A shared playbook for trustworthy third party evaluations
OpenAI shares guidance on third-party AI evaluations, covering how to assess model capabilities, safeguards, and validity for frontier systems.
Insights
Practical writing on software architecture, SaaS products, AI automation, legacy modernisation, and the business of building reliable systems.
Curated links from external sources — not 360Softy original articles.
OpenAI shares guidance on third-party AI evaluations, covering how to assess model capabilities, safeguards, and validity for frontier systems.
Welcome back to “What’s new in two,” your quick hit of Redis releases you might’ve missed over the last month. If your backlog has been winning lately, no worries—we’ve got the recap. We’re covering the biggest updates from May and expanding on what I...
Cloudflare has updated Logpush datasets: Updated fields in existing datasets DEX Device State Events (added): DeviceRegistrationProfileID. Gateway HTTP (added): AddedHeaders, DeletedHeaders, and SetHeaders. HTTP requests (added): MatchedRules. For the complete field definitions for each dataset, refer to Logpush datasets.
The Radar post-quantum TLS support checker now also reports TLS bugs detected during the handshake test. When a scanned host exhibits compatibility issues, the results include details on the specific bugs detected, along with guidance on how to investigate and remediate each issue. The bugs section only appears for hosts where issues are found. The following TLS bugs are detected: Split ClientHello — The connection fails with a fragmented post-quantum ClientHello but succeeds with classical hand
Cloudflare Realtime SFU is a WebRTC Selective Forwarding Unit that runs on Cloudflare's global network, so you can route live audio, video, and data between WebRTC clients around the world without managing SFU infrastructure or regions. When you use the WebSocket adapter to stream WebRTC media to a WebSocket endpoint, the adapter now auto-reconnects and buffers audio and video after brief endpoint disconnects or restarts. Streaming WebRTC media to WebSocket endpoints Many teams also use Realtime
Sandboxes can expose a service running inside the container on a public preview URL through the sandbox.tunnels namespace. The SDK uses cloudflared inside the sandbox so you can share a running service without configuring exposePort() or a custom domain. By default, sandbox.tunnels.get(port) creates a quick tunnel on a zero-config *.trycloudflare.com URL — no Cloudflare account, DNS record, or custom domain required. This is perfect for quick development and for .workers.dev deployments. JavaSc
Security Insights scans now run more often. Cloudflare scans Free accounts every 7 days, Pro and Business accounts every 3 days, and Enterprise accounts daily. In addition, all accounts and zones now receive scans by default. You no longer need to enable scans before Cloudflare checks your account for misconfigurations, vulnerabilities, and other security risks. Granular on-demand scans are now available on any plan. You can trigger an on-demand scan for any zone, insight, insight type from the
I kept seeing vibe coders ship vulnerabilities they didn't write AI coding tools are incredible. Cursor, Windsurf, GitHub Copilot — they let you build faster than ever. But there's a quiet problem nobody's talking about: Your AI coding tool's security context goes stale. Fast. New CVEs drop daily. Your AI doesn't know about them. So it keeps suggesting patterns and dependencies that were safe last month — and aren't anymore. You ship. The vulnerability ships with you. So I built Aigent.ly Aigent
Work with 360Softy
Book a free consultation and we will tell you honestly whether we can help.