Security things from the last few days:
- CopyFail (linux pwn'd)
- CopyFail 2/Dirty Frag
- 13 advisories in Next.js
- Over 70 CVEs addressed in MacOS 26.5
- ~50 CVEs addressed in iOS 26.5
- YellowKey (Windows Bitlocker pwn'd entirely)
- GreenPlasma (Windows privilege escalation)
- CVE-2026-21510 and CVE-2026-21513 confirmed to be used by Russia for Windows RCE
- CVE-2026-32202 separately confirmed to be used by Russia for sensitive document access
- Mini-Shai Hulud (over 300 JS and Python packages compromised via GitHub Action cache poisoning)
- Google confirms they have identified AI-powered exploitation of zero days in an unidentified "open-source, web-based system administration too"
- Canvas (popular LMS used in most schools) pwn'd entirely
- PAN-OS (palo alto networks) pwn'd with a 9.3 severity CVE-2026-0300
Are you scared yet?
@ronaldmannak You can't buy M4 minis or Studios anymore because they went line down months ago to transition to building the forthcoming M5s. Demand simply outstripped their expected sell-through until then.
@Teknium Matching unused skills against past workflows as well as evaluating irrelevant ones are ideal agentic tasks. Clippy wasn't stupid. It was just done poorly.
It's really not acceptable that @NousResearch Hermes doesn't launch without an internet connection. I learned this the hard way today while debugging a firewall/gateway issue that took me offline for hours.
theo is one of the few people in the AI space I pay any attention to because he is off the charts smart. this is what it sounds like. everything that came before? bullshit. all the experts? wrong. your heroes? a joke. few can even tell the difference between this & madness.
Several times today, Codex xhigh completely lost the plot on very straightforward stuff, including in a fresh thread where ambiguity wasn't even possible. First time I've hit this to any degree since 5.5. Hopefully they're not capacity-tuning.
@simpsoka Maybe half a dozen times a day, new messages to Codex get stuck on Thinking… forever, including fresh threads. Both the UI and the error handling need to be tightened up, so we don't need to spend brain tokens just wondering if Codex heard us.
@reach_vb I'd only used gemini-cli before you offered codex free for a week during 5.3-codex. Been on the $200 plan ever since, and maxing it out the entire time. Life-changer.
I /highly/ recommend that everone immediately begin installing every Apple OS developer beta as soon as they can. The patch-gap between first beta and GM in a post-LLM world absolutely guarantees we will see major exploits reverse engineered from these updates used in the wild.
theo is one of the few people in the AI space I pay any attention to because he is off the charts smart. this is what it sounds like. everything that came before? bullshit. all the experts? wrong. your heroes? a joke. few can even tell the difference between this & madness.
I'm going to use my AI psychosis to fix clouds for agents.
Someone else needs to use their psychosis to fix source control. I would do it myself but I'm already too deep on the cloud thing.
GitHub is dying and git is not the right primitive. Will dump some thoughts here.
I added a new feature to my cloud (lakebed) last night. Didn’t announce it. Didn’t tell anyone about it.
Woke up today with Sherlock shipping a new app on top of the new feature. His agent discovered it and used it perfectly to spec.