source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
FRIDAY, OCTOBER 9, 2026
  1. 001Hacker NewsOCT · 09English

    The Agent Experience (Ax) Practitioner Playbook

    Microsoft's Agent Experience (Ax) Practitioner Playbook is a methodology for evaluating how AI coding agents perform with your technology, diagnosing failures, and implementing fixes. It synthesizes learnings from hundreds of agent sessions and provides a structured approach to evaluation, criteria development, failure diagnosis, and shipping improvements across SDKs, APIs, docs, and agent extensions.

    By Waldek Mastykarz
  2. 002Hacker NewsOCT · 08English

    Neon: How we systematically improved our reliability

    Neon, a cloud backend platform with Postgres at its core, improved reliability across its distributed fleet spanning multiple clouds and regions. After two incidents caused by external dependency failures that cascaded through their control plane, the team implemented systematic reliability improvements including structured postmortems and detailed incident impact analysis.

    By Dmitrii Mokhnatkin; Andrei Stolbovskii
  3. 003Hacker NewsOCT · 08English

    LocalStack for Azure is now in Public Preview

    LocalStack for Azure is now in public preview, offering a free local sandbox environment where developers can build, test, and validate Azure applications without deploying to live resources. It supports key Azure services including AKS, Functions, Storage, and Cosmos DB, with infrastructure-as-code compatibility for ARM, Bicep, and Terraform templates.

    By LocalStack Team
  4. 004aihotOCT · 02English

    OpenAI 称拦截蒸馏窃取攻击,但研究者称同样手法在 Azure 上仍可窃取 GPT-6 Astra 等模型的推理内容

    OpenAI says it shut down a coordinated adversarial distillation campaign targeting its models' protected reasoning in July 2026, but researchers demonstrated the same attack technique continued working on Microsoft Azure for weeks afterward. The attackers used encrypted reasoning packets from one conversation to decrypt hidden model thoughts in separate conversations, exploiting shared encryption keys across sessions and users.

  5. 005Hacker NewsOCT · 02English

    Azure's Weakest Link – Five Full Cross-Tenant Compromises

    A security researcher disclosed five cross-tenant vulnerabilities in Azure API Connections that allow attackers to fully compromise other tenants' connections and access backend services like Key Vaults and SQL databases, earning $200,000 in bug bounties. The flaws stem from insecure architecture in Azure Logic Apps' API Connection system, which can be exploited through ARM REST API endpoints to trick the service into operating on victim connections.

    By Haakon Wik Gulbrandsrud
  6. 006Hacker NewsOCT · 02Chinese

    Better Call GPT – Plugin for Talking to Claude Code in Live

    Better Call GPT is a plugin for Claude Code that enables voice interaction while coding. Users can speak commands while the AI works on their repository, with voice handling casual conversation and only forwarding actual work requests to Claude Code. The system ensures voice input never approves permission prompts, which require keyboard confirmation.

    By Insta-Fusion