groundy

all articles

  1. apr 28 policy Citizen Lab Names Three Telcos as Persistent Entry Points for Commercial SS7 Surveillance Vendors
  2. apr 28 devtools Claude Code vs Cursor vs Copilot After the April 2026 Reshuffle: How the Comparison Math Changed
  3. apr 28 agents Council Mode Cuts Multi-Agent LLM Hallucination 35.9% at 4.2x Token Cost on HaluEval
  4. apr 28 infra Crawshaw's 'I Am Building a Cloud': What a Tailscale Co-Founder's Solo Stack Implies for Platform Teams
  5. apr 28 agents CrewAI 1.14.2 Lands Checkpoint TUI with Tree View, Fork Support, and Lineage Tracking
  6. apr 28 culture Google Ignores California's Global Privacy Control 86% of the Time: webXray's 7,000-Site Audit
  7. apr 28 security InstructLab CVE-2026-6859: Hardcoded trust_remote_code=True Turns Any HuggingFace Model Into RCE
  8. apr 28 devtools LangGraph 1.1.10's ToolNode Now Accepts list[Command | ToolMessage]: How That Splits From Pydantic AI
  9. apr 28 agents LLM Agent for Iterative Chart Refinement Exposes a Logging Gap in CrewAI and AutoGen (see also logging gap in CrewAI)
  10. apr 28 security LMDeploy CVE-2026-33626: Vision-LLM SSRF Exploited Within 12 Hours of GHSA (see also SSRF exploited) Publication
  11. apr 28 culture Mercor Breach: 4TB of AI Trainer Voice Samples Stolen from 40,000 Contractors
  12. apr 28 security Mercor's 4TB Lapsus$ Breach Hands Voice-Clone Attackers 40,000 Pre-Verified Targets
  13. apr 28 security Paperclip CVE-2026-41208: Agents Can Mutate Their Own provisionCommand Into Server-Side Shell Injection
  14. apr 28 oss pgBackRest Is No Longer Maintained: PostgreSQL Backup Alternatives After the Project Stalls
  15. apr 28 security PickleScan 1.0.4 Patches a CVSS 10.0 pkgutil.resolve_name Bypass and Six Missing Stdlib RCE Modules
  16. apr 28 devtools Pydantic AI v1.87 Closes the LangGraph Gap: Deferred Tool Calls, OpenTelemetry Eval, Stateful Compaction
  17. apr 28 agents Salesforce TDX 2026: Headless 360 Ships 60+ MCP Tools and Agentforce Vibes 2.0 With Claude Sonnet 4.5
  18. apr 28 industry Six Weeks After the $32B Close, Wiz Expands Coverage to AWS, Azure, and Salesforce Agents
  19. apr 28 security Spring AI 1.0.6 Patches Five CVEs Including CVSS 8.8 SQL Injection in CosmosDBVectorStore.doDelete
  20. apr 28 security Windsurf CVE-2026-30615 Is the Only Zero-Click in the April MCP RCE Wave: HTML Rewrites the Config
  21. apr 27 industry America's 150 GW Geothermal Estimate Reprices AI Data Center Power Procurement
  22. apr 27 industry Anthropic Ends Flat-Fee Enterprise Claude Above 150 Seats and Forces Per-Token Billing on AI Procurement (see also per-token billing)
  23. apr 27 security Bitwarden CLI Compromise Extends the Checkmarx Supply-Chain Campaign to Credential Tooling
  24. apr 27 oss free-claude-code Routes Claude Code Through NVIDIA NIM and Local Models After Anthropic's CLI Ban
  25. apr 27 devtools GitHub Copilot Replaces Premium Request Units With Token-Metered AI Credits on June 1
  26. apr 27 industry Microsoft and OpenAI End Their Exclusive Revenue-Sharing Deal: What It Means for Azure's AI Moat
  27. apr 27 industry Microsoft's First Voluntary Buyout in 51 Years Reframes How Big Tech Sheds Headcount in the AI Capex Era
  28. apr 27 models There Will Be a Scientific Theory of Deep Learning: What arXiv 2604.21691 Argues and Where It Will Lose
  29. apr 27 security Vercel's April 2026 Database Leak Pivoted From Lumma Stealer at Context AI via a Chrome Extension
  30. apr 23 infra Azure NAT Gateway Blocks Tailscale Direct Connect; v1.96.2 Fixes Container Relay Scaling for AKS
  31. apr 23 security Citizen Lab's 'Bad Connection' Names Three Telecom Entry Points, Shows Diameter Silently Falls Back to SS7
  32. apr 23 agents Cloudflare Agents Week Moved Sandbox Execution, Private Networking, and Memory From Framework Code to Network Primitives
  33. apr 23 security CVE-2026-1839: Transformers Trainer's safe_globals Is a No-Op on PyTorch < 2.6, Exposing Checkpoint RCE
  34. apr 23 security CVE-2026-39987's 9-Hour Exploitation Window Exposes the Credential Gap at the Heart of AI Dev Infrastructure
  35. apr 23 security Flowise's CVE-2026-41264 Turns an LLM-Written Import Into RCE, Breaking the Regex-Gated Sandbox
  36. apr 23 agents Frontier LLMs Fail Agentic Threat Hunting: Best Model Catches 3.8% of Malicious Events in 11-Model Benchmark
  37. apr 23 agents FSE 2026: Chain-of-Thought Fails Per-Bias as Debiasing; Axiomatic Cues Cut Sensitivity 51%
  38. apr 23 devtools GitHub CLI v2.91.0 Turns On Default Telemetry: What gh Collects and How to Opt Out in CI and Agent Pipelines
  39. apr 23 devtools GitHub Copilot Drops Opus from Pro and Pauses Signups: The Forced Migration Facing Agentic Workflows (see also forced migration)
  40. apr 23 oss Inside Rowboat's Knowledge Graph: Why an Obsidian-Compatible Vault Sidesteps Vector DBs for Personal AI Memory
  41. apr 23 security LangChain CVE-2026-34070: load_prompt Path Traversal Patched in 1.2.22, Symlink Bypass Left Open
  42. apr 23 security Marimo CVE-2026-39987 Exposed Unauthenticated Root Shells Within Hours of Disclosure
  43. apr 23 security Marimo CVE-2026-39987: Pre-Auth RCE via /terminal/ws in Under 10 Hours
  44. apr 23 security MCP STDIO Executes Even When the Server Fails: One Design Decision, 14 CVEs, 30+ RCEs
  45. apr 23 models STaD Exposes What HumanEval Hides: Compositional Skill Gaps in LLMs That Aggregate Benchmarks Miss
  46. apr 23 infra UCCL-Zip: Lossless Compression for NCCL, 47.5% Faster RL Sync, 10% Lower vLLM Latency
  47. apr 22 agents ACL 2026: Multi-Agent LLM Topologies Accelerate Premature Convergence; Adding Agents Makes It Worse
  48. apr 22 agents Diversity Collapse in Multi-Agent LLM Systems: Structural Coupling Breaks Open-Ended Idea Generation Even When Topologies Are Sparse
  49. apr 22 agents Google's TPU 8i Targets Agentic Workloads. What CrewAI, LangGraph, and AutoGen Must Measure
  50. apr 22 oss Hugging Face's Spring 2026 State of Open Source Report: China Hits 41% of Downloads, Industry Share Collapses From 70% to 37%
  51. apr 22 infra Ingress-Nginx Is Dead, Not Deprecated: The Final CVE Patches Shipped, But Platform Teams Still Need a Migration Plan
  52. apr 22 industry KV Packet's Recomputation-Free Cache Exposes a Gap in How Cloud AI Vendors Price Multi-Document RAG Inference
  53. apr 22 devtools LACE Forces vLLM and SGLang to Rethink How Parallel Reasoning Threads Run
  54. apr 22 devtools LiteRT-LM v0.10.1 Ships Gemma 4 MTP Heads That llama.cpp Can't Access
  55. apr 22 security March-April MCP CVEs Expose the Local-Host Trust Model in AI Agent Frameworks
  56. apr 22 oss Neural Computers From MetaAuto: Video Models Can Replace Shell Interpreters, But Not Stateful Tasks
  57. apr 22 agents Nous Research's Hermes Ships Persistent Memory and Auto-Skill Capture: CrewAI and AutoGen Must Reconsider
  58. apr 22 agents OpenAI Responses API WebSocket Is Production-Ready; Pydantic AI, LangChain, and CrewAI Lack Adapters
  59. apr 22 models Qwen3.6-27B's Dense Architecture Challenges the MoE-Only Playbook for Flagship-Class Coding Models
  60. apr 22 security SGLang's CVE-2026-5760 Turns a GGUF Download Into RCE, Shifting the Trust Boundary to Hugging Face
  61. apr 22 infra Tailscale Peer Relays Behind Azure NAT Gateway: Why the DERP Fallback Hides a Throughput Cliff
  62. apr 22 infra vLLM Block-Level Preemption and FlexKV Shift the Long-Context Bottleneck From GPU Memory to PCIe
  63. apr 21 culture Crutch or Ceiling: What a New Study of LLMs and EFL Writing Reveals About the AI Assistance Trap
  64. apr 21 agents ml-intern's 32% GPQA Gain on a Single H100 Exposes the Assumption That Post-Training Still Needs a Human ML Researcher
  65. apr 21 devtools MR-Coupler: Automated Metamorphic Test Generation via Functional Coupling Analysis
  66. apr 21 agents Neural Computers' Symbolic Stability Failure Contradicts the Case for Pure-Neural Agent Orchestration
  67. apr 21 models Self-Correction Comes to Diffusion Models: What SOAR Means for Iterative Image Generation Pipelines
  68. apr 20 culture EU's 2027 Replaceable Battery Mandate: What It Means for Phone Buyers and Repairers Right Now
  69. apr 20 policy Symbolic Guardrails for AI Agents: Hard Safety Guarantees Without Crippling Capability
  70. apr 19 devtools ACP Registry Is Live: Zed and JetBrains Just Did for AI Agents What LSP Did for Language Servers
  71. apr 19 policy America's AI Researcher Pipeline Dropped 89%. What the Stanford Index Means for Teams Hiring AI Engineers
  72. apr 19 policy Atlassian Turned On AI Training Data Collection by Default — Here's What to Disable
  73. apr 19 devtools Cloudflare Browser Run's CDP and MCP Support: Serverless Browser Automation for AI Agents
  74. apr 19 oss Devstral 2 from Mistral: A Fully Open-Source Coding Agent Model You Can Run on a Laptop
  75. apr 19 oss ggsql Alpha: Write ggplot2-Style Visualizations Directly in SQL
  76. apr 19 oss GitHub CLI's `gh skill` Command: One Standard to Rule Claude Code, Copilot, Cursor, and Gemini
  77. apr 19 infra Google Cloud Is Doubling Peering Egress Costs on May 1. Here's What to Audit Before Then
  78. apr 19 security Jailbreak Scaling Laws: Why Reasoning Models Are Now the Cheapest Attack Vector Against Other LLMs
  79. apr 19 models NVIDIA Ising: Open-Source AI Models That Let Quantum Processors Self-Calibrate
  80. apr 19 industry PwC 2026: Why 80% of Companies Are Running AI Pilots That Won't Pay Off
  81. apr 19 models Qwen3.6-Max-Preview: What Alibaba's Latest Model Means for Open-Weight Competitors
  82. apr 19 policy Stanford's 2026 AI Index: Frontier Model Transparency Scores Collapsed 31% in One Year
  83. apr 19 oss The 2026 OSSRA Report: AI Coding Tools Are Behind a 107% Surge in Open-Source Vulnerabilities
  84. mar 26 policy The AI Grief Split: When Emotional Bonds with Language Models Break
  85. mar 26 agents InsForge: The Backend Framework Built for Agentic Applications
  86. mar 26 infra IonRouter (YC W26): The Custom NVIDIA GH200 Runtime Targeting the LLM Inference Cost Crisis
  87. mar 26 devtools JavaScript's Date Problem Is Finally Fixed: The Temporal API After 9 Years
  88. mar 26 infra OpenRAG: The Open-Source RAG Platform Challenging Pinecone
  89. mar 26 devtools Returning to Rails in 2026: Why Developers Are Abandoning React Complexity
  90. mar 26 culture Static-Site Social Networks: Building AI-Spam-Resistant Communities
  91. mar 26 models Swarm AI for Prediction Markets: Collective Intelligence Gets an Algorithm
  92. mar 23 devtools Cursor vs Windsurf vs GitHub Copilot: Real-World Benchmark on a 50k-Line Codebase
  93. mar 23 devtools DuckDB Is Embarrassing Snowflake on a $999 MacBook
  94. mar 23 devtools Claude Code in GitHub Actions: A Complete Guide to Automated PR Fixes
  95. mar 23 infra MLX vs llama.cpp on Apple Silicon: Which Runtime to Use for Local LLM Inference
  96. mar 23 infra Prefill-Decode Disaggregation: The Architecture Shift Redefining LLM Serving at Scale
  97. mar 23 models Qwen 2.5 vs Llama 3.3: The Open-Weight Showdown Nobody Is Talking About
  98. mar 23 models Running DeepSeek R1 Locally: Hardware Requirements, Quantization, and Real Throughput
  99. mar 23 devtools SWE-bench Verified Explained: What the Coding Agent Leaderboard Actually Measures (and What It Misses)
  100. mar 23 models Chinese AI Models Compared: DeepSeek, Qwen, Kimi, Doubao, and Ernie