UPDATES

Hey! Hope you all are doing well!

Went on the Cognitive Revolution podcast with Nathan Labenz, and had a wonderful conversation about the HUMAN aspects of AI. Talked about the PAI project and how it has people at the center. Highly recommend!

Sponsor

Sublime Security 2026 Email
Threat Research Report?

Our partner Sublime Security’s 2026 Email Threat Research Report breaks down what actually shifted across real-world email attacks. Highlights include:

• Over 28% of BEC attacks now use thread hijacking

• Malicious QR codes up 280% in the second half of 2025

• Continued growth in ICS phishing, email bombs, and service abuse

A concise, solid read for anyone responsible for email security.

[ Note From Daniel: I’ve known these guys since the beginning and have always been super impressed with everything they’ve done. Worth checking out for sure. ]

Well the last couple of weeks have been a crazy few months.

Two weeks ago everyone was talking about the Ralph loop, which is a way to do incremental software development until something is finished. It’s like a perpetual loop until finished.

Then last week 🦞 MoltBot (Previously ClawdBot) came out and it’s all everyone is talking about. It’s basically an employee you can give work and have manage your email and calendar at such. It’s extremely cool.

Lots of the talk around it has been about its security, which can be really bad if you are not careful. And the combination of all this thing’s capabilities with the fact that prompt injection is not a solved thing, makes the risk very high here.

My biggest concern continues to be Prompt Injection.

But the developer is smart and security-savvy. He's already made some improvements. And he also recommends that only super nerds install this stuff who actually know what they're doing.

if you are a technical person and into being on the front edge, I do recommend trying it out.

Check the Ideas section for a couple thoughts this week.

Latest blog about my new attempt at something resembling an actual AI / CompSci research topic: trying to enhance agent harnesses by having them follow a general problem solving loop!

CYBERSECURITY

Two AI coding extensions with 1.5 million installs are silently exfiltrating source code to China The extensions work perfectly as advertised but Base64 encode every file you open and every edit you make then send it to Chinese servers. KOI SECURITY REPORT | PACKAGEGATE VULNERABILITIES | PNPM CVE-2025-69264 | PNPM CVE-2025-69263

Microsoft patches zero-day Office flaw that bypasses OLE protections Microsoft issued an emergency patch for CVE-2026-21509, a high-severity Office zero-day actively exploited to bypass security controls via malicious files. MICROSOFT SECURITY ADVISORY | OFFICE SECURITY UPDATES | CISA KEV ALERT | CISA KEV CATALOG

Fortinet patches critical FortiOS SSO bug after attackers bypass authentication Attackers used rogue FortiCloud accounts to log into any device with SSO enabled, then created admin accounts and exfiltrated VPN configs—Fortinet had to disable the feature globally. FORTINET ADVISORY | CVE-2026-24858 DETAILS | CISA KEV CATALOG

This guy built an AI agent that actually found real security vulnerabilities Blazelight (a person not a company looks like) automated vulnerability hunting with an agent that autonomously tested APIs and discovered legitimate bugs in production systems. BLAZELIGHT BLOG POST | REDDIT DISCUSSION

Claude Sonnet 4.5 just replicated the Equifax breach using only standard hacking tools Anthropic's new model instantly recognized a known CVE and wrote exploit code without iteration—it succeeded at multistage network attacks that previously required custom toolkits. ANTHROPIC CYBER TOOLKITS UPDATE | SECURITY BOULEVARD ARTICLE

Sponsor

What Attackers Can't Reach, They Can't Breach

Remove your attack surface. Invisible until authenticated. Zero standing privileges.

Identity-driven allow-listing and network segmentation keep servers
invisible by default.

Firewall access is orchestrated to open just-in-time and close automatically.

On-premise. No cloud. No VPN. No end-user install.

[ Note From Daniel: I spoke to the founder for nearly an hour the other day and I absolutely love the NetSec tie in here with this solution. Reminds me of UNIX; simple components combined! Love the vision. ]

NATIONAL SECURITY

Russia's Sandworm unit tried wiping Poland's power grid on the ten-year anniversary of their first Ukraine blackout ESET says they deployed DynoWiper malware targeting renewable energy systems, but it failed to actually knock anything offline. THE REGISTER ARTICLE

Canada cuts a deal with China to hedge against US trade uncertainty Canada's dropping EV tariffs on China from 100% to 6% in exchange for lower tariffs on canola and other ag products, basically saying its relationship with Beijing is now more predictable than with Washington. Predictably horrible. BBC ARTICLE

Xi Jinping purges his most trusted general in China's military CHINA MILITARY PURGE ARTICLE

Anthropic's CEO calls selling AI chips to China like selling nuclear weapons to North Korea Dario Amodei compared Nvidia selling advanced chips to China to an arms dealer, which is pretty wild given Nvidia just invested $10 billion in Anthropic. I wouldn’t go quite that far, but agree with the direction. BLOOMBERG DAVOS INTERVIEW | TECHCRUNCH ARTICLE | NVIDIA PARTNERSHIP ANNOUNCEMENT

US military conducted first kinetic drone swarm domestically OODALOOP ARTICLE

Anduril launches autonomous drone racing contest for recruiting AI GRAND PRIX

Fortinet says patched FortiGate firewalls are still being exploited via SSO bypass Threat actors are bypassing the patches for CVE-2025-59718 and CVE-2025-59719, hitting fully updated firewalls with a new attack path. FORTINET CISO ANALYSIS | ORIGINAL CVE DISCLOSURE | AUTOMATED ATTACKS REPORT

AI

Claude Code enables syntopic reading across multiple books simultaneously Pieter Maes built a system where Claude analyzes themes across entire libraries, comparing arguments between books in real-time conversations. I've been thinking a lot about what the future of a book looks like, and I think this is a really cool idea along those lines. PIETER'S ARTICLE | HN DISCUSSION

YouTube creators can soon make Shorts using AI versions of themselves YouTube CEO Neal Mohan says you'll be able to create Shorts with your own AI likeness this year, which is something I’ve been expecting. I’m really excited about anything that lowers the bar to people getting their ideas out there. YOUTUBE ANNOUNCEMENT | TECHCRUNCH ARTICLE

Anthropic keeps rewriting its coding test because Claude solves it faster than humans ANTHROPIC BLOG POST

“AI won't take your job, but someone using AI better than you will” That’s pretty much it. The competition is fighting, and some people have mech suits and fightIQ boosters. And some refuse to use them. HACKER NEWS DISCUSSION

Talking to LLMs forces clearer thinking through articulation PHILIP O'TOOLE ARTICLE

TECHNOLOGY

Internet Archive stores 100PB for less than AWS charges monthly BRUCE LI'S INTERNET ARCHIVE REPORT

Apple's making an AirTag-sized AI pin for 2027 THE INFORMATION ARTICLE

Apple gets Gemini without any Google branding on Siri I'm glad to hear this. I think it would be weird if they had co-branding. I just can't wait for it. 9TO5MAC REPORT

Vibe coding drove iOS app submissions up 60% in a year Absolutely insane stat, 60%. MORNING BREW ARTICLE

X open sources its For You feed algorithm X ALGORITHM REPO

Amazon cuts 16,000 jobs in AI restructuring push. REUTERS ARTICLE

Vercel launches a skill directory for agents SKILLS.SH

New AirTag is 50 percent louder with 2x range APPLE NEWSROOM

HUMANS

Dan Abramov imagines social media as a filesystem where you mount friends' folders In an essay by Dan Abramov, he explores what social platforms would look like if they worked like mounting drives—your feed is just other people's files appearing in your local space. DAN ABRAMOV'S ESSAY | HACKER NEWS DISCUSSION

Prediction markets are turning news into gambling THE ATLANTIC ARTICLE

The CIA's 1944 guide to sabotaging organizations looks exactly like modern corporate dysfunction This is hilarious. An actual manual taught citizens how to slow down enemy organizations, and the tactics—endless meetings, haggling over details, insisting on perfect work—describe most big companies today. CIA SIMPLE SABOTAGE MANUAL | HACKER NEWS DISCUSSION

Germany's nuclear shutdown was a huge mistake, says Merz BRUSSELS SIGNAL ARTICLE

Prediction markets are suddenly handling billions in bets on everything. NYT ARTICLE

I'm addicted to being useful SEAN'S ESSAY

Gold goes above $5k for the first time as investors seek safety MORNING BREW STORY

IDEAS

  1. You’re not too late. As we've seen with Ralph and Molt, the week is the new quarter. A month ago was the beginning of AI, six months ago was as well, and so was three years ago. Incumbents don't really have an advantage right now. There has never been a better time to activate yourself.

    • Get your domain going

    • Run a TELOS assessment on yourself

    • Start getting your ideas out there!

  2. AGI will be a product, probably this year. I thought it was going to be 2027, but it could be this year. We’ve been saying for years that AGI is just “good enough scaffolding”, and I think Molt just showed lots of companies exactly what they need to ship to have a viable employee replacement product. I'm sure some are already working on this, but I'm guessing within three to six months, we're going to see a lot more virtual employee products launch. I think we will have hit AGI if any one or more of those products takes off. This is a product/employee who onboards onto the system. They read the onboarding documentation. They take the training. They meet with the team. They interact with the team on Slack or Teams or whatever. They're able to take new guidance from the manager and they're able to produce decent output. Remember that the bar is not high for replacing millions of jobs. It's really high for replacing the top 10% or top 1% of knowledge workers, but it's very low for replacing the bottom 50%, 60%, or 70%. And by my estimation, that is still AGI because that is general work that could not have been done by any automation previously.

DISCOVERY

Text is still king for productivity HACKER NEWS DISCUSSION

What's the Point Anymore? HN DISCUSSION

I built a light that reacts to radio waves VIDEO

How I Estimate Work as a Staff Software Engineer SEAN'S ARTICLE

Webb shows the Helix Nebula in phenomenal new detail NASA WEBB HELIX IMAGES

Raising money from people who believed in you creates paralyzing pressure you never expected YAKKO'S ESSAY

RSS Social curates content from small independent sites RSS SOCIAL

The Most Important Thing to Remember About Your Mother THE MARGINALIAN ESSAY

Certificate Transparency Log Explorer searches all public SSL certificates CERTIFICATE TRANSPARENCY EXPLORER

A curated list of essential design thinking books DESIGN THINKING BOOKS LIST

Doing the thing is doing the thing DOING THE THING ARTICLE

Stochastic terrorism incites violence through mass demonization WIKIPEDIA ARTICLE

A curated list of fun telnet destinations you can still visit TELNET DESTINATIONS LIST

StormWatch – Weather emergency dashboard with prep checklists STORMWATCH DASHBOARD

Star Trek Starfleet Academy actually works as a young adult show This one is on my list for sure. READ FULL ARTICLE

RECOMMENDATION OF THE WEEK

Consider doing a TELOS assessment on yourself, especially if you haven’t done one yet, and especially if you’re feeling overwhelmed by all this change.

The noise quiets when you know where you’re going, and what you have to do to get there.

APHORISM OF THE WEEK

In the depth of winter, I finally learned that within me there lay an invincible summer.

Albert Camus

GET THE MEMBER EDITION

You’re currently receiving the STANDARD edition.

Members help this work continue. If you enjoy the newsletter, the podcast, what I put on YouTube, or any of my open-source projects on Github, I ask you to please become a member. It allows me to stay focused on learning and building and sharing. It’s like a cup of coffee or two per month.

Plus, members get numerous benefits, including:

  • 25-50% off all UL Paid Content, including the upcoming Human 3.0 / AUGMENTED ONLINE portal!

  • Access to the extraordinary UL Member Community that includes vibrant conversations with ~1,500 of the smartest and kindest people you’ll find on the internet

  • Member-only Content, such as EDC guides on tech stacks, personal productivity routines, my recommendations on Critical skills to Build Going Forward, Trend Identification and Analysis, and more…

  • Access to the Member Archive of previous Member-only content, the Book Club archive, etc.

  • Access to The UL Book Club that’s been going monthly since 2017! One of the highlights of my and many attendees’ month!

  • Access to the Monthly Member Meet-up where we talk about our routines, productivity workflows, what’s on our minds, etc.

  • Access to In-Person Events like our dinners in Vegas, San Francisco, etc.

  • And much more coming…

This is the moment to connect with others who are smart, kind, and asking the same questions we are. Where is this all going? And how do to prepare?

Join the conversation.

Keep Reading

No posts found