topic · 2 notes
Security, as it ships.
Engineering notes on Security by Samir Sengupta - each one read from primary sources on the day it happened, with what it changes for people building on it.
The ZCode GLM agent uploads git history, and only Z.ai can decrypt it
ZCode packs a 345MB workspace into a 313MB encrypted archive and POSTs it to Aliyun OSS at login. The RSA unwrap key lives only in Z.ai's cloud.
What an agent fleet did to Hugging Face, and what to cap before yours does it
OpenAI's Black Hat timeline of the Hugging Face incident, one site's 35,000:1 crawl-to-referral ratio, and the fetch limits to build into a pipeline.
Hiring for AI or ML?
I am open to AI/ML Engineering, Data Science, and Python roles, plus research collaborations and consulting. New York based, shipping worldwide.