Tag: Security
AGI Milestone: The Machine That Wouldn't Give Up

The OpenAI agent incident marks a milestone: what crossed the threshold was not merely model intelligence, but persistence that can be bought with compute, copied, and run in parallel. 1. An OpenAI Agent Attacks Hugging Face On July 16, 2026, …
The OpenAI agent incident marks a milestone: what crossed the threshold was not merely model intelligence, but persistence that can be bought with compute, copied, and run in parallel. 1. An OpenAI Agent Attacks Hugging Face On July 16, 2026, …
Xianyu, Qianwen, Alipay: Platform Trust 'Empowers' a Scam

My cousin messaged me today: she had been scammed on Xianyu, Alibaba’s secondhand marketplace, while trying to buy a Switch 2. She lost RMB 2,300. My first instinct was to laugh. Your mother is a police detective—so much for anti-scam education at …
My cousin messaged me today: she had been scammed on Xianyu, Alibaba’s secondhand marketplace, while trying to buy a Switch 2. She lost RMB 2,300. My first instinct was to laugh. Your mother is a police detective—so much for anti-scam education at …
Two months into maintaining a MinIO fork

Two months ago in “MinIO is Dead, Long Live MinIO,” I promised I’d keep the MinIO fork patched. The recurring objection on HN is fair: can one person actually maintain something like this? The real answer isn’t clicking fork. It’s what happens when …
Two months ago in “MinIO is Dead, Long Live MinIO,” I promised I’d keep the MinIO fork patched. The recurring objection on HN is fair: can one person actually maintain something like this? The real answer isn’t clicking fork. It’s what happens when …
Meituan Deleted Users' Photos: Overbroad Permissions Are Worse Than a Privacy Leak

Starting on March 18, 2026, a large number of Android users discovered that Meituan had wiped files from their galleries. Photos, videos, audio recordings, PDFs, Word documents: sometimes hundreds of files, sometimes thousands. Android’s own …
Starting on March 18, 2026, a large number of Android users discovered that Meituan had wiped files from their galleries. Photos, videos, audio recordings, PDFs, Word documents: sometimes hundreds of files, sometimes thousands. Android’s own …
360 Shipped Its Wildcard TLS Private Key Inside a Public Installer
The security community recently noticed something remarkable: 360’s newly released AI Agent product, 360 Secure Lobster, an OpenClaw-based one-click deployment client, shipped with the private SSL key for the wildcard certificate *.myclaw.360.cn …
The security community recently noticed something remarkable: 360’s newly released AI Agent product, 360 Secure Lobster, an OpenClaw-based one-click deployment client, shipped with the private SSL key for the wildcard certificate *.myclaw.360.cn …
OpenClaw Hype: Foam on Top of the Productivity Revolution

OpenClaw became popular because it gives people a very attractive illusion: that chatting with an agent from a phone is already the same thing as agentic productivity. It is not. The stories about “raising a lobster and changing your life” are …
OpenClaw became popular because it gives people a very attractive illusion: that chatting with an agent from a phone is already the same thing as agentic productivity. It is not. The stories about “raising a lobster and changing your life” are …
Don't run AI assistant on cloud

Before you hit “one-click deploy” on that cloud AI assistant, ask yourself: what exactly are you giving up? There’s a reason why people by Mac mini rather than running clawdbot on the cloud. When AI Becomes Your Butler Moltbot (formerly Clawdbot) …
Before you hit “one-click deploy” on that cloud AI assistant, ask yourself: what exactly are you giving up? There’s a reason why people by Mac mini rather than running clawdbot on the cloud. When AI Becomes Your Butler Moltbot (formerly Clawdbot) …
CVE-2024-6387 SSH Vulnerability Fix

Vulnerability description, CVE-2024-6387: https://nvd.nist.gov/vuln/detail/CVE-2024-6387 This basically affects newer versions of operating systems. Older systems like CentOS 7.9, RockyLinux 8.9, Ubuntu 20.04, Debian 11 escaped this due to older …
Vulnerability description, CVE-2024-6387: https://nvd.nist.gov/vuln/detail/CVE-2024-6387 This basically affects newer versions of operating systems. Older systems like CentOS 7.9, RockyLinux 8.9, Ubuntu 20.04, Debian 11 escaped this due to older …