
UPDATES
Hey! Hope you all are doing well!
BTW: Newsletter was ready Sunday, but was waiting on a particular thing down below!
—

I love this “do a vulnerability” poke-with-stick meme. 😀
—
Incredibly enthused to announce PAI 5.0!
Too many changes to name, but here are the big ones:
PAI is now more of a Life OS than an AI harness. We humans at the center!
The focus is on you and your work, and even less on “coding”
The coding stuff is still there, and better than ever, but as a function to server you and your goals
Massively updated Algorithm system, including a migration from PRD → ISA (Ideal State Artifact) Yuge.
Released like DOUBLE the skills this time!
So so much more…
—
The idea that’s blowing my mind the most right now. TYPE ALL THE THINGS:
Follow up here about human adjustment to this.
—
I’ve noticed recently that I now have tons of cybersecurity stories again, when there haven’t been so many in recent years. And I’m not just posting tons of Mythos stories. Something else is amiss.
—
The inability to articulate ideal state.

A fascinating observation, and precisely why I’m focusing all my efforts (AI and analog) on transitioning from current to ideal state. Which requires that you can articulate that ideal state.
Across my career, the inability to do this has caused more issues than anything else.
Forget AI, this is a massive human problem. AI just makes it more obvious.
—
The craziest conversation I’ve ever had with AI. Pretty much solved everything with one go here. : ) This was Claude, not Kai, btw. Voice mode in the Claude app.
Sponsor
Worried about supply chain attacks?
Trivy. LiteLLM. Telnyx. Axios. Millions of downloads, thousands of GitHub stars, all compromised. 2026 has already been a brutal year for open source security. In every case, attackers exploited the same two vectors: malicious packages without verifiable source code and install-time scripts that execute as soon as a dependency lands in your build.
Chainguard Libraries eliminates both by design. Every Python, Java, and JavaScript package is rebuilt from verified source in an isolated build environment. If we can't verify the source, it never appears in the Chainguard Repository. We also avoid building any library that uses an install-time script.
This makes every Chainguard-built library malware-resistant before it reaches your engineers. Free for all console users until June 30, 2026.
CYBERSECURITY
Copy Fail lets 732-byte exploit give Linux systems root This Linux kernel bug lets unprivileged users become root across many distros, reliably and with portable code.
Copy Fail (CVE-2026-31431) turns local users into root
A 732-byte Python script works on multiple distros
It abuses AF_ALG and splice() to write into page cache
The bug is an authencesn crypto logic flaw plus out-of-bounds scratch write
Patch or mitigate by disabling algif_aead and AF_ALG access
US accuses China of industrial-scale AI model theft via distillation The Trump administration says China-backed actors are using deliberate campaigns to distill and copy U.S. frontier AI models, which could escalate the rivalry ahead of a Beijing visit.
The U.S. claims China-backed actors are distilling and copying frontier AI models.
This is framed as deliberate, industrial-scale theft rather than casual competition.
The accusation intensifies the U.S.-China AI fight into a more confrontational phase.
Bitwarden CLI got trojanized via an npm publish-chain attack SafeDep says the malicious @bitwarden/[email protected] release swapped the real entrypoint for a loader, stole lots of developer and CI secrets, then tried GitHub-based fallbacks. SAFEDEP MALWARE ANALYSIS
Google’s sweep finds indirect prompt injection is real but still sloppy Google teams scanned Common Crawl for indirect prompt injection patterns and ran Gemini classification plus human checks, finding mostly benign experiments but rising malicious activity. GOOGLE SECURITY BLOG ARTICLE
fast16 shows sabotage code existed years before Stuxnet My buddy Gabe’s team, SentinelLABS, finds a previously undocumented framework (“fast16”) from 2005 that uses a Lua-powered worm carrier plus a precision filesystem driver to patch code-in-memory and skew high-end scientific calculations. SENTINELONE LABS ARTICLE
Fast16 was a stealth malware sabotage blueprint before Stuxnet SentinelOne researchers analyze fast16, a 2005-era carrier that used Lua, spread via weak shares, and quietly corrupted nuclear/simulation math. HACKINGPASSION FAST16 POST | MY BUDDY GABES’ TEAMS’ RESEARCH ON FAST16
Weaponized deepfakes are getting easier, and harder to stop Eileen Guo explains how cheap AI image and video tools now create realistic fakes used for sex crimes, scams, and political manipulation. MIT TECHNOLOGY REVIEW ARTICLE
Sponsor
Supply Chain Compromise?
Know If You’re Exposed in Minutes.
A vendor gets breached. A critical library is compromised. A zero-day drops in software your subsidiaries depend on. Mallory correlates the event against your assets, your third-party vendors, and your full attack surface, then tells you exactly where you're exposed and what to do next.
Cloud. Code. Hosts. Subsidiaries. One platform watching it all.
Vercel says hackers stole some customers’ data first Vercel now says it found evidence of a smaller set of customers being compromised before its April breach. It still won’t say how many accounts or how far back the second intrusion goes, but it points to malware stealing keys. TECHCRUNCH ARTICLE
Why you should refuse AI scribing for doctor notes An argument that AI “scribing” systems turn medical visits into recorded data flows, and that patients and providers should refuse consent. MYSTERY AI HYPE THEATER 3000 NEWSLETTER
OpenAI released a local privacy filter for sensitive text OpenAI put out an open-source Privacy Filter model that labels and redacts personal data before other processing. It runs locally, supports long documents, and needs human review for high-stakes cases. THE DECODER ARTICLE
China uses Taiwanese critics as a believable info weapon DEFENSE NEWS REUTERS ARTICLE
China-linked Go backdoor set hits Mongolian government systems THE HACKER NEWS MALWARE REPORT
SIM farm as a service exposes dozens of control panels This write-up explains how ProxySmart powers a large SIM-farm mobile-proxy network, exposing 87 control panels across 17 countries and enabling OTP fraud. CYBERSECURITYNEWS ARTICLE
Mozilla says Mythos AI found hundreds of Firefox bugs, but said humans could have too THE REGISTER ARTICLE
NATIONAL SECURITY
China’s PLA drills increasingly rehearse seizing Taiwan in detail China’s PLA amphibious drills near Taiwan now look more like a real invasion rehearsal, using geographically matched sites, multiple landings, and risky coastal conditions. The article ties that to Pentagon worry about thinner U.S. missile and interceptor stocks. THE MARITIME EXECUTIVE ARTICLE
The shadow fleet is getting bolder and harder to stop This report explains how “shadow” ships evade sanctions, while Baltic and other coastal states respond with inspections, detentions, and escorts that blur legal lines. ATLANTIC COUNCIL REPORT
Dutch intelligence says China has matched US offensive cyber power THE RECORD
Pentagon asks for $54bn to accelerate AI drone warfare The Pentagon wants a huge jump in funding for autonomous drone warfare, driven by a new Defense Autonomous Warfare Group. THE GUARDIAN ARTICLE
US special forces insider trading case hits Polymarket over Maduro raid The DOJ says a US Special Forces master sergeant used classified info about Maduro’s capture to make over $400,000 trading on Polymarket. WIRED STORY
Ukraine is squeezing Russia by hitting oil exports and air defense Al Jazeera reports Russian oil revenues are dropping as Ukrainian strikes disrupt ports, refineries, and transshipment. AL JAZEERA FEATURES
China quietly stops saying “military-civil fusion” while still pursuing it The author checks China’s 15th Five-Year Plan outline and finds no explicit “military-civil fusion” language, then argues China kept the program via less obvious institutions and documents. THE DIPLOMAT FEATURE
AI
Google renames Vertex AI and rolls everything into agents Google used Cloud Next 2026 to rename Vertex AI as the Gemini Enterprise Agent Platform. It also unifies Agentspace, launches Studio and Mariner, and pushes A2A production agent-to-agent protocols.
How to Stop Claude Code from Leaking Sensitive Data SECURE TRAJECTORIES BY SONDERA
The AI pricing battle is squeezing the middle tier I very much agree with this analysis. This is unfortunately the direction that it's currently heading right now, with a lot of people having basic access to basic AI and then very few extreme power users and people that are somewhat in the middle. It's basically becoming harder to be one of those middle people due to cost and other factors. THE NEW STACK ARTICLE
OpenAI’s new clinician ChatGPT beats doctors in a benchmark THE DECODER ARTICLE
DeepSeek shipped V4 preview with 1M context DeepSeek’s V4 preview is live, open-weights are available, and the API now supports two V4 models with long context and agent-friendly upgrades. Lots of talk about how good this one is, but haven’t tried it yet. DEEPSEEK NEWS PAGE
TECHNOLOGY
Tesla will start Optimus V3 robot production in late 2026 Musk says Fremont will begin Optimus production in late July or August, but he won’t promise output volume and expects slow ramp. They also push Gen 3 reveal to later this year. ELECTREK ARTICLE
Meta lays off 8,000 workers to push AI efficiency AXIOS ARTICLE
Also, Meta will track keystrokes to train AI agents, with no opt-out They plan to install tracking software on work laptops to capture keystrokes, clicks, mouse movements, and screenshots for AI training. Workers reportedly say there’s no opt out, and privacy experts call it invasive. CNET PRIVACY ARTICLE
Google backs Anthropic with up to $40B for compute INTERESTINGENGINEERING ARTICLE
GPT-Image-2 turns image prompts into real reasoning and verification OpenAI’s GPT-Image-2 plans first, checks itself, and even searches while generating. This is really cool tech where the image generation itself has it’s own intelligence. NATE B. JONES
Framework Laptop 13 Pro upgrades chassis, battery, display, and Linux This Laptop 13 Pro redesign fixes prior complaints with a stiffer aluminum body, a bigger 74Wh battery, and a new custom 13-inch IPS screen. It also adds haptic clicks and LPCAMM2 upgradable RAM, while selling with Ubuntu pre-installed. BOILING STEAM ARTICLE
HUMANS
Extraordinary commentary on San Francisco. Largely agree with the analysis. THREAD
MIT is asking whether AI becomes a real co-scientist MIT Technology Review lays out how “artificial scientists” are already drafting research plans, running experiments via robots, and influencing what gets studied. It also warns that AI could shrink scientific diversity if it steers researchers toward topics with big existing datasets. MIT TECHNOLOGY REVIEW SCIENCE AI
Desire to migrate drops as the US becomes less appealing Gallup reports that fewer adults worldwide want to permanently move, and the US share falls from 24% to 15%. GALLUP MIGRATION POLL ARTICLE
FBI: Americans Lost More Than $20 billion to Fraud Last Year KNOWBE4 BLOG
Why birds survived the asteroid that killed dinosaurs SCIENTIFIC AMERICAN FEATURE
IDEAS
Services are the new software, and outcomes win Julien Bek arguing AI-native startups will sell delivered outcomes instead of AI products, using intelligence-heavy “autopilot” workflows. FORTUNE EYE ON AI ARTICLE
How he learns to live with his no-self HOW TO SAVE THE WORLD ESSAY
If You Stop Hiring Juniors, Your Senior Engineers Own You This is something I have not thought about, and I think it's a great point. EVALUECODE BLOG ARTICLE
Creativity grows by connection, not separation in M.C. Richards In this Marginalian piece, the author revisits M.C. Richards’ 1971 talk. She argues creativity comes from “force” and “flower,” from the heart, and from resonance between ideas and people, spanning art and science. THEMARGINALIAN CONNECTIONS ESSAY
The world isn’t a database, so stop forcing automation Ben Werdmuller argues Nilay Patel is right: “software brain” tries to flatten lived experience into centralized, controllable data for AI to run. It devalues humans, labor, and the messy friction of being human, even if tools are helpful. I think it's possible to blend both AI and humanity quite easily, and I'm actively trying to do so, but I include this as a counterpoint and something to think about. WERD ARTICLE
Agents are turning office work into “assembly lines” This MIT Tech Review piece explains why agent orchestration matters so much now. It shows multi-agent coding and productivity tools coordinating work and what it will look like in companies going forward. MIT TECHNOLOGY REVIEW ARTICLE
DISCOVERY
🔥 I read this when it came out (early 90s?), and I feel like it honestly activated my curiosity and turned me into a reader. WIRED ESSAY
AI should elevate engineers’ thinking, not replace it AI LEVERAGE VS IMITATION
Short stories feel slower because long stories must rush This argues that long plots rely on frequent dynamic scenes to keep attention, while short stories can afford slow, detailed prose and still feel complete. LESSWRONG ARTICLE
How-to Stand Out When Everyone Uses AI THE ALGORITHMIC BRIDGE GUIDE
I Have ADHD. My AI Agent Is the Best and Worst Thing for It. DIGITAL THOUGHTS
How empathy became a creative superpower through Rilke THE MARGINALIAN ESSAY
RECOMMENDATION OF THE WEEK
If you’ve not used PAI yet, now is a fantastic time to do so.
It’s now much easier to install and functionality has been massively improved.
APHORISM OF THE WEEK
In times of change, learners inherit the earth, while the learned find themselves beautifully equipped to deal with a world that no longer exists.
GET THE MEMBER EDITION
You’re currently receiving the STANDARD edition.
Members help this work continue. If you enjoy the newsletter, the podcast, what I put on YouTube, or any of my open-source projects on Github, I ask you to please become a member. It allows me to stay focused on learning and building and sharing. It’s like a cup of coffee or two per month.
Plus, members get numerous benefits, including:
25-50% off all UL Paid Content, including the upcoming Human 3.0 / AUGMENTED ONLINE portal!
Access to the extraordinary UL Member Community that includes vibrant conversations with ~1,500 of the smartest and kindest people you’ll find on the internet
Member-only Content, such as EDC guides on tech stacks, personal productivity routines, my recommendations on Critical skills to Build Going Forward, Trend Identification and Analysis, and more…
Access to the Member Archive of previous Member-only content, the Book Club archive, etc.
Access to The UL Book Club that’s been going monthly since 2017! One of the highlights of my and many attendees’ month!
Access to the Monthly Member Meet-up where we talk about our routines, productivity workflows, what’s on our minds, etc.
Access to In-Person Events like our dinners in Vegas, San Francisco, etc.
And much more coming…
This is the moment to connect with others who are smart, kind, and asking the same questions we are. Where is this all going? And how do to prepare?
Join the conversation.


