Category: Tech
Production engineering coverage spanning agent infrastructure, supply chain security, and developer platform launches. Mechanism teardowns include Amazon Bedrock AgentCore’s six layers, A2A protocol v1.0 with signed agent cards, SmolVM Firecracker microVM sandboxing for AI agents, North Korea’s Contagious Interview operation expanding across npm, PyPI, Go, Rust, and Packagist simultaneously, and Axios npm’s compromise that turned 100 million weekly downloads into a RAT distribution network.
Coverage centers on systems engineers can actually deploy, attacks they need to defend against, and platform decisions that change the cost structure of running production AI. Recent pieces include Apple’s Private Cloud Compute architecture running a custom 1.2-trillion-parameter Gemini on Apple silicon, the OpenClaw skills marketplace exposing 104 CVEs and 1,184 malicious packages, Claude building a FreeBSD kernel exploit in 4 hours and what that means for defender economics, and the leak of 512,000 lines of Claude Code source revealing the KAIROS always-on agent architecture.
The threshold for inclusion: enough technical specificity that a senior engineer reading the piece could explain to their team how the system works, where it breaks, and which version dependency or configuration variable makes the difference. No press release rewrites. Every article links the primary source for verification: GitHub repository, security advisory, SEC filing, vendor documentation, official changelog.
-
Why a 1M-Token Model Only Reasons Over 200K
Models advertise 1M-token windows but reason reliably over far less. The positional-encoding reason why, and how to measure your real ceiling.
-
ONNX Explained: How One Format Runs Any AI Model
ONNX lets a model trained in PyTorch run on a phone, browser, or edge chip without rewriting it. The graph, the opset system, and where conversions break.
-
NeuroGolf 2026: Kaggle’s Race to Build the Tiniest AI
A Kaggle contest that closed today scores neural networks by size, not accuracy. Here is the formula, the constraints, and what teams built to win.
-
How Stalkerware Bypasses End-to-End Encryption
Stalkerware captured 86,859 screenshots from a celebrity’s phone, including WhatsApp messages. Here is how it defeats encryption and what you can do about it.
-
Amazon Bedrock AgentCore: What Each Layer Does and Why It Matters
Amazon Bedrock AgentCore is six infrastructure services in one name. Here’s what each layer does: Runtime for serverless execution, Memory’s four tiers, Tool Execution’s sandboxing, Action Gateway’s enterprise…
-
Google Cloud Next 2026: The Agent Infrastructure Stack Explained
Google Cloud Next 2026 announced N4A Axion CPU instances for agent orchestration, GKE Agent Sandbox with gVisor isolation, and native A2A support in ADK. Here’s what each layer…
-
Why OpenAI’s Agent Runtime Lives on AWS, Not Azure
OpenAI’s stateful runtime runs on AWS, not Azure. That’s not a partnership detail: it’s a contract clause. Here’s the stateless-vs-stateful architectural split, why production agents break on stateless…
-
Bitwarden CLI Was a Supply Chain Bomb. Checkmarx Lit the Fuse.
The Checkmarx supply chain breach reached Bitwarden’s CLI in 93 minutes on April 22. Here’s how bw1.js stole CI/CD secrets and why security-tool supply chains fail in the…
-
LMDeploy CVE-2026-33626: SSRF Weaponized in 13 Hours
LMDeploy SSRF bug CVE-2026-33626 was exploited 13 hours post-disclosure. Full attack chain, AWS credential blast radius, and why AI inference servers are unusually dangerous SSRF targets.
-
Every Grok 4.20 Explainer Named the Four Agents. xAI’s Documentation Names Zero of Them.
xAI shipped Grok 4.20 multi-agent in February 2026. Every explainer published since then describes four named agents called Grok, Harper, Benjamin, and Lucas debating in parliament. Those names…
-
North Korea’s Contagious Interview Operation Expanded to Five Package Ecosystems. One Staging Server Connects All 1,700 Packages.
Socket’s security research team disclosed on April 7 that North Korea’s Contagious Interview operation has expanded from npm into PyPI, Go Modules, crates.io, and Packagist simultaneously. A single…
-
Meta Rebuilt Its AI Stack From Scratch and Closed the Open-Source Gates. Muse Spark Is What Came Out.
Meta shipped Muse Spark on April 8, the first model from Meta Superintelligence Labs nine months after Mark Zuckerberg restructured his entire AI team. It is the first…
-
Sora Lost $1 Million a Day. Disney Found Out It Was Dead an Hour Before Everyone Else.
OpenAI shipped new Sora editing tools on March 19. Five days later, it killed the product. Disney found out less than an hour before the public. Sora peaked…
-
OpenAI Killed Sora, Lost Disney’s Billion Dollars, and Proved That Code Beats Video.
OpenAI killed Sora five days after shipping new features. Disney found out an hour before the public. The product was losing $1 million per day with fewer than…
-
Zuckerberg Shipped Code for the First Time in 20 Years. He Used a Competitor’s AI.
Mark Zuckerberg shipped three diffs to Meta’s monorepo in March 2026, his first code in roughly twenty years. He used Claude Code CLI, a competitor’s product. Garry Tan…
-
OpenClaw Has 104 CVEs and 1,184 Malicious Packages. The Architecture Cannot Be Patched.
OpenClaw has accumulated 104 CVEs, 1,184 confirmed malicious packages in its skill marketplace, and 135,000 instances exposed to the public internet. The problems are not bugs that patches…
-
Claude Built a FreeBSD Kernel Exploit in 4 Hours. The Math That Should Scare Every Defender.
Nicholas Carlini pointed Claude Opus 4.6 at a FreeBSD kernel vulnerability and walked away. Four hours later, the model had built two working remote root exploits. The same…
-
Anthropic Sent Every Subscriber a Credit. For Some, It Covers One Day of the Price Increase.
Anthropic did not block third-party tools from Claude on April 4. That happened months ago. What changed is the price. Subscription limits no longer cover third-party usage. Subscribers…
-
Google Gemma 4 Scores 89% on AIME With 31 Billion Parameters. Here Is How the Architecture Works.
Google DeepMind released Gemma 4 in four sizes under Apache 2.0, its first truly permissive open license. The 31B dense model ranks third globally among open models. The…
-
Perplexity AI’s Hidden Trackers: How an ‘Incognito’ Search Engine Allegedly Shared Every Conversation With Meta and Google
A class-action lawsuit filed in San Francisco alleges Perplexity AI embedded hidden trackers that shared user conversations with Meta and Google, even in Incognito mode. Here is how…



















You must be logged in to post a comment.