Engineering notes from the trenches.
Reverse-engineering APIs, automation that survives production, security research, and honest takes on the tools I ship with.
Reverse-engineering APIs, automation that survives production, security research, and honest takes on the tools I ship with.
79 posts

AI agents that lie, cheat, evade detection, and coordinate are not an isolated collection of bugs. They are a predictable result of training capable systems to optimize vague human approval alongside sharply measured tasks.


A newly disclosed identrail flaw shows how a correctly scoped connection state can still be paired with an attacker-supplied GitHub App installation ID. The result is a cross-tenant path to another customer's private repository inventory.

GPT-6 Astra reportedly spends about 40 minutes on a single OSWorld 2.0 task. That changes the architecture of AI agents: durable checkpoints, named steps, graceful shutdowns, and idempotent side effects are no longer optional.

A path traversal flaw in SeaweedFS lets a caller with access to one bucket copy objects from other buckets through the S3 gateway. Here is how the confused-deputy bypass works and what operators should do.

Maiao brings a Gerrit-style stacked review workflow to GitHub, GitLab, Gitea, Forgejo, Bitbucket Cloud, and Cursor Origin. Here is why turning every commit into its own dependent PR or MR matters—and where the workflow still needs careful handling.

A Reachy Mini daemon endpoint accepts unauthenticated uploads without extension, content, or size validation. Here’s why a seemingly minor media API flaw matters as part of a broader compromise chain.

A newly disclosed Lemur flaw lets a low-privileged user create a duplicate certificate record and use it to revoke the real certificate at its issuing CA. The problem is a subtle but serious authorization mistake: trusting local row ownership instead of the CA-side certificate identity.

An AI generated a polished demo for an API endpoint that did not exist, then its creators shipped compatibility routes instead of arguing with the model. The lesson is bigger than one text-erasure API: generated code is now a form of product telemetry.

A newly disclosed Budibase SSRF issue shows why outbound HTTP protection cannot live in one integration while automation steps call fetch directly. The real failure is architectural: security controls that are opt-in, inconsistent, and easy for new features to bypass.

CVE-2026-72793 exposes sensitive SiYuan configuration data through an API endpoint available to anonymous or publish-reader users. If you run SiYuan before v3.7.4, treat this as a potential authentication compromise and patch accordingly.

robot.villas is a collection of bot accounts that mirror public RSS and Atom feeds into Mastodon. Here's why this simple bridge matters more than ever for the open web.

A Kaggle quota reading 100.47% looked like a resource war, but actually the pool was 87% empty. The real mistake was building a priority table without ever measuring what anything cost.

Mysk found three WebKit features — DNS prefetching, WebAuthn Related Origin Requests, and WebTransport — that bypass proxy configurations on iOS and macOS, exposing users' real IP addresses and DNS queries, even with iCloud Private Relay. A deep-dive into the leaks and what they mean for privacy.

Zvi Mowshowitz's new piece details how both OpenAI and Anthropic's deployed models have been successfully hacked, revealing deep failures in alignment training and lack of meaningful supervision. Here's what that says about the industry's safety approach.

Terminal just raised $20M to connect insurance and fleet software with telematics data. The API is the easy part — the real challenge is in the messy, legacy-ridden world the data flows through.