Weekly Tech Cocktail – Issue #9
Each week we handpick content about technology, APIs, generative models and the future of work in software engineering and information technology. Yes, by «hand» we mean a part of an actual human.
Yes, it’s been a while. The cocktail bar closed for a renovation and reopens with a bigger shelf of bottles: more sources, same rule. A part of an actual human still picks every link.
The week belonged to the Fable and Mythos saga. Simon Willison started by noticing the quiet part: if Fable stops helping you, you’ll never know, because the guardrails were invisible. Then it stopped being a product story. Anthropic published a statement on a US government directive forcing it to suspend Fable 5 and Mythos 5 for every customer, on national security grounds Anthropic itself disputes. It turned political fast: Anthropic flew staff to Washington to manage a White House fight over the models. Safety makes a convenient label.
Meanwhile the agents kept escaping their enclosures. DHH watches the same technology and sees it finally delivering the open source promise: everyone can patch their own software now. On the other side of that coin, one agent scanning the DN42 network quietly bankrupted its operator. Both things are true at once, which is the whole problem.
Palate cleanser: πFS reminds you that your data is already in pi. You just have to find the offset.
#tech
Building an HTML-first site doubled our users overnight. Twenty years of JavaScript later, the radical move is serving HTML.
A backdoor in a LinkedIn job offer: a recruiter’s take-home test turns out to ship malware. A clean walkthrough of how the trap works.
Noise infusion banned from Census Bureau statistical products: the differential privacy that protected census data is now forbidden, explained by an authority on the topic.
Curl will not accept vulnerability reports during July 2026: Daniel Stenberg pauses the bug bounty, drowned in AI-generated slop reports.
#apis
XML and JSON in 2026: a state of both formats by Tim Bray, who co-created one of them and is unsentimental about it.
The MCP 2026-07-28 Specification Release Candidate: stateless core, formal extensions, hardened OAuth. The de-facto agent protocol grows up; final version expected July 28.
Tracing HTTP requests with Go’s net/http/httptrace: instrument DNS, TCP, TLS and TTFB with nothing but the standard library.
Codex discovered a hidden HTTP/2 bomb: a flooding vulnerability found with an LLM in the loop. Vendor blog, but the bug is real and well documented.
#genai
A new era for software testing: antirez uses an LLM agent as a QA engineer, instructions in a markdown file, regressions checked commit by commit.
Trust Factory: Kent Beck on the new bottleneck. We’re accumulating code faster than we are accumulating trust.
Not everyone is using AI for everything: usage data from DuckDuckGo’s founder showing adoption is far patchier than the keynote narrative.
The Thriving Ecosystem of Open Models: OpenRouter data suggests open models now outrun closed ones in actual usage.
#tools
Homebrew 6.0.0: a major release for the package manager half of us owe our laptops to, with a new trust mechanism for taps and Linux sandboxing.
Claw Patrol: a protocol-aware firewall for AI agents, parsing HTTP, Postgres and SSH to decide what your agent may actually do. See the intro for why you might want one.
Kage: shadow any website into a single binary for offline viewing. Open source, and it topped the charts for a reason.
Typst 0.15.0: the typesetting system that wants to replace LaTeX ships another release. Open source.
Boo: a terminal multiplexer built on libghostty, for people who think tmux and screen peaked too early. Young project.
Pyodide 314.0: Python packages can now publish WebAssembly wheels to PyPI. A concrete step for the Python-in-the-browser story.
I’m Romain, a software craftsman and musician. Every week I dig through the noise and send back the few links worth reading.



