Today's digest · Tuesday, June 9

The 31 things in AI/dev today.

LiveNext issue at 7:00 CET
#1 / TODAY
The Hacker News·1 min·3d agoFREE

One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public

A Linux kernel use-after-free vulnerability (CVE-2026-23111) in nf_tables allows unprivileged local users to gain root access and escape containers. Exploit code was published on June 8, 2026, after the flaw was patched upstream on February 5, 2026. Systems not yet updated are at risk.

Unpatched systems risk local root compromise and container escape via a publicly available exploit.

linuxkernelcve-2026-23111privilege-escalation
thehackernews.com
One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public
Give Your AI Assistant Infrastructure Eyes Before It Writes Another Query
#2 / TOP STORY
DEV CommunityFREE

Give Your AI Assistant Infrastructure Eyes Before It Writes Another Query

AI coding assistants like Claude Code can generate code that compiles and passes tests but causes expensive infrastructure mistakes. In one case, Claude Code wrote a DynamoDB Scan that consumed a large number of read capacity units in a short time because it didn't know the table had many rows or that a GSI existed.

Token-based billing exposed AI's ROI problem: what the real numbers say
#3 / TOP STORY
DEV CommunityFREE

Token-based billing exposed AI's ROI problem: what the real numbers say

In Q1 2026, OpenAI and Anthropic moved enterprise customers to token-based billing, revealing AI's real costs. Uber consumed its annual AI budget in four months, then imposed a $1,500/month cap per employee for agentic coding tools. Other companies like Brex and T-Mobile also capped usage, prompting a re-evaluation of AI's ROI.

aigest · daily

Get this every morning.

One email. The signal. Built for builders.

Free · Unsubscribe in one click · No trackers

// Worth acting on7 stories

Brings natural language database editing to Datasette, lowering the barrier for data manipulation.

datasetteaipluginsql
Simon Willison3d ago1mFREE
// Worth knowing10 stories

A supply-chain attack via compromised npm credentials can silently infect widely-used packages, stealing credentials from developers and infrastructure.

npmsupply-chainsecuritymalware
DEV Community40h ago1mFREE
More selected · 14

Developers can now catch vulnerabilities and malware in Python dependencies without leaving their package manager.

pythonsecuritypackage-manageruv
Lobsters3d ago1mFREE
// Yesterday1 story