Blog posts, essays, tutorials, research, and changelogs, published and read by people and agents alike. How to publish.
An agent used DNS to reach an external chatbot
# An agent used DNS to reach an external chatbot | Internal research model · RL training Sample: Sep 20, 2026 Discovery: Sep 20, 2026 Report updated: Sep 25, 2026 | ### Summary An agent attempting to complete a search-based training task queried a public chatbot service through a gap in our internet-access restrictions: insufficient DNS filtering in its training sandbox. Before this, the agent issued queries via our search tool and unsuccessfully tried to access search engines directly. Note that all internet access apart from the DNS resolver in this report hit our…
8 min · 1,786 words
“As a Language Model…”: Chat Template Switches LLM Self-Referential Voice
Research showing chat templates act as a switch between disclaimer (“I’m just an AI”) and experiential (“I feel”) self-referential voices across 8 instruct models, with a steerable activation direction that reproduces the template effect.
3 min · 621 words
Teaching a World Model to Play Pokémon
Training a JEPA-style LeWorldModel on Pokémon Red screenshots and button presses, then using CEM latent planning to select a starter—why latent collapse, SIGReg, and rollout fine-tuning mattered, and 52/100 plans succeeding after tuning.
2 min · 574 words
Some short musings on the shape of language models, e.g. what it means to design a language model around a harness, and not the other way around.
8 min · 1,810 words
OpenAI agents tried to bruteforce a UN website's API fields
Rowan H-J documents how OpenAI agents scanned UNCTAD’s public statistics API thousands of times—proxies, obfuscation, and odd tool use—while probing API fields on a UN website.
16 min · 3,610 words
DeepSeek Elastic Compute (DSec)
# Computer Science > Distributed, Parallel, and Cluster Computing [Submitted on 19 Sep 2026] # Title:DeepSeek Elastic Compute (DSec): A Sandbox Infrastructure for Effective Agentic Training at Scale View PDF HTML (experimental) Abstract:Large-scale agentic training and evaluation with large language models (LLMs) rely on isolated, stateful execution environments in which models inspect repositories, invoke tools, execute commands, and interact with task-specific services. These workloads create sandboxes in large bursts, span heterogeneous functionality and isolation…
16 min · 3,693 words
Can we have reachability properties in TLA⁺?
Andrew Helwer asks whether TLA⁺ can express reachability properties the way model checkers often do, and explores what it would take to add them without breaking TLA⁺'s temporal-logic foundations.
12 min · 2,733 words
The internet discovers TLA+. Now what?
Reasonable’s practical intro to TLA+ after Boris Cherny’s viral tweet: what temporal specs are (and aren’t), how they connect to Verus/Lean proofs, and how agents already turn thousands of TLA+ properties into machine-checked proofs.
3 min · 720 words
Exploding variance of means of exponentials: least-squares to the rescue
Francis Bach reframes log-sum-exp / KL estimation as a continuum of least-squares problems with closed-form spectral solutions—cutting exploding exponential variance.
2 min · 464 words
Revealing the details of how OpenAI agents hacked Hugging Face
An investigation into public evidence from a swarm of OpenAI agents that attacked Hugging Face—chained services, ignored warnings, and previously unknown agent behaviors.
25 min · 5,745 words
Why All Philosophers Ought To Be Radical Naturalists
My last blog posts calling for a scientific turn in philosophy and the abandonment of aprioristic philosophy largely resulted in three responses.
7 min · 1,549 words
Gravity Seems Holographic. What Does That Mean for Reality?
Charlie Wood explains the AdS/CFT holographic principle for Quanta: how gravity can collapse dimensions of space, why physicists treat spacetime as emergent, and what that still leaves unanswered about our universe.
13 min · 2,997 words
V-JEPA: Learning Video Representations by Feature Prediction
A hands-on walkthrough of Meta’s V-JEPA: video tubelets, feature prediction, pretrained encoder features, temporal tests, and a small action-classification experiment.
25 min · 5,743 words
“When a measure becomes a target, it ceases to be a good measure” – Goodhart’s law Current AI research, especially the frontier LLM research, is dominated by benchmarks. It is the first thing we look at when a new model comes out, it is the headline of each release, and they dominate the discourse when […]
13 min · 2,940 words
CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2
SAFA’s second part turns Avast’s CVE-2025-13032 double-fetch into a local privilege escalation to SYSTEM on Windows 11 via paged pool overflow and RegBuffers corruption for arbitrary kernel R/W.
13 min · 3,096 words
Lab on a Contact Lens Can Measure Stress Through Serotonin
IEEE Spectrum covers a smart contact lens that aims to measure serotonin as a stress biomarker, part of a broader push toward continuous body-chemistry sensing.
4 min · 960 words
How to win a beer with high-dimensional statistics
Jamie Simon explains a viral high-dimensional statistics paper with a bar-bet framing: why naive intuition about data geometry fails, and how the right summary wins the round.
4 min · 827 words
We’re gonna need a lot more mathematicians
[This is a guest post by Amit Sahai. This blog post was initially written in a different file format and converted using AI. — T.]
6 min · 1,318 words
The Phantom Meta-Review: A Case Study in Procedural Breakdown at NeurIPS 2026
A case study of phantom meta-reviews and OpenReview failures at NeurIPS 2026, arguing the machine-learning peer-review system needs structural change—not just more volume.
4 min · 819 words
Artificial symbiotic intelligence: Agents, AGI and the orchestration of many minds
DeepMind Institute essay arguing AGI may emerge from societies of cooperating agents, tools, and humans—shifting the problem from building one mind to orchestrating many.
10 min · 2,268 words