InfoQ Homepage News
-
GitLab Vulnerability under Active Exploitation Enables Unauthenticated Data Exfiltration
CVE-2026-85706 is a critical GitLab path-traversal vulnerability that has moved beyond theoretical risk into confirmed exploitation. It affects self-managed GitLab CE/EE and could allow an unauthenticated remote attacker to read arbitrary files from the GitLab.
-
Istio 1.31 Adds Agentgateway Waypoints and Moves Release Artifacts off Google Cloud
Istio 1.31 adds agentgateway waypoints in ambient mode, with a canary configuration fix included in 1.31.1. It also ends the publication of images and Helm charts to Google Cloud, requiring repository migration ahead of the 13 October outage test and signing-key updates for teams verifying images.
-
AI Agents Are Disrupting Open Source Security Disclosure
A recent article by Anil Madhavapeddy argues that AI agents can turn publicly available clues about software vulnerabilities into working exploits, reducing the effectiveness of traditional disclosure embargoes in open source projects. The author highlights the need for faster patching and release processes as the time between vulnerability disclosure and exploitation shrinks.
-
Uber Eats Rebuilds Search Pipeline to Cut End-to-End Latency by 50%
Uber has rebuilt major parts of the Uber Eats search pipeline, reporting a 50% reduction in end-to-end latency. Changes include Above-the-Fold measurement, reduced retrieval work, parallel hydration, advertising data redesign, infrastructure optimizations, and an agentic coding workflow. Uber is also exploring microbatching, product-based retrieval, and HTTP multipart streaming.
-
Envoy Gateway 1.9.1 Tightens Security and Addresses a Difficult Upgrade Path
Envoy Gateway has released v1.9.1, a maintenance release that focuses heavily on security, upgrade reliability, and operational correctness following the broader v1.9 release.
-
OpenAI DevDay 2026 Recap for Developers
OpenAI announced a series of product and developer updates at DevDay 2026, including GPT-6.1 Sol, computer use for the Agents API, cloud-based Codex environments, a Decisions API, and new plugin capabilities for ChatGPT.
-
Engineering Production Systems for an Agentic Era: QCon San Francisco 2026
QCon San Francisco 2026 will bring together practitioners from Airbnb, OpenAI, Netflix, Honeycomb, and other engineering organizations to share how they are building, operating, and evolving production systems as AI agents take on a larger role.
-
Docker Sandbox Kit Spec: Packaging AI Agent Permissions as OCI Images
Docker has announced that it is bringing the Sandbox Kit Specification to the CNCF, aiming to make what an AI agent may access as portable as the agent itself.
-
DigitalOcean Managed Agents Brings Managed Cloud Infrastructure to AI Agents
DigitalOcean recently launched DigitalOcean Managed Agents in public preview, offering a managed cloud infrastructure layer for AI agents with isolated microVM runtimes, governed tool access, and serverless AI inference.
-
Qualcomm Unveils Linux Preview on Snapdragon X2 to Accelerate Upstream ARM Laptops
Qualcomm has released an early dev preview of Linux for its upcoming Snapdragon X2 Series laptop processors. The initiative focuses on integrating with the mainline Linux kernel ahead of commercial release to reduce software issues historically faced by ARM laptops. The preview includes a functional Debian 13 environment and aims to standardize system initialization and hardware task management.
-
How to Develop Software Engineering Skills in the Age of AI
Software engineering skill development requires slowing down. Generative AI has changed the landscape of skill development for software engineering. Tools and AI can accelerate outcomes, but they may not support skill development. Engineers must understand how systems work to learn things. Senior developers can coach juniors by using learning techniques.
-
TypeSafe AI Releases Jev: a Decision-Only Model That Returns Typed Probabilities Instead of Text
TypeSafe AI, founded by former OpenAI researcher Diogo Almeida, has introduced Jev, a decision-making model that generates typed outputs rather than text. It evaluates inputs in parallel, providing results with probabilistic scores and confidence values. Jev's adoption has been swift, with integrations into platforms like Vercel and Netlify, highlighting its efficiency over traditional models.
-
Container Apps Express Reaches GA on a Newly Generally Available Sandbox Layer
Microsoft has made Azure Container Apps Express generally available alongside Container Apps Sandboxes, the microVM compute layer it runs on. Express skips environment provisioning and scales to zero, with subsecond startup from prewarmed pools. Custom domains, zone redundancy, Key Vault references, OpenTelemetry and Dapr are not supported.
-
InfoQ Online Cohorts Address AI Security and Coding Agent Verification
A look at two InfoQ online certification cohorts covering security and privacy decisions in production AI systems and the verification needed when coding agents work in existing codebases.
-
Cursor Uses S3 WAL to Scale Git Storage to More than 300 Pushes per Second
Cursor has introduced Continuity, a Git storage architecture that uses an S3 backed write ahead log as the source of truth. The design turns local NVMe repositories into warm caches and separates replica coordination from consistency. Cursor reports linear read scaling with up to 100 replicas and more than 300 pushes per second with S3 Express One Zone in synthetic tests.