List-Unsubscribe: The Header That Protects Deliverability Under Gmail and Yahoo’s Rules
Since 2024, Gmail and Yahoo have required one-click unsubscribing from any sender pushing more than 5,000 messages a day to their domains, through the List-Unsubscribe header defined by RFC 8058. This guide covers how…
Back-end
Node.js 26.9.0 ships node:bench and enables FFI by default
Node.js 26.9.0, released on 16 September 2026, adds the built-in benchmarking module node:bench and switches the FFI on by default.…
Symfony 8.2 adds KeyManagement, one API to encrypt data behind any KMS
Unveiled on 15 September 2026, the KeyManagement component gives Symfony 8.2 a single API to encrypt sensitive data behind AWS…
CORS explained: configuring cross-origin resource sharing without the guesswork
Cross-origin resource sharing stays a stubborn source of confusion in web development. Grasping what the browser protects and which headers…
Node.js refreshes its TLS chain: NSS 3.126 roots, OpenSSL 3.5.8, and STORE-loader private keys
Node.js 24.21.0 LTS and 26.8.2 refresh their bundled NSS 3.126 root certificates and OpenSSL 3.5.8. The LTS line also gains…
Laravel 13.31 hardens cookie-based auth and makes Redis queues cluster-safe
Laravel 13.31.0, released on 8 September 2026, closes a security gap in the “remember me” cookie flow and makes Redis…
Python 3.15 locks in: lazy imports, UTF-8 by default, and a sharper JIT
Python 3.15 shipped its final release candidate on 1 September 2026, ahead of a 1 October launch. Explicit lazy imports,…
AI for the web
Copilot Code: Microsoft Lets Non-Developers Build Internal Apps with AI
On September 25, 2026, Microsoft unveiled a Copilot overhaul built around four pillars, including Code, which turns natural-language descriptions into…
GitHub Copilot: a Default Policy for Features Admins Never Touched
On September 24, 2026, GitHub added a global 'Default policy for new features' setting for Copilot Business and Enterprise. Starting…
Claude Marketplace: Anthropic centralizes connectors and agents
Anthropic launches a single place to discover MCP connectors, Claude-powered agents and service partners, with payment possible through an already-signed…
Claude Opus 5.5: Anthropic optimizes for cost per task, not raw scores
Anthropic launched Claude Opus 5.5 on September 22, 2026, cutting cost by 40% on agentic workloads compared to Opus 5…
GitHub Copilot adds Grok 4.7 for agentic coding
GitHub has rolled out Grok 4.7, xAI's newest reasoning model, across Copilot Pro, Pro+, Max, Business and Enterprise. Built for…
Claude Code 2.1.271 brings fast mode to remote sessions and per-command network allowlists
Claude Code 2.1.271 extends fast mode to remote sessions in the cloud or on self-hosted runners. It also adds a…
Security
Two Critical Flaws Hit Widely Used WordPress Plugins
Two vulnerabilities rated 9.8 out of 10 affect Visual Composer Website Builder and the WAWP plugin for WooCommerce, letting unauthenticated…
Drupal patches a critical remote code execution flaw in Webform
The Webform module ships around twenty security advisories in a single window, including a critical remote code execution flaw. Version…
WordPress 7.1.2 patches a critical file-inclusion flaw
WordPress 7.1.2 fixes a critical vulnerability that let an unauthenticated attacker force page-template resolution to include an arbitrary PHP file.…
OpenAI Breached Through an ImageMagick Flaw Exploited With Claude Opus 5
Researchers chained a flaw in the libheif library used by ImageMagick with a single sign-on weakness to reach OpenAI employee…
WordPress 7.1.1 ships an urgent fix for eleven security flaws
WordPress 7.1.1 closes eleven security flaws in core and the block editor, including an authenticated path traversal in REST templates.…
Chrome ships an emergency fix for an actively exploited V8 flaw (CVE-2026-85046)
Google shipped an emergency Chrome update on 4 September 2026 to patch CVE-2026-85046, a type-confusion bug in the V8 engine…
DevOps & servers
Cloudflare takes Python Workers to general availability
Cloudflare has moved Python Workers out of beta, with FastAPI, Django and Flask running natively and direct access to PostgreSQL…
Migrating a WordPress site to a new host without downtime
Switching hosts exposes a WordPress site to downtime when DNS TTL and cutover order aren't planned ahead of time. This…
HTTP caching: getting Cache-Control, revalidation and URL versioning right
HTTP caching is the cheapest performance lever a site has, provided Cache-Control, ETag revalidation and URL versioning are set right.…
GitHub Actions locks down CI cache access with cache-mode
GitHub is generally rolling out cache-mode, a setting that applies least privilege to the cache used by Actions workflows. The…
Backing up a production site: applying the 3-2-1 rule and testing your restores
The 3-2-1 rule protects a site against hardware failure, human error and ransomware. But it only counts if backups are…
Symfony lsp:check brings framework-aware diagnostics to your CI pipeline
The Symfony 5.20 CLI ships lsp:check, a command that replays the editor's diagnostics inside continuous integration. It catches unknown routes,…
The publication
Technical news for web professionals, verified and dated
Mail Studio covers front-end and back-end development, infrastructure, security, email and deliverability, AI applied to the web, and running an independent business. Every article is dated, its sources are named, and any reported factual error is corrected visibly.