Welsh teen James Taylor holds 5 world records after teaching himself freestyle football online
Fourteen-year-old Welsh football freestyler James Taylor has earned a bronze medal at the World Championship. Taylor holds five Guinness World Records, a feat he achieved through self-teaching via online tutorials and consistent daily practice. His dedication has inspired his younger brother, who has gone on to claim three world records of his own. Together, the two siblings have accumulated a combined total of eight Guinness World Records for their family.
22-Year-Old Stabbed 17 Times in East Delhi Argument, Dies
A 22-year-old man was fatally stabbed 17 times in the Mandawali area of east Delhi. The attack followed an altercation between the victim and two individuals. The incident took place near a school in the locality. Police officials confirmed the death on Friday. Authorities are investigating the circumstances surrounding the deadly confrontation.

Ripple Integrates AI Agents Into Its $1 Billion Corporate Treasury System
Ripple has introduced artificial intelligence agents into its corporate treasury operations, which are valued at $1 billion. The AI software is designed to monitor cash flow, assess risk, and generate financial forecasts. It can also suggest potential financial moves to human operators. However, all AI-recommended actions require explicit human approval before being executed, keeping people firmly in the decision-making loop.

How Node.js Webhook Consumers Should Handle Rate Limits and Dead-Letter Queues
A technical guide for B2B SaaS platforms warns that successful HTTP delivery responses do not confirm that downstream business actions—like renewal reminders—actually completed on time. The core principle is that a consumer must treat the business deadline as the primary service-level objective, making rate limits, retry policies, and dead-letter decisions explicit parts of the system contract. Engineers are advised to define three key numbers before choosing queue technology: the business deadline, the sustainable downstream processing rate, and the maximum tolerable duplicate effect. The guide distinguishes between acknowledgement, negative acknowledgement, and dead-lettering as separate outcomes based on the future likelihood of success, not HTTP status codes. Duplicate handling is flagged as an application-level responsibility under at-least-once delivery, with uniqueness constraints on event IDs recommended to prevent stale or repeated actions.
How a Stale Retry Silently Restored Access to a Deactivated Account
A technical case study highlights how a timed-out provisioning job can inadvertently restore access to a deactivated user account in distributed systems. In the described scenario, access was correctly removed from a deactivated account, but an older queued worker woke up and replayed the original group-addition request minutes later, bypassing the deactivation. Each individual system component behaved as designed, yet the combined sequence produced an incorrect and insecure final state. The article argues that queues preserve work but cannot guarantee that queued work remains valid, making generation-based checks and idempotent reconciliation essential safeguards. It also warns that provisioning systems often treat delayed onboarding as more urgent than delayed removal, leaving access-revocation gaps that are harder to detect through standard API success metrics.
Developer builds preflight scanner to catch MCP tool security flaws before deployment
A developer has created an open-source preflight security scanner targeting Model Context Protocol (MCP) tools, addressing gaps that standard demos fail to reveal. The tool runs static and behavioral checks across four rule categories, flagging issues such as unsafe shell commands, excessive scope declarations, embedded secrets, and unvalidated user inputs. Behavioral tests go further by calling a local fixture server to verify tenant isolation, write approval enforcement, and quota limits. Each finding is assigned a severity level, a remediation step, and a trackable status, turning security observations into actionable engineering tasks. The scanner is positioned as a bounded first-pass filter rather than a full penetration test, with source code available on GitHub at github.com/glatinone/mcp-security-preflight.
How to Securely Bridge Webhooks to Kafka, Redpanda, and NATS at the Edge
Directly ingesting webhooks into event brokers like Kafka or NATS exposes systems to synchronous timeout failures, replay attacks, and duplicate deliveries. An edge-gateway pattern addresses this by terminating TLS, validating provider-specific HMAC signatures from services like Stripe, GitHub, and Shopify before any payload parsing occurs. Signature checks must use constant-time comparisons and run against the raw request body, while deduplication relies on provider-supplied delivery IDs. Verified events are then normalized into the CloudEvents standard format and routed to the appropriate broker partition based on entity identifiers. Observability metrics and dead-letter queue handling are also essential components of a production-grade implementation.
Reconstructing Concurrency Invariants Through Medieval East Asian Logic
Article URL: https://oborona.zip/post/a-middle-period-engine-reconstructing-concurrency-invariants-through-east-asian-structural-logic Comments URL: https://news.ycombinator.com/item?id=49653509 Points: 3 # Comments: 2
How MCP Servers Must Change When Moving From Local to Multi-Tenant Deployments
Model Context Protocol (MCP) servers that run locally on a single machine behave very differently once deployed behind a gateway accessible to multiple users or teams. A developer built a local lab environment to surface the key problems that emerge in this transition, including authentication, tenant data isolation, and write-tool approvals. The core findings suggest that bearer token validation must happen at the gateway level on every request, and tenant scoping should be enforced at the edge rather than inside individual tools to prevent data leakage. Write operations require time-bound, request-specific approvals, meaning a stale or mismatched approval cannot authorize unintended actions. The author distilled the lessons into a five-point checklist covering per-request auth, edge-level tenancy, expiring approvals, structured audit logs, and pre-tested failure modes.
How Duplicate Webhook Deliveries Silently Corrupt Payment Data
Payment providers like Stripe, Midtrans, and Xendit routinely retry webhook events, but most applications are not built to handle these retries safely. Common failure modes include duplicate event delivery, out-of-order processing, malformed payloads, mid-process timeouts, and partial commits followed by failed downstream calls. A developer built a local test lab with 18 deterministic tests to reproduce these failure scenarios and validate fixes without involving real transactions. Key recommended safeguards include verifying HMAC signatures against the raw request body, storing both event IDs and payload hashes to detect suspicious retries, enforcing strict state machine transitions, and capping automatic retries at a fixed number before routing events to a human-review queue. Together, these measures address the subtle, compounding bugs that typically cause payment integrations to fail in production.
xbrowser Adds MCP Server in One Day, Built Without Official SDK
Browser-automation CLI tool xbrowser shipped a stdio-based Model Context Protocol server in version 1.23.1, exposing 7 browser tools to AI agents such as Claude Desktop and Cursor. The team deliberately skipped the official MCP SDK, instead hand-writing a roughly 60-line JSON-RPC 2.0 protocol layer to avoid new dependencies and keep the code fully debuggable. All MCP tool calls route through the same internal functions used by the existing CLI, meaning the tool inherits xbrowser's full 4,000-test suite and any future engine improvements automatically. Two bugs were caught during initial smoke testing: the CLI mistakenly tried to execute protocol JSON as browser commands, and a shutdown race condition triggered early process exit while the browser was still launching. Both issues were fixed before release, and the team notes the experience highlights why thin, hand-written protocol layers are preferable for globally installed CLI tools.
CSS Units Explained: When to Use px, vw, and vh in Web Design
Web developers use three common CSS units to control the size and layout of elements on a page. Pixels (px) are fixed units that remain constant regardless of screen size or browser window changes. Viewport width (vw) is a relative unit tied to the browser window's width, so 10vw on a 1200px-wide screen equals 120px but shrinks to 60px if the window narrows to 600px. Viewport height (vh) works similarly but is based on screen height, making it useful for elements like hero images that need to fill the full vertical space of any device. Choosing between these units depends on whether a design element should stay fixed or scale dynamically with the user's screen.
Samantha Ruth Prabhu opens up about myositis struggle and pregnancy news
Actress Samantha Ruth Prabhu has spoken candidly about her experience battling myositis, an illness that severely impacted her self-esteem and sense of identity. She described feeling a complete loss of control during the difficult period of her diagnosis and treatment. Despite the challenges, Samantha said she found inner strength, hope, and faith while coping with the condition. The actress also revealed that she is expecting her first child, sharing the pregnancy news during the filming of a music video.
ED raids Ramnandi Hotels at 9 locations over alleged Rs 132-crore bank fraud
The Enforcement Directorate conducted searches across nine locations in three states targeting Ramnandi Hotels and Resorts Ltd. The company is accused of diverting Rs 58 crore obtained through bank loans using fraudulent reports and personal guarantees. Investigators allege that five properties pledged as collateral were recently sold at prices below their actual value. The ED suspects these transactions were carried out deliberately to obstruct asset attachment and recovery of proceeds from the alleged crime.
How a 5-Minute Pre-Interview Research Habit Helped One Candidate Land 3 Offers
A job seeker credits receiving three job offers to a simple five-minute routine practiced right before each interview. Instead of rehearsing personal pitches, they spend the time identifying the company's most pressing current problem using sources like recent news, Glassdoor reviews, or the job posting itself. That insight is then shaped into a single, targeted question to ask the interviewer. The candidate says this approach consistently shifts the tone of interviews, prompting more engaged and candid responses from hiring managers. The core idea is to enter the conversation already focused on the employer's challenges rather than solely on self-promotion.
How Al-Qaeda's 19 Hijackers Carried Out the Devastating 9/11 Attacks
On September 11, 2001, nineteen Al-Qaeda operatives executed a coordinated terrorist attack on the United States by hijacking four commercial aircraft. Two of the planes were deliberately flown into the Twin Towers of New York's World Trade Center, destroying both structures. A third hijacked aircraft struck the Pentagon in Virginia, the headquarters of the US Department of Defense. The fourth plane crashed into a field near Shanksville, Pennsylvania, after passengers bravely attempted to overpower the hijackers. The attacks remain among the deadliest acts of terrorism in modern history.


