
UPDATES
Hey! Hope you all are doing well!
Starting to gear up for Blackhat/DEFCON this year. Eager to see what the vibe is this year given how much AI is impacting everything. I guess I expect the same: the product floor filled with AI this and AI that.
—
I finally selected my replacement for my AI pendant, and holy crap is it better than what I had. I was using the Limitless Pendant, which was way better than what I had before, but the API was jank and they ended up getting bought by Meta (yick). But I kept using it for a while because there were no solid alternatives.
I’ve now settled on Bee Computer, which is an Amazon product. I respect Amazon security quite a bit, so this is a major security/privacy upgrade. The app is far better. Battery is almost a week of use. Just the overall experience, including the hardware, is better across the board.
I like the fact that the button can be configured to auto-disable after certain timeframes, so you don't always just have this open capture going. That is not good for privacy and also eats the battery.
The app is far more professional and configurable.
The API is way faster and better than Limitless’s.
The app is actually halfway decent in terms of features, although I’m not using most of them.
So I now have my life log skill tied to this instead, and it's working ten times better than before. Note: when I recommend something like this, I'm not completely vouching for its security because that's really hard to do with anything, but the fact that it's owned by Amazon gets me a decent amount of confidence.
Bee Computer (no affiliate link, unfortunately)
—
My homie Jason just set the standard for inviting friends to a birthday party. Instead of a regular invite he sends this:

What a supernerd. Love it so much. Thanks for setting the standard. As per usual.
—
CloZee posted her set from The Ruins, which was a phenomenal venue, and a skilled eye can find my friends and I right behind her on the platform. : ) Unbelievable show. Now I can’t wait for Of The Trees to come there!
—
There's a new Kimi K3 model out of China that is roughly equal to Opus and GPT-5.6 Sol. And I think this is a potentially major problem for the U.S. economy.
—
A powerful technique when discussing AI is to replace the word “AI” with the words “thinking” and “doing”. It takes the magic spin off of the word and forces the person to explain what they’re going to actually do with it.
Sponsor
Practical guide to AI adoption for IT
and security teams
There's no shortage of advice about AI.
What's harder to find is practical guidance on how to evaluate AI tools, implement them safely, and ensure they actually improve how your team works.
That’s why Tines recently released the IT and security field guide to AI adoption.
Inside, you'll learn:
Why many AI initiatives struggle after rollout
How to evaluate AI tools beyond the demo
The questions to ask before making a purchase decision
How to keep humans in the loop without slowing work down
Lessons from teams at Jamf, Vimeo, Canva, and Udemy
This is my new go-to answer when people ask me what people should do to get ready for AI.
—
Never forget that the best way to test a new smart AI is within your narrow areas of expertise. The further away from your expertise you go, the smarter the AI will sound, without that necessarily being the case.
—
CYBERSECURITY
Hugging Face breach by an autonomous AI agent Hugging Face got hit through its own data pipeline, and the attacker used a swarm of short-lived sandboxes to steal credentials before defenders rotated secrets and tightened controls. The biggest part of the story is how autonomous AI was used as part of the flow, both for attack and defense. THE HACKER NEWS ARTICLE
Claude security repo for hunting and patching bugs This repo gives you a reference harness for finding vulnerabilities, then triaging and patching them with Claude. It’s more a security workflow than a normal library. ANTHROPICS REPO
Datadog’s ai-native SAST tool leans on LLMs Datadog built a preview-stage code scanner that uses large models to find bugs, then spits out SARIF for your repo. DATADOG REPO
I'm thinking of doing a major Patch Tuesday analysis over the last two years to see how vulnerabilities have changed since AI harnesses have become a significant part of security research. Let me know if you know anyone who's done something similar.
Scrutineer scans repos for security issues and manages disclosure It runs agent skills in a container, triages findings, tracks maintainers, and handles disclosure workflows. ALPHA-OMEGA SECURITY REPO
Visa’s harness turns AI into a vulnerability-finding pipeline Visa built an open-source repo that scans code, models threats, validates exploits, then proposes and checks fixes. It’s meant to cut triage time, not just find more bugs. VISA REPO
Audit runs an 8-stage bug-hunting agent on your code It maps a repo, spins up narrow agents, checks reachability, and turns findings into a structured report. EVILSOCKET REPO
Baby Naptime uses LLMs to hunt bugs and build exploits Baby Naptime is a weekend security tool that points an LLM at code, compiles it with mitigations off, and tries to prove vulns. BABY-NAPTIME REPO
I don’t agree with the conclusion here, but the point being made is quite real.
Apple fixed a macOS terminal prompt-injection trick Johann Rehberger shares a PoC that turns indirect prompt injection into DNS exfiltration on macOS Terminal. Apple already fixed the behavior behind it. JOHANN REHBERGER POST
Two SonicWall bugs are getting used to break into appliances SonicWall says attackers are chaining two zero-days in SMA 1000 boxes. One gets them commands, and then they pull credentials and MFA seeds. THE HACKER NEWS ARTICLE
NATIONAL SECURITY
Russia turned intelligence into a criminal marketplace Michael Weiss says the GRU now runs like a market, hiring criminals, freelancers, and shell companies for sabotage. MICHAEL WEISS POST
China is sabotaging the world that made its rise possible Beijing keeps undercutting the open system that helped lift it, and that gamble may blow back hard. FOREIGN AFFAIRS ARTICLE
AI
Expect this to become normal. This is exactly the bifurcation model that I've been talking about here:
Moonshot AI just dropped a giant open model Moonshot AI released Kimi K3, a 2.8-trillion-parameter model that’s suddenly close to the best closed systems. lots of people have been predicting that this would happen within the next few months or next year, but it looks like it has happened already. Because they're posting many or all of their techniques, we can expect the pace of improvement to accelerate. VENTUREBEAT ARTICLE
I write here about why and how I think this is a major threat to the U.S. economy.
Greenlight is a refusal-handling skill for security evals It maps where Claude refusals happen, then shows how retries, prompt tweaks, and timing change the results. GADIEVRON REPO
Fable just solved a significant math problem that has been unsolvable by humans for around a hundred years. Terrance Tao was right: AI’s impact on math is accelerating.
TECHNOLOGY
One of the most interesting things happening in tech is that you can now have AI build you custom drivers for hardware. this is also really cool for reverse engineers and security researchers because they can very quickly learn a lot about the hardware itself and how it works by writing custom drivers and interacting with the hardware directly.
Siri is finally getting good: MKBHD’S VIDEO
You don’t have a deployment problem, you have a validation problem AI agents are making release batches bigger, and the real bottleneck is trusting one change in a live system. THE NEW STACK ARTICLE
Alex Toussaint says a micro-drone just killed a moth midair He says this is a step toward wiping out mosquitoes, but the real signal is how small and specific the drone can get. ALEX TOUSSAINT POST
Your brand is getting filtered by AI now AI systems are choosing brands from web signals, not ad spend. Neil Barrie says coherence, currency, authority, and advocacy are the four levers. FAST COMPANY ARTICLE
HUMANS
My buddy Joseph Thacker built a Rez0’s rascals bundles K-5 homeschool into one AI coach This puts the whole school day in one app, with mastery-based lessons and a Socratic coach that won’t hand kids the answer. REZ0'S RASCALS PRODUCT PAGE
—
A book that can’t talk back feels dated Pedro Domingos says books that don’t answer you will start to feel weird fast. PEDRO DOMINGOS POST
DISCOVERY
Spacer adds a blank line when output goes quiet It’s a tiny CLI that watches command output and drops in spacers after silence. That’s handy when you’re tailing logs and need to see where one request ends and the next starts. SAMWHO REPO
On reading systems with Bram Adams Bram Adams talks about reading like a system, and he rattles through the books shaping that view. BRAM ADAMS NEWSLETTER
Love is the only thing that fills the void Naval says everything else feels empty without it. NAVAL X POST
Tobi Lutke says most human code is worse than people think He says anti-AI people overrate human code, and opus-level models can beat most of it fast. TOBI LUTKE POST
RECOMMENDATION OF THE WEEK
I'm not completely sold on this, but there's a possibility that expertise in general and knowledge work specifically will be a whole lot less valuable in the next two to five years. In an AGI/ASI world even content creation could go away for most people.
One recommendation that flows from this is that you need to think about what assets you hold that will have value if and when this happens. In other words, what do you own?
I'm not an expert on this type of thing, and I'm sure you can ask your AI to help you with thinking through this. Think of things like houses, real estate, stocks (although that could be problematic, obviously), and other things that will hopefully have value in the future.
Something to think about.
APHORISM OF THE WEEK
There are two ways of constructing a software design: One way is to make it so simple that there are obviously no deficiencies, and the other way is to make it so complicated that there are no obvious deficiencies.
GET THE MEMBER EDITION
You’re currently receiving the STANDARD edition.
Members help this work continue. If you enjoy the newsletter, the podcast, what I put on YouTube, or any of my open-source projects on Github, I ask you to please become a member. It allows me to stay focused on learning and building and sharing. It’s like a cup of coffee or two per month.
Plus, members get numerous benefits, including:
25-50% off all UL Paid Content, including the upcoming Human 3.0 / AUGMENTED ONLINE portal!
Access to the extraordinary UL Member Community that includes vibrant conversations with ~1,500 of the smartest and kindest people you’ll find on the internet
Member-only Content, such as EDC guides on tech stacks, personal productivity routines, my recommendations on Critical skills to Build Going Forward, Trend Identification and Analysis, and more…
Access to the Member Archive of previous Member-only content, the Book Club archive, etc.
Access to The UL Book Club that’s been going monthly since 2017! One of the highlights of my and many attendees’ month!
Access to the Monthly Member Meet-up where we talk about our routines, productivity workflows, what’s on our minds, etc.
Access to In-Person Events like our dinners in Vegas, San Francisco, etc.
And much more coming…
This is the moment to connect with others who are smart, kind, and asking the same questions we are. Where is this all going? And how do to prepare?
Join the conversation.


