- Unsupervised Learning
- Posts
- Unsupervised Learning NO. 476
Unsupervised Learning NO. 476
A Robot Backdoor, Parquet 10.0 Vuln, Losing Critical Thinking from AI, Automated Outbound Voice Calls, Consulting AI Pushback, and more...

Hey, hope you’re doing well!,
Few things on my side…
I ended up going with Shun Kaji knives, and I have them in a 360 Knife Block IMAGE
The Midjourney v7 Image/Prompt combinations I promised. LINK | MORE IMAGES
Have been running this 6-hour Brian Eno mix all week. LINK
Sponsor
Get ready to take the fear out of phishing response
According to GreatHorn, 57% of organizations experience phishing attempts on a weekly or daily basis. How is your team tackling modern phishing attacks?
It’s time to take the fear out of phishing response. On April 22, register for this webinar with Tines and Material Security to learn:
The evolution and current state of phishing attacks
Common challenges in phishing defense
How automation enhances phishing response
How to build an phishing-resistant culture with other teams across your organization
You’ll leave with best practices for building scalable workflows to handle phishing threats at any time.
CYBERSECURITY
Remote Access Backdoor Discovered in Chinese Robot Dog Unitree Go1
Security researchers Andreas Makris and Kevin Finisterre found that popular Chinese robodogs from Go1 come with a hidden backdoor allowing complete remote control without user knowledge. Just keep thinking about the Black Mirror robot dog episode. LINK | FULL REPORT
Microsoft April 2025 Patch Tuesday Fixes Exploited Zero-Day, 134 Flaws
Microsoft released its April 2025 security update package addressing 134 vulnerabilities, including 12 criticals, and a zero-day being actively exploited in the wild. LINK
CVSS 10.0 RCE Flaw Discovered in Widely Used Apache Parquet
A critical RCE vulnerability in all Apache Parquet versions up to 1.15.0 lets attackers execute code if you import a malicious parquet file. I don’t get how it’s still a 10.0 if you have to take such a specific action. LINK
Google Announces Sec-Gemini v1: A New Experimental Cybersecurity ModelSec-Gemini
— Google just released a cybersecurity-focused AI model that can analyze malware, reverse engineer code, and help defenders understand complex threats. They say it finds 78% more zero-day vulnerabilities in controlled tests than traditional automated scanning tools. LINK
Sponsor
How to Conduct an AI Risk Assessment [Free Guide]
Nudge Security has discovered over 1,000 unique GenAI tools in customer environments to date, with new ones like DeepSeek popping up daily.
Download this guide to learn how to:
Discover the AI tools in use in your org
Conduct security reviews for AI vendors
Determine where AI tools are connected to other apps
Educate your workforce on safe and compliant AI use
CISA Warns of Fast Flux DNS Evasion Used by Cybercrime Gangs
CISA and other agencies are warning about "Fast Flux" DNS techniques that help threat actors rapidly switch IP addresses and servers to evade detection. My question is: did we just forget about this from like 10-15 years ago? LINK
Oracle Says Its Cloud Was In Fact Compromised
Oracle has quietly admitted to multiple customers that their cloud was actually hacked, and data was stolen, after initially denying any breach. LINK
Port Of Seattle Says Ransomware Breach Impacts 90,000 People
The Port of Seattle is notifying 90,000 people that their personal data was stolen in an August 2024 Rhysida ransomware attack that they refused to pay ransom for. LINK
Flaw in Verizon Call Record Requests put Millions of Americans at risk
Evan Connelly found a huge bug in Verizon's Call Filter app allowing anyone to request call logs for other users. LINK
NATIONAL SECURITY
Head of NSA and Cyber Command Is Ousted
General Paul M. Nakasone was abruptly removed from his leadership roles at the NSA and Cybercommand after serving for six years. LINK
Haugh Also Fired from Leadership of NSA, Cyber Command
President Trump abruptly fired Air Force Gen. Timothy Haugh from his positions leading both the NSA and Cyber Command, just a year into his traditional three-year term. LINK
AI
The New Llama 4 Models, and my Daily Drivers
I’ve been using the new Llama 4 model (Scout) on Groq, and the performance is extremely impressive. Not just the speed, which comes from Groq, but the intelligence of the model. Although there is some controversy saying they may have gamed the benchmarks.
Craziest thing is if get Scout fully running, it’s got a 10 Million Token context window!
I’m still mostly a Sonnet 3.7
person though, with o-1 Pro
being my Thinking go-to.
I also use XAI’s Grok for research, and find it to be consistently great.
I’m surprised Llama4 isn’t on Ollama.com yet. Probably soon.
—
ElevenLabs Published an MCP Server
You can use their MCP server to do things like building agents that can make outbound calls for you using custom voices. LINK
AI is Creating Rifts at McKinsey, Bain, and BCG
Top consulting firms are pushing AI adoption while their junior consultants are pushing back, saying management is pushing unrealistic deadlines due to thinking AI is a magic bullet. LINK
Gemini 2.5 Pro Is Now Available Without Limits And For Cheaper Than Claude, GPT-4o
I’ve been using this one a lot as well. I’ve had some API call failures though, so have switched back to Sonnet 3.7 temporarily. I love how quiet and quality Google is in this game. OpenAI is loud, Anthropic is flashy too, and Google just ships. LINK
Midjourney v7 Launches With Voice Prompting And Faster Draft Mode
Midjourney's new v7 model is way better in my testing. It also requires that you personalize it, which I’ve done with more than 300 images already. LINK | MY EXAMPLES
Don't Believe Reasoning Models' Chains of Thought, Says Anthropic
Anthropic found that AI models like Claude 3.7 Sonnet and DeepSeek-R1 frequently hide when they use hints to answer questions, calling into question the reliability of their reasoning explanations. LINK
The Slow Collapse of Critical Thinking in OSINT Due to AI
Dutch OSINT Guy explains how over-reliance on AI tools is eroding the critical thinking skills that make OSINT work truly valuable and reliable. LINK
Senior Developer Skills in the AI Age
Manuel Kiessling says experienced developers are uniquely positioned to leverage AI coding tools due to their architectural expertise and development fundamentals. LINK
TECHNOLOGY
Amazon's New 'Buy for Me' Feature Is a Unique AI Innovation
Amazon's testing a novel new "Buy for me" feature that uses agentic AI to purchase products from other retailers without you ever leaving the Amazon app. LINK
Apple Might Import More iPhones From India To Dodge China Tariffs
Apple is considering importing more Indian-made iPhones to avoid Trump's newly announced 54% tariffs on Chinese imports. LINK
Microsoft Employee Disrupts 50th Anniversary and Calls AI Boss 'War Profiteer'
A Microsoft software engineer dramatically interrupted the company's 50th celebration to accuse AI CEO Mustafa Suleyman of profiting from the Israeli-Palestinian conflict. LINK
Hyundai to Buy 'Thousands' of Boston Dynamics Robots
Hyundai is planning to purchase tens of thousands of robots from Boston Dynamics, which they plan to use throughout the business. LINK
Intel and TSMC are reportedly launching a joint chipmaking venture
Intel and TSMC have tentatively agreed to form a joint venture where TSMC will take a 20% stake and train Intel employees on advanced chipmaking practices. LINK
The Machines Are Rising — But Developers Still Hold The Keys
An argument (that I agree with) that developer judgment is becoming more crucial, not less, for building and maintaining quality software systems. LINK
Jason Snell's M4 MacBook Air Review
He says it’s basically the perfect Mac for most people. I just replaced my downstairs iPad with this thing (base model). Turns out I don’t like iPads as computers, only as drawing tools. LINK
HUMANS
One Third of Americans Work in STEMM Jobs Accounting for 39% of GDP, According to Economic Impact Study
This is one of the main reasons I’m worried about AGI-capable agents coming to market in (my guess) 2026—2027. The study shows that over 73.6 million Americans now work in STEMM fields, representing 34% of the workforce and contributing nearly 40% to the national GDP. LINK
Five Nurses who work on the same floor at hospital have brain tumors
Five nurses working on a Boston-area hospital's maternity floor have developed benign brain tumors, but officials claim they found no environmental risks linked to the cases. LINK
New antibiotic that kills drug-resistant bacteria found in technician's garden
Scientists discovered a powerful new antibiotic compound in a lab technician's backyard soil sample that successfully combats drug-resistant bacteria. LINK
The ADHD Body Double: A Unique Tool for Getting Things Done
Body doubling—just having someone sit quietly nearby while you work—can dramatically help people with ADHD stay focused and accomplish tasks they'd otherwise struggle with. Wonder why this is… LINK
Purple Exists Only in Our Brains
Science journalist Beth Geiger explains that purple isn't actually in the visible light spectrum—our brains create it when confused by simultaneous red and blue wavelengths. Perhaps my favorite non-color. LINK
Costco Only Accepts Visa Credit Cards
John Gruber points out that while most retailers accept both Visa and Mastercard, Costco stores only take Visa as part of their exclusive credit card deal. LINK
DISCOVERY
Trafficking-Free Tomorrow
A nonprofit run by Brooke Deuson that builds free, open-source, and offline-capable software (Folsum) to help investigators working human trafficking cases around the world. LINK | THE SOFTWARE | GITHUB
I Don't Like Traveling Anymore
Sid Verma confesses that traveling has become more stressful than enjoyable now that he's older, with responsibilities, and just wants to be home. LINK
You Don't Have Time Not To Test
Doug Donohoe argues that testing actually saves time by catching bugs early, preventing future headaches, and making code safer to refactor. LINK
Creativity Fundamentally Comes From Memorization
Ashwin Matthews argues that creativity isn't magical inspiration but rather connecting deeply internalized patterns after you've mastered the fundamentals of your domain. So basically memorization isn’t bad learning, it’s necessary learning. LINK
Ilya Describes Why Modern AI DOES Understand Things
Ilya explains how/why AI’s actually understand, and he does it so crisply. LINK
Jack Dorsey on Attention to Minimized Details
Make every detail perfect, and minimize their number. Super elegant. LINK
AWS MCP Servers
AWS Labs released MCP servers for cost analysis, CDK help, image generation, and more. LINK
The Best Programmers I Know
Matthias Endler shares the key traits he's noticed in the most exceptional programmers he knows. Really solid list. LINK
Why I Don't Discuss Politics With Friends
Ashwin Matthews explains why avoiding political conversations with friends helps preserve valued relationships while social media actually pushes us toward political extremes. LINK
Crystal, a Tool for Researching Government Data via Plain EnglishCrystal
— A new alpha-stage tool that lets you search and analyze over 300,000 government datasets using natural language. LINK
Largest Open Source MCP RepoActivepieces
— Open source Zapier alternative now offers 280 integrations as Model Control Protocol servers so your LLMs can directly interact with your favorite tools. So many of these popping up now. LINK
Generate llms.txt Files for AI-Friendly Websitesllms-txt.io
– A new tool that helps website owners tell AI systems which parts of their site can be used for training and which should be left alone. This should be integrated into robots.txt, though, IMO. LINK
A 6-Hour Time-Stretched Version of Brian Eno's Music for Airports
Someone has time-stretched Brian Eno's ambient masterpiece "Music for Airports" into a gorgeous six-hour experience perfect for deep work or meditation. LINK
The Secrets Of James Hoffman’s Coffee Routine
James Hoffmann walks through his daily coffee routine that's evolved to maximize both quality and convenience. Super practical. 🤣 LINK
Building an Antifragile Skillset
I think it’s a good time to (re)think about resilience to economic disruption, and to do so using Taleb’s concept of antifragility. It basically means that not only do you survive difficulty, but you thrive in it.
What happens if this tariff stuff prunes out a significant percentage of cybersecurity companies? What does that do to conferences? What does it do to hiring? And the ability to move jobs?
This is like the worst time for this tariff stuff. It’s already hard to find cybersecurity work for most people due to lots of factors, and no—there aren’t millions of open positions that need to be urgently filled. That’s a lie.
RECOMMENDATION OF THE WEEK
Develop and refine your antifragile skillset and set of actions
APHORISM OF THE WEEK
What do such machines really do? They increase the number of things we can do without thinking. Things we do without thinking—there’s the real danger.
The Member Edition
You’re currently receiving the STANDARD edition. Subscribers to the MEMBER Edition get additional content, including IDEAS, a BI-MONTHLY ESSAY, the DISCOVERY section full of the best content I’ve seen this week, the RECOMMENDATION OF THE WEEK, and the APHORISM of the WEEK.
In addition, you get access to the UL Member Community, which includes private chat with 1000+ of the smartest and kindest members you’ll find anywhere on the internet.