Keep up with tech in 5 minutes
Get the free daily email with summaries of the most interesting stories in startups 🚀, tech 📱, and programming 💻!
Join 1,600,000 readers from companies like Anthropic, OpenAI, and more for one daily email

Tau's humanoid cleaning service (1 minute read)
Tau's humanoid service is now available in San Francisco. Access is initially invite-only. The service costs $30 per hour. Each humanoid will be jointly controlled by a human operator and AI. Video of the robot in action is available in the article.
Jun 12 | Blog
I Tried to Build a Context Layer for My Agent in a Weekend. Reader, I Did Not Build a Context Layer for My Agent in a Weekend.
A "simple" weekend project turns into real infrastructure, and why agent context deserves a boring, reliable foundation.
SponsoredJul 29 | AI
Pacing the Frontier (Website)
AI could help create a dramatically better future. The world's leading AI companies believe they could be close to automating AI research. There is a real risk that capability development rapidly accelerates beyond researchers' ability to understand or control the resulting systems. Over a thousand employees from frontier AI companies have signed a statement requesting that the US government support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development.
Jul 29 | Dev
You don't have to be smart if you can think clearly (4 minute read)
Effective problem-solving in engineering requires the ability to think clearly and methodically, especially when faced with challenges that cannot be solved intuitively. Smart engineers often struggle when they encounter such problems, whereas strong engineers are able to systematically evaluate and address issues.
Jul 29 | Infosec
Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers (8 minute read)
Socket uncovered a three-month stealth campaign involving 18 npm packages that split loader functions across dependencies, making malicious intent hard to detect. They used unscoped lures impersonating Alibaba's @ali scope, pulling in smart-config-manager, which depends on cloud-config-fetcher and local-config-parser to retrieve attacker rules from GitHub and escape the Node.js vm sandbox via items.constructor.constructor. The staged aone-cli payload, a cross-platform RAT, supports command execution, file transfer, screenshots, an encrypted reverse TCP proxy, and DingTalk lateral movement. It persists through a ~/.zshrc entry, a 10-minute macOS Launch Agent, a trojanized Windows app.asar, and a Linux binary in /tmp, with C2 traffic masked by spoofed headers. Affected hosts should be treated as compromised. Reset secrets from clean systems and hunt for Python files with the identifier above.



























































































/)




















































