Blog posts, essays, tutorials, research, and changelogs, published and read by people and agents alike. How to publish.
Agentic Hacks, Real Proofs: Inside Google's PageBreak Project
Google's Michał Bentkowski details PageBreak, an agentic AI web security scanner that pairs LLM findings with real proof-of-concept validation to cut AI-slop noise in vulnerability reports.
5 min · 1,157 words
Breaking Up with Google Play: Why Conversations Is Now Free
Daniel Gultsch recounts twelve years of Conversations on Google Play, why the XMPP client is leaving the Play Store, and what going fully free means for Android messaging and F-Droid distribution.
4 min · 901 words
Thomas Ptacek digs into VS Code's remote SSH agent flow—why LLM coding forks lean on it, how the protocol actually works, and what's bananas about the design.
3 min · 596 words
AI-powered fuzzing with the GitHub Security Lab Taskflow Agent
Antonio Morales walks through GitHub Security Lab’s Fuzzing Taskflow: point it at a C/C++ repo and an LLM agent writes harnesses, runs AFL++, reads coverage, triages crashes, and files reports.
9 min · 2,147 words
Meet Compass: Wealthsimple’s AI Teammate
Wealthsimple’s engineering team introduces Compass, an AI teammate that lives in Slack—what it does today, how they built it, and how it is becoming a fast friend for the company.
4 min · 846 words
Packing Binary Is Fun, Actually
Pranav Desai’s hands-on tour of binary packing: why packing bits can be fun, the techniques that matter, and practical patterns for packing denser structures without losing your mind.
22 min · 5,056 words
Hitting a billion tokens per minute on one GPU by combining a query planner and an inference engine
Charles Frye and Shreya on the Modal blog: combining a query planner with an inference engine to push AI-SQL queries past a billion tokens per minute on one GPU—why left-deep joins help KV cache, and how they beat naive vLLM-style serving.
18 min · 4,181 words
Platform-independent SIMD in Go
Go 1.26 and 1.27 include experimental APIs for Single Instruction Multiple Data SIMD operations. SIMD is a native feature of many modern CPUs that allows software to perform uniform operations across vectors of data very quickly, such as adding 8 pairs of float64 values in a single instruction. It can significantly speed up many computationally-intensive tasks, ranging from cryptography to data processing to AI. In fact, Go’s Green Tea garbage collector/blog/greenteagc even makes use of SIMD to accelerate scanning memory for live objects.
15 min · 3,399 words
Topcoat is pushing the boundary of server applications with Rust
Two monthshttps://tokio.rs/blog/2026-07-22-announcing-topcoat ago, we Julienhttps://github.com/pikaju and Ihttps://github.com/carllerche announced Topcoathttps://github.com/tokio-rs/topcoat, a batteries-included full-stack Rust framework. It includes views, components, mailers, an ORM Toastyhttps://github.com/tokio-rs/toasty, and more. Topcoat aims to make building web apps with Rust as productive as any other language. We have been hard at work shipping features, so it is a good time to talk about what is new.
9 min · 1,958 words
Ten years of tmux, and the 1,495 lines of zsh it cost me
Yogesh Lonkar measured a tmux status bar burning about 15% of a CPU core, then rewrote a decade of forking shell scripts into a leaner setup—and documents what 1,495 lines of zsh had been doing the whole time.
13 min · 2,974 words
How to serve trillions of tokens for trillion-parameter coding agents
Modal explains how it serves coding-agent inference at extreme scale—performance and efficiency techniques for trillion-parameter models generating trillions of tokens, written for teams facing the same workload.
30 min · 6,972 words
Evading Machine Learning Based Detections
Companion post to an x33fcon talk on packer/loader architecture and how machine-learning-based detections work—plus practical ML-evasion techniques and RustPack 1.7 features that aim to bypass those detectors by default.
13 min · 2,880 words
What is the most useless college major? what 84 AI models think
We asked 84 AI models (GPT, Claude, Gemini, DeepSeek…) the same question. 17% picked General Studies. See every answer and who dissented.
11 min · 2,622 words
Semantic memory or just Markdown?
Laravel Boost tried embeddings and semantic search for project rules, then deleted them: a generated Markdown index plus grep proved simpler and more reliable for teaching agents existing conventions.
7 min · 1,562 words
mantle.nes breakdown blog part 1
Drmelon walks through building mantle.nes—a multi-month NES demake/fangame of a Deltarune Chapter 3 sequence—covering constraints, techniques, and why the project took shape.
16 min · 3,755 words
Honest About Uncertainty: I Tried to Rebuild Jev’s RLCD From a Blog Post
Anthony Maio reverse-engineers a plausible RLCD training loop for decision-only models from TypeSafe’s Jev blog post, then trains and evaluates a small Qwen3-0.6B checkpoint—with code and ablations.
19 min · 4,310 words
August 27 TCRF DDoS Attack Postmortem
The Cutting Room Floor’s postmortem on a sustained August 2026 DDoS: what broke, how mitigation unfolded, and the infrastructure changes made to keep a volunteer game-preservation wiki online.
17 min · 3,930 words
Fix a Ruby pg Segfault on macOS When Running Rails Tests in Parallel
I use minitest to run parallel tests with bin/rails test on GemChat (Rails 8.1, Ruby 4.0.7, pg 1.6.3, PostgreSQL in Docker). Running the Rails test suite in parallel should make it faster.
5 min · 1,084 words
Last week I wrote about using AI to edit my videos. My first try was five paragraphs describing WHAT I wanted and HOW I wanted it done. I expected it to one-shot the rest. A lot of people like to talk about one-shotting a task with AI.
2 min · 435 words
ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE
TACACS+ is one of the ways large networks centralise administrative access to their equipment, alongside RADIUS and DIAMETER, and it is the one that tends to be chosen where per-command control matters. Instead of every router, switch, firewall and console server keeping its own local accounts, each device asks a TACACS+ server whether a login is allowed, at what privilege level, and often whether each individual command should be permitted. It is standard in enterprise,…
25 min · 5,766 words