
Почти любой бэкенд рано или поздно сталкивается с необходимостью отложенной обработки задач: отправить email после регистрации, пересчитать агрегаты, выполнить задачу по расписанию. Часто для этого подключают отдельную систему — RabbitMQ, Kafka, Redis-очереди. Но если ваши данные уже живут в YDB, нужные примитивы уже рядом: таблицы, changefeed, топики и координационные ноды.
В этой статье разберём четыре подхода к асинхронной обработке задач — от простой таблицы до архитектуры, пригодной для production-сценариев. Каждый следующий подход решает проблемы предыдущего, но добавляет сложности. Вместо абстрактных описаний — рабочий код на Go с использованием ydb-go-sdk.
Festival organisers defend show after criticism from sister of Meredith Kercher, Knox’s murdered former flatmate
The Edinburgh festival fringe has said it is “not afraid of controversy” after it faced calls to cancel a sold-out show by Amanda Knox, who was wrongfully convicted for the 2007 murder of her flatmate Meredith Kercher in Italy.
Knox’s comedy show, Cartwheel, has been condemned by Kercher’s family, with her sister, Stephanie, saying it “normalises and trivialises violence against women”. A petition calling for it to be cancelled has been signed by more than 9,000 people.
Continue reading...
Договор с клиентом, фрагмент кода, медицинская карта — отважные пользователи нейросетей каждый день загружают данные, которые никогда бы не отправили незнакомому человеку. При этом мало кто понимает, куда физически они попадают, кто может их увидеть и использовать, что происходит после нажатия «удалить».
Читать далее
Разбираю тот же сценарий увольнения, который в прошлый раз хвалил за гейтинг и идемпотентность - но теперь прикладываю к нему приказ Роскомнадзора № 179 про подтверждение уничтожения персональных данных. Из пяти обязательных сведений журнал закрывает от силы полтора, экспорта нет вообще, а подпись под актом в любом случае ставит человек. Отдельно - почему резервная копия уволенного может жить бессрочно, даже когда с документами всё в порядке.
К разбору приказа
Что произойдет, если большая языковая модель (LLM) добавит в код пакет, которого никогда не существовало? Разработчик может принять рекомендацию за корректную, а злоумышленник – опубликовать под придуманным именем вредоносный пакет. Тогда ошибка модели превращается в возможность атаки на цепочку поставки.
Перед вами обзор исследования We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs. Авторы проверили 16 моделей, сгенерировали 576 000 образцов кода на Python и JavaScript и изучили, как часто в ответах появляются несуществующие пакеты. Их работу отметили наградой “Distinguished Paper Award” на конференции USENIX Security 2025.
Читать далее
Republican Sen. Bill Cassidy of Louisiana announced Friday he'll vote in favor of confirming Todd Blanche for Attorney General, offering a lifeline to President Donald Trump’s nominee.
In an address on the Senate floor, Cassidy acknowledged Blanche "is not perfect," but argued no one is, and suggested another nominee may not fare any better.
Cassidy lost his re-election primary in May to a Trump-backed candidate, but he emphasized his personal relationship with the President was irrelevant.
"This process should be about Mr. Blanche and how he will go forward in a difficult job, and how the American people can be best served," he said. "I have a history with Mr. Trump, but that history does not matter one bit."
Admitting he still has some concerns regarding Blanche, Cassidy said the nominee "showed poor judgment in approving the anti-weaponization slush fund and exempting the President from IRS audits."
Blanche needed Cassidy’s support for his pending Senate confirmation after two prominent Republican Senators publicly declared they were unwilling to back him. The path toward confirmation for the acting Attorney General looked increasingly difficult in a Senate where Republicans hold a slim 53-47 majority.
The Republican margin was further complicated by the weeks-long absence of Sen. Mitch McConnell of Kentucky, who remains away from public duties as he recovers from a hospital stay prompted by a fall.
In the hours before Cassidy's statement, GOP Sen. Lisa Murkowski of Alaska announced her intention to vote against the confirmation of Blanche, who formerly served as Trump's personal attorney.
Despite several “constructive meetings” with Blanche, Murkowski determined she could not support the nomination, stating that while the “politicization—even weaponization—of the [Justice] Department” did not start with the Trump Administration, it has “accelerated” during it.
“I take issue with the handling of the release of the Epstein files; the sweeping immunity protections granted to the President, his family, and their businesses; the statements that have been made to anti-abortion groups; and the repeated targeting of individuals ranging from former Administration staff to sitting U.S. Senators,” Murkowski said.
The Alaska lawmaker also factored in Trump’s planned “anti-weaponization” fund, citing she was aware it is “only off the table because this nomination is pending and the Senate has leverage.”
The fund has been a point of contention across party aisles due to concerns the payouts to those who the Trump Administration claims were unfairly persecuted by the government could extend to people who participated in the Jan. 6, 2021, Capitol riots.
Blanche on Aug. 2 persuaded former GOP holdouts Senators John Cornyn of Texas and Thom Tillis of North Carolina to support his confirmation by assuring them, in writing, that the “anti-weaponization” fund had been rescinded.
But for Murkowski, it was not enough to sway her vote.
“I will oppose his nomination,” she said. “The country needs an Attorney General who will check the worst impulses of this Administration. I hope Mr. Blanche is able to achieve that, if confirmed, but I simply do not have confidence that will be the case.”
White House press secretary Karoline Leavitt, in an emailed statement to TIME, referred to Murkowski's decision as "disappointing" and said Blanche is "exceptionally qualified and should be confirmed as the next Attorney General of the United States, so the Administration can continue to keep America safe."
GOP Sen. Susan Collins of Maine announced her own opposing vote on Tuesday, saying that while she views Blanche as a “capable lawyer,” she is concerned the DOJ “has become increasingly political” and believes Blanche himself has “taken several actions that have further eroded the Department’s independence.”
Murkowski and Collins, who is facing a tough re-election race in the November midterms, have often broken ranks with the President. In recent weeks, they have voted to limit Trump’s ability to continue the Iran war without congressional authorization.
Trump publicly criticized Murkoswki just a day before she announced her decision on Blanche.
“I am against Murkowski,” he said in an interview, when asked about the possibility of the lawmaker opposing his nominee. “I do more for Alaska than any President in history. No President has done for Alaska what I've done. She's not good.”
This post is a follow-up to our July 27, 2026, announcement about CVE-2026-63077.
Since our initial announcement on July 27, 2026, we have received reports of active exploitation, as well as attempted exploitation, targeting unpatched TeamCity servers.
Before these reports were received, we had already investigated the issue, developed mitigations, and made fixes available to all supported customers as part of our standard security response process.
If you have not yet applied one of the available mitigation options below, we strongly recommend doing so immediately to help protect your TeamCity environment.
CVE-2026-63077 has been fixed in TeamCity 2025.11.7 and 2026.1.3. Customers should update to one of these versions as soon as possible.
If you are unable to update immediately, a security patch plugin is available for TeamCity 2017.1 and later.
For complete update and mitigation instructions, including information about installing the security patch plugin, please refer to our original announcement.
Important: The security patch plugin addresses only CVE-2026-63077. We always recommend upgrading your server to the latest version to benefit from other security updates.
TeamCity Cloud customers do not need to take any action, as the necessary mitigations have already been applied.
CVE-2026-63077 can be exploited without authentication. An unauthenticated attacker with HTTP(S) access to a vulnerable TeamCity server could exploit the vulnerability via the TeamCity agent polling protocol to execute arbitrary operating system commands with the privileges of the TeamCity server process.
Depending on the privileges granted to the TeamCity server process, a successful exploit could expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI/CD pipelines.
As a precaution, administrators may wish to review their TeamCity server logs for occurrences of the following message:
com.thoughtworks.xstream.converters.ConversionException
While the above message alone does not confirm exploitation, it may indicate an attempted or successful exploit and warrants further investigation. If you have any questions or would like assistance interpreting your logs, please contact the TeamCity Support team by submitting a ticket.
If you have already installed the security patch plugin or upgraded to a fixed version, you may also wish to review the TeamCity server logs for occurrences of the following message:
com.thoughtworks.xstream.security.ForbiddenClassException
This message may indicate that an attempt was made to exploit the vulnerability after your server had been patched. In this case, the message indicates the attempt was successfully blocked by the security patch or fixed TeamCity version.
Administrators may also wish to review the list of unauthorized build agents for unexpected entries, particularly agents with names beginning with scan. The presence of such agents may indicate an attempted exploit on servers whose URL was reachable by an attacker. These agents can be safely removed. Please note that the date shown for an unauthorized agent does not necessarily indicate when the exploit attempt occurred. Instead, you should rely on the timestamps of the relevant log messages when determining when an attempt may have taken place. If you have any questions or would like assistance interpreting your logs or investigating these indicators, please contact the TeamCity Support team by submitting a ticket.
If your TeamCity server is publicly accessible over the internet and you are unable to apply one of the available mitigation options immediately, we strongly recommend temporarily restricting external access until you have done so.
As a longer-term security best practice, we recommend limiting network access to TeamCity servers to trusted networks wherever possible and running the TeamCity server with the minimum operating system privileges required for normal operation.
Internet-facing TeamCity servers should also consider requiring connections through a VPN or implementing an additional security layer to help prevent unauthorized access.
TeamCity servers should also run on dedicated hosts separate from build agents, as described in our documentation.
If you have any questions about this issue or encounter problems updating your server or installing the security patch plugin, please contact the TeamCity Support team by submitting a ticket.
The power battle over Vanessa Gold’s shares and the David Sullivan Panorama allegations are overshadowing the start of the season in the Championship
There have been 10 summers of West Ham’s London Stadium tenancy and a number of winters of discontent. As the Hammers kick off the new season on Saturday, a Carabao Cup first-round fixture with Portsmouth is a stark reminder of reduced circumstances, further confirmation of last season’s relegation from the Premier League. The summer has been as bleak as any of those winters, with a number of factors colliding to deepen the gloom of relegation.
Certain clubs, including West Ham back in 2011-12 when promotion was achieved at first time of asking under Sam Allardyce, have used the Championship to take a beat, to refresh and replenish. Can this be the case at West Ham 2026? The Hammers are short-odds favourites for promotion but behind the scenes it has been a summer of turbulence, particularly in the boardroom, where a power struggle is being fought.
Continue reading...The favourite for 1500m gold at the European Championships on her second chance after quitting at 23, learning from Keely Hodgkinson and eyeing an LA 2028 double
‘I grew up and was always just good at running,” says Georgia Hunter Bell, as she remembers the moment she felt her career was over at 23. “I always thought that I would be a professional athlete, go to the Olympics, all of that. So it was quite brutal when I had to make peace with the fact that it was not going to happen.”
At that stage Hunter Bell’s body was broken. Her teenage promise – she was the UK’s top 15-year-old having run a 2min 8sec 800m – worn away by injuries aggravated by overtraining in the US collegiate system. She retired; found a job in tech; didn’t run on the track for five years. And then came a comeback straight out of a Hollywood feel-good movie.
Continue reading...
Всем привет, в этой статье мы доработаем проект офлайн логгер из прошлой статьи. Добавим датчики и напиши обработчик логов с sd карты!
Читать далееЯ пишу ядро операционной системы на Rust. Не потому что собираюсь заменить Linux, а потому что мне интересно, что получится, если закладывать безопасность в архитектуру с нуля, а не встраивать в готовое.
Довольно быстро выяснилась вещь, о которой в разговорах про Rust в системном программировании говорят реже, чем стоило бы. Язык закрывает один класс ошибок и оставляет другой нетронутым. И второй класс ловится куда хуже первого.
Расскажу про конкретный баг, который я ловил дольше всего.
Читать далее
В мае на конференциях C++ Russia и HolyJS мы предложили участникам оценить технологии, инструменты и инженерные практики, с которыми они работают или за которыми следят. Так появились данные для двух технических радаров: по экосистеме C++ и по JavaScript.
Сырые цифры сами по себе рассказывают немного, поэтому мы отдали результаты на разбор эксперту. Виктор Новиков, руководитель группы разработки в «Лаборатории Касперского», посмотрел на распределения голосов и поделился своим мнением, почему CMake уверенно побеждает, а PostgreSQL раскалывает аудиторию пополам. В этой статье — его анализ C++-части исследования. Про техрадар JavaScript мы расскажем в другой статье.
Посмотреть радар и принять участие в голосовании можно на странице проекта.
Читать далее
U.S. employers cut 23,000 jobs in July, and job gains for the two previous months were weaker than initially reported, according to a report Friday from the Labor Department.
(Image credit: Joe Raedle)
A Trump administration framework on AI testing leaves a lack of transparency – and plenty of open questions
After months of talking with tech industry leaders, the Trump administration finalized a framework this week for how it will test new artificial intelligence models for safety and cybersecurity risks. So far, the White House is keeping details of the framework private, in a blow to transparency and potential boon for secretive AI companies.
On Tuesday, staff from OpenAI, Anthropic, Meta, Google, Nvidia and Microsoft attended a private meeting with White House officials to review the AI framework. Multiple outlets have since reported that although the volunteer vetting process for new AI models has been settled, the White House does not plan to release its policy publicly and will only share testing criteria with a select few tech companies.
Continue reading...Robyn Cory says daughter Kristen was not protected, amid questions about why it took six years to identify remains
The family of Kristen Galvan, a 15-year-old Houston girl who was sex trafficked and murdered, says law enforcement failed her twice by not protecting her after she gave forensic interviews about her traffickers, and later by taking more than six years to identify her remains.
The Texas attorney general’s office announced on 28 July that Kristen’s remains had been positively identified using advanced DNA testing conducted over the past year. Parts of her skull, clothing and an earring were found beneath a bridge beside a jogging trail in Missouri City, about 10 miles outside Houston.
Continue reading...Domestic flights cost 26.5% more than last year, data shows, amid demand for travel and reduced oil refining capacity
Even if a lasting ceasefire between the US and Iran lowers oil prices, travelers hoping to snag cheaper airfare should buckle their seatbelts and expect continued turbulence.
US domestic airfares are 26.5% higher than a year ago, according to June’s consumer price index data, and analysts say prices globally are up 25-30% compared with 2025.
Continue reading...
OpenAI готовит собственное устройство, которое в компании рассматривают как первый шаг к новой аппаратной экосистеме. По данным Bloomberg, первым гаджетом станет небольшая умная колонка необычной формы, размером примерно с пончик.
Читать далее