Lotu RadarAbout · RSS

Latest News Archive - Page 636

Cybersecurity · The Hacker News

Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps

The Hacker News published: Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps

Developers & Open Source · langchain-ai/langchain Releases

langchain-core==1.4.1

<p>Changes since langchain-core==1.4.0</p> <p>release(core): 1.4.1 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4597810930" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37922" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37922/hovercard" href="https://github.com/langchain-ai/langchain/pull/37922">#37922</a>)<br> fix(core): remove Bedrock prevalidation from <code>load</code> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4592680005" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37909" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37909/hovercard" href="https://github.com/langchain-ai/langchain/pull/37909">#37909</a>)<br> docs(core): expand and link <code>ModelProfile</code> docstrings (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4591647991" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37904" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37904/hovercard" href="https://github.com/langchain-ai/langchain/pull/37904">#37904</a>)<br> release(anthropic): 1.4.4 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4543498732" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37757" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37757/hovercard" href="https://github.com/langchain-ai/langchain/pull/37757">#37757</a>)<br> chore(core): bump <code>uuid-utils</code> to 0.16.0 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4525842562" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37699" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37699/hovercard" href="https://github.com/langchain-ai/langchain/pull/37699">#37699</a>)<br> chore(infra): bump <code>langchain-tests</code> floor to 1.1.9 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497023947" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37610" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37610/hovercard" href="https://github.com/langchain-ai/langchain/pull/37610">#37610</a>)<br> release(standard-tests): 1.1.9 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496957401" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37609" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37609/hovercard" href="https://github.com/langchain-ai/langchain/pull/37609">#37609</a>)<br> chore: bump idna from 3.11 to 3.15 in /libs/core (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4479657767" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37539" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37539/hovercard" href="https://github.com/langchain-ai/langchain/pull/37539">#37539</a>)<br> ci(infra): harden Dependabot version-bound preservation (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4472777700" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37510" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37510/hovercard" href="https://github.com/langchain-ai/langchain/pull/37510">#37510</a>)<br> hotfix: bump lockfiles (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4472641768" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37508" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37508/hovercard" href="https://github.com/langchain-ai/langchain/pull/37508">#37508</a>)<br> docs(core): note override for <code>_get_ls_params</code> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4471721228" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37503" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37503/hovercard" href="https://github.com/langchain-ai/langchain/pull/37503">#37503</a>)<br> chore(core,langchain,openai): refresh stale OpenAI model references (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466657134" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37487" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37487/hovercard" href="https://github.com/langchain-ai/langchain/pull/37487">#37487</a>)<br> chore: bump langsmith from 0.7.31 to 0.8.0 in /libs/core (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4441353832" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37395" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37395/hovercard" href="https://github.com/langchain-ai/langchain/pull/37395">#37395</a>)<br> fix(core): accept <code>Serializable</code> constructor-envelope wire shape in <code>_convert_to_message</code> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4457144717" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37456" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37456/hovercard" href="https://github.com/langchain-ai/langchain/pull/37456">#37456</a>)<br> fix(core): preserve chunk <code>additional_kwargs</code> across v3 stream assembly (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4448050812" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37435" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37435/hovercard" href="https://github.com/langchain-ai/langchain/pull/37435">#37435</a>)<br> fix(core): preserve reasoning blocks alongside tool_call in v3 stream (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4448032665" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37434" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37434/hovercard" href="https://github.com/langchain-ai/langchain/pull/37434">#37434</a>)<br> chore: bump jupyter-server from 2.17.0 to 2.18.0 in /libs/core (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4423384072" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37354" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37354/hovercard" href="https://github.com/langchain-ai/langchain/pull/37354">#37354</a>)<br> chore: bump mistune from 3.1.4 to 3.2.1 in /libs/core (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4423382656" data-permission-text="Title is private" data-url="https://github.com/langchain-ai/langchain/issues/37353" data-hovercard-type="pull_request" data-hovercard-url="/langchain-ai/langchain/pull/37353/hovercard" href="https://github.com/langchain-ai/langchain/pull/37353">#37353</a>)</p>

Cybersecurity · BleepingComputer

Over 900 US gas station tank gauge systems exposed to attacks

BleepingComputer published: Over 900 US gas station tank gauge systems exposed to attacks

AI · Google AI Blog

The latest AI news we announced in May 2026

Here are Google’s latest AI updates from May 2026

Cybersecurity · BleepingComputer

What 2026 DBIR Confirms: Attacks Are Living in the Browser

BleepingComputer published: What 2026 DBIR Confirms: Attacks Are Living in the Browser

Startups & Funding · TechCrunch Startups

The ‘together tech’ wave might be the most intriguing startup bet of 2026

TechCrunch Startups published: The ‘together tech’ wave might be the most intriguing startup bet of 2026

Developers & Open Source · JetBrains Blog

Why Zig Isn’t 1.0 (Yet)

Most programming languages follow a familiar trajectory: early experimental releases, rapid iteration, and then – at some point – a 1.0 version that signals stability and the potential for serious adoption. Zig hasn’t followed that well-trodden path. What could be the reason? Andrew Kelley quit his job in 2018 to build a programming language. Eight […]

Cybersecurity · SecurityWeek

In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA

Other noteworthy stories that might have slipped under the radar: Ultrahuman data leak, The Gentlemen ransomware analysis, Hola Browser bundles miner. The post In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA appeared first on SecurityWeek . ]]>

Cloud & Infrastructure · Cloudflare Blog

Your AI bill is out of control. Cloudflare can fix it now.

AI Gateway now features real-time spend limits to prevent runaway token bills across multiple AI providers. By integrating with Cloudflare Access, companies can use identity-driven budgets and policies.

Cybersecurity · The Hacker News

New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework

The Hacker News published: New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework

Cybersecurity · SecurityWeek

Hackers Leak DentaQuest Information Impacting 2.6 Million

The ShinyHunters extortion group leaked roughly 234 GB of data allegedly stolen from the dental benefits administrator. The post Hackers Leak DentaQuest Information Impacting 2.6 Million appeared first on SecurityWeek . ]]>

Cybersecurity · The Hacker News

Only 10% of SOCs Say They’re Getting Excellent Value From AI. Here’s What the Second Wave Has to Deliver

The Hacker News published: Only 10% of SOCs Say They’re Getting Excellent Value From AI. Here’s What the Second Wave Has to Deliver

Cybersecurity · SecurityWeek

Chrome 149 Patches 429 Vulnerabilities

Over 100 bugs are critical or high-severity, mainly use-after-free and insufficient validation of untrusted input flaws. The post Chrome 149 Patches 429 Vulnerabilities appeared first on SecurityWeek . ]]>

Developers & Open Source · cloudflare/workers-sdk Releases

@cloudflare/wrangler-bundler@0.1.2

<h3>Patch Changes</h3> <ul> <li>Updated dependencies [<a href="https://github.com/cloudflare/workers-sdk/commit/c6c61b59431443b2bcda25f3af7624dd2ce19b9b"><code>c6c61b5</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/c6c61b59431443b2bcda25f3af7624dd2ce19b9b"><code>c6c61b5</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/a3eea277aae46450aec1f0c811e3fe256022c46e"><code>a3eea27</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/7a6b1a4f4e9d8d5bd88732c8e11368c3ad7f867b"><code>7a6b1a4</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/7539a9bfcf03a14b2c16f281d541b6bc45523a80"><code>7539a9b</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/3b8b80ab32e3ac33b5df9f6944dca9cdf72c5495"><code>3b8b80a</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/0bb2d55116ce90a147582a7b4d96e3090cddf7ee"><code>0bb2d55</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/8400fb945a781e7a7a78a3614a702ace2d1fbc87"><code>8400fb9</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/b502d5445b9e9e030020a3d65c0334507393aa64"><code>b502d54</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/7949f81bd258292a4a0b9c5a339c6c035f27d7ca"><code>7949f81</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/d46201384f656815bf9e90a595098edff43f1b32"><code>d462013</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/c2280cdb589c9289bb4082d0a068846f3dd22b37"><code>c2280cd</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/ea12b584ee1c3141286f0ecf6b742bd79971407e"><code>ea12b58</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/acf7817266b39be9707a09b918d670a468302ebc"><code>acf7817</code></a>]: <ul> <li>wrangler@4.98.0</li> </ul> </li> </ul>

Developers & Open Source · cloudflare/workers-sdk Releases

wrangler@4.98.0

Minor Changes #14089 c6c61b5 Thanks @alsuren ! - Add migrations_pattern to D1 database bindings The D1 binding now accepts an optional migrations_pattern field, allowing you to point wrangler d1 migrations apply and wrangler d1 migrations list at migration files in nested layouts (e.g. ORM-generated folders like migrations/0000_init/migration.sql ). migrations_pattern is a glob (relative to the wrangler config file) and defaults to ${migrations_dir}/*.sql , which preserves today's behaviour. Files that do not match the pattern are not executed. { "d1_databases" : [ { "binding" : " DB " , "database_name" : " my-db " , "database_id" : " ... " , "migrations_dir" : " migrations " , "migrations_pattern" : " migrations/*/migration.sql " } ] } When no migrations match the configured pattern but files matching the common migrations/*/migration.sql (drizzle-style) layout do exist, Wrangler logs a hint suggesting migrations_pattern as an opt-in. wrangler d1 migrations create now returns an actionable error if the generated migration filename would not match the configured pattern. #14153 7a6b1a4 Thanks @dario-piotrowicz ! - Generalize wrangler deploy and wrangler versions upload positional argument from [script] to [path] Both wrangler deploy and wrangler versions upload now accept a generic [path] positional argument that can point to either a Worker entry-point file or a directory of static assets. The type is auto-detected. For example: File : wrangler deploy ./src/index.ts deploys a Worker (same as before) Directory : wrangler deploy ./public deploys a static assets site (no interactive confirmation prompt) The --script named option is now hidden and deprecated for both commands. It continues to work for backwards compatibility but only accepts file paths. Passing a directory to --script now produces a clear error message suggesting the positional path argument or --assets flag instead. #13863 3b8b80a Thanks @aslakhellesoy ! - getPlatformProxy() now passes through workflow bindings that have a script_name Workflows without a script_name are still stripped (and warned about) because the engine for an internal workflow can't run inside the empty proxy worker that backs getPlatformProxy() . Workflows with a script_name are handed to miniflare unchanged; miniflare reroutes the engine's USER_WORKFLOW binding through the dev-registry-proxy when the target worker is running in another Miniflare instance — the same mechanism Durable Objects already use. This means SvelteKit/Remix (and similar split-process setups) can call platform.env.MY_WORKFLOW.create({ ... }) directly from their server-side request handlers in dev, as long as the workflow class is exposed by another worker registered in the dev registry. Closes #7459 . #14164 b502d54 Thanks @G4brym ! - Rename the web_search binding kind to websearch Pre-launch rename of the public binding type from web_search to websearch so the on-the-wire shape matches the product name (Web Search). The wrangler config key, the binding-type string sent to the Cloudflare API, and the miniflare option key all move from web_search / webSearch to websearch . Update your wrangler config: - "web_search": { "binding": "WEBSEARCH" } + "websearch": { "binding": "WEBSEARCH" } The runtime WebSearch type exposed on env.WEBSEARCH is unchanged. Patch Changes #14089 c6c61b5 Thanks @alsuren ! - Restore the D1 executeSql logger level via try/finally wrangler d1 execute --json and the internal executeSql helper temporarily lower the global logger to "error" to keep human-readable output out of the JSON payload. Previously the level was restored only on the happy path, so any early return or thrown error left the singleton logger muted, silencing later logger.warn / logger.log output (notably from migration helpers that wrap executeSql and are commonly mocked in tests). The level swap is now wrapped in try / finally so it is always restored. #14175 a3eea27 Thanks @dependabot ! - Update dependencies of "miniflare", "wrangler" The following dependency versions have been updated: Dependency From To workerd 1.20260601.1 1.20260603.1 #14121 7539a9b Thanks @petebacondarwin ! - Extract the OAuth 2.0 + PKCE flow into a new @cloudflare/workers-auth package. The OAuth login / logout / refresh logic, the auth-config TOML file IO, the OAuth token exchange + local callback server, and the Cloudflare Access detection helpers that previously lived in packages/wrangler/src/user/ have moved to the new internal-only @cloudflare/workers-auth package. Wrangler now wires the OAuth flow up via a small glue module that injects its logger, browser opener, interactivity detector, and config cache via a dependency- injection context. What stays in wrangler: The yargs login / logout / whoami / auth token commands Environment-based credential resolution ( CLOUDFLARE_API_TOKEN , CLOUDFLARE_API_KEY / CLOUDFLARE_EMAIL , etc.) Cloudflare account selection ( requireAuth , getOrSelectAccountId ) The OAuth scope catalog (passed into the OAuth flow as a generic string[] ) whoami / account fetching No behavior change for end users. The on-disk TOML format and location remain identical, and all telemetry message labels are preserved verbatim. @cloudflare/workers-auth is published with prerelease: true and is not intended for external use — its APIs may change without notice. #14162 0bb2d55 Thanks @dario-piotrowicz ! - In non-interactive mode remove the skills installation message When Wrangler run in non interactive mode and it detected agents that it could install skills for, it would print a message such as: Cloudflare agent skills are available for: . Run wrangler in an interactive terminal to install them, or use '--install-skills' to install without prompting. This message seems to be confusing and unhelpful so it has now been removed. #14165 8400fb9 Thanks @NuroDev ! - Limit wrangler versions list to the 10 most recent deployable versions The versions API ignores pagination when filtering to deployable versions, so Wrangler now caps the command output client-side. This keeps the command aligned with its help text and avoids overwhelming terminal output for Workers with many versions. #14151 7949f81 Thanks @dario-piotrowicz ! - Skip stale bundles during dev server reload to avoid redundant restarts When rapidly saving a wrangler config file with remote bindings, each save would trigger a full reload cycle (remote connection setup, miniflare restart), causing many sequential "Reloading local server... / Establishing remote connection..." messages (while blocking the user). The runtime controllers now check whether a newer bundle has been queued at each expensive async boundary and bail out early if the current bundle is stale. This ensures that only the latest config change triggers a reload, making wrangler dev much more responsive during repeated config edits. #14072 d462013 Thanks @himanshu-cf ! - Update wrangler secret bulk command description to reflect create/update/delete capabilities The help text for wrangler secret bulk now accurately describes that the command can create, update, or delete multiple secrets in a single request, with up to 100 secrets per command. The file argument description also clarifies that setting a key to null in JSON will delete it, and that deletion is not supported with .env files. #13979 c2280cd Thanks @matingathani ! - Warn when a named environment silently inherits custom_domain routes from the top-level config When an env. block does not override routes , it inherits the top-level routes array. If that array contains entries with custom_domain: true , every deploy to the named environment will silently reassign the custom domain away from the top-level Worker and towards the env Worker, causing routing drift. Wrangler now emits a warning in this situation and suggests adding "routes": [] to the env block to prevent inheritance. #14170 ea12b58 Thanks @petebacondarwin ! - Tighten on-disk permissions of the OAuth credentials file to 0600 The user auth config file written by wrangler login (typically ~/.config/.wrangler/config/default.toml on Linux/macOS, or .toml for non-production Cloudflare API environments) is now written with mode 0600 and re- chmod -ed on every save. This prevents other local users on shared hosts from reading the stored OAuth tokens. Existing files with looser permissions written by older Wrangler versions are tightened the next time Wrangler refreshes the token or the user logs in again. The change is a no-op on Windows, which does not honour POSIX mode bits. #14022 acf7817 Thanks @petebacondarwin ! - Show the actual OAuth error instead of hanging when wrangler login is rejected by the OAuth provider (for example with invalid_scope ). Previously, if the OAuth callback returned with an error other than access_denied , Wrangler would never respond to the browser. Because server.close() 's callback only fires once all open connections have ended, the login command would hang until the 120 second OAuth timeout — at which point it would print a generic timeout message rather than the actual OAuth failure. The same gap existed for the case where the OAuth provider redirected back without an authorisation code, and for failures during the auth-code-to-access-token exchange. The OAuth provider's error_description (RFC 6749 §4.1.2.1) is now also surfaced, so the message includes the specific reason for the failure rather than just the bare error code. For example, a misconfigured staging scope now surfaces as: OAuth error: invalid_scope The OAuth 2.0 Client is not allowed to request scope 'browser:write'. instead of hanging silently. Updated dependencies [ a3eea27 , 1fdd8de , b502d54 , 3b8b80a ]: miniflare@4.20260603.0

Developers & Open Source · cloudflare/workers-sdk Releases

@cloudflare/workers-utils@0.23.0

<h3>Minor Changes</h3> <ul> <li> <p><a href="https://github.com/cloudflare/workers-sdk/pull/14089" data-hovercard-type="pull_request" data-hovercard-url="/cloudflare/workers-sdk/pull/14089/hovercard">#14089</a> <a href="https://github.com/cloudflare/workers-sdk/commit/c6c61b59431443b2bcda25f3af7624dd2ce19b9b"><code>c6c61b5</code></a> Thanks <a href="https://github.com/alsuren">@alsuren</a>! - Add <code>migrations_pattern</code> to D1 database bindings</p> <p>The D1 binding now accepts an optional <code>migrations_pattern</code> field, allowing you to point <code>wrangler d1 migrations apply</code> and <code>wrangler d1 migrations list</code> at migration files in nested layouts (e.g. ORM-generated folders like <code>migrations/0000_init/migration.sql</code>).</p> <p><code>migrations_pattern</code> is a glob (relative to the wrangler config file) and defaults to <code>${migrations_dir}/*.sql</code>, which preserves today's behaviour. Files that do not match the pattern are not executed.</p> <div class="highlight highlight-source-json-comments notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="{ "d1_databases": [ { "binding": "DB", "database_name": "my-db", "database_id": "...", "migrations_dir": "migrations", "migrations_pattern": "migrations/*/migration.sql" } ] }"><pre>{ <span class="pl-ent">"d1_databases"</span>: [ { <span class="pl-ent">"binding"</span>: <span class="pl-s"><span class="pl-pds">"</span>DB<span class="pl-pds">"</span></span>, <span class="pl-ent">"database_name"</span>: <span class="pl-s"><span class="pl-pds">"</span>my-db<span class="pl-pds">"</span></span>, <span class="pl-ent">"database_id"</span>: <span class="pl-s"><span class="pl-pds">"</span>...<span class="pl-pds">"</span></span>, <span class="pl-ent">"migrations_dir"</span>: <span class="pl-s"><span class="pl-pds">"</span>migrations<span class="pl-pds">"</span></span>, <span class="pl-ent">"migrations_pattern"</span>: <span class="pl-s"><span class="pl-pds">"</span>migrations/*/migration.sql<span class="pl-pds">"</span></span> } ] }</pre></div> <p>When no migrations match the configured pattern but files matching the common <code>migrations/*/migration.sql</code> (drizzle-style) layout do exist, Wrangler logs a hint suggesting <code>migrations_pattern</code> as an opt-in.</p> <p><code>wrangler d1 migrations create</code> now returns an actionable error if the generated migration filename would not match the configured pattern.</p> </li> <li> <p><a href="https://github.com/cloudflare/workers-sdk/pull/14164" data-hovercard-type="pull_request" data-hovercard-url="/cloudflare/workers-sdk/pull/14164/hovercard">#14164</a> <a href="https://github.com/cloudflare/workers-sdk/commit/b502d5445b9e9e030020a3d65c0334507393aa64"><code>b502d54</code></a> Thanks <a href="https://github.com/G4brym">@G4brym</a>! - Rename the <code>web_search</code> binding kind to <code>websearch</code></p> <p>Pre-launch rename of the public binding type from <code>web_search</code> to <code>websearch</code> so the on-the-wire shape matches the product name (Web Search). The wrangler config key, the binding-type string sent to the Cloudflare API, and the miniflare option key all move from <code>web_search</code> / <code>webSearch</code> to <code>websearch</code>.</p> <p>Update your wrangler config:</p> <div class="highlight highlight-source-diff notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="- "web_search": { "binding": "WEBSEARCH" } + "websearch": { "binding": "WEBSEARCH" }"><pre><span class="pl-md"><span class="pl-md">-</span> "web_search": { "binding": "WEBSEARCH" }</span> <span class="pl-mi1"><span class="pl-mi1">+</span> "websearch": { "binding": "WEBSEARCH" }</span></pre></div> <p>The runtime <code>WebSearch</code> type exposed on <code>env.WEBSEARCH</code> is unchanged.</p> </li> <li> <p><a href="https://github.com/cloudflare/workers-sdk/pull/14146" data-hovercard-type="pull_request" data-hovercard-url="/cloudflare/workers-sdk/pull/14146/hovercard">#14146</a> <a href="https://github.com/cloudflare/workers-sdk/commit/c4f45e8b8694c60fb1808f7fbb130e4b4893d20c"><code>c4f45e8</code></a> Thanks <a href="https://github.com/dario-piotrowicz">@dario-piotrowicz</a>! - Simplify <code>constructWranglerConfig</code> to accept a single worker instead of an array</p> <p>The <code>constructWranglerConfig</code> function now accepts a single <code>APIWorkerConfig</code> object instead of <code>APIWorkerConfig | APIWorkerConfig[]</code>. The multi-environment array support has been removed since the array use-case was removed and now the only call site already passes a single worker object. This is a breaking change to the function's public signature.</p> </li> </ul>

Developers & Open Source · cloudflare/workers-sdk Releases

@cloudflare/vitest-pool-workers@0.16.13

<h3>Patch Changes</h3> <ul> <li>Updated dependencies [<a href="https://github.com/cloudflare/workers-sdk/commit/c6c61b59431443b2bcda25f3af7624dd2ce19b9b"><code>c6c61b5</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/c6c61b59431443b2bcda25f3af7624dd2ce19b9b"><code>c6c61b5</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/a3eea277aae46450aec1f0c811e3fe256022c46e"><code>a3eea27</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/7a6b1a4f4e9d8d5bd88732c8e11368c3ad7f867b"><code>7a6b1a4</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/7539a9bfcf03a14b2c16f281d541b6bc45523a80"><code>7539a9b</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/1fdd8def456011c29c5879fe49be6fa90ad9858d"><code>1fdd8de</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/3b8b80ab32e3ac33b5df9f6944dca9cdf72c5495"><code>3b8b80a</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/0bb2d55116ce90a147582a7b4d96e3090cddf7ee"><code>0bb2d55</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/8400fb945a781e7a7a78a3614a702ace2d1fbc87"><code>8400fb9</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/b502d5445b9e9e030020a3d65c0334507393aa64"><code>b502d54</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/7949f81bd258292a4a0b9c5a339c6c035f27d7ca"><code>7949f81</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/d46201384f656815bf9e90a595098edff43f1b32"><code>d462013</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/c2280cdb589c9289bb4082d0a068846f3dd22b37"><code>c2280cd</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/3b8b80ab32e3ac33b5df9f6944dca9cdf72c5495"><code>3b8b80a</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/ea12b584ee1c3141286f0ecf6b742bd79971407e"><code>ea12b58</code></a>, <a href="https://github.com/cloudflare/workers-sdk/commit/acf7817266b39be9707a09b918d670a468302ebc"><code>acf7817</code></a>]: <ul> <li>wrangler@4.98.0</li> <li>miniflare@4.20260603.0</li> </ul> </li> </ul>

Developers & Open Source · cloudflare/workers-sdk Releases

miniflare@4.20260603.0

<h3>Minor Changes</h3> <ul> <li> <p><a href="https://github.com/cloudflare/workers-sdk/pull/14164" data-hovercard-type="pull_request" data-hovercard-url="/cloudflare/workers-sdk/pull/14164/hovercard">#14164</a> <a href="https://github.com/cloudflare/workers-sdk/commit/b502d5445b9e9e030020a3d65c0334507393aa64"><code>b502d54</code></a> Thanks <a href="https://github.com/G4brym">@G4brym</a>! - Rename the <code>web_search</code> binding kind to <code>websearch</code></p> <p>Pre-launch rename of the public binding type from <code>web_search</code> to <code>websearch</code> so the on-the-wire shape matches the product name (Web Search). The wrangler config key, the binding-type string sent to the Cloudflare API, and the miniflare option key all move from <code>web_search</code> / <code>webSearch</code> to <code>websearch</code>.</p> <p>Update your wrangler config:</p> <div class="highlight highlight-source-diff notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="- "web_search": { "binding": "WEBSEARCH" } + "websearch": { "binding": "WEBSEARCH" }"><pre><span class="pl-md"><span class="pl-md">-</span> "web_search": { "binding": "WEBSEARCH" }</span> <span class="pl-mi1"><span class="pl-mi1">+</span> "websearch": { "binding": "WEBSEARCH" }</span></pre></div> <p>The runtime <code>WebSearch</code> type exposed on <code>env.WEBSEARCH</code> is unchanged.</p> </li> <li> <p><a href="https://github.com/cloudflare/workers-sdk/pull/13863" data-hovercard-type="pull_request" data-hovercard-url="/cloudflare/workers-sdk/pull/13863/hovercard">#13863</a> <a href="https://github.com/cloudflare/workers-sdk/commit/3b8b80ab32e3ac33b5df9f6944dca9cdf72c5495"><code>3b8b80a</code></a> Thanks <a href="https://github.com/aslakhellesoy">@aslakhellesoy</a>! - Support cross-worker workflow bindings via the dev registry</p> <p>When a workflow binding has a <code>scriptName</code> that refers to a worker registered in another Miniflare instance (via <code>unsafeDevRegistryPath</code>), miniflare now reroutes the engine's <code>USER_WORKFLOW</code> binding through the dev-registry-proxy worker — the same mechanism Durable Objects already use for cross-worker <code>scriptName</code> bindings.</p> <p>Previously the workflow engine was bound directly to a local service <code>core:user:<scriptName></code>, so workerd refused to start when that script lived in a different process.</p> <p>This unblocks <code>getPlatformProxy()</code> (and any other split-Miniflare setup) for users whose workflow class is defined in a separate worker — for example SvelteKit/Remix on Cloudflare, where <code>adapter-cloudflare</code>'s dev integration runs the user's worker in a sidecar.</p> <p>See <a href="https://github.com/cloudflare/workers-sdk/issues/7459" data-hovercard-type="issue" data-hovercard-url="/cloudflare/workers-sdk/issues/7459/hovercard">#7459</a>.</p> </li> </ul> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://github.com/cloudflare/workers-sdk/pull/14175" data-hovercard-type="pull_request" data-hovercard-url="/cloudflare/workers-sdk/pull/14175/hovercard">#14175</a> <a href="https://github.com/cloudflare/workers-sdk/commit/a3eea277aae46450aec1f0c811e3fe256022c46e"><code>a3eea27</code></a> Thanks <a href="https://github.com/apps/dependabot">@dependabot</a>! - Update dependencies of "miniflare", "wrangler"</p> <p>The following dependency versions have been updated:</p> <table> <thead> <tr> <th>Dependency</th> <th>From</th> <th>To</th> </tr> </thead> <tbody> <tr> <td>workerd</td> <td>1.20260601.1</td> <td>1.20260603.1</td> </tr> </tbody> </table> </li> <li> <p><a href="https://github.com/cloudflare/workers-sdk/pull/14081" data-hovercard-type="pull_request" data-hovercard-url="/cloudflare/workers-sdk/pull/14081/hovercard">#14081</a> <a href="https://github.com/cloudflare/workers-sdk/commit/1fdd8def456011c29c5879fe49be6fa90ad9858d"><code>1fdd8de</code></a> Thanks <a href="https://github.com/dario-piotrowicz">@dario-piotrowicz</a>! - Detect early workerd exit instead of hanging indefinitely</p> <p>When <code>workerd</code> exits during startup before writing all expected listen events to the control file descriptor (e.g. due to an IPv6 bind failure, permission error, or missing library), Miniflare's <code>waitForPorts()</code> would block forever. This caused <code>wrangler dev</code> to stall at "Starting local server..." with no error and no timeout.</p> <p>The fix races <code>waitForPorts()</code> against the child process exit event so that any unexpected <code>workerd</code> termination is detected immediately. When <code>workerd</code> exits early, Miniflare now throws <code>ERR_RUNTIME_FAILURE</code> with the runtime's stderr output included in the error message, making the root cause diagnosable without external tools.</p> </li> </ul>

Developers & Open Source · JetBrains Blog

Java Annotated Monthly – June 2026

A fresh edition of Java Annotated Monthly has landed! The world of software development keeps moving at full speed, and this month’s selection helps you keep up without drowning in tabs. Inside, you’ll find hand-picked articles, podcasts, videos, and thought-provoking reads covering Java, Kotlin, AI, and the technologies shaping the next generation of development. Grab […]

Products & Consumer Tech · Product Hunt

Navi+ Menu Builder

<p> Add Tab Bar, Mega Menu & more to any website — no code </p> <p> <a href="https://www.producthunt.com/products/navi-menu-builder?utm_campaign=producthunt-atom-posts-feed&amp;utm_medium=rss-feed&amp;utm_source=producthunt-atom-posts-feed">Discussion</a> | <a href="https://www.producthunt.com/r/p/1164206?app_id=339">Link</a> </p>

Cybersecurity · SecurityWeek

Industry Reactions to New Trump AI Cybersecurity Executive Order: Feedback Friday

Experts commented on the EO’s voluntary nature, the balance between innovation and security, and potential implementation gaps. The post Industry Reactions to New Trump AI Cybersecurity Executive Order: Feedback Friday appeared first on SecurityWeek . ]]>

Products & Consumer Tech · Product Hunt

BooBar

AI Dynamic Island for your Mac Discussion | Link

Products & Consumer Tech · Product Hunt

Krisp Voice Translation API

Real-time speech-to-speech translation API Discussion | Link

AI · MIT Technology Review AI

The Meta hack shows there’s more to AI security than Mythos

On June 5, 404 Media reported that attackers had been using Meta’s AI customer support agent to steal Instagram accounts. Their approach was simple: They asked the agent to link the accounts to email addresses that they controlled, and the agent complied. One attacker broke into the dormant Obama White House account and made pro-Iran…