@joaxcar I know many cases where website administrators intentionally avoided updating because the new CMS versions were not backward compatible with legacy plugins that were critical to the site’s functionality.
I remember when it took weeks, sometimes months, for exploits to appear after a vulnerability was disclosed. A patch would land, the diff would sit in public view, and the world still had a grace period. People argued about responsible disclosure timelines measured in days.
Within hours of the advisory, researchers were feeding the issue to frontier models.
Frontier AI models are making it easier to turn disclosed vulnerabilities into working exploits. Finding the bug still takes talent. Turning a public patch into a working PoC used to take the same kind of talent: reverse engineering, framing the chain, polishing a payload. The zero-day is turning into a zero-hour: the timeline from disclosure to exploitation is compressing from weeks into hours.
Patch windows already got much shorter!
#wp2shell
OpenClaw replaced its setup wizard with an AI agent.
When I installed the latest OpenClaw, I thought setup was already done because it drops you into what looks like the normal agent UI. It even auto-selected Codex as the backend without asking.
More importantly, why is setup AI-driven at all? Configuration should be deterministic - pick option 1 or 2 and move on. I don't want to describe my config in natural language and hope the AI gets it right.
Setup should be deterministic, not a conversation. It's a critical step, and I want to be in control of every decision.
@steipete
hey @grok what the heck is Crestodian in OpenClaw?
It randomly showed up today in terminal when I was trying to diagnose errors after upgrading to 5.18.
Somehow I am also back to using Claude Opus 4.7 with my openclaw after the update?
Statement Regarding the Suspension of https://t.co/ku1Zi3GLMi
The .ME Registry works closely with law enforcement to monitor and mitigate issues across the .ME domain in accordance with applicable laws, including sanctions requirements.
On 13 July, First VPN Service (1VPNS) was included as a sanctioned entity by the U.S. Department of the Treasury. A Telegram channel using the https://t.co/ku1Zi3GLMi domain was among 1VPNS identified infrastructure. Accordingly, the https://t.co/ku1Zi3GLMi domain was suspended.
On 14 July, Telegram provided confirmation that it had removed its links and affiliations with 1VPNS. Once the confirmation was reviewed and verified, the suspension was removed from the https://t.co/ku1Zi3GLMi domain.
We appreciate Telegram’s prompt cooperation in resolving this matter.
Orca doesn’t handle remote sessions very well. In practice, you can’t easily (at least not without hacks or workarounds) run an agent on a VPS and connect to it through Orca.
Almost all of my agents run on remote VPSs. For example, if I want to access them from Orca Mobile, I have to run an Orca Server on the VPS, which requires a graphical environment.
herdr + herdr-mirror plugin solve this perfectly.
Sometimes I use AI for translations or to help expand my own ideas — or express them more clearly. In theory, a comment like that could also be classified as AI-generated due to certain stylistic markers, such as the use of an em dash. However, I'm confident that this kind of automatic blocking is a poor approach because it carries a high risk of false positives.
Check that your website has an HTTPS DNS record.
It allows browsers to skip an extra round trip and connect over HTTP/3 (QUIC) right away. Otherwise, the browser first establishes a TCP connection, discovers the Alt-Svc header, and only then switches to UDP/HTTP/3.
https://t.co/rysKbq3tj2
Banning social media for teenagers only puts them in greater danger.
Teens are forced to switch to VPNs — and unlock far worse illegal content.
We’ve seen this before. When the Russian government banned Telegram, 95% of Russian teenagers kept using it. They just moved to VPNs.
Ah, the oldest trick in politics: wrap censorship in concern for children and hope nobody notices.
Funny how these "child protection" laws always end up requiring adults to prove who they are online, while teenagers learn how to use a VPN in about five minutes.
Kids bypass the restrictions, adults lose privacy, and governments gain more control.