What Edu is reading this week (Apr 27 - May 3, 2026)

Posted on May 3, 2026

Big week: a no-race, 100% reliable Linux LPE hitting all major distributions, a flood of AI agent sandboxing content, and another wave of Claude Code tooling.

Reading list header image

Security

  • Copy Fail — CVE-2026-31431 / Copy Fail: 732 Bytes to Root: A 100% reliable Linux local privilege escalation exploiting AF_ALG + splice() for a 4-byte page cache write — no race condition, no per-distro offsets, bypasses on-disk file-integrity tools and crosses containers. A 732-byte PoC gets root on Ubuntu, Amazon Linux, RHEL, and SUSE.
  • tgies/copy-fail-c: Cross-platform C port of the Copy Fail PoC (CVE-2026-31431), disclosed by Theori / Xint on April 29.
  • NorskHelsenett/copy-fail-destroyer: Mitigation tooling for Copy Fail.
  • GTFOBins: Curated list of Unix binaries exploitable to bypass local security restrictions in misconfigured systems — always useful.

Cloud, Kubernetes & Infrastructure

AI, Agents & Tools

Claude Code & AI Coding Tools

  • Orchestrate teams of Claude Code sessions: Official Claude Code docs for coordinating multiple instances with shared tasks, inter-agent messaging, and centralized management.
  • Manage costs effectively: Claude Code cost management — token usage tracking, spend limits, context management, model selection, and preprocessing hooks.
  • Common workflows: Claude Code guide including parallel sessions with git worktrees.
  • Conductor: Mac app for running parallel Codex + Claude Code agents in isolated workspaces — see what they’re working on at a glance, then review and merge.
  • endorhq/flightplanner: Framework-agnostic E2E testing principles and AI-assisted workflows for coding agents.
  • ralph-wiggum: Claude Code plugin for autonomous, long-running multi-task execution loops.
  • Claude Code On-The-Go: Running six Claude Code agents in parallel from an iPhone via cloud VM, Tailscale, mosh, and push notifications.
  • Plugins for Claude Code / CLAUDE.md Management plugin: Claude Code plugin marketplace — including a plugin to maintain and audit CLAUDE.md files.
  • openclaw/clawsweeper / openclaw/clownfish / openclaw/gitcrawl: Steipete’s AI-powered GitHub maintenance stack — ClawSweeper scans issues/PRs weekly to suggest closures, Clownfish resolves issue clusters at scale, gitcrawl crawls for maintainer triage. Closed ~4000 issues in a single day.
  • nilbuild/diffity: GitHub-style diff viewer for reviewing code changes from Claude Code, Cursor, and other AI tools.
  • Vibe Maintainer: Steve Yegge on what it’s like maintaining a large OSS project flooded with AI-generated PRs.
  • How I use AI in 2026: A maintainer and developer’s practical AI workflow — coding, triaging PRs, and handling CI failures.
  • systalyze/utilyze / Systalyze: Platform for uncovering and eliminating inefficiencies in AI workloads — claims up to 90% cost reduction.

Linux & Systems

Development, Web & Tools

Apple / macOS

Fun & Misc

  • synth.html v0.7.0: A modular synthesizer in a single HTML file — no server, no build step, no npm install. Drag nodes, patch cables, and sculpt sound like it’s 1972 but your browser is the Moog.
  • Is my blue your blue?: Interactive color perception test — does everyone see the same blue?
  • ¿Cuánto te cuestan realmente tus gastos?: Opportunity cost calculator (in Spanish) — what your daily coffee actually costs in 20 years at a 7% return.