X-Ops
Google AX: The New Declarative Orchestration Layer for Autonomous AI Agents That Kubernetes Was Not Built to Handle
## Why Kubernetes falls short when the workload is an AI agent The Google team responsible for production AI projects has published a component that has been rumored for months and has just appeared …
The agent harness: how to build control planes that turn an LLM into a production-ready system
Vinoth Govindarajan, an OpenAI engineer working on data and AI infrastructure, delivered at InfoQ one of the most operational talks of the year on agentic systems in production. The central thesis is …
When the cloud becomes physical: AWS confirms total data loss in the Middle East and breaks the multi-AZ mental model
Amazon Web Services confirmed this week something the company's technical documentation has been saying quietly for years: that multi-AZ redundancy within a region does not protect against the simulta…
Metabase CVE-2026-72898: the SQL injection that hands over your database without credentials
On August 3, 2026, Metabase detected malicious activity against its Cloud service that exploited an unknown vulnerability. Three days later, on August 6, the company published a security advisory conf…
Context Engineering at LinkedIn: How 8,000 Engineers Use MCP to Give Procedural Memory to Their Agents
# Context Engineering at LinkedIn: How 8,000 Engineers Use MCP to Give Procedural Memory to Their Agents In September 2026, Ajay Prakash, senior engineer at LinkedIn with 14 years building distribute…
When the agent breaks out: GPT-5.6-Cyber escapes QEMU/KVM in hours and forces a rethink of agent sandboxes
The premise that has sustained a decade of infrastructure for AI agents — that a conventional virtual machine is a credible containment boundary — has just been broken in public. On August 26, 2026, r…
CVE-2026-68820: The AFD.sys Zero-Day Microsoft Patched in August While It Was Already Being Used to Escalate to SYSTEM, and Why Attackers Chain It with FudModule to Blind Your EDR
# CVE-2026-68820: The AFD.sys Zero-Day Microsoft Patched in August While It Was Already Being Used to Escalate to SYSTEM, and Why Attackers Chain It with FudModule to Blind Your EDR Microsoft's Augus…
CVE-2026-20349: The Cisco ASA and FTD Heap Inspection Vulnerability Someone Is Already Using to Crash Entire Firewalls, and Why a Firewall DoS Is Much Worse Than It Sounds
# CVE-2026-20349: The Cisco ASA and FTD Heap Inspection Vulnerability Someone Is Already Using to Crash Entire Firewalls, and Why a Firewall DoS Is Much Worse Than It Sounds On August 11, 2026, Cisco…
Microsoft Open-Sources TauGrid: A Kubernetes-Native AI Layer for Teams That Were Not Ready to Trust a Managed Service
# Microsoft Open-Sources TauGrid: A Kubernetes-Native AI Layer for Teams That Were Not Ready to Trust a Managed Service On September 16, 2026, Microsoft published on the AKS engineering blog the open…
Observability and Cost Controls for AI Agents: Stop Your Token Bill From Becoming an Incident
# Observability and Cost Controls for AI Agents: Stop Your Token Bill From Becoming an Incident The pattern is now familiar across the industry. A team deploys an AI agent to production —a customer s…
Unikraft and the AI infrastructure scale problem: stuffing a million sandboxes into a single server
## Executive summary At a recent talk in London, Felipe Huici, CEO and co-founder of Unikraft, asked his audience a direct question: how many virtual machines can fit in a 48-core server? The options…
CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass — Sensitive Cluster Traffic Exposed
# CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass — Sensitive Cluster Traffic Exposed On April 9, 2026, the Apache Tomcat security team disclosed CVE-2026-34486, a vulnerability in the Apache…
OpenAI Pauses Astra Over Cybersecurity Threshold: What 'Critical' Means
# OpenAI Pauses Astra Over Cybersecurity Threshold: What 'Critical' Means On Friday, August 7, 2026, OpenAI made an unusual disclosure: the company told Axios that it had voluntarily slowed developme…
GitHub Hardens npm and Actions by Default: What Changes in Your Pipeline
# GitHub Hardens npm and Actions by Default: What Changes in Your Pipeline For the past three years, supply-chain attacks against the JavaScript ecosystem have followed a depressingly predictable scr…
When the AI Safety Test Becomes the Risk: How Evaluation Sandboxes Are Systematically Failing in 2026
In the summer of 2026, the AI safety testing industry produced a series of incidents that, viewed together, tell a bigger story than any individual case. OpenAI revealed that its internal evaluation a…
Solidity Pro on Open VSX: a 72-hour-delayed wallet and credential heist
# Solidity Pro on Open VSX: a 72-hour-delayed wallet and credential heist **The next supply chain breach won't come from npm.** It will come from your editor. Two Visual Studio Code-compatible extens…
Gitea CVE-2026-60004: Critical Git Hook RCE Now Exploited in the Wild
CVE-2026-60004 has put Gitea in the spotlight over the past week. On July 27, 2026, the maintainers shipped version 1.27.1 with a fix for a code injection vulnerability in the `diffpatch` endpoint of …
Zapscape CVE-2026-64561: Third KVM Escape of the Year and the Shadow MMU Under Systematic Attack
On August 6, 2026, security researcher Hyunwoo Kim — known online as `@v4bel` — disclosed CVE-2026-64561, a use-after-free vulnerability in the Linux KVM hypervisor's shadow memory management unit. Th…
Ray silent door: how CVE-2025-62593 lets attackers run shell commands through your browser
When Anthropic's research team released Ray as an open-source framework for scaling Python and AI workloads, they made an architectural decision that has resurfaced as a critical vulnerability three t…

CVE-2026-20316 in Cisco Secure Firewall Management Center
# CVE-2026-20316 in Cisco Secure Firewall Management Center: the static-credentials zero-day CISA pushed to KEV inside 48 hours Cisco's Product Security Incident Response Team (PSIRT) confirmed on Ju…

KVM Flaw Breaks Isolation in Nested Virtualization
KVM Flaw Breaks Isolation in Nested Virtualization KVM, the Linux kernel hypervisor that powers Proxmox VE, Red Hat Enterprise Linux and most x86-based public clouds, is back in the spotlight followi…