groundy

all articles

  1. apr 28 security Windsurf CVE-2026-30615 Is the Only Zero-Click in the April MCP RCE Wave: HTML Rewrites the Config
  2. apr 28 agents CrewAI 1.14.2 Lands Checkpoint TUI with Tree View, Fork Support, and Lineage Tracking
  3. apr 28 security Paperclip CVE-2026-41208: Agents Can Mutate Their Own provisionCommand Into Server-Side Shell Injection
  4. apr 28 security Spring AI 1.0.6 Patches Five CVEs Including CVSS 8.8 SQL Injection in CosmosDBVectorStore.doDelete
  5. apr 28 security LMDeploy CVE-2026-33626: Vision-LLM SSRF Exploited Within 12 Hours of GHSA Publication
  6. apr 28 security InstructLab CVE-2026-6859: Hardcoded trust_remote_code=True Turns Any HuggingFace Model Into RCE
  7. apr 28 security PickleScan 1.0.4 Patches a CVSS 10.0 pkgutil.resolve_name Bypass and Six Missing Stdlib RCE Modules
  8. apr 28 devtools Pydantic AI v1.87 Closes the LangGraph Gap: Deferred Tool Calls, OpenTelemetry Eval, Stateful Compaction
  9. apr 28 security Mercor's 4TB Lapsus$ Breach Hands Voice-Clone Attackers 40,000 Pre-Verified Targets
  10. apr 28 culture Google Ignores California's Global Privacy Control 86% of the Time: webXray's 7,000-Site Audit
  11. apr 28 agents Council Mode Cuts Multi-Agent LLM Hallucination 35.9% at 4.2x Token Cost on HaluEval
  12. apr 28 devtools Claude Code vs Cursor vs Copilot After the April 2026 Reshuffle: How the Comparison Math Changed
  13. apr 28 policy California SB 1119 and AB 2023 Cleared Committee April 21: Companion Chatbots Owe Annual AG-Filed Audits
  14. apr 28 devtools LangGraph 1.1.10's ToolNode Now Accepts list[Command | ToolMessage]: How That Splits From Pydantic AI
  15. apr 28 agents Salesforce TDX 2026: Headless 360 Ships 60+ MCP Tools and Agentforce Vibes 2.0 With Claude Sonnet 4.5
  16. apr 28 infra Crawshaw's 'I Am Building a Cloud': What a Tailscale Co-Founder's Solo Stack Implies for Platform Teams
  17. apr 27 security Vercel's April 2026 Database Leak Pivoted From Lumma Stealer at Context AI via a Chrome Extension
  18. apr 27 devtools GitHub Copilot Replaces Premium Request Units With Token-Metered AI Credits on June 1
  19. apr 27 oss free-claude-code Routes Claude Code Through NVIDIA NIM and Local Models After Anthropic's CLI Ban
  20. apr 27 industry Microsoft and OpenAI End Their Exclusive Revenue-Sharing Deal: What It Means for Azure's AI Moat
  21. apr 27 industry Anthropic Ends Flat-Fee Enterprise Claude Above 150 Seats and Forces Per-Token Billing on AI Procurement
  22. apr 27 industry America's 150 GW Geothermal Estimate Reprices AI Data Center Power Procurement
  23. apr 27 security Bitwarden CLI Compromise Extends the Checkmarx Supply-Chain Campaign to Credential Tooling
  24. apr 27 models There Will Be a Scientific Theory of Deep Learning: What arXiv 2604.21691 Argues and Where It Will Lose
  25. apr 23 devtools GitHub CLI v2.91.0 Turns On Default Telemetry: What gh Collects and How to Opt Out in CI and Agent Pipelines
  26. apr 23 devtools GitHub Copilot Drops Opus from Pro and Pauses Signups: The Forced Migration Facing Agentic Workflows
  27. apr 23 agents Cloudflare Agents Week Moved Sandbox Execution, Private Networking, and Memory to Network Primitives
  28. apr 23 security Flowise's CVE-2026-41264: LLM-Written `import` Becomes Unauthenticated RCE
  29. apr 23 oss Inside Rowboat's Knowledge Graph: Why an Obsidian-Compatible Vault Sidesteps Vector DBs for Personal AI Memory
  30. apr 23 infra UCCL-Zip: Lossless Compression for NCCL, 47.5% Faster RL Sync, 10% Lower vLLM Latency
  31. apr 23 security Citizen Lab's 'Bad Connection' Names Three Telecom Entry Points, Shows Diameter Silently Falls Back to SS7
  32. apr 22 agents Diversity Collapse in Multi-Agent LLM Systems: Structural Coupling, Not Topology, Breaks Open-Ended Ideation
  33. apr 22 devtools LiteRT-LM v0.10.1 Ships Gemma 4 MTP Heads That llama.cpp Can't Access
  34. apr 22 oss Hugging Face's Spring 2026 Report: China 41% of Downloads, Industry Share Collapses From 70% to 37%
  35. apr 22 models Qwen3.6-27B's Dense Architecture Challenges the MoE-Only Playbook for Flagship-Class Coding Models
  36. apr 22 security SGLang's CVE-2026-5760 Turns a GGUF Download Into RCE, Shifting the Trust Boundary to Hugging Face
  37. apr 22 oss Neural Computers From MetaAuto: Video Models Can Replace Shell Interpreters, But Not Stateful Tasks
  38. apr 22 security March-April MCP CVEs Expose the Local-Host Trust Model in AI Agent Frameworks
  39. apr 22 infra Ingress-Nginx Is Dead, Not Deprecated: Final CVE Patches Shipped, But Platform Teams Need a Migration Plan
  40. apr 22 devtools LACE Forces vLLM and SGLang to Rethink How Parallel Reasoning Threads Run
  41. apr 21 agents ml-intern's 32% GPQA Gain on One H100 Exposes the Assumption That Post-Training Still Needs a Human Researcher
  42. apr 20 culture EU's 2027 Replaceable Battery Mandate: What It Means for Phone Buyers and Repairers Right Now
  43. apr 19 devtools ACP Registry Is Live: Zed and JetBrains Just Did for AI Agents What LSP Did for Language Servers
  44. apr 19 policy Atlassian Turned On AI Training Data Collection by Default: Here's What to Disable
  45. apr 19 oss GitHub CLI's `gh skill` Command: One Standard to Rule Claude Code, Copilot, Cursor, and Gemini
  46. mar 26 infra OpenRAG: The Open-Source RAG Platform Challenging Pinecone
  47. mar 26 devtools JavaScript's Date Problem Is Finally Fixed: The Temporal API After 9 Years
  48. mar 26 agents InsForge: The Backend Framework Built for Agentic Applications
  49. mar 26 policy The AI Grief Split: When Emotional Bonds with Language Models Break
  50. mar 23 infra MLX vs llama.cpp on Apple Silicon: Which Runtime to Use for Local LLM Inference
  51. mar 23 infra Prefill-Decode Disaggregation: The Architecture Shift Redefining LLM Serving
  52. mar 23 devtools SWE-bench Verified Explained: What the Coding Agent Leaderboard Actually Measures (and What It Misses)
  53. mar 23 models Chinese AI Models Compared: DeepSeek, Qwen, Kimi, Doubao, and Ernie
  54. mar 23 devtools Claude Code in GitHub Actions: A Complete Guide to Automated PR Fixes
  55. mar 23 models Running DeepSeek R1 Locally: Hardware Requirements, Quantization, and Real Throughput
  56. mar 14 infra Google LiteRT: Running LLMs on Your Phone Without the Cloud
  57. mar 14 devtools JetBrains' New Language Lets You Talk to LLMs in Specs, Not English
  58. mar 14 models Fish-Speech: The Open-Source TTS Model That's Threatening ElevenLabs
  59. mar 14 devtools Alibaba's Page-Agent: Control Any Website With Natural Language
  60. mar 14 culture AI Diagnostics in 2026: Where Machines Now Outperform Radiologists
  61. mar 14 agents AI Agents That Actually Learn: The Architecture Behind Hindsight Memory
  62. mar 13 devtools GitHub Copilot vs Cursor vs Claude Code: The 2026 AI Coding Showdown
  63. mar 13 policy Detecting AI Content in 2026: The Arms Race Nobody Is Winning
  64. mar 12 infra Microsoft's BitNet: How 1-Bit LLMs Could Make GPU Farms Obsolete
  65. mar 12 security How Researchers Hacked McKinsey's AI Platform: What It Reveals
  66. feb 27 infra WebAssembly AI: Running Models in the Browser
  67. feb 27 agents Superpowers: The Agentic Framework Replacing Your Dev Process
  68. feb 26 models Synthetic Data Is Eating AI Training
  69. feb 26 devtools Rust Is Quietly Replacing Python in AI Infrastructure
  70. feb 26 industry OpenAI's For-Profit Pivot: What It Means for the Future of AI
  71. feb 26 agents How AI Agents Remember: Memory Architectures That Work
  72. feb 26 models Google's TimesFM: A Foundation Model for Time Series
  73. feb 26 models Gemini 2.0 Pro's 2 Million Token Context: What Can You Actually Do With It?
  74. feb 26 industry Cursor's Meteoric Rise: Inside the AI Editor Hitting $300M ARR
  75. feb 26 industry Stargate: Inside OpenAI's $100B Infrastructure Buildout
  76. feb 26 models DeepSeek V3/R1: How Chinese Engineers Matched GPT-4 for $6 Million
  77. feb 26 models Claude's Web Search Changes Everything for AI Research
  78. feb 26 models The Million-Token Context Window: What Can You Actually Do?
  79. feb 20 oss Keep Android Open: F-Droid's Fight Against a Locked-Down Mobile Future
  80. feb 20 devtools Claude Code Plugins: Anthropic's Official Plugin Ecosystem Explained
  81. feb 20 devtools Claude Code Plugins: Anthropic's Official Extension Ecosystem
  82. feb 19 security The Mysterious Case of Chinese Bot Traffic in 2026: How AI-Powered Bots Are Rewriting the Rules of Detection
  83. feb 19 policy Anthropic Bans Third-Party Subscription Auth: The Three-Stage Repricing
  84. feb 18 infra Tailscale Peer Relays: The Missing Piece for True P2P Networking
  85. feb 18 infra DNS-Persist-01 Validation: Let's Encrypt's Model for Permanent ACME Certificate Authorization
  86. feb 18 models Gemini 3.1 Pro: Google's New Reasoning Model Explained
  87. feb 18 industry NautilusTrader: Building Production-Ready Algorithmic Trading Systems
  88. feb 18 devtools Prompt Engineering Patterns 2026: What Actually Works Now
  89. feb 18 policy If You're an LLM, Please Read This: The Dark Truth About AI Training Data
  90. feb 17 devtools Rowboat: The Open-Source AI Coworker That Actually Remembers
  91. feb 17 models Kimi Claw: Moonshot AI's Answer to Claude and ChatGPT
  92. feb 17 agents Function Calling Best Practices: LLMs That Actually Use APIs Correctly
  93. feb 17 models WiFi DensePose: Full-Body Tracking Through Walls Using Your Router
  94. feb 14 devtools Natural Language to SQL: AI Is Finally Making Databases Accessible
  95. feb 14 devtools GitHub Models: Free LLM Access for Testing and Prototyping
  96. feb 14 policy Constitutional AI: Teaching Models to Self-Correct Before They Act
  97. feb 14 models AI Code Generation Benchmarks 2026: Which Model Actually Writes Better Code?
  98. feb 13 devtools Tree-Sitter Code Indexing: The Secret to Better AI Code Understanding
  99. feb 13 devtools Claude Code /fast Mode: Is 6x Pricing Worth It?
  100. feb 11 infra The Complete Guide to Local LLMs