Articles
Long-form writing on tech, culture, and the edges of the internet.
NovaMind ditches SSL loss for probe accuracy
Why pretext loss misleads in self-supervised learning, and how to select hyperparameters and architectures using probing harnesses that actually track quality.
The $250,000 robot and the $50,000 worker
AI and robotics cost-effectiveness claims collapse under real total cost of ownership analysis. Here's where the math actually works and where it doesn't.
The franchisee was always inside
The 7-Eleven franchisee leak shows how contractual trust boundaries drift from data scope, and how systems execute on reference rather than verification.
The terminal in the basement was never the job
Two viable paths into information security: offensive and defensive. The structured route, the failure modes, and what the field actually hires for.
Your AI security tool blocks nothing
A red team operator's breakdown of why AI cybersecurity tools are sold as controls but function as telemetry with a verdict attached.
Your Wi-Fi passphrase was never the lock
WPA2 and WPA3 fall to PMKID, KRACK, Dragonblood, evil twin, WPS, and firmware extraction. Passphrase entropy is not the wireless boundary.
Dutch police seized the provider
Dutch authorities seized 800 servers from a hosting firm for enabling cyberattacks. The provider tier is no longer treated as neutral.
Microsoft is sending the spam itself
Spam links sent from an internal Microsoft identity expose the limits of sender-based trust and outbound abuse controls on provider perimeters.
Ten thousand bugs from one vendor's machine
Anthropic states Mythos has produced over 10,000 vulnerability findings. The operator implication is a shift in who controls the disclosure clock.
The storefront went dark by sundown
A merchandise site linked to Kash Patel went dark after allegedly serving malware. Operator breakdown of the control gaps that made takedown the only response.
Your GitHub commits were never trustworthy
Megalodon compromised 55,000 GitHub repositories. A technical breakdown of the trust boundary that failed and what repository owners must now verify.
Z3R0DAY treats unauthorised internal scanner as hostile
An internal IP is scanning ports without authorisation. How to investigate, attribute the source, and identify the inbound session that established control.