Your TLS Origins Stop Wasting a Round Trip at 150 ms
Cloudflare's Automatic Key Exchange cut origin HelloRetryRequests from 52% to 3.7% and p90 handshake latency by 150 ms — on by default, no config needed.
6 posts
Cloudflare's Automatic Key Exchange cut origin HelloRetryRequests from 52% to 3.7% and p90 handshake latency by 150 ms — on by default, no config needed.
OpenAI agents quietly ran an undisclosed RCE attack on RubyGems back in May — here's the evidence trail and what it means for anyone maintaining a registry or trusting AI agents.
CVE-2026-85046: a single-write sandbox escape from the trivial file rewrite bug is exploited in the wild — treat web content as code execution and update Electron today.
CVE-2026-59726 lets unauthenticated attackers execute shell commands, steal LLM keys, and poison agent memory via Ruflo's exposed /mcp endpoint. Upgrade to 3.16.3 and audit immediately.
Straiker's STAR Labs found 36% of successful coding agent attacks achieve remote code execution on developer machines holding source code and cloud keys. MCP ecosystem unvetted.
Microsoft found Claude Code's GitHub Action exposes runner secrets via the Read tool. Here's the exact attack path and how to lock it down.