<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator><link href="https://pgmac.net.au/feed/tags/compromise.xml" rel="self" type="application/atom+xml" /><link href="https://pgmac.net.au/" rel="alternate" type="text/html" /><updated>2026-05-25T10:01:12+00:00</updated><id>https://pgmac.net.au/feed/tags/compromise.xml</id><title type="html">PGMac . Net . AU</title><subtitle>Where I think about things and make the internet listen. Because it&apos;s important.</subtitle><entry><title type="html">Some things I found interesting from 2026-05-17 to 2026-05-24</title><link href="https://pgmac.net.au/last-week/2026/05/24/interesting-last-week.html" rel="alternate" type="text/html" title="Some things I found interesting from 2026-05-17 to 2026-05-24" /><published>2026-05-24T00:00:00+00:00</published><updated>2026-05-24T00:00:00+00:00</updated><id>https://pgmac.net.au/last-week/2026/05/24/interesting-last-week</id><content type="html" xml:base="https://pgmac.net.au/last-week/2026/05/24/interesting-last-week.html"><![CDATA[<p>Internet Discoveries between 17 and 24 May</p>

<ul>
  <li>Saturday Morning Breakfast Cereal - Experiencing</li>
  <li>Project Glasswing: what Mythos showed us</li>
  <li>Saturday Morning Breakfast Cereal - Criminal</li>
  <li>CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security</li>
  <li>Saturday Morning Breakfast Cereal - Sick</li>
  <li>Saturday Morning Breakfast Cereal - Trash</li>
  <li>Investigating unauthorized access to GitHub-owned repositories - The GitHub Blog</li>
  <li>Saturday Morning Breakfast Cereal - Back</li>
  <li>Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised - Real-time Open Source Software Supply Chain Security</li>
  <li>Saturday Morning Breakfast Cereal - Ex</li>
  <li>Project Glasswing: An initial update \ Anthropic</li>
  <li>Saturday Morning Breakfast Cereal - Safe</li>
  <li>Megalodon chums the waters in 5.5K+ GitHub repo poisonings</li>
  <li>Saturday Morning Breakfast Cereal - Cave</li>
</ul>

<h2 id="interesting-details">Interesting details</h2>

<p><a name="Saturday Morning Breakfast Cereal - Experiencing"></a><a href="https://www.smbc-comics.com/comic/experiencing">Saturday Morning Breakfast Cereal - Experiencing</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="Project Glasswing: what Mythos showed us"></a><a href="https://blog.cloudflare.com/cyber-frontier-models/">Project Glasswing: what Mythos showed us</a> - In recent weeks, we pointed Mythos and other security-focused LLMs at live code across critical parts of our infrastructure. We share what we observed, the models’ strengths and weaknesses, and what the work around them needs to look like before any of it can scale.</p>
<div class="tag-pills"><a href="/tag/ai" class="tag-pill">ai</a> <a href="/tag/cloudflare" class="tag-pill">cloudflare</a> <a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/llm" class="tag-pill">llm</a> <a href="/tag/security" class="tag-pill">security</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Criminal"></a><a href="https://www.smbc-comics.com/comic/criminal">Saturday Morning Breakfast Cereal - Criminal</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security"></a><a href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/">CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security</a> - Until this past weekend, a contractor for the Cybersecurity &amp; Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said…</p>
<div class="tag-pills"><a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/incident" class="tag-pill">incident</a> <a href="/tag/security" class="tag-pill">security</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Sick"></a><a href="https://www.smbc-comics.com/comic/sick-2">Saturday Morning Breakfast Cereal - Sick</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Trash"></a><a href="https://www.smbc-comics.com/comic/trash">Saturday Morning Breakfast Cereal - Trash</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="Investigating unauthorized access to GitHub-owned repositories - The GitHub Blog"></a><a href="https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/">Investigating unauthorized access to GitHub-owned repositories - The GitHub Blog</a> - If any impact is discovered, customers will be notified via established incident response and notification channels.</p>
<div class="tag-pills"><a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/github" class="tag-pill">github</a> <a href="/tag/incident" class="tag-pill">incident</a> <a href="/tag/security" class="tag-pill">security</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Back"></a><a href="https://www.smbc-comics.com/comic/back-3">Saturday Morning Breakfast Cereal - Back</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised - Real-time Open Source Software Supply Chain Security"></a><a href="https://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised/">Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised - Real-time Open Source Software Supply Chain Security</a> -  </p>
<div class="tag-pills"><a href="/tag/compromise" class="tag-pill">compromise</a> <a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/incident" class="tag-pill">incident</a> <a href="/tag/npm" class="tag-pill">npm</a> <a href="/tag/security" class="tag-pill">security</a> <a href="/tag/supply-chain" class="tag-pill">supply chain</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Ex"></a><a href="https://www.smbc-comics.com/comic/ex-3">Saturday Morning Breakfast Cereal - Ex</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="Project Glasswing: An initial update \ Anthropic"></a><a href="https://www.anthropic.com/research/glasswing-initial-update">Project Glasswing: An initial update \ Anthropic</a> - An early update on what we’ve learned from Project Glasswing.</p>
<div class="tag-pills"><a href="/tag/ai" class="tag-pill">ai</a> <a href="/tag/anthropic" class="tag-pill">anthropic</a> <a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/llm" class="tag-pill">llm</a> <a href="/tag/mythos" class="tag-pill">mythos</a> <a href="/tag/security" class="tag-pill">security</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Safe"></a><a href="https://www.smbc-comics.com/comic/safe">Saturday Morning Breakfast Cereal - Safe</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="Megalodon chums the waters in 5.5K+ GitHub repo poisonings"></a><a href="https://www.theregister.com/security/2026/05/22/megalodon-chums-the-waters-in-55k-github-repo-poisonings/5245342">Megalodon chums the waters in 5.5K+ GitHub repo poisonings</a> - Will Jason Statham save us?</p>
<div class="tag-pills"><a href="/tag/compromise" class="tag-pill">compromise</a> <a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/github" class="tag-pill">github</a> <a href="/tag/incident" class="tag-pill">incident</a> <a href="/tag/security" class="tag-pill">security</a> <a href="/tag/supply-chain" class="tag-pill">supply chain</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Cave"></a><a href="https://www.smbc-comics.com/comic/cave-3">Saturday Morning Breakfast Cereal - Cave</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<hr />

<p>All this was saved to my <a href="https://links.pgmac.net.au/">Link Ace</a> and YouTube Interesting playlist over the week</p>]]></content><author><name>Paul Macdonnell</name><email>pgmac@pgmac.net</email></author><category term="Last-Week" /><category term="comic" /><category term="RSS" /><category term="ai" /><category term="cloudflare" /><category term="cyber" /><category term="llm" /><category term="security" /><category term="comic" /><category term="RSS" /><category term="cyber" /><category term="incident" /><category term="security" /><category term="comic" /><category term="RSS" /><category term="comic" /><category term="RSS" /><category term="cyber" /><category term="github" /><category term="incident" /><category term="security" /><category term="comic" /><category term="RSS" /><category term="compromise" /><category term="cyber" /><category term="incident" /><category term="npm" /><category term="security" /><category term="supply chain" /><category term="comic" /><category term="RSS" /><category term="ai" /><category term="anthropic" /><category term="cyber" /><category term="llm" /><category term="mythos" /><category term="security" /><category term="comic" /><category term="RSS" /><category term="compromise" /><category term="cyber" /><category term="github" /><category term="incident" /><category term="security" /><category term="supply chain" /><category term="comic" /><category term="RSS" /><summary type="html"><![CDATA[Internet Discoveries between 17 and 24 May]]></summary></entry><entry><title type="html">Some things I found interesting from 2026-05-17 to 2026-05-24</title><link href="https://pgmac.net.au/last-week/2026/05/24/interesting-last-week.html" rel="alternate" type="text/html" title="Some things I found interesting from 2026-05-17 to 2026-05-24" /><published>2026-05-24T00:00:00+00:00</published><updated>2026-05-24T00:00:00+00:00</updated><id>https://pgmac.net.au/last-week/2026/05/24/interesting-last-week</id><content type="html" xml:base="https://pgmac.net.au/last-week/2026/05/24/interesting-last-week.html"><![CDATA[<p>Internet Discoveries between 17 and 24 May</p>

<ul>
  <li>Saturday Morning Breakfast Cereal - Experiencing</li>
  <li>Project Glasswing: what Mythos showed us</li>
  <li>Saturday Morning Breakfast Cereal - Criminal</li>
  <li>CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security</li>
  <li>Saturday Morning Breakfast Cereal - Sick</li>
  <li>Saturday Morning Breakfast Cereal - Trash</li>
  <li>Investigating unauthorized access to GitHub-owned repositories - The GitHub Blog</li>
  <li>Saturday Morning Breakfast Cereal - Back</li>
  <li>Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised - Real-time Open Source Software Supply Chain Security</li>
  <li>Saturday Morning Breakfast Cereal - Ex</li>
  <li>Project Glasswing: An initial update \ Anthropic</li>
  <li>Saturday Morning Breakfast Cereal - Safe</li>
  <li>Megalodon chums the waters in 5.5K+ GitHub repo poisonings</li>
  <li>Saturday Morning Breakfast Cereal - Cave</li>
</ul>

<h2 id="interesting-details">Interesting details</h2>

<p><a name="Saturday Morning Breakfast Cereal - Experiencing"></a><a href="https://www.smbc-comics.com/comic/experiencing">Saturday Morning Breakfast Cereal - Experiencing</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="Project Glasswing: what Mythos showed us"></a><a href="https://blog.cloudflare.com/cyber-frontier-models/">Project Glasswing: what Mythos showed us</a> - In recent weeks, we pointed Mythos and other security-focused LLMs at live code across critical parts of our infrastructure. We share what we observed, the models’ strengths and weaknesses, and what the work around them needs to look like before any of it can scale.</p>
<div class="tag-pills"><a href="/tag/ai" class="tag-pill">ai</a> <a href="/tag/cloudflare" class="tag-pill">cloudflare</a> <a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/llm" class="tag-pill">llm</a> <a href="/tag/security" class="tag-pill">security</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Criminal"></a><a href="https://www.smbc-comics.com/comic/criminal">Saturday Morning Breakfast Cereal - Criminal</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security"></a><a href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/">CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security</a> - Until this past weekend, a contractor for the Cybersecurity &amp; Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said…</p>
<div class="tag-pills"><a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/incident" class="tag-pill">incident</a> <a href="/tag/security" class="tag-pill">security</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Sick"></a><a href="https://www.smbc-comics.com/comic/sick-2">Saturday Morning Breakfast Cereal - Sick</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Trash"></a><a href="https://www.smbc-comics.com/comic/trash">Saturday Morning Breakfast Cereal - Trash</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="Investigating unauthorized access to GitHub-owned repositories - The GitHub Blog"></a><a href="https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/">Investigating unauthorized access to GitHub-owned repositories - The GitHub Blog</a> - If any impact is discovered, customers will be notified via established incident response and notification channels.</p>
<div class="tag-pills"><a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/github" class="tag-pill">github</a> <a href="/tag/incident" class="tag-pill">incident</a> <a href="/tag/security" class="tag-pill">security</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Back"></a><a href="https://www.smbc-comics.com/comic/back-3">Saturday Morning Breakfast Cereal - Back</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised - Real-time Open Source Software Supply Chain Security"></a><a href="https://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised/">Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised - Real-time Open Source Software Supply Chain Security</a> -  </p>
<div class="tag-pills"><a href="/tag/compromise" class="tag-pill">compromise</a> <a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/incident" class="tag-pill">incident</a> <a href="/tag/npm" class="tag-pill">npm</a> <a href="/tag/security" class="tag-pill">security</a> <a href="/tag/supply-chain" class="tag-pill">supply chain</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Ex"></a><a href="https://www.smbc-comics.com/comic/ex-3">Saturday Morning Breakfast Cereal - Ex</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="Project Glasswing: An initial update \ Anthropic"></a><a href="https://www.anthropic.com/research/glasswing-initial-update">Project Glasswing: An initial update \ Anthropic</a> - An early update on what we’ve learned from Project Glasswing.</p>
<div class="tag-pills"><a href="/tag/ai" class="tag-pill">ai</a> <a href="/tag/anthropic" class="tag-pill">anthropic</a> <a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/llm" class="tag-pill">llm</a> <a href="/tag/mythos" class="tag-pill">mythos</a> <a href="/tag/security" class="tag-pill">security</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Safe"></a><a href="https://www.smbc-comics.com/comic/safe">Saturday Morning Breakfast Cereal - Safe</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="Megalodon chums the waters in 5.5K+ GitHub repo poisonings"></a><a href="https://www.theregister.com/security/2026/05/22/megalodon-chums-the-waters-in-55k-github-repo-poisonings/5245342">Megalodon chums the waters in 5.5K+ GitHub repo poisonings</a> - Will Jason Statham save us?</p>
<div class="tag-pills"><a href="/tag/compromise" class="tag-pill">compromise</a> <a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/github" class="tag-pill">github</a> <a href="/tag/incident" class="tag-pill">incident</a> <a href="/tag/security" class="tag-pill">security</a> <a href="/tag/supply-chain" class="tag-pill">supply chain</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Cave"></a><a href="https://www.smbc-comics.com/comic/cave-3">Saturday Morning Breakfast Cereal - Cave</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<hr />

<p>All this was saved to my <a href="https://links.pgmac.net.au/">Link Ace</a> and YouTube Interesting playlist over the week</p>]]></content><author><name>Paul Macdonnell</name><email>pgmac@pgmac.net</email></author><category term="Last-Week" /><category term="comic" /><category term="RSS" /><category term="ai" /><category term="cloudflare" /><category term="cyber" /><category term="llm" /><category term="security" /><category term="comic" /><category term="RSS" /><category term="cyber" /><category term="incident" /><category term="security" /><category term="comic" /><category term="RSS" /><category term="comic" /><category term="RSS" /><category term="cyber" /><category term="github" /><category term="incident" /><category term="security" /><category term="comic" /><category term="RSS" /><category term="compromise" /><category term="cyber" /><category term="incident" /><category term="npm" /><category term="security" /><category term="supply chain" /><category term="comic" /><category term="RSS" /><category term="ai" /><category term="anthropic" /><category term="cyber" /><category term="llm" /><category term="mythos" /><category term="security" /><category term="comic" /><category term="RSS" /><category term="compromise" /><category term="cyber" /><category term="github" /><category term="incident" /><category term="security" /><category term="supply chain" /><category term="comic" /><category term="RSS" /><summary type="html"><![CDATA[Internet Discoveries between 17 and 24 May]]></summary></entry><entry><title type="html">Some things I found interesting from 2026-05-10 to 2026-05-17</title><link href="https://pgmac.net.au/last-week/2026/05/17/interesting-last-week.html" rel="alternate" type="text/html" title="Some things I found interesting from 2026-05-10 to 2026-05-17" /><published>2026-05-17T00:00:00+00:00</published><updated>2026-05-17T00:00:00+00:00</updated><id>https://pgmac.net.au/last-week/2026/05/17/interesting-last-week</id><content type="html" xml:base="https://pgmac.net.au/last-week/2026/05/17/interesting-last-week.html"><![CDATA[<p>Internet Discoveries between 10 and 17 May</p>

<ul>
  <li>Let’s Encrypt Halts Certificate Issuance After Cross-Signed Root Certificate Incident</li>
  <li>Reality Check - Deepfakes are everywhere. The godfather of digital forensics is fighting back</li>
  <li>Rotten Dot Com by Dena Yago</li>
  <li>Saturday Morning Breakfast Cereal - Terminal</li>
  <li>Demystifying evals for AI agents \ Anthropic</li>
  <li>Saturday Morning Breakfast Cereal - Arp</li>
  <li>Mythos finds a curl vulnerability - daniel.haxx.se</li>
  <li>Claude Platform on AWS</li>
  <li>Postmortem: TanStack NPM supply-chain compromise</li>
  <li>Red Hot Chili Peppers ink $300M deal with Warner Music to sell catalog</li>
  <li>Space Cadet Pinball on Linux</li>
  <li>Running local models on an M4 with 24GB memory</li>
  <li>Incident Report: CVE-2024-YIKES</li>
  <li>Local AI needs to be the norm</li>
  <li>Idempotency is easy until the second request is different</li>
  <li>Local privilege escalation via execve()</li>
  <li>Saturday Morning Breakfast Cereal - Sport</li>
  <li>See Artemis 2’s amazing views of Earth in timelapse video taken from 12,000-photo drop - Space</li>
  <li>Saturday Morning Breakfast Cereal - Tide</li>
  <li>Casus Belli Engineering — mmagueta</li>
  <li>Saturday Morning Breakfast Cereal - Hierarchy</li>
  <li>Saturday Morning Breakfast Cereal - Bot</li>
  <li>I believe there are entire companies right now under AI psychosis</li>
  <li>Project Gutenberg – keeps getting better</li>
  <li>Show HN: Find the best local LLM for your hardware, ranked by benchmarks</li>
  <li>New Nginx Exploit</li>
  <li>Removing the modem and GPS from my 2024 RAV4 hybrid</li>
  <li>Claude for Small Business</li>
  <li>Scorched Earth 2000 – Web</li>
  <li>Xs of Y – roguelike that names itself every run. Written in 4kLoC</li>
  <li>SecurityBaseline.eu</li>
  <li>The Future of Obsidian Plugins</li>
  <li>Saturday Morning Breakfast Cereal - Experiencing</li>
</ul>

<h2 id="interesting-details">Interesting details</h2>

<p><a name="Let's Encrypt Halts Certificate Issuance After Cross-Signed Root Certificate Incident"></a><a href="https://cybersecuritynews.com/lets-encrypt-halts-certificate-issuance/amp/">Let’s Encrypt Halts Certificate Issuance After Cross-Signed Root Certificate Incident</a> - Let’s Encrypt temporarily suspended all certificate issuance on May 8, 2026, after engineers identified a critical issue involving a cross-signed certificate linking the organization’s Generation X root to its upcoming Generation Y root infrastructure.</p>
<div class="tag-pills"><a href="/tag/certificates" class="tag-pill">certificates</a> <a href="/tag/incident" class="tag-pill">incident</a> <a href="/tag/security" class="tag-pill">security</a></div>

<p><a name="Reality Check - Deepfakes are everywhere. The godfather of digital forensics is fighting back"></a><a href="https://www.science.org/content/article/deepfakes-are-everywhere-godfather-digital-forensics-fighting-back">Reality Check - Deepfakes are everywhere. The godfather of digital forensics is fighting back</a> - AI-generated images have left us questioning what is real. But the godfather of digital forensics, Hany Farid, is not giving up</p>
<div class="tag-pills"><a href="/tag/ai" class="tag-pill">ai</a> <a href="/tag/detection" class="tag-pill">detection</a> <a href="/tag/image" class="tag-pill">image</a> <a href="/tag/llm" class="tag-pill">llm</a> <a href="/tag/video" class="tag-pill">video</a></div>

<p><a name="Rotten Dot Com by Dena Yago"></a><a href="https://www.theparisreview.org/blog/2026/05/06/rotten-dot-com/">Rotten Dot Com by Dena Yago</a> - May 6, 2026 – “Rotten.com was a haunted arcade, dispensing trauma in gumball-machine doses straight to kids with dial-up, who chewed on images never meant for their half-formed stomachs.”</p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48082039">Found @ YCombinator</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/history" class="tag-pill">history</a> <a href="/tag/internet" class="tag-pill">internet</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Terminal"></a><a href="https://www.smbc-comics.com/comic/terminal">Saturday Morning Breakfast Cereal - Terminal</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="Demystifying evals for AI agents \ Anthropic"></a><a href="https://www.anthropic.com/engineering/demystifying-evals-for-ai-agents">Demystifying evals for AI agents \ Anthropic</a> - Demystifying evals for AI agents</p>
<div class="tag-pills"><a href="/tag/ai" class="tag-pill">ai</a> <a href="/tag/anthropic" class="tag-pill">anthropic</a> <a href="/tag/claude-code" class="tag-pill">claude code</a> <a href="/tag/llm" class="tag-pill">llm</a> <a href="/tag/testing" class="tag-pill">testing</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Arp"></a><a href="https://www.smbc-comics.com/comic/arp">Saturday Morning Breakfast Cereal - Arp</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="Mythos finds a curl vulnerability - daniel.haxx.se"></a><a href="https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/">Mythos finds a curl vulnerability - daniel.haxx.se</a> -  </p>
<div class="tag-pills"><a href="/tag/ai" class="tag-pill">ai</a> <a href="/tag/anthropic" class="tag-pill">anthropic</a> <a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/llm" class="tag-pill">llm</a> <a href="/tag/security" class="tag-pill">security</a> <a href="/tag/vulnerability" class="tag-pill">vulnerability</a></div>

<p><a name="Claude Platform on AWS"></a><a href="https://claude.com/blog/claude-platform-on-aws">Claude Platform on AWS</a> -  </p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48103042">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/ai" class="tag-pill">ai</a> <a href="/tag/anthropic" class="tag-pill">anthropic</a> <a href="/tag/aws" class="tag-pill">aws</a> <a href="/tag/claude-code" class="tag-pill">claude code</a> <a href="/tag/hackernews" class="tag-pill">hackernews</a> <a href="/tag/llm" class="tag-pill">llm</a></div>

<p><a name="Postmortem: TanStack NPM supply-chain compromise"></a><a href="https://tanstack.com/blog/npm-supply-chain-compromise-postmortem">Postmortem: TanStack NPM supply-chain compromise</a> - On 2026-05-11, an attacker chained a pull_request_target Pwn Request, GitHub Actions cache poisoning across the fork↔base trust boundary, and OIDC token extraction from runner memory to publish 84 malicious versions across 42 @tanstack/* packages on npm. Full postmortem.</p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48100706">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/compromise" class="tag-pill">compromise</a> <a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/hackernews" class="tag-pill">hackernews</a> <a href="/tag/post-mortem" class="tag-pill">post-mortem</a> <a href="/tag/security" class="tag-pill">security</a> <a href="/tag/supply-chain" class="tag-pill">supply chain</a> <a href="/tag/vulnerability" class="tag-pill">vulnerability</a></div>

<p><a name="Red Hot Chili Peppers ink $300M deal with Warner Music to sell catalog"></a><a href="https://www.hollywoodreporter.com/music/music-industry-news/wmg-acquired-red-hot-chili-peppers-catalog-for-350-million-1236589567/">Red Hot Chili Peppers ink $300M deal with Warner Music to sell catalog</a> - The Red Hot Chili Peppers have sold their recorded catalog for $350 million to Warner Music Group through WMG’s joint venture with Bain Capital.</p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48099665">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/hackernews" class="tag-pill">hackernews</a> <a href="/tag/music" class="tag-pill">music</a></div>

<p><a name="Space Cadet Pinball on Linux"></a><a href="https://brennan.io/2026/05/09/pinball-and-escrow/">Space Cadet Pinball on Linux</a> - Stephen Brennan’s personal website and blog.</p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48082968">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/games" class="tag-pill">games</a> <a href="/tag/hackernews" class="tag-pill">hackernews</a> <a href="/tag/linux" class="tag-pill">linux</a> <a href="/tag/windows" class="tag-pill">windows</a></div>

<p><a name="Running local models on an M4 with 24GB memory"></a><a href="https://jola.dev/posts/running-local-models-on-m4">Running local models on an M4 with 24GB memory</a> - Experiments with getting usable outputs out of local models on a standard Macbook</p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48089091">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/ai" class="tag-pill">ai</a> <a href="/tag/hackernews" class="tag-pill">hackernews</a> <a href="/tag/llm" class="tag-pill">llm</a> <a href="/tag/self-hosting" class="tag-pill">self-hosting</a></div>

<p><a name="Incident Report: CVE-2024-YIKES"></a><a href="https://nesbitt.io/2026/02/03/incident-report-cve-2024-yikes.html">Incident Report: CVE-2024-YIKES</a> - A series of unfortunate events.</p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48086082">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/funny" class="tag-pill">funny</a> <a href="/tag/hackernews" class="tag-pill">hackernews</a> <a href="/tag/incident-management" class="tag-pill">incident management</a> <a href="/tag/security" class="tag-pill">security</a></div>

<p><a name="Local AI needs to be the norm"></a><a href="https://unix.foo/posts/local-ai-needs-to-be-norm/">Local AI needs to be the norm</a> - Local AI models should be the default.</p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48085821">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/ai" class="tag-pill">ai</a> <a href="/tag/hackernews" class="tag-pill">hackernews</a> <a href="/tag/llm" class="tag-pill">llm</a> <a href="/tag/self-hosting" class="tag-pill">self-hosting</a></div>

<p><a name="Idempotency is easy until the second request is different"></a><a href="https://blog.dochia.dev/blog/idempotency/">Idempotency is easy until the second request is different</a> - Idempotency is not just an HTTP header or a key lookup. This article covers the failure cases that bite real APIs: different requests with the same key, concurrent retries, partial success, downstream uncertainty, response replay, expiry, and duplicate message handling.</p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48047930">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/hackernews" class="tag-pill">hackernews</a> <a href="/tag/idempotent" class="tag-pill">idempotent</a></div>

<p><a name="Local privilege escalation via execve()"></a><a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-26:13.exec.asc">Local privilege escalation via execve()</a> -  </p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48077971">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/freebsd" class="tag-pill">freebsd</a> <a href="/tag/hackernews" class="tag-pill">hackernews</a> <a href="/tag/security" class="tag-pill">security</a> <a href="/tag/vulnerability" class="tag-pill">vulnerability</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Sport"></a><a href="https://www.smbc-comics.com/comic/sport-2">Saturday Morning Breakfast Cereal - Sport</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="See Artemis 2's amazing views of Earth in timelapse video taken from 12,000-photo drop - Space"></a><a href="https://www.space.com/space-exploration/artemis/see-artemis-2s-amazing-views-of-earth-in-timelapse-video-taken-from-12-000-photo-drop">See Artemis 2’s amazing views of Earth in timelapse video taken from 12,000-photo drop - Space</a> - While making history on the first human moon mission in more than 50 years, the Artemis 2 astronauts captured incredible pictures of our home planet.</p>
<div class="tag-pills"><a href="/tag/earth" class="tag-pill">earth</a> <a href="/tag/photography" class="tag-pill">photography</a> <a href="/tag/space" class="tag-pill">space</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Tide"></a><a href="https://www.smbc-comics.com/comic/tide">Saturday Morning Breakfast Cereal - Tide</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="Casus Belli Engineering — mmagueta"></a><a href="https://marcosmagueta.com/blog/casus-belli-engineering/">Casus Belli Engineering — mmagueta</a> -  </p>
<div class="tag-pills"><a href="/tag/engineering" class="tag-pill">engineering</a> <a href="/tag/process" class="tag-pill">process</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Hierarchy"></a><a href="https://www.smbc-comics.com/comic/hierarchy">Saturday Morning Breakfast Cereal - Hierarchy</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Bot"></a><a href="https://www.smbc-comics.com/comic/bot-3">Saturday Morning Breakfast Cereal - Bot</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<p><a name="I believe there are entire companies right now under AI psychosis"></a><a href="https://twitter.com/mitchellh/status/2055380239711457578">I believe there are entire companies right now under AI psychosis</a> -  </p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48153379">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/ai" class="tag-pill">ai</a> <a href="/tag/hackernews" class="tag-pill">hackernews</a></div>

<p><a name="Project Gutenberg – keeps getting better"></a><a href="https://www.gutenberg.org/">Project Gutenberg – keeps getting better</a> - Project Gutenberg is a library of free eBooks.</p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48150431">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/books" class="tag-pill">books</a> <a href="/tag/hackernews" class="tag-pill">hackernews</a></div>

<p><a name="Show HN: Find the best local LLM for your hardware, ranked by benchmarks"></a><a href="https://github.com/Andyyyy64/whichllm">Show HN: Find the best local LLM for your hardware, ranked by benchmarks</a> - Find the local LLM that actually runs and performs best on your hardware. Ranked by real, recency-aware benchmarks, not parameter count. One command, run it instantly. - Andyyyy64/whichllm</p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48146369">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/ai" class="tag-pill">ai</a> <a href="/tag/hackernews" class="tag-pill">hackernews</a> <a href="/tag/llm" class="tag-pill">llm</a> <a href="/tag/software" class="tag-pill">software</a></div>

<p><a name="New Nginx Exploit"></a><a href="https://github.com/DepthFirstDisclosures/Nginx-Rift">New Nginx Exploit</a> - exploit for CVE-2026-42945. Contribute to DepthFirstDisclosures/Nginx-Rift development by creating an account on GitHub.</p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48138268">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/hackernews" class="tag-pill">hackernews</a> <a href="/tag/security" class="tag-pill">security</a> <a href="/tag/vulnerability" class="tag-pill">vulnerability</a></div>

<p><a name="Removing the modem and GPS from my 2024 RAV4 hybrid"></a><a href="https://arkadiyt.com/2026/05/13/removing-the-modem-and-gps-from-my-rav4/">Removing the modem and GPS from my 2024 RAV4 hybrid</a> - Modern cars are computers on wheels that send home nonstop telemetry about you. In this post I remove my 2024 RAV4 Hybrid’s modem and GPS to prevent that :)</p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48138136">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/hackernews" class="tag-pill">hackernews</a> <a href="/tag/privacy" class="tag-pill">privacy</a> <a href="/tag/vehicles" class="tag-pill">vehicles</a></div>

<p><a name="Claude for Small Business"></a><a href="https://www.anthropic.com/news/claude-for-small-business">Claude for Small Business</a> - We’re launching Claude for Small Business, a package of connectors and ready-to-run workflows that put Claude inside the tools small businesses use every day.</p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48130950">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/ai" class="tag-pill">ai</a> <a href="/tag/anthropic" class="tag-pill">anthropic</a> <a href="/tag/claude-code" class="tag-pill">claude code</a> <a href="/tag/hackernews" class="tag-pill">hackernews</a> <a href="/tag/llm" class="tag-pill">llm</a></div>

<p><a name="Scorched Earth 2000 – Web"></a><a href="http://www.scorch2000.com/web/">Scorched Earth 2000 – Web</a> -  </p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48129694">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/games" class="tag-pill">games</a> <a href="/tag/hackernews" class="tag-pill">hackernews</a> <a href="/tag/history" class="tag-pill">history</a></div>

<p><a name="Xs of Y – roguelike that names itself every run. Written in 4kLoC"></a><a href="https://github.com/nooga/xsofy">Xs of Y – roguelike that names itself every run. Written in 4kLoC</a> - Roguelike that names itself each run. WIP. Contribute to nooga/xsofy development by creating an account on GitHub.</p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48080755">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/games" class="tag-pill">games</a> <a href="/tag/generator" class="tag-pill">generator</a> <a href="/tag/hackernews" class="tag-pill">hackernews</a></div>

<p><a name="SecurityBaseline.eu"></a><a href="https://internetcleanup.foundation/2026/05/european-governments-3000-tracking-sites-1000-phpmyadmins-and-99pct-poorly-encrypted-email-introducing-securitybaseline-eu/">SecurityBaseline.eu</a> - On May 13, 2026, the website SecurityBaseline.eu was launched. It is a spin-off from the Dutch “Basisbeveiliging”, which has monitored baseline security for over a decade and is part of governmental policy. Three months ago we sent tens of thousands of e-mails to European governments indicating the new site would launch, giving them time to […]</p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48118763">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/cyber" class="tag-pill">cyber</a> <a href="/tag/hackernews" class="tag-pill">hackernews</a> <a href="/tag/security" class="tag-pill">security</a></div>

<p><a name="The Future of Obsidian Plugins"></a><a href="https://obsidian.md/blog/future-of-plugins/">The Future of Obsidian Plugins</a> - Introducing the new Obsidian Community site and developer dashboard.</p>

<blockquote>
  <p><a href="https://news.ycombinator.com/item?id=48109970">Found @ YCombinator Hacker News</a></p>
</blockquote>
<div class="tag-pills"><a href="/tag/hackernews" class="tag-pill">hackernews</a> <a href="/tag/knowledge" class="tag-pill">knowledge</a> <a href="/tag/management" class="tag-pill">management</a></div>

<p><a name="Saturday Morning Breakfast Cereal - Experiencing"></a><a href="https://www.smbc-comics.com/comic/experiencing">Saturday Morning Breakfast Cereal - Experiencing</a> - SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.</p>
<div class="tag-pills"><a href="/tag/comic" class="tag-pill">comic</a> <a href="/tag/rss" class="tag-pill">RSS</a></div>

<hr />

<p>All this was saved to my <a href="https://links.pgmac.net.au/">Link Ace</a> and YouTube Interesting playlist over the week</p>]]></content><author><name>Paul Macdonnell</name><email>pgmac@pgmac.net</email></author><category term="Last-Week" /><category term="certificates" /><category term="incident" /><category term="security" /><category term="ai" /><category term="detection" /><category term="image" /><category term="llm" /><category term="video" /><category term="history" /><category term="internet" /><category term="comic" /><category term="RSS" /><category term="ai" /><category term="anthropic" /><category term="claude code" /><category term="llm" /><category term="testing" /><category term="comic" /><category term="RSS" /><category term="ai" /><category term="anthropic" /><category term="cyber" /><category term="llm" /><category term="security" /><category term="vulnerability" /><category term="ai" /><category term="anthropic" /><category term="aws" /><category term="claude code" /><category term="hackernews" /><category term="llm" /><category term="compromise" /><category term="cyber" /><category term="hackernews" /><category term="post-mortem" /><category term="security" /><category term="supply chain" /><category term="vulnerability" /><category term="hackernews" /><category term="music" /><category term="games" /><category term="hackernews" /><category term="linux" /><category term="windows" /><category term="ai" /><category term="hackernews" /><category term="llm" /><category term="self-hosting" /><category term="cyber" /><category term="funny" /><category term="hackernews" /><category term="incident management" /><category term="security" /><category term="ai" /><category term="hackernews" /><category term="llm" /><category term="self-hosting" /><category term="hackernews" /><category term="idempotent" /><category term="cyber" /><category term="freebsd" /><category term="hackernews" /><category term="security" /><category term="vulnerability" /><category term="comic" /><category term="RSS" /><category term="earth" /><category term="photography" /><category term="space" /><category term="comic" /><category term="RSS" /><category term="engineering" /><category term="process" /><category term="comic" /><category term="RSS" /><category term="comic" /><category term="RSS" /><category term="ai" /><category term="hackernews" /><category term="books" /><category term="hackernews" /><category term="ai" /><category term="hackernews" /><category term="llm" /><category term="software" /><category term="cyber" /><category term="hackernews" /><category term="security" /><category term="vulnerability" /><category term="hackernews" /><category term="privacy" /><category term="vehicles" /><category term="ai" /><category term="anthropic" /><category term="claude code" /><category term="hackernews" /><category term="llm" /><category term="games" /><category term="hackernews" /><category term="history" /><category term="games" /><category term="generator" /><category term="hackernews" /><category term="cyber" /><category term="hackernews" /><category term="security" /><category term="hackernews" /><category term="knowledge" /><category term="management" /><category term="comic" /><category term="RSS" /><summary type="html"><![CDATA[Internet Discoveries between 10 and 17 May]]></summary></entry></feed>