanStack npm supply-chain compromiseOriginal post: https://news.ycombinator.com/item?id=48100706&utm_source=wondercraft_ai(03:25): Mythos Finds a Curl VulnerabilityOriginal post: https://news.ycombinator.com/item?id=48091737&utm_source=wondercraft_ai(04:52): Ratty – A terminal emulator with inline 3D graphicsOriginal post: https://news.ycombinator.com/item?id=48093100&utm_source=wondercraft_ai(06:20): Gmail registration now requires scanning a QR code and sending a text messageOriginal post: https://news.ycombinator.com/item?id=48092028&utm_source=wondercraft_ai(07:48): GitLab announces workforce reduction and end of their CREDIT valuesOriginal post: https://news.ycombinator.com/item?id=48100500&utm_source=wondercraft_ai(09:15): Software engineering may no longer be a lifetime careerOriginal post: https://news.ycombinator.com/item?id=48095550&utm_source=wondercraft_ai(10:43): CUDA-oxide: Nvidia's official Rust to CUDA compilerOriginal post: https://news.ycombinator.com/item?id=48096692&utm_source=wondercraft_ai(12:10): The greatest shot in television: James Burke had one chance to nail this scene (2024)Original post: https://news.ycombinator.com/item?id=48090521&utm_source=wondercraft_ai(13:38): If AI writes your code, why use Python?Original post: https://news.ycombinator.com/item?id=48100433&utm_source=wondercraft_aiThis is a third-party project, independent from HN and YC. Text and audio generated using AI, by wondercraft.ai. Create your own studio quality podcast with text as the only input in seconds at app.wondercraft.ai. Issues or feedback? We'd love to hear from you: team@wondercraft.ai
In Season 15 episode 2, Elixir Wizards Sundi Myint and Charles Suggs chat with Micah Cooper to talk about distributed systems, data replication, and what it actually looks like to build these ideas in Elixir. Micah shares his journey from Ruby to Elixir and walks us through Visor, a library he's building based on the Viewstamps replication algorithm. Inspired by systems like TigerBeetle, Visor explores how you can replicate state across nodes using GenServers, giving you fault tolerance and recovery without relying entirely on traditional database patterns. We talk about the difference between distributed systems and data replication, where things tend to get misunderstood, and what changes when you start thinking about state this way. The conversation also touches on event sourcing, tradeoffs in system design, and how Elixir's distributed model makes some of these concepts more approachable than you might expect. Along the way, we talk about building for curiosity, experimenting with new ideas, and how projects like this push the ecosystem forward. Topics discussed in this episode: Building Visor and working with the Viewstamps replication model Replicating GenServer state across nodes Distributed systems vs. data replication Lessons from TigerBeetle and financial system design Event sourcing challenges and tradeoffs Rethinking database-first architectures Snapshotting, recovery, and fault tolerance The role of Elixir's distributed model Experimentation, learning, and building for curiosity Links mentioned: Micah's GitHub https://github.com/mrmicahcooper Micah's GitLab https://gitlab.com/mrmicahcooper The Visor repository: https://gitlab.com/mrmicahcooper/visor Visor Hex Package https://hex.pm/packages/visor Ruby on Rails https://rubyonrails.org/ Phoenix LiveView Framework https://www.phoenixframework.org/ Zig Programming Language https://ziglang.org/ TigerBeetle https://tigerbeetle.com/ TigerBeetle internal docs https://github.com/tigerbeetle/tigerbeetle/tree/main/docs/internals The BEAM https://www.erlang-solutions.com/blog/the-beam-erlangs-virtual-machine/ GenServer https://hexdocs.pm/elixir/GenServer.html Apache Kafka https://github.com/apache/kafka RabbitMQ https://www.rabbitmq.com/ Redpanda https://www.redpanda.com/ SQL https://www.ibm.com/think/topics/structured-query-language Kubernetes https://kubernetes.io/ YAML https://yaml.org/ Nomad Workload Orchestrator https://developer.hashicorp.com/nomad Flutter https://flutter.dev/ Commanded https://hexdocs.pm/commanded/Commanded.html Go Programming Language https://go.dev/ Clojure Programming Language https://clojure.org/ Nebulex https://hexdocs.pm/nebulex/Nebulex.html Mnesia https://www.erlang.org/doc/apps/mnesia/mnesia.html Cachex https://hexdocs.pm/cachex/Cachex.html libgraph https://hexdocs.pm/libgraph/Graph.html Horde https://hexdocs.pm/horde/Horde.Registry.html NocFree split keyboard https://www.nocfree.com/ Micah's LinkedIn https://www.linkedin.com/in/micah-cooper-4a737560/
I'm back with my friend and colleague Sabine Hossenfelder for another episode of “What's New in Science”. Spending time with Sabine was a nice chance to step away from my physics lecture series for a bit. I know many of you have been enjoying the lectures, so don't worry, they'll be back soon.In this episode, we covered an incredibly wide range of science topics. Sabine opened with reported claim that the CIA used quantum magnetometry to find the downed pilot in Iran. The report, in the NY Post, looked fishy. We explain why it is. Then I described a new discovery in the physics of material that may solve perhaps the biggest problem in AI now: heat generation in computers. Sabine talked about a new claimed Big Bang Theory that might have some relevance to quantum gravity. Then I countered with a discussion of yet a new result that suggests the standard model of cosmology may have troubles, or that observers are wrong. After that, Sabine introduced a paper describing a possible new way to measure gravitational waves. I think it is a fine piece of work, though it is not clear if it is practical. If it were, then the huge interferometers that are now being used could be replaced by ‘tabletop' detectors. We will see. Finally, I described an amazingly interesting news story that might have implications for the future of medicine. It also demonstrates what one person, with determination and wealth, can do to possibly cure their own maladies. Sid Sijbrandij, a billionaire tech CEO of Gitlab, was diagnosed with inoperable spine cancer, and launched an amazing program of diagnostics, AI data mining, and a group of scientists who developed vaccines specific to his genetic makeup. After implementing all the procedures, he has been cancer free for a year. While this is beyond the reach of people without these resources now, Sid's story demonstrates the potential power of combining AI and genetic medicine in the future.As always, an ad-free video version of this podcast is also available to paid Critical Mass subscribers. Your subscriptions support the non-profit Origins Project Foundation, which produces the podcast. The audio version is available free on the Critical Mass site and on all podcast sites, and the video version will also be available on the Origins Project YouTube. Get full access to Critical Mass at lawrencekrauss.substack.com/subscribe
After watching Project Hail Mary, Cal sees more than a sci-fi story about saving the stars—he sees a blueprint for how humans might survive the age of AI. That insight leads him to a real-life story even more extraordinary. When tech founder Sid Sijbrandij is diagnosed with a rare, aggressive cancer, the traditional medical system eventually runs out of answers. Most people would accept that outcome. Sid does the opposite. He treats his own disease like an open- source problem—gathering data, building a team, and chasing solutions across the globe with the same mindset that helped build GitLab into a billion-dollar company. With the help of AI, Cal translates this complex scientific journey into a human story anyone can follow. One that's filled with pancakes, partnerships, love, and a radical idea: What if the future of survival—against disease, against uncertainty, against AI itself—belongs to those who adapt fastest? This episode is about more than cancer. It's about how humans fight back.
The Twenty Minute VC: Venture Capital | Startup Funding | The Pitch
AGENDA: 04:14 Anthropic's $30B Raise at $380B 06:18 Why SaaS Stocks Keep Getting Crushed 18:15 Wall Street's New Religion: AI Replaces Headcount 22:42 The Bear Case for Shopify: What Could Go Wrong? 31:51 Replit and Lovable are Proof Figma Missed Out: Figma; Buy or Sell? 48:42 Stripe Raises at $140BN: Is Stripe Wildly Overvalued or Adyen Undervalued? 54:36 OpenAI Buys OpenClaw 01:06:28 Thrive's $10B Growth Fund 01:09:10 Arif Janmohamed Leaves Lightspeed for New Firm 01:17:12 Workday's Founder Returns as CEO: Will it Work? 01:20:34 Which Founder Returns Next: HubSpot, Twilio, Gitlab? 01:24:03 Is Monday.com a Screaming Buy? 01:28:25 Jason and Harry Bet $200,000
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Microsoft Patches Four Azure Vulnerabilities (three critical) https://msrc.microsoft.com/update-guide/vulnerability Evaluating and mitigating the growing risk of LLM-discovered 0-days https://red.anthropic.com/2026/zero-days/ Gitlab AI Gateway Vulnerability CVE-2026-1868 https://about.gitlab.com/releases/2026/02/06/patch-release-gitlab-ai-gateway-18-8-1-released/