The consultancy and product studio that bridges AI strategy and execution—because knowing what AI could do isn't the same as knowing how to do it. CEO: @andrsnu
The security breaches in the developer supply chain scared the F out of me.
I mean Claude has taken possession of parts of my Macbook and although I tried to keep up some kind of system, I couldn’t remember most of it after 3 months.
So what would happen if The Mini Shai-Hulud campaign would find its way in? Would I even recognize it? Be able to trace back the source? I think we have been so overly enthusiastic about AI, most of us (including me) never thought about attacks like these.
That’s the subject of this weekend’s Inside Tech newsletter that will find its way to your doorstep a week earlier than planned. Just because getting this message out was more important than sticking to my schedule.
Subscribe now and you’ll make sure you don’t miss it. https://t.co/QgTcYAfZ7I
1/ 76% of small businesses are already using AI. Only 14% have actually embedded it into how they work.
That gap is the whole story right now. It's not a technology problem. It's an implementation problem — and almost everyone is stuck there.
I just open-sourced our #uptime#monitor cause I was fed up with companies forcing us into higher paid tiers through shenanigans. Here you go - have fun monitoring your stack. Link below
Latest @ANDRS_Projects newsletter is out, who are the frontrunners and what are they doing right. Plus one tool and a search query to find out where you stand.
Ask Seve now turns your saved places into a day-by-day trip plan — spread across days, shareable with anyone traveling with you. What used to take an hour takes minutes.
Exactly why we built this👇 The time it took me to compare #invoices to money going out on the credit card, painstaking excercise and always the balance didn’t add up. Now it all runs automatically, no matter what currency the original invoice is in.
Gaps are easy to spot and fix, and a complete audit trail from invoice to payment. 👏👏👏
#bankreconciliation
If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised and follow tanstack’s instructions: 👇
SECURITY ADVISORY — TanStack npm packages
A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package.
Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down.
Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys.
If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised:
• Rotate cloud, GitHub, and SSH credentials immediately
• Audit cloud audit logs for the last several hours
• Pin to a prior known-good version and reinstall from a clean lockfile
Detection — the malicious manifest contains:
"optionalDependencies": {
"@tanstack/setup": "github:tanstack/router#79ac49ee..."
}
Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root).
Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level.
Full technical breakdown, complete package and version list, and rolling status updates:
https://t.co/Zy8qG7PA9f
Credit to the security researcher for responsible disclosure.
Just updated the Domain Memory Skill for Claude to have the promoted rules enforced.
I found that I was encountering issues that had been the basis for a hypothesis on a fix - and that fix was then promoted to a rule after 5 confirmations.
However Claude was not following this rule on immediate execution where these issues re-occurred (only in second instance after reading the domain.knowlegde.file) .
So I hardened the enforcement by adding the rules automatically to the Claude. md itself as well.
3️⃣Anthropic is doubling Claude Code’s five-hour rate limits for Pro, Max, Team, and seat-based Enterprise plans.
Second, they are removing the peak hours limit reduction on Claude Code for Pro and Max accounts.
Third, they are raising their API rate limits considerably for Claude Opus models.
Last 24 hrs we’ve seen some interesting news from Anthropic:
1️⃣Dreaming in Claude Managed Agents as a research preview. Dreaming extends memory by reviewing past sessions to find patterns and help agents self-improve.
2
2️⃣They are also making outcomes, multiagent orchestration, and webhooks available to developers building with Managed Agents.
Together, these updates make agents more capable at handling complex tasks with minimal steering. 🧵 1/ ⬇️
This is for all the AI #wiki builders. Read this first: 👇
There’s a 30-year-old framework from organizational theory that most builders have never read, and it explains exactly why every “AI second brain” setup eventually collapses into noise.
#claude#memory
Link ⬇️
Some of this week’s tech headlines
- Openclaw users will not be happy: https://t.co/4vjYXXRyWx
- Goblins are apparently top of mind in ChatGPT models : https://t.co/DPR7ymwmJi
- and Musk and Altman are going head to head : https://t.co/TD4bqNp2Vf
#technews
The prevailing wisdom was simple: businesses would consolidate onto these sprawling platforms because switching costs were too high and integration headaches too painful to maintain multiple specialized tools.
But two forces are quietly dismantling this assumption. 🧵
Sometimes a simple post generator is all you need. No Al, no sign-in, no adds, no paywall - just social-ready images and mockups in seconds.
#socialmedia#marketing#posterdesign#mockups#dropkit
https://t.co/yvlDMvgRib
Want to make sense of how AI can benefit your #business?
Get our monthly Field Briefs straight in your inbox. A Field Brief is our structured, one-page distillation of a key strategic question. Each brief diagnoses the root cause, maps where the gap shows up, and closes with
a concrete next step.
Designed to be read in under 5 minutes and acted on immediately.
#AILeadership#FutureOfWork#TechLeadership
Ready to build AI that actually moves the needle for your business? Our AI consultancy specializes in this exact challenge.