Axios compromised on NPM – Malicious versions drop remote access trojan

https://cdn.prod.website-files.com/673b71f0790aabf30bd30bf8/69cb2363fdc3f8e8fa0460a5_blog-cover-image.png
StepSecurity identified malicious versions of the axios HTTP client library published to npm, axios@1.14.1 and axios@0.30.4, which inject a remote access trojan (RAT) dropper. Developers who installed these versions should rotate all secrets and credentials, check network logs, and downgrade to safe versions, and StepSecurity provides end-to-end npm supply chain security across three pillars: ...

Open source CAD in the browser (Solvespace)

SolveSpace has a web version that runs in the browser with some speed penalty and bugs. It's experimental and can be hosted locally like static web content.

Combinators

https://tinyapl.rubenverg.com/combinators/same.svg
Combinators are functions that refer to their arguments without modifying them. They are often represented by bird names in APL, such as Kestrel and Cardinal.

Ollama is now powered by MLX on Apple Silicon in preview

https://files.ollama.com/ollama_mlx.png
Ollama now runs faster on Apple silicon with MLX framework, leveraging GPU Neural Accelerators for speedup. Ollama 0.19 sees 1851 token/s prefill and 134 token/s decode with improved memory efficiency and model accuracy.

Claude Code's source code has been leaked via a map file in their NPM registry

Something went wrong, but don’t fret — let’s give it another shot. Some privacy related extensions may cause issues on x.com. Please disable them and try again.

Artemis II is not safe to fly

https://idlewords.com/images/oig_heat_shield.jpg
NASA's Orion spacecraft has a defective heat shield that could kill the crew on Artemis II due to spalling, impact from heat shield fragments, and bolt erosion. Despite this, NASA is planning to fly the mission with a crew, citing a change in the re-entry trajectory and a new heat shield design for future missions.

Audio tapes reveal mass rule-breaking in Milgram's obedience experiments

https://sp-ao.shortpixel.ai/client/to_webp,q_glossy,ret_img,w_750,h_375/https://www.psypost.org/wp-content/uploads/2024/01/stanley-milgram-experiment-1-750x375.jpg
Researchers analyzed audio recordings from the Milgram experiment and found that obedient participants broke the rules of the study most of the time, often ignoring the scientific procedure. This suggests that the laboratory environment was one of unauthorized violence, rather than a legitimate scientific study.

Oracle slashes 30k jobs with a cold 6 a.m. email

Oracle laid off 20,000-30,000 employees, roughly 18% of its workforce, in a single email with no advance notice. The cuts are tied to Oracle's aggressive expansion into AI infrastructure, freeing up $8-10 billion in cash flow.

Fedware: Government apps that spy harder than the apps they ban

https://www.sambent.com/content/images/size/w160/2025/07/370-----Photos-1.png
The US government's mobile apps, including the White House app, request excessive permissions and embed trackers, violating users' privacy. These apps, part of a surveillance apparatus, collect sensitive data that feeds into ICE raids and warrantless location tracking.

Universal Claude.md – cut Claude output tokens

https://opengraph.githubassets.com/51e61dfbcd98b9faca0cb7e47d57dfdbf9b19326ffa23c3c1c377eea914ef093/drona23/claude-token-efficient
A CLAUDE.md file reduces Claude output verbosity by ~63% without code changes, targeting sycophancy, verbosity, and formatting noise. It's most beneficial for high-output use cases, and users can customize it to target specific failure modes and compose multiple files for different project types.

Google's 200M-parameter time-series foundation model with 16k context

https://opengraph.githubassets.com/3a715ab5ed97409698fa19e1f50846332c191dbd18b04dbc7566243837cc8897/google-research/timesfm
TimesFM is a pretrained time-series model by Google Research for forecasting. It can be installed via pip and used for point and quantile forecasting.

What major works of literature were written after age of 85? 75? 65?

https://statmodeling.stat.columbia.edu/wp-content/uploads/2026/03/author_age_at_publication-1024x614.png
The author discussed major works published by authors over 85, citing Sophocles' Philoctetes and Goethe's Faust, but found few notable works by authors over 80. A list of notable works by authors over 65 includes V. Hugo's Ninety-three, T. Mann's Doctor Faustus, and J. Saramago's Blindness.

Do your own writing

LLMs can undermine authenticity and credibility by generating writing that lacks thought and understanding. Effective writing requires human thoughtfulness and effort to establish credibility and increase understanding.

Multiple Sclerosis

Last week Sherri and I met with my neurologist to review the findings of blood and cerebral-spinal fluid lab analyses. I received a diagnosis of Relapsing-Remitting Multiple Sclerosis. If you ever watched The West Wing, you might recall this was the illness President Jeb Bartlett had and tried to keep secret. Well, I’m not planning to run for higher office, so am free to share the news in ...

30 Years Ago, Robots Learned to Walk Without Falling

https://spectrum.ieee.org/media-library/collage-of-hondas-p2-humanoid-robot-from-1996-against-a-background-of-figures-related-to-its-technical-features.jpg?id=65402169&width=980&quality=85
Honda's Prototype 2 (P2) was a humanoid robot developed in 1996 that could walk and climb stairs without falling. It was the first autonomous robot to achieve this feat and paved the way for future humanoid robots.

Good CTE, Bad CTE

https://boringsql.com/og-images/good-cte-bad-cte-og.jpg
CTEs are now inlined by default in PostgreSQL 12, allowing the planner to apply normal optimisations. Materialization is used when a CTE is referenced multiple times or contains side effects.

GitHub backs down, kills Copilot pull-request ads after backlash

https://regmedia.co.uk/2024/05/21/github1_shutterstock.jpg
GitHub removed Copilot's ability to insert ads into pull requests after backlash from developers. The feature was disabled after users complained of unwanted ads in their pull requests.

Clojure: The Documentary, official trailer [video]

7,655 Ransomware Claims in One Year: Group, Sector, and Country Breakdown

https://ciphercue.com/img/og-card.png
Ransomware groups posted 7,655 victim claims to public leak sites from March 2025 to March 2026, with Qilin being the most active group posting 1,179 claims across 74 countries. The top 5 groups accounted for 40% of the claims, and the remaining 124 groups collectively posted 4,628 claims, suggesting that disrupting any single group is unlikely to reduce the overall total significantly.

How to turn anything into a router

https://nbailey.ca/images/router.jpg
User wants to create a homebrew router using a Linux-powered device, such as a mini-PC, to bypass a US policy banning new consumer router imports.

RamAIn (YC W26) Is Hiring

https://bookface-images.s3.amazonaws.com/small_logos/9fe951afa5872a811734029111550a11062d931e.png
RamAIn builds AI agents for enterprise work, automating repetitive tasks 10x faster and more reliably than humans. We're hiring a Founding AI/ML researcher to design and deploy agents that reason, plan, and execute complex workflows autonomously.

Android Developer Verification

https://blogger.googleusercontent.com/img/a/AVvXsEgKvPOrkQ6xhfp3JzKhlQS63WlgsKEc3iI6Jl6VdfitojtR0j9py3hJ3S3dkp2JF39HU6lUswIJpFupt2fm5uFfWB7408f4mhvHWsM8JeO5tk0-M0jHpk4A40an8gtipxyKpGJrGBtdE7JadUHnRodVFB9NIMkwmnNJFqWw0x1ncIAoVb9h13CeV1p_jyQ
Android is rolling out developer verification to prevent malware and ensure user safety. Users will see no change in app installation experience until 2027, when unregistered apps will require ADB or advanced flow.

Turning a MacBook into a touchscreen with $1 of hardware (2018)

https://anishathalye.com/_next/static/images/explanation-5a0858b9a077cc4868d9b8c2c0a539d2.png
A team created a touchscreen MacBook using a $1 mirror and computer vision, allowing for touch input without an external webcam. The system uses a webcam, mirror, and computer vision to translate finger movements into mouse events, making existing apps touch-enabled.

Distributed data centers in our basements

This is likely a bit unrealistic, but why can't we make a half rack server to go in someones basement that can also heat up their hot water and use the basement floor as a heat sink as well? It seems like a lot of the blight of data centers is the energy to remove the heat. By distributing them into cool basements and even connecting them into the home heating system we could reduce that ...

In Expanding de Sitter Space, Quantum Mechanics Gets More Elusive

https://www.quantamagazine.org/wp-content/uploads/2026/03/Shalma-Wegsman-alt-profile.webp
Physicists are struggling to understand the quantum world in an expanding universe, particularly in de Sitter space where space expands exponentially. They are trying to learn from black holes to make sense of quantum mechanics in de Sitter space.

Acceptance of entomophagy among Canadians at an insectarium

https://media.springernature.com/w215h120/springer-static/image/art%3A10.1038%2Fs41538-024-00260-3/MediaObjects/41538_2024_260_Fig1_HTML.png
As global food systems face mounting sustainability pressures, insects are gaining attention as a promising alternative protein source. Yet, entomophagy remains culturally unfamiliar or stigmatized in many Western countries, including Canada. This study investigates attitudes toward insect consumption among 252 adult visitors to the Montreal Insectarium, a public institution promoting insect ...

We're Pausing Asimov Press

https://substackcdn.com/image/fetch/$s_!1IpX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07d4d237-15c0-4311-a297-02db1d4f74e0_2000x1260.jpeg
Asimov Press is going on hiatus in April due to new projects for its founders. The press has published 149 articles and two anthologies, reaching half a million readers monthly.

Nobody Is Coming to Save Your Career

https://images.unsplash.com/photo-1620416265040-cc777cad1883?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxtaXJyb3J8ZW58MHx8fHwxNzc0Mzg0MzEyfDA&ixlib=rb-4.1.0&q=80&w=1080
Your manager is not responsible for your career growth, you must take ownership and initiate conversations about your goals. To start, tell your manager you want to grow and discuss what's needed for a promotion, then take action to make progress toward your goals.

One of the largest salt mines in the world exists under Lake Erie

https://dims.apnews.com/dims4/default/1084da3/2147483647/strip/true/crop/3000x2000+0+0/resize/599x399!/quality/90/?url=https%3A%2F%2Fassets.apnews.com%2Fcc%2Fb5%2Fc2010f26ccc4dfba7ecbf50e5430%2F8c40ec4f614243f3901baa511683e7ec
Cargill's Whiskey Island salt mine in Cleveland extracts 3-4 million tons of salt annually to supply the Northeast and Great Lakes. The mine operates year-round to meet high demand due to a colder-than-usual winter.

Anthropic: Claude Code users hitting usage limits 'way faster than expected'

https://regmedia.co.uk/2016/03/11/empty-gauge.jpg
Users of Claude Code are experiencing high token usage and early quota exhaustion due to a combination of factors including reduced quotas during peak hours, bugs, and unclear usage limits. Anthropic is actively investigating the issue and users are negotiating with providers over acceptable pricing and usage models for AI development.