Vercel breach traced to Roblox cheats and OAuth overreach
A four-hop supply chain attack started with a vendor employee downloading Roblox cheat malware and ended with Vercel environment variables exposed.
Aperture: Your Team's Private AI Gateway
Aperture is a Tailscale-native proxy that centralises AI provider access across a tailnet, removing the need to distribute API keys to individual machines.
smolvm: portable, lightweight microVMs with sub-200ms cold starts
smolvm wraps libkrun for hardware-isolated Linux VMs with sub-200ms cold starts on macOS and Linux, packed into a single portable .smolmachine file.
Cotypist: AI Autocomplete for Mac
Cotypist is a Mac-only AI autocomplete that predicts next words across apps, running locally on Apple Silicon. Augments rather than replaces your voice.
DockDoor - Free Alt+Tab and Dock Preview Window Switcher for Mac
DockDoor is a free, open-source macOS menu bar app with Windows-style dock hover previews, enhanced Alt+Tab switching, gestures, and zero telemetry.
Folder Peek: Pin Folders to the macOS Menu Bar
Folder Peek by Sindre Sorhus pins folders to the macOS menu bar with file previews, drag and drop, and keyboard shortcuts. A faster Dock folder-stacks replac...
Hyperkey: turn caps lock into a free shortcut namespace on macOS
Hyperkey is a lightweight macOS utility that turns caps lock into a hyper key (control+option+command+shift), opening a shortcut namespace that never collides.
TypeWhisper 1.1 for macOS - Private Speech-to-Text
TypeWhisper 1.1 is a macOS speech-to-text app that runs locally with no telemetry, offering system-wide dictation, six engines, per-app profiles, and a local...
Everything Claude Code: Preloaded Agent Skills and Commands
A TikTok on the Everything Claude Code repo (100k+ stars) that bundles agent skills and slash commands. The advice: install only the parts you need.
CCGram: Telegram Bridge for AI Coding Agents via tmux
CCGram bridges Telegram to tmux sessions running Claude Code, Codex CLI, or Gemini CLI, so you can watch output and answer prompts from your phone.
OpenScreen: Free Open-Source Alternative to Screen Studio
OpenScreen is a free, open-source Screen Studio alternative for product demos and walkthroughs. Core recording and editing, no subscriptions, no watermarks.
Why Switzerland Has 25 Gbit Internet and America Doesn't
Switzerland gets 25 Gbit/s residential fiber by mandating shared neutral infrastructure open to any ISP, while the US and Germany produce monopolies.
Sol: Free Open-Source macOS Launcher
Sol is a free, open-source macOS launcher consolidating app search, clipboard history, window management, calendar integration, and more into one keyboard-dr...
LinkedIn Is Illegally Searching Your Computer
LinkedIn runs hidden JavaScript that scans visitors' browsers for extensions and software, transmitting results to third parties without consent. Fairlinked ...
ngrok: AI & API Gateway - Secure Tunnels & Traffic
ngrok evolved from localhost tunneling into a cloud networking gateway for API routing, AI traffic, DDoS protection, and CEL-based Traffic Policy rules.
Tuna - Native macOS Launcher with Modal Input Modes
Tuna is a native macOS launcher built in Swift, inspired by Quicksilver, with four input modes and one-time purchase. Requires macOS 15 Sequoia or newer.
Pocket ID - Lightweight Passkey-Only OIDC Provider
Pocket ID is a self-hosted passkey-only OIDC provider with LDAP sync, user group restrictions, audit logs, and a REST API for homelab and small-org use.
Hong Kong Police Can Now Demand Phone Passwords by Law
Hong Kong's amended National Security Law lets police demand phone passwords and encryption keys without a warrant, with criminal penalties for refusal.
Pocket ID - simple passkey-only OIDC provider for self-hosted services
Pocket ID is a lightweight, self-hosted OIDC provider using passkeys as the sole auth method, filling the gap between Keycloak and no SSO for self-hosted ser...
Tinyauth - lightweight OIDC authentication server for self-hosted apps
Tinyauth is a minimal OIDC authentication server for self-hosted setups that runs entirely from environment variables, with built-in OAuth and LDAP support.