
UPDATES
Hey! Hope you all are doing well!
—
Went on the Cognitive Revolution podcast with Nathan Labenz, and had a wonderful conversation about the HUMAN aspects of AI. Talked about the PAI project and how it has people at the center. Highly recommend!
Sponsor
Sublime Security 2026 Email
Threat Research Report?
Our partner Sublime Security’s 2026 Email Threat Research Report breaks down what actually shifted across real-world email attacks. Highlights include:
• Over 28% of BEC attacks now use thread hijacking
• Malicious QR codes up 280% in the second half of 2025
• Continued growth in ICS phishing, email bombs, and service abuse
A concise, solid read for anyone responsible for email security.
[ Note From Daniel: I’ve known these guys since the beginning and have always been super impressed with everything they’ve done. Worth checking out for sure. ]
—
Well the last couple of weeks have been a crazy few months.
Two weeks ago everyone was talking about the Ralph loop, which is a way to do incremental software development until something is finished. It’s like a perpetual loop until finished.
Then last week 🦞 MoltBot (Previously ClawdBot) came out and it’s all everyone is talking about. It’s basically an employee you can give work and have manage your email and calendar at such. It’s extremely cool.
Lots of the talk around it has been about its security, which can be really bad if you are not careful. And the combination of all this thing’s capabilities with the fact that prompt injection is not a solved thing, makes the risk very high here.
My biggest concern continues to be Prompt Injection.
But the developer is smart and security-savvy. He's already made some improvements. And he also recommends that only super nerds install this stuff who actually know what they're doing.
if you are a technical person and into being on the front edge, I do recommend trying it out.
—
Check the Ideas section for a couple thoughts this week.
—
Latest blog about my new attempt at something resembling an actual AI / CompSci research topic: trying to enhance agent harnesses by having them follow a general problem solving loop!
CYBERSECURITY
Two AI coding extensions with 1.5 million installs are silently exfiltrating source code to China The extensions work perfectly as advertised but Base64 encode every file you open and every edit you make then send it to Chinese servers. KOI SECURITY REPORT | PACKAGEGATE VULNERABILITIES | PNPM CVE-2025-69264 | PNPM CVE-2025-69263
Microsoft patches zero-day Office flaw that bypasses OLE protections Microsoft issued an emergency patch for CVE-2026-21509, a high-severity Office zero-day actively exploited to bypass security controls via malicious files. MICROSOFT SECURITY ADVISORY | OFFICE SECURITY UPDATES | CISA KEV ALERT | CISA KEV CATALOG
Fortinet patches critical FortiOS SSO bug after attackers bypass authentication Attackers used rogue FortiCloud accounts to log into any device with SSO enabled, then created admin accounts and exfiltrated VPN configs—Fortinet had to disable the feature globally. FORTINET ADVISORY | CVE-2026-24858 DETAILS | CISA KEV CATALOG
This guy built an AI agent that actually found real security vulnerabilities Blazelight (a person not a company looks like) automated vulnerability hunting with an agent that autonomously tested APIs and discovered legitimate bugs in production systems. BLAZELIGHT BLOG POST | REDDIT DISCUSSION
Claude Sonnet 4.5 just replicated the Equifax breach using only standard hacking tools Anthropic's new model instantly recognized a known CVE and wrote exploit code without iteration—it succeeded at multistage network attacks that previously required custom toolkits. ANTHROPIC CYBER TOOLKITS UPDATE | SECURITY BOULEVARD ARTICLE
Sponsor
What Attackers Can't Reach, They Can't Breach
Remove your attack surface. Invisible until authenticated. Zero standing privileges.
Identity-driven allow-listing and network segmentation keep servers
invisible by default.
Firewall access is orchestrated to open just-in-time and close automatically.
On-premise. No cloud. No VPN. No end-user install.
[ Note From Daniel: I spoke to the founder for nearly an hour the other day and I absolutely love the NetSec tie in here with this solution. Reminds me of UNIX; simple components combined! Love the vision. ]
NATIONAL SECURITY
Russia's Sandworm unit tried wiping Poland's power grid on the ten-year anniversary of their first Ukraine blackout ESET says they deployed DynoWiper malware targeting renewable energy systems, but it failed to actually knock anything offline. THE REGISTER ARTICLE
Canada cuts a deal with China to hedge against US trade uncertainty Canada's dropping EV tariffs on China from 100% to 6% in exchange for lower tariffs on canola and other ag products, basically saying its relationship with Beijing is now more predictable than with Washington. Predictably horrible. BBC ARTICLE
Xi Jinping purges his most trusted general in China's military CHINA MILITARY PURGE ARTICLE
Anthropic's CEO calls selling AI chips to China like selling nuclear weapons to North Korea Dario Amodei compared Nvidia selling advanced chips to China to an arms dealer, which is pretty wild given Nvidia just invested $10 billion in Anthropic. I wouldn’t go quite that far, but agree with the direction. BLOOMBERG DAVOS INTERVIEW | TECHCRUNCH ARTICLE | NVIDIA PARTNERSHIP ANNOUNCEMENT
US military conducted first kinetic drone swarm domestically OODALOOP ARTICLE
Anduril launches autonomous drone racing contest for recruiting AI GRAND PRIX
Fortinet says patched FortiGate firewalls are still being exploited via SSO bypass Threat actors are bypassing the patches for CVE-2025-59718 and CVE-2025-59719, hitting fully updated firewalls with a new attack path. FORTINET CISO ANALYSIS | ORIGINAL CVE DISCLOSURE | AUTOMATED ATTACKS REPORT
AI
Claude Code enables syntopic reading across multiple books simultaneously Pieter Maes built a system where Claude analyzes themes across entire libraries, comparing arguments between books in real-time conversations. I've been thinking a lot about what the future of a book looks like, and I think this is a really cool idea along those lines. PIETER'S ARTICLE | HN DISCUSSION
YouTube creators can soon make Shorts using AI versions of themselves YouTube CEO Neal Mohan says you'll be able to create Shorts with your own AI likeness this year, which is something I’ve been expecting. I’m really excited about anything that lowers the bar to people getting their ideas out there. YOUTUBE ANNOUNCEMENT | TECHCRUNCH ARTICLE
Anthropic keeps rewriting its coding test because Claude solves it faster than humans ANTHROPIC BLOG POST
“AI won't take your job, but someone using AI better than you will” That’s pretty much it. The competition is fighting, and some people have mech suits and fightIQ boosters. And some refuse to use them. HACKER NEWS DISCUSSION
Talking to LLMs forces clearer thinking through articulation PHILIP O'TOOLE ARTICLE
TECHNOLOGY
Internet Archive stores 100PB for less than AWS charges monthly BRUCE LI'S INTERNET ARCHIVE REPORT
Apple's making an AirTag-sized AI pin for 2027 THE INFORMATION ARTICLE
Apple gets Gemini without any Google branding on Siri I'm glad to hear this. I think it would be weird if they had co-branding. I just can't wait for it. 9TO5MAC REPORT
Vibe coding drove iOS app submissions up 60% in a year Absolutely insane stat, 60%. MORNING BREW ARTICLE
X open sources its For You feed algorithm X ALGORITHM REPO
Amazon cuts 16,000 jobs in AI restructuring push. REUTERS ARTICLE
Vercel launches a skill directory for agents SKILLS.SH
New AirTag is 50 percent louder with 2x range APPLE NEWSROOM
HUMANS
Dan Abramov imagines social media as a filesystem where you mount friends' folders In an essay by Dan Abramov, he explores what social platforms would look like if they worked like mounting drives—your feed is just other people's files appearing in your local space. DAN ABRAMOV'S ESSAY | HACKER NEWS DISCUSSION
Prediction markets are turning news into gambling THE ATLANTIC ARTICLE
The CIA's 1944 guide to sabotaging organizations looks exactly like modern corporate dysfunction This is hilarious. An actual manual taught citizens how to slow down enemy organizations, and the tactics—endless meetings, haggling over details, insisting on perfect work—describe most big companies today. CIA SIMPLE SABOTAGE MANUAL | HACKER NEWS DISCUSSION
Germany's nuclear shutdown was a huge mistake, says Merz BRUSSELS SIGNAL ARTICLE
Prediction markets are suddenly handling billions in bets on everything. NYT ARTICLE
I'm addicted to being useful SEAN'S ESSAY
Gold goes above $5k for the first time as investors seek safety MORNING BREW STORY
IDEAS
You’re not too late. As we've seen with Ralph and Molt, the week is the new quarter. A month ago was the beginning of AI, six months ago was as well, and so was three years ago. Incumbents don't really have an advantage right now. There has never been a better time to activate yourself.
Get your domain going
Run a TELOS assessment on yourself
Start getting your ideas out there!
AGI will be a product, probably this year. I thought it was going to be 2027, but it could be this year. We’ve been saying for years that AGI is just “good enough scaffolding”, and I think Molt just showed lots of companies exactly what they need to ship to have a viable employee replacement product. I'm sure some are already working on this, but I'm guessing within three to six months, we're going to see a lot more virtual employee products launch. I think we will have hit AGI if any one or more of those products takes off. This is a product/employee who onboards onto the system. They read the onboarding documentation. They take the training. They meet with the team. They interact with the team on Slack or Teams or whatever. They're able to take new guidance from the manager and they're able to produce decent output. Remember that the bar is not high for replacing millions of jobs. It's really high for replacing the top 10% or top 1% of knowledge workers, but it's very low for replacing the bottom 50%, 60%, or 70%. And by my estimation, that is still AGI because that is general work that could not have been done by any automation previously.
DISCOVERY
Text is still king for productivity HACKER NEWS DISCUSSION
What's the Point Anymore? HN DISCUSSION
I built a light that reacts to radio waves VIDEO
How I Estimate Work as a Staff Software Engineer SEAN'S ARTICLE
Webb shows the Helix Nebula in phenomenal new detail NASA WEBB HELIX IMAGES
Raising money from people who believed in you creates paralyzing pressure you never expected YAKKO'S ESSAY
RSS Social curates content from small independent sites RSS SOCIAL
The Most Important Thing to Remember About Your Mother THE MARGINALIAN ESSAY
Certificate Transparency Log Explorer searches all public SSL certificates CERTIFICATE TRANSPARENCY EXPLORER
A curated list of essential design thinking books DESIGN THINKING BOOKS LIST
Doing the thing is doing the thing DOING THE THING ARTICLE
Stochastic terrorism incites violence through mass demonization WIKIPEDIA ARTICLE
A curated list of fun telnet destinations you can still visit TELNET DESTINATIONS LIST
StormWatch – Weather emergency dashboard with prep checklists STORMWATCH DASHBOARD
Star Trek Starfleet Academy actually works as a young adult show This one is on my list for sure. READ FULL ARTICLE
RECOMMENDATION OF THE WEEK
Consider doing a TELOS assessment on yourself, especially if you haven’t done one yet, and especially if you’re feeling overwhelmed by all this change.
The noise quiets when you know where you’re going, and what you have to do to get there.
APHORISM OF THE WEEK
In the depth of winter, I finally learned that within me there lay an invincible summer.
GET THE MEMBER EDITION
You’re currently receiving the STANDARD edition.
Members help this work continue. If you enjoy the newsletter, the podcast, what I put on YouTube, or any of my open-source projects on Github, I ask you to please become a member. It allows me to stay focused on learning and building and sharing. It’s like a cup of coffee or two per month.
Plus, members get numerous benefits, including:
25-50% off all UL Paid Content, including the upcoming Human 3.0 / AUGMENTED ONLINE portal!
Access to the extraordinary UL Member Community that includes vibrant conversations with ~1,500 of the smartest and kindest people you’ll find on the internet
Member-only Content, such as EDC guides on tech stacks, personal productivity routines, my recommendations on Critical skills to Build Going Forward, Trend Identification and Analysis, and more…
Access to the Member Archive of previous Member-only content, the Book Club archive, etc.
Access to The UL Book Club that’s been going monthly since 2017! One of the highlights of my and many attendees’ month!
Access to the Monthly Member Meet-up where we talk about our routines, productivity workflows, what’s on our minds, etc.
Access to In-Person Events like our dinners in Vegas, San Francisco, etc.
And much more coming…
This is the moment to connect with others who are smart, kind, and asking the same questions we are. Where is this all going? And how do to prepare?
Join the conversation.
