Three hidden costs of running 24/7 AI agents and how to reduce them
Running AI agents around the clock is often marketed as passive automation, but practitioners warn it quietly drains attention, compute resources, and review time. Keeping unused tools connected to an agent inflates costs, as each idle server adds charges on every request cycle. Constant notifications from agents can erode focus rather than improve productivity, and batching reports into a single daily digest is recommended as a structural fix. Honest review of agent output requires dedicated time, and skipping that step simply defers the work rather than eliminating it. The authors suggest using a second adversarial agent to sample and reject the first agent's output, making audits cheaper and more reliable than continuous oversight.
Paxos Gold Smart Contract Rated Low On-Chain Risk, Centralization Flagged as Key Threat
A DeFi security research team published a vulnerability analysis of Paxos Gold (PAXG), a tokenized gold asset on Ethereum, on October 26, 2023. The protocol holds approximately $1.91 billion in total value locked and is backed 1:1 by physical gold bullion held by Paxos Trust Company. Analysts assigned an overall risk score of 3.2 out of 10, citing minimal on-chain attack surface due to the contract's straightforward ERC-20 design with no complex financial logic. The greatest identified risk is centralization, as Paxos holds sole authority over minting, burning, and pausing the contract, meaning a compromised owner key could have critical consequences. Secondary risks include off-chain dependencies such as vault security and regulatory compliance, as well as vulnerabilities that may arise when PAXG is used as collateral in third-party DeFi protocols.
Annya Leads Uses AI Agents to Enrich, Score, and Route Sales Leads Automatically
A team built Annya Leads, an agentic lead generation system, as an entry for the AllThingsAgenticHackathon on DEV Community. The platform addresses a common sales problem: inbound leads often arrive with incomplete data and no consistent process for prioritization or follow-up. Annya Leads combines lead enrichment, scoring, and intelligent orchestration into a modular pipeline that automatically fills data gaps, assesses conversion likelihood, and routes each lead to the appropriate team or workflow. The system relies on domain rules, external enrichment signals, and AI-assisted evaluation to improve decision-making quality. Its modular architecture is designed to integrate with existing sales and marketing tools while remaining scalable and operationally traceable.
GCC Technique Enables Indirect Calls to Nested Functions Without Executable Stack
A technical article published on August 29, 2026, explores a method for indirectly calling nested functions in GCC without requiring an executable stack. Nested functions in GCC traditionally rely on trampoline code stored on the stack, which demands executable stack permissions and poses security risks. The article outlines an alternative approach that avoids this dependency, potentially improving security in programs using nested functions. The post appeared on Hacker News, attracting minimal engagement at the time of indexing with only 5 points and no comments.
How Ganguly's 'king' mindset reshaped Indian cricket's fighting spirit
Former Indian cricketer Deep Dasgupta has spoken about the lasting impact Sourav Ganguly had on Team India's culture during his captaincy. Ganguly promoted a bold, self-assured mindset that encouraged players to hold their ground against opposition sledging. This shift in attitude helped foster a more combative and confident approach within the squad. The change in team mentality under Ganguly's leadership contributed to significant victories for India both at home and on overseas tours.
NIST Finalizes Post-Quantum Standards as 'Harvest Now, Decrypt Later' Threat Looms
Post-quantum cryptography refers to algorithms built to withstand attacks from both classical and quantum computers, addressing a vulnerability in today's widely used encryption methods. Although no quantum computer can currently break modern encryption, adversaries can collect and store encrypted data now to decrypt it once quantum capability matures — a strategy known as 'harvest now, decrypt later'. In 2024, the US standards body NIST finalized its first post-quantum algorithms, ML-KEM for key exchange and ML-DSA for digital signatures, which governments and large organizations are beginning to adopt. Security experts currently recommend a hybrid approach — pairing classical algorithms with post-quantum ones — so that protection holds unless both simultaneously fail. Organizations are advised to audit their cryptographic usage, prioritize long-lived sensitive data, and rely on vetted libraries rather than custom-built solutions.
How to Fix Cloudflare's 'Enable JavaScript and Cookies' Block Error
The 'Enable JavaScript and cookies to continue' message appears when Cloudflare's security layer blocks a request, detecting that the client fails its browser integrity checks. This commonly affects automated HTTP tools like curl, Python requests, or axios, as well as browsers with JavaScript or cookies disabled. To resolve it in a standard browser, users should enable JavaScript and cookies in settings and temporarily disable privacy extensions such as uBlock Origin or Ghostery. Developers using HTTP clients can bypass the challenge by using libraries like cloudscraper, which simulates a real browser and handles dynamic cookies automatically. Those with access to Cloudflare's backend can also temporarily lower the security challenge level in development environments, though disabling protections in production is strongly discouraged.
HookProbe Deploys Multi-Engine Detection for Critical N-central Auth Bypass Flaw
A critical vulnerability, CVE-2026-18556, has been identified in N-able N-central, a widely used Remote Monitoring and Management platform serving MSPs and IT departments. The flaw is classified as an authentication bypass via an alternate path, allowing unauthenticated remote attackers to gain administrative access without valid credentials. Exploiting the vulnerability involves manipulating HTTP request URIs or headers to circumvent the platform's primary authentication filter and reach the administrative backend. If successfully exploited, an attacker could deploy malicious scripts across all managed endpoints, exfiltrate sensitive client data, or lock out legitimate administrators. Security tool HookProbe has responded by integrating dedicated detection signatures across its three engines — HYDRA, NAPSE, and AEGIS — to identify and flag exploitation attempts at network, host, and behavioral levels.
YAML Basics Explained: Syntax, Use Cases, and Kubernetes Config Guide
YAML is a human-readable data serialization language, similar to JSON and XML, designed to transfer data between applications built on different technologies using a common format. Unlike XML and JSON, YAML relies on line separation and strict indentation rather than brackets or tags, making it intuitive for developers to read and write. It is widely used in DevOps tooling, including Docker Compose, Kubernetes, Ansible, and Prometheus, primarily for writing configuration files. Core YAML syntax supports key-value pairs, nested objects, lists, boolean values, and inline arrays, all structured through indentation levels. In Kubernetes, YAML files define resources such as Pods by specifying fields like apiVersion, metadata, and spec, which contain nested objects and lists describing containers and volumes.
How Coco Gauff's 2019 Wimbledon Win Over Venus Williams Shaped Her Career
In 2019, a teenage Coco Gauff defeated tennis legend Venus Williams at Wimbledon in a result that shocked the sporting world. The victory marked a turning point for Gauff, elevating her from a promising junior player to a globally recognized tennis name. The win served as a major confidence boost and launchpad for her professional growth. Gauff went on to build on that momentum over the following years, ultimately clinching her first Grand Slam title in 2023.
Passerby rescues UP woman who threatened to jump off Gomti River bridge
A woman in Uttar Pradesh climbed onto the railing of Pakka Pul bridge over the Gomti River, threatening to jump. The incident was triggered by an argument with her family members. Police reached the scene and tried to talk her down from the ledge. Before they could succeed, a passerby stepped in and physically pulled her to safety. The situation, rooted in a domestic dispute, was ultimately resolved without any harm.
Debian approves policy permitting responsible use of generative AI
The Debian project has voted to adopt a policy allowing the responsible use of generative AI tools within its development processes. The decision reflects a measured approach, acknowledging both the potential benefits and risks associated with AI-generated content. The policy is intended to set boundaries around how contributors may use such tools while maintaining Debian's standards for software quality and transparency. This makes Debian one of the notable open-source projects to formally address generative AI use through an official governance vote.
Harmanpreet calls for defensive improvement after India finish eighth at Hockey WC
India's men's hockey team ended the World Cup with an eighth-place finish, a result captain Harmanpreet Singh described as disappointing. The skipper highlighted defensive frailties against top-ranked opponents as a key area requiring urgent attention. Despite showing competitive spirit against Belgium during the tournament, the team failed to meet its overall expectations. India now shifts focus to the Asian Games, where winning gold would secure their berth at the 2028 Los Angeles Olympics.
FieldOS Part 3: Role-Based Field Service App Built With Multi-User Interface
Developer behind the FieldOS field service platform has completed its front-end interface, offering 13 role-specific views — including portals for technicians, dispatchers, customers, and accountants — all accessible through a single login. Technicians can clock in and out directly on a job, with hours automatically flowing into invoices, while dispatchers can assign and reassign work from a live board without phone calls. Customers can track their reported issues from submission to completion and approve quotes through a dedicated portal. Building a real, clickable interface uncovered several bugs missed during isolated testing, including a text-vs-number sorting error in parts inventory, an off-by-one date display caused by timezone handling, and a URL conflict that crashed one page intermittently. A public demo mode — which resets the system on every login — was also found to have silently generated 83 fake draft invoices in the background before the reset logic was updated to clear them.
Theragun Sense Review: A User-Friendly Massage Gun for Everyday Recovery
Theragun's Sense is a consumer-focused massage gun designed to make daily muscle recovery more accessible and straightforward. The device targets everyday aches and pains, including those caused by minor physical strain or poor sleeping positions. TechCrunch reviewed the product, noting it stands out from cheaper off-brand alternatives in the massage gun market. The reviewer, who had previously been skeptical of such devices, found the Theragun Sense to be a more convincing option for routine recovery use.
Cost Model Estimates Token Speed for 276B AI Model Streamed Directly from SSD
A developer built a roughly 250-line cost model to predict how fast a 276B-parameter mixture-of-experts AI model, Inkling-Small, could run on a 24 GB Mac mini by streaming weights from an SSD rather than loading them into RAM. Unlike dense models, mixture-of-experts architectures activate only a subset of weights per token, making it feasible to read required weights from disk on demand. The cost model takes only configuration files as input and derives byte counts to estimate per-token data transfer, without downloading any model weights. It was validated against two independent artifacts, though a later correction revealed one gate had passed due to two offsetting errors rather than accurate modelling. The key finding was that total parameter count matters little; per-token cost is driven by the number of active experts, layers, and expert size, with only 10% of Inkling-Small's experts fitting in 24 GB of RAM.
