Front-page articles summarized hourly.
Archaeologists in Oaxaca’s San Pablo Huitzo, Mexico, uncovered a 1,400-year-old Zapotec tomb dating to around 600 CE. The site features intricate carvings, multicolored murals, and an owl sculpture above the burial chamber entrance, with a carved head inside the beak—likely the occupant. Thresholds show two guardian figures; the chamber contains a vivid mural of processions with copal. Owls symbolize night and death in Zapotec belief. INAH is stabilizing the fragile murals; officials call it Mexico’s most significant archaeological find in years.
Notepad++’s update infrastructure was compromised June–Sept 2025 via a hosting incident, letting attackers push malicious updates. Kaspersky observed three evolving infection chains (July–Aug; Sep–Oct; Oct 2025). Chains delivered NSIS installers dropping payloads and a Metasploit downloader to fetch a Cobalt Strike Beacon; C2/update URLs and domains rotated monthly. Chain #3 used a BluetoothService sideload with Chrysalis. Victims included individuals in Vietnam, El Salvador and Australia, plus a Philippine government entity and a Vietnam IT provider. IOCs include NSIS artifacts, temp.sh uploads, and Cobalt Strike domains; scan for NSIS installers and unusual temp.sh traffic.
Simon, a software engineer turned hardware founder, recounts manufacturing 500 Brighter lamps after a $400k crowdfunding. Initial LED tests underperformed; he redesigned the electronics, boosted LEDs, and enlarged the heatsink. Tariffs climbed to as high as 150%, hitting costs. Miscommunications in China caused a faulty heatsink and later swapped PCB pins; knobs scraped due to missing spacing in the DFM. Final fixes required remaking 1000 knobs. Production shipped from Oct; customers noted cable length and minor QC issues. Lessons: plan longer, overcommunicate, test on many units, heed geopolitics, visit suppliers early. Right moves: validate market, price sustainably, prioritize support.
Trust is essential to society, but we confuse interpersonal trust with social trust, a mismatch amplified by AI. AIs will appear as friends, but they are services built by profit-maximizing firms that surveil and manipulate. To achieve trustworthy AI, government must regulate the organizations that control and deploy AI—not the AI as a person. Proposals include AI transparency and safety laws, enforcement with real penalties, data fiduciaries for personal data, and public AI models built for the public. With such governance, AI can be trustworthy services rather than double agents.
Access to acm.org is blocked by Cloudflare's security. The page notes cookies are required and that certain actions (words, SQL commands, or malformed data) can trigger a block. To resolve, email the site owner with what you were doing and include the Cloudflare Ray ID (9c8506464fbcfa92) and your IP (192.155.84.206).
Bloomberg displays a bot-check notice: unusual activity detected, ask users to verify they are not a robot, ensure JavaScript and cookies are enabled and not blocked. It cites Terms of Service and Cookie Policy, offers support with a reference ID, and promotes a Bloomberg subscription.
Oxen performance study shows commit >50 minutes vs add ~1 minute for 1M files. Profiling reveals >90% of time spent locking RocksDB during staging-to-commit, driven by cross-layer data shuttling (clone/db.open) of file metadata. A refactor cut unnecessary data movement and complexity, exposing RocksDB’s poor fit for parallel reads. The fix—remove code and simplify design—yields ~20x speedup. Lesson: fewer layers and careful system-wide profiling deliver real performance gains.
Vibe coding uses an AI chatbot to generate code, making developers effectively clients of the AI. The piece argues this could erode Open Source ecosystems by drawing activity away from OSS projects, making it harder to start new ones, and reducing engagement with libraries, docs, and forums. Outputs reflect training-data biases, favoring popular dependencies, and LLMs rarely interact with maintainers, report bugs, or understand issues. JavaScript/Python ecosystems could be hit first; productivity and cognitive skills may decline. The impact remains uncertain but potentially serious.
Hari Kunzru's essay 'Another London' traces a 'second' London beneath the surface—a psychogeographic map of myth, occult histories, and countercultural energy. Through a walk from the British Museum to Greenwich, he blends the Situationists’ dérive, Hawksmoor’s austere churches, and writers like Blake, Machen, and Moore to show how London is shaped by visions, power, and the Spectacle. Personal memory—punk, surveillance, and hidden tunnels—meets political magic: reenchanting a city by tracing its secret geographies. Though exhausted, he remains hopeful: another London is still possible.
Senko Rašić describes sandboxing AI agents on Linux using bubblewrap to run Claude Code with controlled permissions. He prefers a lightweight, locally hosted sandbox that mimics his dev environment: read access only to current project, write only to that project, and network access for AI providers and a server. He dismisses full Docker security as overkill for his use. The post includes a concrete bubblewrap script binding essential dirs, injecting .claude.json, and mapping $HOME/.claude, with notes on tweaking and using strace to tailor bindings.
IEEE Spectrum reports China’s CMSA aims to land astronauts on the Moon by 2030 with the Mengzhou crew ship and Lanyue lander, launched by Long March 10 rockets. Mengzhou would stay in lunar orbit while Lanyue lands (carrying a rover), in an Apollo-style two-vehicle architecture. Robotic tests start in 2026–27; joint missions in 2028–29; first crewed Moon landing about 2030. Grounded in Project 921, China’s integrated, multi-element program could spur NASA to accelerate Artemis, even as officials deny a formal space race.
PII-Shield is a zero‑code Kubernetes log-sanitization sidecar that redacts PII and secrets before they leave pods. It uses context‑aware entropy analysis to detect high‑entropy secrets without keys, preserves JSON integrity, and replaces secrets with deterministic hashes (e.g., [HIDDEN:a1b2c]). Written in Go for high performance, it’s a drop‑in, language‑agnostic solution installed via Docker. Configurable via env vars (PII_SALT, PII_ADAPTIVE_THRESHOLD, PII_DISABLE_BIGRAM_CHECK). It can run as a pipe wrapper or as a Kubernetes initContainer, and is validated by unit tests, fuzzing, and stress tests. Apache-2.0.
Narrator analyzes top AI models for creative writing in 2026, using a three-model system: Brainstorming Model for ideas and world-building, Writer Model for drafting chapters and narrative, and Memory Model for maintaining context. The platform offers leaderboards (Daily, Weekly, Monthly, All Time) and browsing by genres, tags, and content ratings. Users can request benchmarks on Discord and suggest new models.
Y Combinator will let its spring cohort receive funding—typically around $500,000—in stablecoins, specifically Circle's USDC. Founders can opt to receive USDC on blockchains like Ethereum and Solana, with more stablecoins possible on demand. YC partner Nemil Dalal says stablecoins are a key pillar and expects startups to raise capital on-chain in the future. The move signals growing mainstream interest in stablecoins, independent of crypto price swings.
Argues that 1 kilobyte can be 1000 or 1024 bytes. The 1024-byte convention stems from binary addressing, but decimal units are common, and the mismatch grows with larger units (e.g., 1 GB ≈ 1.0737×10^9 vs 1.0×10^9). To resolve confusion, IEC defined binary prefixes (KiB, MiB, GiB) alongside decimal prefixes (kB, MB, GB). Yet industry inertia means mixed usage across hardware, software, and OS, keeping the debate and confusion alive.
AliSQL is Alibaba’s MySQL fork optimized for large-scale production, with a DuckDB-based native storage engine and vector processing via HNSW ANN (up to 16,383 dimensions) through SQL for AI apps. Version 8.0.44 (LTS) is open-source since December 2025. Roadmap includes DDL optimization, RTO improvements, and replication optimization for faster crash recovery. Build requires CMake 3.x, Python 3, and a C++17 compiler; licensed under GPL-2.0.
Made by Johno Whitaker using FastHTML