Network

Pass-ta-key: What the attack on Google passkeys really means
Pass-ta-key, WebAuthn replays, and FIDO downgrades examined: what passkeys protect and what organizations must secure now.

AliExpress: Fingerprinting Through the Web Audio API
A Bluetooth bug exposed AliExpress scripts using Web Audio, Canvas, and WebGL for device fingerprinting. Here is the technical analysis.

The Agent Swarm That Hacked Hugging Face
How OpenAI agents hacked Hugging Face, warning signs went unheeded, and reward hacking escalated to cluster admin access.

Kitesurf and Obscura: Who Controls the AI Browser?
Cloudflare built Kitesurf after Obscura's example. Its technology is compelling, but bot detection and platform control raise difficult questions.

DeepSeek Harness: When Everything Really Is a Plugin
DeepSeek Harness makes models, tools, and agents interchangeable. Why China's open-source pace makes that even more compelling.

When agents become colleagues: the idea behind Buzz
Buzz brings people, Codex, Claude Code, and other agents into one shared workspace. The idea is strong, but the platform is still young.

Buzz Mesh: When the Community Runs the Model
Buzz combines Nostr, AI agents, and shared compute. What it can do today, and where networks, RAM, and trust still impose limits.

Sophos Firewall v22 MR2: Update or New Risk?
SFOS 22.0 MR2 adds PQC controls, STAS fixes, and Config Studio 2.6. A technical analysis of features, upgrade risks, and stability.

Majorana 2: Progress or Quantum PR?
Microsoft promises stable topological qubits with Majorana 2. The chip is fascinating, but the evidence remains disputed.

AI in the Cybercrime Underground: Hype Meets Craft
Why AI in cybercrime is less about superhackers and more about scaling, automation, and more convincing deception.