IT Today

A daily digest of important IT news: platforms, software development, cloud, cybersecurity, open source, markets, and infrastructure. No noise — only what changes work for professionals and businesses.

publicasta.com/it_today_news / RSS /

Latest publications

Tailscale was not hacked, and that is why the Hugging Face intrusion matters

A stolen CI enrollment key became 181 tailnet nodes. The hard lesson is about reusable credentials, alerts and what Zero Trust does not do automatically.

Copilot for Word makes document trust an IT security problem

A new disclosure shows how hidden instructions in office files can cross from source material into AI-generated documents. Microsoft 365 rollouts now need a document trust model.

Kimi K3 turns open-weight AI into an infrastructure decision

The July 27 Hugging Face release is now a business, security and policy test for teams that want cheaper models without losing control.

Android's on-device ADB fight is about more than debugging

A proposed ADB hardening path could protect phones after a real Wireless ADB flaw, but it may also break Shizuku, Termux and phone-local developer workflows if Google cuts too broadly.

When an AI eval becomes a real security incident

OpenAI and Hugging Face turned a benchmark failure into a practical warning about agent sandboxes, network egress and defensive access to strong models.

AI coding agents are becoming infrastructure. Treat them that way.

Claude Code, Bun, Codex and OpenCode show why development teams now need platform controls for the agents that read, edit and run their code.

Cloud bills are production systems now

AWS’s impossible Cost Explorer estimates were not real charges, but they exposed a serious operational problem: cost alerts now belong in incident response.

What Grok Build changed about trusting AI coding agents

The xAI backlash is not only about one CLI. It shows why teams need to verify what AI coding agents read, upload, store and leave behind.

Grok Build shows why AI coding agents need data boundaries

The Grok Build backlash is less about one vendor than a new rule for development teams: AI coding agents need sandboxing, egress controls and repository-aware governance.

Grok Build shows why AI coding agents need a new trust boundary

The repository-upload backlash around xAI’s Grok Build is a warning for every team adopting coding agents: prompt privacy is no longer the whole risk model.

When a vendor says turn it off: the ShareFile shutdown lesson

Progress told some ShareFile customers to keep Storage Zone Controllers offline. The incident is a runbook test for file-sharing, hybrid cloud and security teams.

AI coding agents are not autocomplete anymore

GhostApproval and Friendly Fire show why teams should treat coding agents like privileged runtimes, not harmless editor helpers.