AI assisted security findings are coming in

AI assisted security findings are coming in

XINT.io, with the help of AI, just demonstrated a 732 byte exploit that gets root on every major Linux distribution shipped since 2017. This is a flaw that went unnoticed for almost a decade now. You can only imagine how many more AI is going to help people find.

Copy Fail (CVE-2026-31431) is a logic bug in the Linux kernel’s authencesn cryptographic template. It lets an unprivileged local user trigger a deterministic, controlled 4-byte write into the page cache of any readable file on the system. A single 732-byte Python script can edit a setuid binary and obtain root on essentially all Linux distributions shipped since 2017.

3D AI Generated worlds

3D AI Generated worlds

Project Genie is an experimental Google DeepMind AI system that creates interactive, navigable 3D worlds from text prompts, sketches, or images. Powered by the Genie 3 world model, it simulates physics and consistent environments in real-time.

U.S. Military Archbishop Timothy Broglio

U.S. Military Archbishop Timothy Broglio

How does the Catholic Church view a lot of recent US military actions and dramatically different political methods from over 100 years of established policy?

While the US government’s way of handling of foreign affairs may be changing dramatically, the Church’s stances on these topics are not. US military Archbishop Broglio gives a great summary of the Catholic Church’s long-standing moral teaching principles including Just War doctrine (which goes back to St Ambrose and St Augustine).

OOP’s impact on data arrangement was a 35 year mistake

OOP’s impact on data arrangement was a 35 year mistake

Casey Muratori at the Better Software Conference walks us through how data in game development (and other systems) started with simple coherent structures that were best for cpu and cache coherency layout and then morphed into hierarchies of objects that following the in-vogue trend of late 90’s programming.

This lead to changing the compile-time data arrangement from what’s best for the computer to compiling data into arbitrarily arranged memory locations that matched the real-world things you’re trying to model.

He does a great job of breaking down the history and effects of what has happened in the 20 years since. I remember going to a GDC talk in which a game developer building a racing game struggled and struggled to get performance from his OOP arranged data. In the end, he realized that he should simply lay out the data in memory linearly and got multiple times more speed.

Today, developers from racing games to AI are re-discovering that laying things out linearly and adhering to cache consistent access (ex: GPUs) is where the highest end performance is unleashed.

Horseshoe politics – so open minded your brain fell out

Horseshoe politics – so open minded your brain fell out

Despite being a supposed bastion of progressive liberals, Portland has been globally lambasted for it’s anti-science stances. Firstly, for voting down fluoride in it’s water not once or twice, but 4 times in a decade.

Portland is also so progressive as to not believe in the evils of the chemicals in vaccinations. Oregon now has the 2nd highest nonmedical vaccination exemption rate in the country. Starting 2 years ago in 2024, now Portland is seeing a regular occurrence of measles outbreaks. Here’s some of the 11 statewide outbreaks from just the last few months. The CDC can give you even more.

I no longer believe those cute little signs people in Portland put in their lawns that say they believe in science. They clearly do not.

Zero-day vulnerabilities to exploit

Zero-day vulnerabilities to exploit

I knew the pace of exploitation of security issues was getting faster and faster, but this chart shocked me. In just 5 years since 2021, the time between when a security issue is found and security researchers find people trying to exploit it went from 1.3 years to 1.6 DAYS.

While not entirely due to AI, I think hackers and exploiters are likely using AI to more quickly generate exploits. Project Glasswing was started because the upcoming version of Anthropic’s AI was finding zero-day exploits in browsers and operating systems at an alarming rate. Instead of just releasing the AI, they’re working with OS vendors from Apple to Microsoft to Linux to fix many of them before hackers take advantage of the holes.

The code that showed up in the Terminator movie

The code that showed up in the Terminator movie

Turns out, a lot of it is 6502 assembly language. That’s right, the cpu used in the Commodore Vic-20, Atari 400 and 800, and Apple II.

Blocks of code displayed? How about code to load the VTOC (volume table of contents) from a floppy disk from the Apple II DOS 3.3 era.

Installing IRIX 6.5.2 on MAME

Installing IRIX 6.5.2 on MAME

SGI system’s were the absolute pinnacle of 80’s and 90’s era graphics computing. Re-creating that world, however, is harder than one thinks. While old OS’s are often easily run in virtual machines, SGI’s Irix and other os’s do not run well in virtual machines. In fact, only certain versions of MAME seem to work – and getting it working is a real experiment in patience.

Here’s one of the few instruction threads that seems to work.

90% of losses caused by drones

90% of losses caused by drones

The Russians are having a very rough spring. The Ukrainian forces have very reliable and verifiable numbers that over 35,000 Russian soldiers were killed or seriously wounded in March alone.

Even more crazy is that 95% of those causalities were cause by drones. Drones are becoming so prevalent, they’re regularly attacking and killing targets up to 100km behind enemy lines.

Modern warfare is changing profoundly as we watch. While these drones are all piloted by actual people, imagine turning thousands and thousands of AI controlled drones with grenades loose on a battlefield. Entire battles could be won with automated killers.

This could also be done by terrorist groups or assassins. Drones could be turned loose at a rally or in government office building to seek and destroy key targets or cause mass casualties. The future is frightening.