<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>The Commit Log</title>
<link>https://thecommitlog.com</link>
<atom:link href="https://thecommitlog.com/rss.xml" rel="self" type="application/rss+xml"/>
<description>A curated journal of writing on technology, programming, design, AI, DevOps, and careers in tech — tutorials, deep dives, and field notes.</description>
<language>en-us</language>
<lastBuildDate>Mon, 10 Aug 2026 10:47:24 GMT</lastBuildDate>
<item><title>Google slashes AI Plus to $4.99, doubles storage, ignites price war</title><link>https://thecommitlog.com/article/google-ai-plus-price-war-storage</link><guid isPermaLink="true">https://thecommitlog.com/article/google-ai-plus-price-war-storage</guid><pubDate>Wed, 10 Jun 2026 11:34:49 GMT</pubDate><category>Technology</category><description>Google reduces Google AI Plus to $4.99/month and doubles quota to 400 GB, signaling the U.S. adoption of aggressive, emerging-market pricing that pressures standalone AI IPO valuations.</description></item><item><title>Six Proto6 Flaws in protobuf.js Enable RCE and DoS Across Node.js Ecosystems</title><link>https://thecommitlog.com/article/protobuf-js-rce-dos-vulnerabilities</link><guid isPermaLink="true">https://thecommitlog.com/article/protobuf-js-rce-dos-vulnerabilities</guid><pubDate>Wed, 10 Jun 2026 11:22:44 GMT</pubDate><category>DevSecOps</category><description>Six new vulnerabilities in protobuf.js allow attackers to execute arbitrary code and crash services by exploiting how the library handles untrusted schemas.</description></item><item><title>Microsoft Suspends 70+ Repos After AI Dev Password Theft</title><link>https://thecommitlog.com/article/microsoft-github-repos-ai-dev-password-theft</link><guid isPermaLink="true">https://thecommitlog.com/article/microsoft-github-repos-ai-dev-password-theft</guid><pubDate>Wed, 10 Jun 2026 11:14:38 GMT</pubDate><category>DevSecOps</category><description>Attackers injected credential-harvesting malware into more than 70 Microsoft GitHub repositories, triggering inside AI coding assistants and exposing supply-chain fragility.</description></item><item><title>Anthropic Splits Mythos Weights in Claude Fable 5, Routes Risk to Opus</title><link>https://thecommitlog.com/article/anthropic-ships-claude-fable-5-shared-weights</link><guid isPermaLink="true">https://thecommitlog.com/article/anthropic-ships-claude-fable-5-shared-weights</guid><pubDate>Wed, 10 Jun 2026 11:04:38 GMT</pubDate><category>AI &amp; ML</category><description>Anthropic ships Claude Fable 5 with identical weights to Mythos 5, routing high-risk queries to Opus 4.8 and locking pricing at $10/$50 per million tokens.</description></item><item><title>Nintendo Engineers Separate Switch 2 SKU for EU Right-to-Repair Mandates</title><link>https://thecommitlog.com/article/nintendo-switch-2-eu-battery-regulation</link><guid isPermaLink="true">https://thecommitlog.com/article/nintendo-switch-2-eu-battery-regulation</guid><pubDate>Thu, 04 Jun 2026 04:34:52 GMT</pubDate><category>Technology</category><description>Nintendo registers a distinct Switch 2 variant marked &quot;OSM&quot; to meet EU Battery Regulation, splitting mechanical design and logistics from global baselines ahead of the February 2027 enforcement window.</description></item><item><title>Ammar Askar Leaks VS Code OAuth Exploit Amid Microsoft Disclosure Revolt</title><link>https://thecommitlog.com/article/vs-code-oauth-exploit-ammar-askar</link><guid isPermaLink="true">https://thecommitlog.com/article/vs-code-oauth-exploit-ammar-askar</guid><pubDate>Wed, 03 Jun 2026 17:41:00 GMT</pubDate><category>Technology</category><description>Independent researcher Ammar Askar publishes a working Visual Studio Code exploit in roughly one hour, citing dismissed MSRC submissions and escalating the zero-day conflict driven by Nightmare Eclipse.</description></item><item><title>Espressif's ESP32-S31 Collapses Connectivity Chains Into a Single RISC-V Die</title><link>https://thecommitlog.com/article/esp32-s31-risc-v-soc-gigabit-ethernet</link><guid isPermaLink="true">https://thecommitlog.com/article/esp32-s31-risc-v-soc-gigabit-ethernet</guid><pubDate>Wed, 03 Jun 2026 17:32:53 GMT</pubDate><category>Technology</category><description>Espressif releases the ESP32-S31, a dual-core RISC-V SoC at 320 MHz featuring Wi-Fi 6, Bluetooth 5.4, and Gigabit Ethernet, signaling a total architectural shift and aggressive BOM compression.</description></item><item><title>Anthropic Selects Morgan Stanley, Goldman Sachs to Lead IPO</title><link>https://thecommitlog.com/article/anthropic-morgan-stanley-goldman-sachs-ipo</link><guid isPermaLink="true">https://thecommitlog.com/article/anthropic-morgan-stanley-goldman-sachs-ipo</guid><pubDate>Wed, 03 Jun 2026 17:23:28 GMT</pubDate><category>Technology</category><description>Anthropic selects Morgan Stanley and Goldman Sachs to lead its IPO, mirroring rival OpenAI's advisory setup and signaling a pivot toward institutional-scale capital absorption amid surging enterprise revenue.</description></item><item><title>Trump Signs Voluntary 30-Day Pre-Release Review Framework for Frontier AI</title><link>https://thecommitlog.com/article/frontier-models-voluntary-review</link><guid isPermaLink="true">https://thecommitlog.com/article/frontier-models-voluntary-review</guid><pubDate>Wed, 03 Jun 2026 11:41:37 GMT</pubDate><category>AI &amp; ML</category><description>June 2 brings a voluntary 30-day pre-release review for covered frontier models. Industry lobbying shrank the window from 90 days, trading regulatory rigidity for launch velocity and faster vulnerability disclosure.</description></item><item><title>Anthropic Expands Project Glasswing to Secure Critical Software Supply Chains</title><link>https://thecommitlog.com/article/expanding-project-glasswing</link><guid isPermaLink="true">https://thecommitlog.com/article/expanding-project-glasswing</guid><pubDate>Tue, 02 Jun 2026 13:34:22 GMT</pubDate><category>AI &amp; ML</category><description>Anthropic adds roughly 150 new partners to Project Glasswing, targeting critical infrastructure and vendors to scale defenses against imminent AI-driven cyber threats.</description></item><item><title>Instagram's Goofy Account Takeover Exposes Broken API Controls</title><link>https://thecommitlog.com/article/instagram-broken-api-controls</link><guid isPermaLink="true">https://thecommitlog.com/article/instagram-broken-api-controls</guid><pubDate>Tue, 02 Jun 2026 12:30:10 GMT</pubDate><category>DevSecOps</category><description>Threat actor &quot;Solonik&quot; dumps 17.5 million records, revealing how flawed password-reset triggers and weak API gateways enable trivial account hijacks.</description></item><item><title>Pacific Fusion Validates 440 GW Pulse, Targets 2030 Net Facility Gain</title><link>https://thecommitlog.com/article/pacific-fusion-440-gw-pulse</link><guid isPermaLink="true">https://thecommitlog.com/article/pacific-fusion-440-gw-pulse</guid><pubDate>Tue, 02 Jun 2026 12:02:08 GMT</pubDate><category>Technology</category><description>Pacific Fusion's prototype pushes 440 gigawatts in an 80-nanosecond burst, validating a modular pulsed-power approach that aims to slash driver costs and achieve net facility gain by 2030.</description></item><item><title>Jane Street Builds Interactive Debugging Dashboards From Linear Logs</title><link>https://thecommitlog.com/article/interactive-debugging-dashboards-linear-logs</link><guid isPermaLink="true">https://thecommitlog.com/article/interactive-debugging-dashboards-linear-logs</guid><pubDate>Tue, 02 Jun 2026 09:46:42 GMT</pubDate><category>Programming</category><description>Jane Street engineers deploy Bonsai_term to render strace output as interactive terminal dashboards, exposing a 2026 engineering pivot toward composable, keyboard-first toolchains.</description></item><item><title>Dashlane Suspends Accounts After Brute-Force Attack Sparks User Lockouts</title><link>https://thecommitlog.com/article/dashlane-brute-force-account-lockouts</link><guid isPermaLink="true">https://thecommitlog.com/article/dashlane-brute-force-account-lockouts</guid><pubDate>Tue, 02 Jun 2026 07:48:53 GMT</pubDate><category>DevSecOps</category><description>Dashlane auto-suspended accounts to halt a May 31 brute-force campaign, triggering cascading 2FA failures, email glitches, and lingering access disputes that expose operational fragility.</description></item><item><title>Nvidia CEO Audits Salaries Across 42,000-Employee Workforce</title><link>https://thecommitlog.com/article/nvidia-ceo-audits-salaries-42000-employees</link><guid isPermaLink="true">https://thecommitlog.com/article/nvidia-ceo-audits-salaries-42000-employees</guid><pubDate>Tue, 02 Jun 2026 04:43:21 GMT</pubDate><category>Career</category><description>Jensen Huang insists on paying employees &quot;as much as possible,&quot; personally reviewing every salary recommendation at Nvidia to maintain a 2.5% turnover rate against industry norms.</description></item><item><title>Anthropic files S-1 at $965B valuation, eyes fall 2026 IPO</title><link>https://thecommitlog.com/article/anthropic-s-1-965b-valuation-ipo</link><guid isPermaLink="true">https://thecommitlog.com/article/anthropic-s-1-965b-valuation-ipo</guid><pubDate>Tue, 02 Jun 2026 04:36:14 GMT</pubDate><category>Technology</category><description>Anthropic confidentially filed an S-1 carrying a $965 billion post-money valuation, overtaking OpenAI as the highest-valued private AI firm and targeting a fall 2026 public debut.</description></item><item><title>Strava Charges $11.99 Monthly Fee To Stop Zero-Code AI Scrapers</title><link>https://thecommitlog.com/article/strava-developer-subscription-fee</link><guid isPermaLink="true">https://thecommitlog.com/article/strava-developer-subscription-fee</guid><pubDate>Mon, 01 Jun 2026 17:32:51 GMT</pubDate><category>Technology</category><description>Strava closes anonymous access and introduces a flat developer subscription to manage a 448 percent surge in automated requests ahead of its IPO filing.</description></item><item><title>AI Savings Misses Should Alarm Executives, Bain Warns</title><link>https://thecommitlog.com/article/ai-savings-misses-bain-warns</link><guid isPermaLink="true">https://thecommitlog.com/article/ai-savings-misses-bain-warns</guid><pubDate>Mon, 01 Jun 2026 07:30:19 GMT</pubDate><category>AI &amp; ML</category><description>Only 31% of CFOs report satisfaction with AI deployments, yet 83% plan to raise enterprise spending by over 15%. The growing gap between capital allocation and realized returns demands immediate executive attention.</description></item><item><title>Dell Resurrects XPS 13 to Challenge Apple’s Budget Floor</title><link>https://thecommitlog.com/article/dell-xps-13-intel-silicon-students</link><guid isPermaLink="true">https://thecommitlog.com/article/dell-xps-13-intel-silicon-students</guid><pubDate>Mon, 01 Jun 2026 04:52:57 GMT</pubDate><category>Technology</category><description>Dell brings back the XPS 13 with a $699 MSRP and $599 promo, deploying modern Intel silicon to reclaim the sub-$600 student and productivity segment.</description></item><item><title>SoftBank Pledges €75 Billion for Five Gigawatts of French AI Infrastructure</title><link>https://thecommitlog.com/article/softbank-french-ai-infrastructure</link><guid isPermaLink="true">https://thecommitlog.com/article/softbank-french-ai-infrastructure</guid><pubDate>Sun, 31 May 2026 08:12:56 GMT</pubDate><category>Technology</category><description>SoftBank Group is deploying €75 billion to build five gigawatts of AI data centers in France, locking in a major European infrastructure play tied to sovereign compute goals.</description></item><item><title>PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation</title><link>https://thecommitlog.com/article/globalprotect-authentication-bypass-active-exploitation</link><guid isPermaLink="true">https://thecommitlog.com/article/globalprotect-authentication-bypass-active-exploitation</guid><pubDate>Sat, 30 May 2026 07:35:41 GMT</pubDate><category>DevSecOps</category><description>CISA mandated a June 1 federal remediation deadline after researchers tracked active exploitation of a narrowly configured but structurally devastating authentication bypass in Palo Alto Networks’ GlobalProtect stack.</description></item><item><title>MCP Is Dead? No, Just Splitting Under Weight.</title><link>https://thecommitlog.com/article/mcp-splitting-weight-token-bloat-rce</link><guid isPermaLink="true">https://thecommitlog.com/article/mcp-splitting-weight-token-bloat-rce</guid><pubDate>Sat, 30 May 2026 06:43:13 GMT</pubDate><category>Programming</category><description>OX Security uncovered a critical RCE in Anthropic's MCP SDKs spanning 150 million downloads. Anthropic called the flaw expected. Token bloat and architectural rigidity are driving a bifurcation away from heavyweight wrappers toward lightweight CLI alternatives.</description></item><item><title>Enterprise AI Pilots Stall as Overcommitment Collides With Operational Reality</title><link>https://thecommitlog.com/article/enterprise-ai-pilots-stall-overcommitment</link><guid isPermaLink="true">https://thecommitlog.com/article/enterprise-ai-pilots-stall-overcommitment</guid><pubDate>Fri, 29 May 2026 18:38:46 GMT</pubDate><category>Technology</category><description>Generative AI initiatives are consistently missing targets. Corporations spending heavily on compute and custom models are learning that workflow integration outweighs algorithmic novelty.</description></item><item><title>Waymo Unveils Ojai Robotaxi: Cheaper Units, Faster Scale, and a Hard Pivot</title><link>https://thecommitlog.com/article/waymo-ojai-robotaxi-cheaper-units</link><guid isPermaLink="true">https://thecommitlog.com/article/waymo-ojai-robotaxi-cheaper-units</guid><pubDate>Fri, 29 May 2026 14:43:07 GMT</pubDate><category>Technology</category><description>Waymo introduces the Ojai robotaxi in San Francisco, Los Angeles, and Phoenix, prioritizing free trials and reduced unit costs. The launch marks a strategic pivot toward scalable robotics as the company manages fleet-wide safety recalls.</description></item><item><title>Russian-Linked GREYVIBE Targets Ukraine With AI-Automated Kill Chains</title><link>https://thecommitlog.com/article/greyvibe-ai-automated-kill-chains</link><guid isPermaLink="true">https://thecommitlog.com/article/greyvibe-ai-automated-kill-chains</guid><pubDate>Fri, 29 May 2026 13:19:01 GMT</pubDate><category>DevSecOps</category><description>Russian-linked GREYVIBE weaponizes generative AI across its kill chain to target Ukrainian entities, demonstrating how skill compression enables low-sophistication operators to run high-volume, multi-vector campaigns.</description></item><item><title>Browser-Native AI Turns Public Pages Into Covert Command Payloads</title><link>https://thecommitlog.com/article/prompt-injection-browser-native-ai</link><guid isPermaLink="true">https://thecommitlog.com/article/prompt-injection-browser-native-ai</guid><pubDate>Fri, 29 May 2026 13:07:48 GMT</pubDate><category>DevSecOps</category><description>ChatGPT's browser integration treats loaded webpages as authoritative input, allowing attackers to hide prompt injections in third-party markup. Ordinary sites become credential-harvesting traps that bypass traditional access controls.</description></item><item><title>AI Is Turning Summer Internships Into Hyper-Competitive Gauntlets</title><link>https://thecommitlog.com/article/ai-summer-internships-hyper-competitive</link><guid isPermaLink="true">https://thecommitlog.com/article/ai-summer-internships-hyper-competitive</guid><pubDate>Fri, 29 May 2026 11:14:21 GMT</pubDate><category>Career</category><description>Traditional entry-level pipelines are fracturing as generative automation collapses routine tasks. Students must now prove AI-fluency and high-judgment just to secure a placement.</description></item><item><title>Adobe's AI Agent Demands Constant Correction</title><link>https://thecommitlog.com/article/adobe-ai-agent-human-oversight</link><guid isPermaLink="true">https://thecommitlog.com/article/adobe-ai-agent-human-oversight</guid><pubDate>Fri, 29 May 2026 10:38:22 GMT</pubDate><category>Design</category><description>Adobe launches a conversational AI assistant for Express and Photoshop, promising agentic creativity. Early demos reveal a system that executes commands mechanically but struggles with abstract direction, demanding relentless human oversight.</description></item><item><title>The 1.44 MB Limit Forces Engineering Hygiene Back Into Mobile Apps</title><link>https://thecommitlog.com/article/144mb-limit-engineering-hygiene-mobile-apps</link><guid isPermaLink="true">https://thecommitlog.com/article/144mb-limit-engineering-hygiene-mobile-apps</guid><pubDate>Fri, 29 May 2026 10:00:46 GMT</pubDate><category>Programming</category><description>A revived floppy disk standard caps downloads at 1.44 MB, stripping cross-platform runtimes and forcing rapid cold starts. The constraint reveals what happens when size dictates architecture.</description></item><item><title>Explosive Static-Fire Failure Halts Blue Origin's New Glenn Ahead of Critical Payload Manifest</title><link>https://thecommitlog.com/article/blue-origin-new-glenn-static-fire-failure</link><guid isPermaLink="true">https://thecommitlog.com/article/blue-origin-new-glenn-static-fire-failure</guid><pubDate>Fri, 29 May 2026 08:02:03 GMT</pubDate><category>Technology</category><description>Blue Origin's New Glenn detonated during a static-fire test at Cape Canaveral, threatening Amazon Kuiper deployments and NASA Artemis timelines amid escalating ground-level failures.</description></item>
</channel>
</rss>