InfoQ Homepage News
-
Google's Android Security State Libraries Enable Component-Level Security Verification
Google's AndroidX Security State libraries enables apps to verify security patch status at the individual component level, rather than relying on a single, device-wide security patch date.
-
Pizza Bot: Open-Source Inbox for Background AI Agents
A team of developers working at AWS recently open-sourced Pizza Bot, a self-hosted application designed to let AI agents run tasks in the background and return results through an inbox-style interface. Agents can perform scheduled or webhook-triggered work, delegate tasks to specialized workers, and pause for human approval when needed.
-
New Archestra's OpenAPPA Saturates Two Major Security Benchmarks with a 0% Attack Success Rate
Archestra released OpenAPPA, an open-source security engine designed to stop data exfiltration caused by prompt injection or model hallucination. The team reports zero successful attacks when running security benchmarks Bench-Corp (20 multi-step enterprise workflows) and AgentThreatBench, versus 10% for Claude Code’s auto mode and 31% for Microsoft FIDES.
-
GitLab Vulnerability under Active Exploitation Enables Unauthenticated Data Exfiltration
CVE-2026-85706 is a critical GitLab path-traversal vulnerability that has moved beyond theoretical risk into confirmed exploitation. It affects self-managed GitLab CE/EE and could allow an unauthenticated remote attacker to read arbitrary files from the GitLab.
-
Istio 1.31 Adds Agentgateway Waypoints and Moves Release Artifacts off Google Cloud
Istio 1.31 adds agentgateway waypoints in ambient mode, with a canary configuration fix included in 1.31.1. It also ends the publication of images and Helm charts to Google Cloud, requiring repository migration ahead of the 13 October outage test and signing-key updates for teams verifying images.
-
AI Agents Are Disrupting Open Source Security Disclosure
A recent article by Anil Madhavapeddy argues that AI agents can turn publicly available clues about software vulnerabilities into working exploits, reducing the effectiveness of traditional disclosure embargoes in open source projects. The author highlights the need for faster patching and release processes as the time between vulnerability disclosure and exploitation shrinks.
-
Uber Eats Rebuilds Search Pipeline to Cut End-to-End Latency by 50%
Uber has rebuilt major parts of the Uber Eats search pipeline, reporting a 50% reduction in end-to-end latency. Changes include Above-the-Fold measurement, reduced retrieval work, parallel hydration, advertising data redesign, infrastructure optimizations, and an agentic coding workflow. Uber is also exploring microbatching, product-based retrieval, and HTTP multipart streaming.
-
Envoy Gateway 1.9.1 Tightens Security and Addresses a Difficult Upgrade Path
Envoy Gateway has released v1.9.1, a maintenance release that focuses heavily on security, upgrade reliability, and operational correctness following the broader v1.9 release.
-
OpenAI DevDay 2026 Recap for Developers
OpenAI announced a series of product and developer updates at DevDay 2026, including GPT-6.1 Sol, computer use for the Agents API, cloud-based Codex environments, a Decisions API, and new plugin capabilities for ChatGPT.
-
Engineering Production Systems for an Agentic Era: QCon San Francisco 2026
QCon San Francisco 2026 will bring together practitioners from Airbnb, OpenAI, Netflix, Honeycomb, and other engineering organizations to share how they are building, operating, and evolving production systems as AI agents take on a larger role.
-
Docker Sandbox Kit Spec: Packaging AI Agent Permissions as OCI Images
Docker has announced that it is bringing the Sandbox Kit Specification to the CNCF, aiming to make what an AI agent may access as portable as the agent itself.
-
DigitalOcean Managed Agents Brings Managed Cloud Infrastructure to AI Agents
DigitalOcean recently launched DigitalOcean Managed Agents in public preview, offering a managed cloud infrastructure layer for AI agents with isolated microVM runtimes, governed tool access, and serverless AI inference.
-
Qualcomm Unveils Linux Preview on Snapdragon X2 to Accelerate Upstream ARM Laptops
Qualcomm has released an early dev preview of Linux for its upcoming Snapdragon X2 Series laptop processors. The initiative focuses on integrating with the mainline Linux kernel ahead of commercial release to reduce software issues historically faced by ARM laptops. The preview includes a functional Debian 13 environment and aims to standardize system initialization and hardware task management.
-
How to Develop Software Engineering Skills in the Age of AI
Software engineering skill development requires slowing down. Generative AI has changed the landscape of skill development for software engineering. Tools and AI can accelerate outcomes, but they may not support skill development. Engineers must understand how systems work to learn things. Senior developers can coach juniors by using learning techniques.
-
TypeSafe AI Releases Jev: a Decision-Only Model That Returns Typed Probabilities Instead of Text
TypeSafe AI, founded by former OpenAI researcher Diogo Almeida, has introduced Jev, a decision-making model that generates typed outputs rather than text. It evaluates inputs in parallel, providing results with probabilistic scores and confidence values. Jev's adoption has been swift, with integrations into platforms like Vercel and Netlify, highlighting its efficiency over traditional models.