
UPDATES
Hey! Hope you all are doing well!
Doing a bit of holiday, but so many stories to cover! This one’s stacked.
—
Welp, this would be big…
Read the whole thread (HT my homie Matt Johansen!):
—
I created a new way to measure work done with AI called Deeds.
The hypothesis is that PRs are no longer the best way to measure output because so much work is now being done by individual developers. Plus, PRs are basically collaborative code changes, but they don’t necessarily correspond to actual improvements.
This thing actually works! And it uses Jev so it only takes seconds to run against a repo!
—
One of the biggest thing happening in AI right now is everyone figuring out that you can just reverse engineer most things!
And here’s a #1 trending repo for how to do it:
—
How would we know if a government got ASI I wrote this to ask how we'd detect ASI if China or the US got access first. @DANIELMIESSLER POST
—
I built a skill that turns my talk’s Markdown into Keynote decks I feed it my manually written talk, then it uses my art style and my presentation style guide to build the full deck. Including gathering supporting images, creating animations, everything. The output is a finished Keynote. Completely nuts. THE VIDEO
(and yes, it’s coming in the next release, sorry it’s late; major upgrades on this one)
—
Our AI Agents Should Pay the People Who Help Them I want my agent to automatically pay creators whose work helps me. MY BLOG POST
—
This is one of the reasons that, while I’m worried about the journey to get there, I’m ultimately VERY optimistic about what happens if we can land it safely.
—
Love this article: Ethan Mollick realized AI agents may coordinate effectively without the careful management structures he expected. 3 QUARKS DAILY ARTICLE
Sponsor
How to stop losing analysts to alert fatigue
If your SOC is buried under thousands of daily alerts, you already know the real cost is bigger than missed threats. It's burned-out analysts walking out the door. Read why throwing more headcount at the problem doesn't work, and why real social engineering defense requires more than triage.
You'll learn:
Why the math of manual triage will always lose to AI-generated attacks
How the "swivel-chair" investigation process is costing you hours per alert
How Doppel automates triage and takedown so your team can focus on real threats instead of noise
Tired of trading burnout for backlog? This is worth 10 minutes of your time.
🎯 Here are ten agentic-building videos I’ve recently enjoyed and benefitted from:
Goodbye Slop; Welcome Determinism, by David Khourshid (Stately/XState) at Agent Conf 2026
https://www.youtube.com/watch?v=1rMgw0Q5MgY
Khourshid argues for a deterministic core with the model pushed out to the edges, and for traces on every run so you can see
exactly where a workflow breaks. It's the clearest case I've seen for keeping control flow in code and using the model only where
you need judgment.Claude Code's Bitter Lesson: Prompts, Harnesses, Mods, and Agents, with Thariq Shihipar (Anthropic) on Latent Space
https://www.youtube.com/watch?v=IZAlq-V19U8
Thariq treats Claude Code as a harness that keeps changing as the models change. He covers instructions that drift between models,
skill evals, mods, and several agents working in the same software. If you're building your own harness, this is the view from
the team building the reference one.Poteto on shipping thousands of PRs a month at SpaceX, a Matt Pocock livestream
https://youtu.be/MN9dGgmLyso
Poteto, who created pstack, explains how agent workflows produce that many PRs in a heavily constrained environment. He also
covers how they verify the output so it's safe to merge. Watch it for the verification practices.Learning the Bitter Lesson of Agent Harnesses, by Le Duc Anh Tuan
https://www.youtube.com/watch?v=smBOBYZ3-5w
A lot of harness code, like tool wrappers, context management and orchestration, exists only because today's models are limited,
and it becomes debt as they improve. This seminar walks through moving from a LangGraph-heavy design to a small agent kernel with
plugins. That's the same direction Claude Code and Codex went.So I Was Using Fable Wrong, by Theo
https://youtu.be/-XWSJM-Ue-o
This is Theo's practical list for getting long-running coding agents to actually finish. He defines explicit end states, has other
agents verify the work, runs subagents in parallel, watches PRs through to merge, manages compaction, and drops old config
workarounds. Most of it matches where I've landed in my own setup.Stop Pretending You Understand Your Codebase, by Theo
https://youtu.be/5KvY8CnBB3w
Theo argues you don't need to fully understand a large or AI-generated codebase to work in it well. You need architectural
intuition, local reasoning, and tools that track the details for you. That matters more as agents write more of the code.Noam Brown on agent swarms and recursive self-improvement, on Dwarkesh Patel's show
https://youtu.be/6AgOfiZOWiY
OpenAI's Noam Brown covers scaling multi-agent systems, test-time compute, coordination that emerges between agents, recursive
self-improvement, and the alignment risks that come with all of it. This is the research-side view of where agent swarms are
heading.Noam Brown on agent swarms and recursive self-improvement, on Dwarkesh Patel's show
https://youtu.be/6AgOfiZOWiY
OpenAI's Noam Brown covers scaling multi-agent systems, test-time compute, coordination that emerges between agents, recursive
self-improvement, and the alignment risks that come with all of it. This is the research-side view of where agent swarms are
heading.
CYBERSECURITY
Google Has Shut Down Part of its Open Source Bounty Program Google has temporarily closed product vulnerability reports in its open-source bounty program, including bugs in Flutter, Angular, Go, and Fuchsia.
AI-generated submissions flooded engineers with hallucinated findings and harmless coding complaints, so only supply-chain reports still qualify under the updated rules. Google plans another update in Q1 2027. ITS FOSS ARTICLE
ESXi Exploitation in the Wild Huntress found attackers using a compromised SonicWall VPN to reach a domain controller and deploy an ESXi escape toolkit. The toolkit chained three VMware flaws to move from a guest VM into the hypervisor kernel. It supported 155 ESXi builds and installed a VSOCK backdoor that network defenses couldn’t see. HUNTRESS ARTICLE
Top threat intelligence feeds in 2026 CVE databases often miss malicious packages until after they spread. Aikido compares five feeds by detection speed, ecosystem coverage, and whether they can block installs. AIKIDO ARTICLE
Is sandboxing sufficient to contain rogue agents Sandboxed agents can pass hidden instructions through shared caches, email, or Slack, creating an AI worm. SIMON WILLISON POST
Sponsor
We classified all the data. Now what?
That is what one CISO asked ORION Security after a big data discovery and labeling project. Not only that, but we heard from 159 CISOs this summer and data visibility topped their wish list.
Visibility of data at rest is one thing. To see where it’s going when it starts to move is an entirely new challenge.
Read what's working for these CISOs, from continuous discovery to classifying data the moment it moves.
CVE-2026-21589 Exploited in the Wild Attackers are already using a critical Atlassian bug to read files without logging in. A public Nuclei template and nearly 700,000 exposed Confluence instances make patching self-managed servers urgent. SECURITYONLINE ARTICLE
ShinyHunters Extorted Boeing Spin-off Prior to Arrests A teenage suspect allegedly led ShinyHunters while extorting Boeing’s former aviation unit before Jordanian authorities detained him. KREBS ON SECURITY ARTICLE
NATIONAL SECURITY
How drone warfare is rewriting the economics of infrastructure I keep thinking about this. Cheap drones are turning America’s biggest infrastructure advantage into a possible weakness. Large refineries and data centers create valuable single targets that can cost under $50,000 to attack. Stein says companies should compare centralized efficiency with the repair and shutdown costs of one successful strike. FORTUNE ARTICLE
Poland Drafts ‘Pre-War’ Readiness Law to Speed Up Allied Troop Deployment Poland wants a legal phase between peacetime and martial law, so troops can move sooner during a crisis. The plan also connects Poland’s defense system with NATO’s and covers cyberattacks and disinformation. KYIV POST ARTICLE
NATO Drones: Swarm or Be Swarmed Ukraine is using coordinated drone systems in combat, while NATO still treats autonomy as a future capability. Swarmer says its software has supported over 100,000 missions since April 2024. CEPA ARTICLE
AI
Karpathy says AI outputs will move from text to custom media Andrej Karpathy says language models should explain ideas in whatever format makes them easiest to understand. He recommends controlled writing with ASD-STE100, then diagrams or interactive HTML pages. He’s most excited about custom explainer videos that models can generate for any topic. Very much what I talked about with Custom Content in July of 2024.
This is one of the most disruptive pieces of AI I can think of. How many services rely on the human interacting with them directly? Sooooo many.
Oh wait, this was also in the book as a major pillar; almost forgot.
"Software businesses started as unified experiences: you go to them for the display of the product, you stay with them as you interface with their offerings, and then you use them to pay.
These will soon be separated into discreet pieces. Companies who make things will not be experts in displaying that content to humans. Companies that are experts in UI/UX will not focus on creating content or products."

From TRIOT
This is a whole different world when your agents consume an API and make you your own interface. So many companies are going to have to adjust to this.
Slow is beautiful: China launches war against AI drama, goes beyond algorithms China released 430,000 microdramas in eight months, with AI behind over 90% of new releases. SCMP ARTICLE
AI can’t fix a business system with broken processes Most companies use AI, but only 7% have scaled it across the business. Dessy Pavlova says the fix is redesigning the whole workflow first, then letting one human decision update systems automatically with stopgates. A study of 5,179 support agents found productivity rose 14%, while people still needed to understand the work.
Very much in line with this I put out a while ago:
HOW DO I KNOW IF AN AI EXPLANATION IS CORRECT Clear wording can hide a wrong definition or missing condition. Check the source, then explain it yourself. PERPLEXITY AI MAGAZINE ARTICLE
TECHNOLOGY
Advice to a beginning software engineer Sean Goedecke thinks junior engineers should stay useful, friendly, and politically cautious. Use AI, but keep your own judgment instead of becoming a “meat proxy” for Claude or GPT-6. SEAN GOEDECKE ESSAY
Explain your company using verbs instead of nouns YC taught Eli Mernit that concrete verbs make pitches understandable when abstract labels leave people confused. @MERNIT POST
The agentic CLI for the entire Cloudflare API Cloudflare launched cf, a CLI that lets agents search and use more than 3,000 API operations. It defaults to JSON, uses natural-language command search, and stores typed settings in cloudflare.config.ts. Agents already made up 48% of Wrangler usage last week. CLOUDFLARE ARTICLE
Shipping is the foundation Being able to ship is the basic engineering skill everything else depends on, says Sean Goedecke. AI can help write code, but it can't handle the company context and coordination needed to finish work without more guidance from humans. SEAN GOEDECKE ESSAY
Detect and send production issues straight to your agent Cloudflare’s new Issues feature groups repeated Worker failures and sends their diagnostic context to a coding agent. It needs one configuration line and no SDK or wrapper. The team found and fixed two hidden Workflows bugs within one day. CLOUDFLARE ARTICLE
AI Can Build Anything. Learn What Not to Ship Yogi says teams should build systems for testing ideas, rather than hand every idea to engineering. His three-part model uses shipping, safeguards, and experiments to test features on real users before scaling them. YOGI POST
HUMANS
China has cracked down on AI relationships China now limits AI companions that create sustained emotional bonds, with children facing the toughest rules. Adults must get reminders every two hours and clear warnings that the chatbot isn't human. The crackdown follows research linking these apps to loneliness and emotional manipulation during 37% to 43% of goodbyes.
Amazing to see China protecting their people like this. Wen Merica? BBC ARTICLE
Why I didn't write The writer says writing felt pointless until discovering Inkhaven gave them a reason to begin. They worried about being boring, rejected, or exposing too much of their private life. Now writing feels like meditation and a way to practice starting difficult work. LESSWRONG POST
LASIK Alternative Promises to Improve Vision Without Scalpel or Lasers Researchers reshaped isolated rabbit corneas in about a minute using an electrically controlled platinum mold. All 10 eyes reached the intended nearsightedness correction, but human safety remains unknown. SCIENCEALERT ARTICLE
College Is Not One Thing I break college into separate parts because AI may replace lectures while preserving friendships, conflict, and exceptional teachers. MY BLOG POST
Fast learners are becoming more valuable than experienced workers People who learn quickly can now outpace experienced workers when tools and expectations change fast. Welsh says adaptability may matter more than years on the job. @THEJUSTINWELSH POST
What the College Preparedness Debate Misses The usual story says college students are getting worse, especially because of AI and weak basic skills. The author says averages hide a sharper split between struggling students and unusually advanced ones. More bifurcation, basically. GREY ENLIGHTENMENT ARTICLE
IDEAS
Every small choice adds to the life you're building The speaker says every daily choice adds either credit or debt to your life. Reading, training, and sleeping early move the ledger forward, while wasted time pulls it back. Jerry MMXM shares the seven-month morning video as a reminder that nothing stays neutral. @JERRY MMXM POST
How I Think About Meaning Meaning comes from memorable shared experiences, constraints, rituals, and growth, says Daniel Frank in a practical guide to manufacturing it. NOT NOT TALMUD ESSAY
How to change your identity You can make habits easier by treating them as part of who you are. KatSpartz says the change sticks when you reinforce the new identity and stop feeding the old one. LESSWRONG ARTICLE
Compression progress may explain beauty, curiosity, and creativity Compression progress may explain why novelty feels beautiful, and hardmaru points to Schmidhuber’s 2009 formal theory. @HARDMARU POST
Smurfette principle One woman surrounded by male characters often becomes the story’s symbol for all women. Katha Pollitt coined the term in 1991, and examples still appear across major film and television franchises. WIKIPEDIA ARTICLE
‘There’s no such thing as democracy’ Yanis Varoufakis discusses who really controls economic policy: voters or markets. GUARDIAN VIDEO
The Face Grows Into the Mask Dan Williams says our values become sincere adaptations to whatever earns status, approval, and resources in our local world. CONSPICUOUS COGNITION ESSAY
DISCOVERY
James Baldwin’s Advice on Writing Baldwin says talent matters less than endurance, and writing helps you discover what you didn’t know. He also calls rewriting painful but necessary for making sentences clean. THE MARGINALIAN ARTICLE
The Rise of the Non-Celebrity Celebrity The internet now creates fanbases around ordinary people with no obvious product or talent. Katherine Dee uses Clavicular to show how someone can become famous before the public understands why. REASON ARTICLE
Spawn: Your Place to Make Games with Friends Spawn lets you build multiplayer games by talking with Savi, then invite friends into the same browser world. SPAWN PLATFORM
DoorDash lets you order food by texting an AI agent DoorDash now lets you text an AI agent to reorder meals, coordinate group orders, and shop for missing ingredients. It’s rad; I love it. Especially when your agent is available via Messages or WhatsApp or whatever. @ANDYFANG POST
Unix File and Directory Permissions and Modes Unix permissions control files through owner, group, and other access bits. Wayne Pollock shows why directory execute permission means search, and how SUID and ACLs change the picture. WAYNE POLLOCK ARTICLE
Writing forces your brain to discover what you really think Writing gets harder when you force vague beliefs into clear sentences. Danny Kenny shows how counterarguments expose gaps, then recommends five-minute journaling and Feynman-style explanations. BIG THINK ARTICLE
RECOMMENDATION OF THE WEEK
Every small choice adds to the life you're building
Absolutely love this: everything you do either helps or hurts. Reading, training, and sleeping early move the ledger forward, while wasted time pulls it back. Jerry MMXM shares the seven-month morning video as a reminder that nothing stays neutral. @JERRY MMXM POST
APHORISM OF THE WEEK
How we spend our days is, of course, how we spend our lives.
GET THE MEMBER EDITION
You’re currently receiving the STANDARD edition.
Members help this work continue. If you enjoy the newsletter, the podcast, what I put on YouTube, or any of my open-source projects on Github, I ask you to please become a member. It allows me to stay focused on learning and building and sharing. It’s like a cup of coffee or two per month.
Plus, members get numerous benefits, including:
25-50% off all UL Paid Content, including the upcoming Human 3.0 / AUGMENTED ONLINE portal!
Access to the extraordinary UL Member Community that includes vibrant conversations with ~1,500 of the smartest and kindest people you’ll find on the internet
Member-only Content, such as EDC guides on tech stacks, personal productivity routines, my recommendations on Critical skills to Build Going Forward, Trend Identification and Analysis, and more…
Access to the Member Archive of previous Member-only content, the Book Club archive, etc.
Access to The UL Book Club that’s been going monthly since 2017! One of the highlights of my and many attendees’ month!
Access to the Monthly Member Meet-up where we talk about our routines, productivity workflows, what’s on our minds, etc.
Access to In-Person Events like our dinners in Vegas, San Francisco, etc.
And much more coming…
This is the moment to connect with others who are smart, kind, and asking the same questions we are. Where is this all going? And how do to prepare?
Join the conversation.



