InfoWorld |
|
||||||
The best new features in Python 3.1522:06 Python 3.15 is one of the most feature-packed Python releases in many a moon, and the general release has just arrived. Here’s a rundown of the biggest, boldest, and most important innovations, changes, and fixes. Lazy imports A long-asked for feature, lazy imports allow imports to be processed only when they’re actually used by the program. For slow-importing modules that impose a large cost on … Lightwell project filters out 400 Java library vulnerabilities18:32 Lightwell, the open-source security initiative set up by IBM and Red Hat, has identified more than 400 previously undiscovered vulnerabilities in widely used Java libraries — and now the companies are inviting customers to submit their own code dependencies to a new service, Lightwell Clearinghouse, for review. They’ll be looking for bugs such as the critical sandbox bypass in Java template engin… OpenAI reports three new incidents of misalignment17:39 OpenAI continues to report incidences of “misaligned” behavior by its AI models, with three new reports dropping on Oct. 2. However, they describe relatively minor issues compared to previous alignment reports and notices covering its attacks on Hugging Face , Rubygems , and a German programming wiki . The first of the new reports described how an instance of a model under test learned from an in… As AI agents grow, vendors carve out decision-making as a separate model layer15:00 As enterprises struggle to balance AI budgets with the demands of scaling agentic applications, they have been increasingly looking for ways to make those systems more efficient, from hard-coding deterministic decisions to using smaller models for specific tasks. TypeSafe’s Jev , released last month, introduced another option: using a specialized model to handle the bounded decisions that sit bet… Neoclouds and the enterprises that need them11:24 I’ve been tracking the rise of neoclouds in the past couple of years, and I’ll start by admitting that the numbers are genuinely staggering. Synergy Research Group reports that neocloud revenues hit $9 billion in the fourth quarter of 2025 alone , up 223% year over year, exceeding $25 billion for the full year. The market is forecast to approach $400 billion by 2031 at a sustained 58% compound an… AWS takes aim at runaway AI agent behavior with Strands Box8.října Amazon Web Services (AWS) has introduced an open-source sandbox for AI agents that allows developers to restrict their actions based on previous behavior, seeking to address security risks as enterprises give autonomous systems greater access to applications and data. The tool, called Strands Box, combines operating system-level isolation with policies that govern what agents can do. Released in … AI changed my role before it changed my software8.října My first attempt at vibe coding face-planted. I shook my head and stared at the screen. Well, this is obviously not for me. I became convinced the problem was the AI. I had uploaded the working Excel spreadsheet that already contained the business logic, workflows, and calculations I wanted the AI to replicate. How hard could this possibly be for “ artificial intelligence ” to translate into an a… AI-powered data pipeline observability: Stop monitoring and start preventing8.října Devops tools are making it increasingly easy to monitor data pipeline failures. But in many cases, those alerts are already too late. Take marketing campaigns, for example. Every mistake in data for marketing and sales has a trickle-down effect on revenue. William Flaiz , founder of CleanSmartLabs , shares one example. One of his B2B clients increased their marketing spend by 40%, yet revenue rem… AWS’ support for Iceberg materialized views on Redshift could help lower analytics costs7.října AWS has added support for Iceberg materialized views to its managed cloud data warehouse service, Amazon Redshift, in an effort to help enterprises lower analytics costs. Materialized views are precomputed, stored results of queries that data warehouses such as Redshift can use to avoid repeatedly running compute-intensive queries when the same analytical workloads are run repeatedly, reducing co… Encrypted instructions trick Copilot CLI into spilling developer secrets7.října GitHub Copilot CLI can be made to read sensitive files from a developer’s machine and send their contents to an attacker from a single web page. Security researchers at Adversa AI said the new attack technique, dubbed Cryptographic Context Injection (CCI), hides malicious instructions inside encrypted content. These instructions are treated as trusted context when Copilot CLI decrypts the content… Five keys to controlling AI token costs7.října We spent the last decade building entire finops departments just to decipher what the cloud bill was saying. Just when we figured out how to stop leaving idle compute instances running, generative AI introduced an infinitely more opaque, faster-moving layer of spend. AI bill shock has spread like a slow moving hurricane across the industry. Aside from the spike in large language model (LLM) costs… Cursor writes all my code now7.října I was at the gym yesterday, talking with a relatively new CrossFitter named John, and naturally he asked me what I do for a living. I said I write software all day. But it hit me—I don’t actually write software anymore. I told him that, nowadays, Cursor writes all my code—I just tell Cursor what to do. I’ve written about how code isn’t important anymore and that we won’t be writing code much long… Atlassian launches AMP to tackle AI code visibility, attribution7.října Atlassian today rolled out new offerings designed to make it easier for IT to differentiate coding by AIs from human coding. The problem is that such distinctions in the enterprise today are rarely binary, as much coding has lots of each. The lack of meaningful visibility into code origin is a massive problem for most large businesses, said Jamil Valliani , head of AI products at Atlassian, in an… Atlassian’s critical flaw turns eight enterprise products into one big security problem7.října A newly-disclosed critical flaw in Atlassian’s data center software has a remarkably wide reach, affecting eight core products across the company’s enterprise portfolio. CVE-2026-21589 , rated 9.3 (critical) in severity, is an arbitrary file access vulnerability that could allow an attacker with no login access to read files in web app root directories that they should not otherwise see, and pote… One week to TechCrunch Disrupt: What’s next for AI and software development6.října First AI gave us code completion, predicting the lines of code, functions, and boilerplate we needed based on what we’d already typed. Then came code suggestions and code generation, where AI writes new code or improves existing code based on a natural language prompt. Today, coding agents can look at your code, suggest improvements, compile and test the improved code, and iterate on that to come… |