MongoBleed (CVE-2025-14847) is basically Heartbleed for MongoDB
- unauthenticated memory disclosure
- public POC, trivial to exploit
- leaks creds, tokens, cloud keys straight from RAM
- huge exposed surface on the internet
Good writeups and technical details here:
https://t.co/LgK4RABmJu
https://t.co/DWtByJQ3au
https://t.co/LUwfnF6uXG
Patch fast, rotate secrets, and assume exposed instances were scanned(!)
@Zakka_Jacob This is how Trump killed the the #h1bvisa . .
- A fee of 100k non-refundable (even if denied)
- Per annum, so the company/sponsor has to pay 100k for each year that they employ the H1B.
- Minimum salary moves from 60k/yr to 150k/yr
- Tenure for 1 year (automatic renewal)
Trump just killed the H1B visa.
Companies now have to pay $100K per year to bring foreign hi-skilled workers to the U.S.
This will dissuade them from doing so, some jobs will be offshored.
For Indian techies, the American dream just got killed.
An attempt to explain (current) ChatGPT versions.
I still run into many, many people who don't know that:
- o3 is the obvious best thing for important/hard things. It is a reasoning model that is much stronger than 4o and if you are using ChatGPT professionally and not using o3 you're ngmi.
- 4o is different from o4. Yes I know lol. 4o is a good "daily driver" for many easy-medium questions. o4 is only available as mini for now, and is not as good as o3, and I'm not super sure why it's out right now.
Example basic "router" in my own personal use:
- Any simple query (e.g. "what foods are high in fiber"?) => 4o (about ~40% of my use)
- Any hard/important enough query where I am willing to wait a bit (e.g. "help me understand this tax thing...") => o3 (about ~40% of my use)
- I am vibe coding (e.g. "change this code so that...") => 4.1 (about ~10% of my use)
- I want to deeply understand one topic - I want GPT to go off for 10 minutes, look at many, many links and summarize a topic for me. (e.g. "help me understand the rise and fall of Luminar"). => Deep Research (about ~10% of my use). Note that Deep Research is not a model version to be picked from the model picker (!!!), it is a toggle inside the Tools. Under the hood it is based on o3, but I believe is not fully equivalent of just asking o3 the same query, but I am not sure.
All of this is only within the ChatGPT universe of models. In practice my use is more complicated because I like to bounce between all of ChatGPT, Claude, Gemini, Grok and Perplexity depending on the task and out of research interest.
These MCPs are cheat codes that make Cursor "just work."
Here's how they eliminate errors, save time, and improve your app:
(Bookmark this for later)
1. Magic MCP
Not only does it upgrade your UI and animations, it shows you a preview of variations before coding it.
Introducing PageOn AI 2.0 / @PageOnai
It is a new kind of visual communication tool.
It works like Cursor but for content that goes far beyond slides.
You tell it your goal. It plans, researches, and designs full pages.
YO this is my favorite thing on tech x this week:
1) kid makes leet code cheating tool for big tech interviews
2) uses it on Amazon interview, gets offer
3) YOUTUBES THE WHOLE THING, tells Amazon to f*** off
4) Amazon gets mad and emails Columbia, gives him disciplinary letter
5) TWEETS THE LETTER
@im_roy_lee do you want an internship brother because this is AMAZING
This is wild - UC Berkeley shows that a tiny 1.5B model beats o1-preview on math by RL!
They applied simple RL to Deepseek-R1-Distilled-Qwen-1.5B on 40K math problems, trained at 8K context, then scaled to 16K & 24K.
3,800 A100 hours ($4,500) to beat o1-preview in math!
Best thing is they open-sourced everything: the model, the training code (based on ByteDance verl library), and the dataset.
Anyone who thinks DeepSeek just came out of nowhere should see this graph.
For each model on this graph, weights, code, and detailed papers were released.
This is a team with a strong track record and has been working hard for a while. They didn't come out of nowhere.
🚨BREAKING: China DEFEATED Silicon Valley.
Alibaba just launched "Qwen" another most powerful AI model.
Qwen2.5 beats DeepSeek, OpenAI and Google.
Here's why it's a game-changer & why the US government should be worried:🧵
An Open Source AI model {Deepseek r1} launched 72 hours ago.
This Chinese AI model just broke the internet.
People are running r1 model on:
- self hosted servers
- mobile phones
- raspberry pi
- mac books
Here're all the cool experiments, you check:
🧵