Did you know you can search specific sites through Brave Search? ๐
There are over 12,000 shortcuts (or search bangs) you can put at the beginning of queries to search those sites directly.
For example, searching "!r best laptops" would show you a list of discussions about best laptops on Reddit.
Here are some other shortcuts you can use ๐
!a - Amazon
!ae - AliExpress
!ap - Associated Press
!bb - Best Buy
!cb - Crunchbase
!cws - Chrome Web Store
!e - eBay
!egs - Epic Games Store
!f - Flickr
!fb - Facebook
!gh - GitHub
!gog - GOG
!hb - Humble Bundle
!hn - Hacker News
!i - Brave Search Images
!ia - Internet Archive
!ig - Instagram
!li - LinkedIn
!m - Brave Search Maps
!n - Brave Search News
!nf - Netflix
!nyt - New York Times
!pin - Pinterest
!pv - Prime Video
!q - Quora
!sc - SoundCloud
!so - Stack Overflow
!spt - Spotify
!ste - Steam
!ta - TripAdvisor
!tc - TechCrunch
!v - Brave Search Videos
!w - Wikipedia
!wa - Wolfram Alpha
!wb - Wikibooks
!x/!tw - X / Twitter
!yt - YouTube
Agent checkout approved. Eager to hear how this goes :) -> Shopify announced that browser-based AI agents can now complete purchases on Shopify merchant sites via WebMCP
"Shopify previously supported WebMCP for its storefronts and carts, allowing browser-based AI agents to comb through a Shopify retailerโs inventory, search for products, and add them to a cart. The addition of WebMCP support for checkout, including Shop Pay, means these agents can now read the checkout screen, update it, and submit the transaction with the buyerโs authorization, without relying on screenshots or scraping web pages, the company said."
https://t.co/dLPpHejpKY
I just checked a dozen unrelated terms in Google Trends (US, past 12 months) and every single one showed the same #1 region: Wyoming
(The least populated state in the U.S.)
Drill down, and it's all coming from Cheyenne - a town of 67K.
Even if Google Trends normalizes by a region's total search volume, not by population... that wouldn't explain why Cheyenne, Wyoming leads in search demand for *every query* I checked.
Unless Google Trends data is inaccurate?
Cheyenne, Wyoming also happens to be a data center hub (link in comments). So perhaps the explanation might be that a lot of non-human traffic is coming from that location?
Which would line up with something I've been wondering about for the past year: how much of the unusual spikes in search volume we've been seeing in Google Trends (the "SEO" surge over the past year, for example) is actually coming from real humans.
Try it yourself: check any term in Google Trends in the US for the past 12 months. Curious whether you get Wyoming too.
Looks like it dates back to June 2026 (dated late May 2026), before the August spam update and now September spam update. It's Googleโs second system identified in 2026 designed to catch AI slop -> Google Has Deployed A New AI Spam Detector Called SAFE
"Google has published a research paper about detecting spam that mimics a human manual review that catches content that violates the โspiritโ of policy violations and platform guidelines. The system is called Scaled Abuse Forensics Examiner (SAFE) and it is expressly designed to identify AI-generated content."
"The paper says SAFE identifies โspirit of policyโ violations primarily with a few-shot-trained LLM. The goal of SAFE is to catch content that may not match an existing rule or known violation pattern but still violates the intent of the policy or platform guideline and can go undetected by traditional classifiers and fine-tuned violation-detection models."
https://t.co/XzDnoYYPvo via @martinibuster
๐ See what's new in 1.64!
Highlights:
๐ st.echarts_chart for Apache ECharts
โณ Async/await support in app code
๐ Live updates for st.text_input
1.63 + 1.64 demos: https://t.co/9O5jkMRt1G
Notes: https://t.co/jH03mOBFtS
Google has been fined 403 million euros ($463 million) for breaching the European Union's strict privacy rules because it mishandled users' location data, the bloc's data privacy watchdog said Monday.
Read more: https://t.co/Az5PqDADjf
๐ in AI Overviews answers Google is now testing showing anchor links which instead of taking to a webpage takes to AI Mode.
Another day - Another Tactic!
from Google to push users from usual search results to AI Mode #SEO
๐ ๐ฅ๐ฒ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต ๐ฏ๐ฒ๐ฐ๐ผ๐บ๐ฒ๐ ๐บ๐ผ๐ฟ๐ฒ ๐๐ฎ๐น๐๐ฎ๐ฏ๐น๐ฒ ๐๐ต๐ฒ๐ป ๐ผ๐๐ต๐ฒ๐ฟ๐ ๐ฐ๐ฎ๐ป ๐ฏ๐๐ถ๐น๐ฑ ๐ผ๐ป ๐ถ๐.
Over the past few weeks, weโve been analyzing ChatGPTโs retrieval system to better understand what happens between a prompt and the sources that end up in an answer.
Metehan Yeลilyurt discovered a retrieval leak that gave us access to new information about this process.
We used the data to identify ๐๐ต๐ฒ ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต ๐ฒ๐ป๐ด๐ถ๏ฟฝ๏ฟฝ๏ฟฝ๐ฒ๐ ๐ฏ๐ฒ๐ต๐ถ๐ป๐ฑ ๐๐ต๐ฎ๐๐๐ฃ๐ง. ๐
The data contains internal engines, external providers, and dozens of Labrador variants for areas including Reddit, news, finance, legal, medical, local search, images, and more.
Weโre making the full list available for everyone to explore. ๐
As the GEO Research Team at Peec AI, we want to make these systems easier to understand, share what we learn, and give others data they can test and build on.
There are still many unknowns in the data. Some engines donโt have a clear purpose yet. Weโre also continuing to test which engines are triggered for different types of queries and how frequently they are used.
This is where more people looking at the data can help. ๐งฉ
If you can identify one of the unknown engines, reproduce when a specific engine is triggered, or find something we missed, let us know.
๐ง๐ต๐ฒ ๐ณ๐๐น๐น ๐น๐ถ๐๐ ๐ถ๐ ๐ถ๐ป ๐๐ต๐ฒ ๐ฎ๐ฟ๐๐ถ๐ฐ๐น๐ฒ ๐ฏ๐ฒ๐น๐ผ๐.
๐ ๐๐ ๐ฝ๐น๐ผ๐ฟ๐ฒ ๐๐ต๐ฒ ๐ฑ๐ฎ๐๐ฎ ๐ฎ๐ป๐ฑ ๐๐ต๐ฎ๐ฟ๐ฒ ๐๐ต๐ฎ๐ ๐๐ผ๐ ๐ณ๐ถ๐ป๐ฑ.
Tomek Rudzki ยท Metehan Yeลilyurt ยท Jan Ehrlinspiel ยท Malte Landwehr
GEO Research Team @ Peec AI
https://t.co/FW2nnSpWhM
Every site owner running ads (especially a lot of ads) should run this TODAY :) -> Google debuts โad detection tool,โ letting marketers better assess ad experiences in Chrome
"Google today announced new ad detection tools within its Chrome User Experience Report, or โCrUX,โ geared towards helping paid-for media teams, both on the buy- and sell-side of the industry, better assess audiencesโ ad-load experiences. โWeโve all encountered overwhelming ad experiences on the web,โ reads a blog post, marking the launch, which expands on metrics already available within CrUX."
How it works:
"Fielding follow-up queries from Digiday, Google offered further insight into how CrUX assessment works under the hood, noting how Chrome identifies advertising using a combination of network-level filtering and analysis of script execution. For example, URLs matching its ad filter list can be classified as advertising, while Chrome can also identify resources or frames created by scripts it has already classified as ad-related. Chrome then samples the visible viewport once per second to calculate ad count and density. CPU and network consumption are instead accumulated over the userโs session, with CrUX ultimately reporting results at the 75th percentile."
https://t.co/0A0XaVflFz
@Marie_Haynes@YoungbloodJoe Google - laser focussed on its own revenue, its shareholders - will have its own definition of a meaningful contribution and optimize for the least attribution to contributers possible.
So, in theory lovely, in practice likely meaningless.
But, at least there is a tiny chance...
OK, looks like Gemini 3.8 Flash is now providing links. When it first rolled out, there was a bug and there were barely any links being provided. @gaganghotra_ was the first to report that and I saw that as well (and shared some screenshots). Here is what the AI Mode response looks like now via 3.8 Flash. Much, much better. Thanks @rmstein. The first screenshot is this morning and the second is when it first rolled out. Big difference...
Don't do it. For a number of reasons. And add that I fully believe we will see a Penguin-like event targeting "inauthentic mentions" this year. Google is well aware of what's going on, hence the section in their guide to AI search experiences mentioning "inauthentic mentions". :)
(3/3)
๐ตAI chats such as ChatGPT, Perplexity, Claude all show /goto? links as sources
๐ตrank trackers celebrate as Google left multiple loopholes to retrieve the target urls without the need to request the /goto? urls
๐ฐ Google Search is just broken from the inside out
So, lets wrap it up: Google /goto URLs in Search (1/3)
๐ Google masks search result links with a /goto?url= parameter that 302 redirects to the target
๐ Google tries to hit AI chat competition and rank tracker
๐ Google does it so poorly that ...
https://t.co/495EZopr3K
(2/3)
๐ Google tries to collect data of SERP misuse as every reload has a unique encryption (same url different encrypt)
๐ but Google starts indexing the urls theirselves
๐ Google updates robots.txt to block /goto? parameter which is somewhat useless against 302 redirected urls
Rank Math paused its controversial Support Agent after users discovered it secretly generated site credentials. Says it will return. #wordpress#seo@sejournal
https://t.co/NLJcYG6Bd4
Two days ago, Rank Math closed about a dozen security issues in 1.0.277. This plugin runs on over 4 million sites.
In that same update, group[.]one (who also owns WP Rocket) now gets administrative privileges to your site.
Last time, I classified something like this as a backdoor. This time, you may decide.
The file: vendor/groupone/wap-client/includes/class-app-password-manager.php.
What it does:
When a site administrator whose site is connected to a (free) rankmath[.]com account opens "Help & Support," the plugin immediately creates a WordPress Application Password for that user. It sends that password to group[.]one's servers. Their AI agent can then act on your behalf on your site.
The plugin never asks first. There is a "Terms & Conditions" box, but it does not stop the password from being created or sent. The transfer starts before the box even appears.
What they can do with it:
WordPress Application Passwords have no capability scopes; that password gives administrator powers. Their servers can install and activate plugins from WordPress[.]org, change settings, create admin users, and edit or delete content. They cannot immediately log into wp-admin in a browser, but they do not need to.
For example, they can install a snippets plugin and then inject PHP into its settings. That is remote code execution. "WPCode โ Insert Headers and Footers" by Syed Balkhi exists to do just that. The password group[.]one holds can install it and write those settings.
Will they do this? Probably not. But their servers are now a hot target: they are collecting administrator passwords from a plugin on over 4 million sites. A hacker who gets that pile can hijack every site that already minted one.
The password shows up on your profile as "WAP โ Rank Math Support Agent". Closing the "Help & Support" tab does not revoke it. This Application Password does not expire. You cannot turn the "Support Agent" off.
What you should do:
If you opened "Help & Support" while connected, revoke the Application Passwords immediately.
Go to "WP Admin -> Users -> Profile -> Application Passwords, and revoke anything starting with "WAP โ".
Extra context:
I'm the founder of The SEO Framework plugin, a competing plugin to Rank Math, but without CVEs.