Happening Now
Headlines
All
Agentic
Security
Career
Web
Backend
Databases
Go
Java
Rust
Testing
PHP
Open Source
Python
Magento and Adobe Commerce zero-day CVE-2026-75650 under active attack, hotfix available
3m ago
Laravel Cloud adds Next.js and Nuxt deployment from Laravel monorepos
10h ago
PHP 8.6 adds partial function application to complement the pipe operator
10h ago
Elementor Pro CVE-2026-32475 sees 190K blocked exploit attempts via file upload bypass
64h ago
Slim 4.15.3 patches route parameter constraint bypass vulnerability
6d ago
Laravel ships first-party language server for any LSP-compatible editor
6d ago
WordPress narrows vulnerability disclosure scope to high-impact privilege escalations
7d ago
13 malicious Packagist themes deliver iOS spyware stealing crypto wallet seeds
Aug 31
Laravel Scout adds semantic and hybrid vector search with pg_vector and Turbopuffer
Aug 31
Symfony 6.4, 7.4 and 8.1 ship coordinated security hardening releases
Aug 30
PHP 8.6 RFC passes to allow default values on readonly properties
Aug 30
GiveWP WordPress donation plugin gets max-severity RCE patch after prior breach
Aug 28
Laravel starter kits switch to Vite+ unified toolchain, dropping ESLint and Prettier
Aug 28
WordPress launches Core Security Initiative to handle AI-driven surge in vulnerability reports
Aug 28
Critical RCE chain in Avada WordPress theme patched after agentic exploit discovery
Aug 26
Swoole open-sources TypePHP, an ahead-of-time compiler that compiles PHP to native binaries
Aug 26
Attackers exploit miniOrange WordPress plugin auth bypass to forge admin sessions
Aug 24
PHP 8.6 hits soft feature freeze with partial application and clamp() locked in
Aug 22
PHP Foundation launches ecosystem security team backed by Alpha-Omega grant
Aug 21
Laracon US 2026 brings Laravel LSP, Pest 5, and major Laravel Cloud updates
Aug 21
Critical Elementor Pro file upload flaw allows unauthenticated RCE on WordPress sites
Aug 20
WordPress 7.1 ships with collaboration features, new blocks and expanded image format support
Aug 20
Laravel 13.26 ships read-through filesystem driver, debounced listeners and Queue::forward()
Aug 19
Laravel 13.26 ships lazy filesystem migration driver with a file resurrection bug
Aug 19
StopAndProtect campaign uses 2,000 hacked WordPress sites to hit 6,000+ victims
Aug 18
NativePHP v4 compiles Blade components into native SwiftUI and Jetpack Compose views
Aug 17
Symfony releases official LSP server with Twig, YAML and DI-aware tooling
Aug 17
Laravel 13.25 adds global queue pausing and new artisan dev terminal UI
Aug 13
Mercure 1.0 alpha ships with IETF Internet-Draft protocol and OAuth 2.0 authorization
Aug 11
BdThemes supply chain hack creates rogue WordPress admins across 100,000+ installs
Aug 10