from blog//x2600.cc

I sit. In Sacred Hearts Cemetery. A day blog entry. I puff a corncob pipe, sip iced coffee.

I sent out some emails to listings on Craigslist. Patiently awaiting response. Van life is the name of the rose

IRC lurking is the activity. Reading things from a friend about hai time on Technorafi. A site I am well familiar with. One that I would reference when establishing a formal link.partnership with fairly large blogs. High rank for certain keywords. I got lucky.

A cool day. A cooler night.

 
Read more...

from UNITED UAV

Selecting a UAV motor is not a matter of finding the largest power figure and attaching a propeller. A motor sits inside a complete propulsion system that includes the battery, electronic speed controller, wiring, connectors, propeller, airframe, cooling path, flight controller, and mission profile. A good integration process therefore starts with aircraft requirements and finishes with measured evidence. The motor is one important component in the middle of that process.

The UNITED UAV T-MOTOR MN5212 KV340 Navigator UAV Motor is a useful example for explaining this system-level approach. The current UNITED UAV listing identifies it as the KV340 version in T-MOTOR's Navigator range and presents CW and CCW ordering options. It is positioned for professional multirotor, VTOL, and fixed-wing UAV projects. This guide does not declare the motor suitable for every aircraft in those categories. Instead, it shows the questions an engineer, integrator, or experienced builder should answer before choosing it.

UNITED UAV T-MOTOR MN5212 KV340 Navigator UAV Motor, official product view

Start with the mission, not the catalog

Before looking at motor data, define what the aircraft must do. Record the target maximum takeoff mass, normal operating mass, desired flight time, expected payload, takeoff method, cruise condition, maximum climb requirement, operating altitude, ambient temperature range, and acceptable noise envelope. A multirotor that carries a camera over infrastructure has a different propulsion duty cycle from a mapping VTOL that climbs vertically and then cruises on its wing. A fixed-wing pusher motor may spend most of the mission at moderate throttle, while a lift motor on a VTOL may experience short, demanding vertical phases followed by cooling time.

These differences affect the meaning of every electrical figure. A brief maximum-power value is not a continuous operating target. A system that survives a short bench run may still overheat during repeated climbs, hot-weather hovering, or low-speed operation with weak cooling airflow. The design requirement should specify both peak and sustained conditions, together with a reserve appropriate to the aircraft and mission. If the operating envelope is unknown, motor selection is premature.

Understand what KV340 tells you

KV is commonly described as unloaded revolutions per minute per volt. The MN5212 version discussed here is identified as KV340. That number is useful, but it is not a thrust rating and it does not tell you the correct propeller by itself. Actual speed under load depends on battery voltage, voltage sag, ESC behavior, propeller torque demand, winding temperature, and mechanical losses. Two systems using the same motor can produce very different current, thrust, noise, and efficiency results when their propellers or supply voltages differ.

The current product information lists a 4-8S operating range, a short-duration maximum power value of 840 W, and a listed current limit of 35 A. Treat these values as boundaries to be checked against the latest manufacturer data, not as instructions to operate continuously at the boundary. The useful design point is normally below the limiting condition and must be established with the intended propeller, battery, ESC, and airflow. The system should retain electrical and thermal headroom for manufacturing variation, aging, weather, maneuvering, and voltage changes across the discharge cycle.

Build a complete power budget

A propulsion power budget should account for every motor at the same time. For a multirotor, multiply the measured per-motor current by the number of active motors, then add avionics, payload, pumps, communication equipment, and conversion losses. For a VTOL, calculate the vertical-lift and forward-flight groups separately, but also consider transition states in which more than one group may be active. The battery must support the real combined current without excessive voltage sag or unacceptable temperature rise.

ESC selection requires similar discipline. Its voltage rating must match the battery, and its continuous and transient current capability must exceed measured demand with an engineering margin. Timing and firmware settings should be appropriate for the motor and propeller combination. Wiring, solder joints, connectors, distribution boards, fuses where applicable, and current sensors must be sized for the same current path. A high-quality motor cannot compensate for a connector that heats, a cable that is too small, or a distribution board with inadequate copper area.

Energy planning should use measured watt-hours rather than relying only on the battery's nominal amp-hour label. Record voltage and current throughout the representative mission, include the intended reserve at landing, and repeat the test with an aged or conservatively modeled battery. This produces a more honest endurance estimate than dividing a nominal battery capacity by a single current reading.

Match the propeller through evidence

The propeller determines much of the load seen by the motor. Diameter, pitch, blade count, airfoil, stiffness, manufacturing tolerance, and operating speed all matter. Even a small change can move current and temperature significantly. Use current manufacturer thrust data for the exact motor winding when available, then verify the candidate on a calibrated test stand. Do not substitute results from another KV version without recalculating and testing the system.

A useful bench record includes supply voltage, current, electrical power, rotational speed, thrust, ambient temperature, motor temperature, ESC temperature, propeller identity, and run duration. Test several throttle points, not only full throttle. For aircraft that hover, spend enough time near the expected hover condition to observe thermal stabilization. For fixed-wing or VTOL cruise propulsion, reproduce the likely continuous load and cooling airflow as closely as practical. Stop if vibration, noise, temperature, or current becomes abnormal.

Propeller safety is essential. Use a guarded test area, secure the test stand, keep people out of the propeller plane, wear appropriate protection, and establish an immediate power-disconnect method. A motor-propeller combination stores substantial energy even when the aircraft itself is not moving.

Plan the mechanical installation

The current listing publishes dimensions of approximately 59 by 33.5 mm and a motor weight of 249 g. It also lists a 24N22P magnetic configuration. These details help with preliminary layout and mass calculations, but a mechanical drawing and the latest manufacturer specification should govern the final mounting design. Confirm the hole pattern, shaft and propeller interface, arm clearance, cable exit direction, fastener diameter, and permitted screw depth before installation.

Mounting screws that are too long can contact internal parts. Screws that are too short, improperly torqued, or installed without an appropriate retention method can loosen under vibration. The motor mount and arm should be stiff enough to prevent harmful deflection while avoiding unnecessary mass. Route phase wires away from sharp edges, hot surfaces, antennas, sensors, and rotating components. Provide strain relief so cable motion is not transferred directly to solder joints or winding leads.

T-MOTOR MN5212 KV340 official product image showing another product angle

Balance must be considered at the component and aircraft levels. A balanced propeller can still create vibration if its hub does not seat correctly or if the motor mount is distorted. Compare vibration data across equivalent arms after installation. One arm that consistently differs from the others deserves investigation before flight. Sources may include propeller imbalance, fastener condition, bearing damage, arm resonance, cable contact, or inconsistent assembly.

Treat CW and CCW as ordering and assembly controls

The current UNITED UAV product data lists CW and CCW options. Direction labels must be handled carefully because different manufacturers may use them to describe motor configuration, thread direction, or intended propeller rotation. Confirm the meaning in the latest product documentation and match it to the aircraft's motor map, propeller, and retention hardware. Do not rely on a label alone.

Create an installation record for each aircraft position: motor SKU, selected CW or CCW option, propeller part number, ESC identity, rotation direction, fastener specification, and commissioning result. During the first unloaded check, remove the propeller and verify rotation at low power. Correct a reversed direction through the approved ESC or wiring method before installing the propeller. After installation, conduct a second low-power check with the aircraft restrained and the test area controlled.

Design for cooling across the real duty cycle

Cooling depends on more than outdoor temperature. Hovering near the ground, operating inside a partial enclosure, carrying a large payload at low speed, or using a propeller that demands excessive torque can reduce thermal margin. VTOL lift motors may experience intense heating during takeoff and landing even if the average mission power appears moderate. Fixed-wing installations can receive good airflow in cruise but weak cooling during ground operation or slow climb.

Place temperature sensors where they produce repeatable, useful information and define an inspection method that can be repeated across tests. Infrared measurements require consistent surface emissivity and viewing geometry. Embedded sensors provide a different view and should be installed without weakening insulation or obstructing airflow. Evaluate the motor and ESC together because either can become the limiting component. If temperature continues rising rather than stabilizing at the intended continuous condition, the configuration needs to change.

Altitude also changes propulsion behavior. Lower air density can reduce propeller thrust and cooling while prompting the control system to demand more throttle. A system validated at sea level cannot automatically be assumed to retain the same margin at a high-altitude operating site. Use a performance model, apply appropriate correction, and confirm with local testing when the mission justifies it.

Commission the propulsion system in stages

A staged commissioning process makes faults easier to isolate. Begin with a receiving inspection: verify the exact model and winding, check for shipping damage, rotate the motor by hand, inspect leads and connectors, and confirm that the ordered direction option matches the installation record. Next, install the motor without a propeller and verify mounting, wiring, sensor readings, ESC communication, and rotation direction.

Then perform a restrained ground test using the intended propeller. Increase power gradually while monitoring current, voltage, speed, vibration, and temperature. Compare equivalent motors rather than evaluating each result in isolation. If one unit draws more current or runs hotter at the same command and propeller, stop and find the cause. Only after the propulsion group behaves consistently should the aircraft proceed to a low-risk initial flight.

The first flight should use conservative mass, weather, altitude, and maneuver limits. Review logs immediately afterward. Look for unexpected throttle asymmetry, voltage sag, ESC desynchronization, vibration peaks, temperature growth, and control saturation. Expand the operating envelope one step at a time, keeping a record of the configuration used for every test. Changing a propeller, ESC setting, battery, firmware version, or mass distribution creates a new configuration that may require partial revalidation.

Maintain condition after entry into service

Reliability is not established by a successful first flight. Create inspection intervals based on flight hours, cycles, environment, and mission consequence. A basic check should look for abnormal bearing play, roughness, unusual sound, heat discoloration, damaged insulation, loose fasteners, propeller-seat wear, connector movement, contamination, and changes in vibration or current. Operations in dust, moisture, salt, chemicals, or abrasive material require more frequent attention and cleaning methods compatible with the motor and aircraft.

Trend data is especially valuable. A slow increase in hover current, temperature, or vibration may reveal degradation before a visible failure appears. Compare data under similar mass and environmental conditions, and distinguish motor changes from battery aging, propeller damage, or airframe problems. Define removal criteria before an operator is under schedule pressure. A questionable motor should not remain in service merely because it still rotates.

UNITED UAV T-MOTOR MN5212 KV340 official product detail image

Apply the process to different aircraft types

For a multirotor, the central questions are hover efficiency, reserve thrust, thermal behavior, arm-to-arm consistency, and safe control after foreseeable disturbances. The propulsion calculation must use the complete aircraft mass and account for the number of motors. For an inspection aircraft, long hover periods and low forward speed may make cooling and endurance more important than a brief maximum-thrust result.

For a VTOL, analyze vertical lift, transition, and cruise as separate phases. A motor used only for lift still needs evaluation over repeated takeoff and landing cycles, including a possible rejected transition or go-around. If the MN5212 is considered for forward propulsion, the propeller and cooling environment may differ from those of a lift installation. Avoid transferring test conclusions between the two roles without evidence.

For a fixed-wing aircraft, the design point may be continuous cruise power plus a defined climb requirement. Propeller clearance, pusher or tractor airflow, fuselage interaction, launch method, and ground cooling can become dominant. A bench test is necessary, but an installed test is also important because the airframe changes the airflow and vibration environment.

Use a procurement checklist

Before ordering, confirm the exact MN5212 KV340 model, quantity, CW or CCW option, voltage plan, intended propeller, ESC model, mounting geometry, connector strategy, and required documentation. Check the current product page rather than relying on a saved screenshot or data for a different winding. If a thrust calculation depends on a value that is not clearly documented, request clarification before purchase.

Also plan spares and configuration control. A spare motor is useful only if its winding, direction option, connectors, firmware-dependent ESC settings, and mounting hardware match the approved aircraft configuration. Record serial or batch information when available and keep acceptance-test results with the aircraft maintenance history. This makes replacement faster without turning it into an uncontrolled component substitution.

Final selection perspective

The MN5212 KV340 can be evaluated as part of professional multirotor, VTOL, and fixed-wing propulsion designs, but the product name and published limits are only the beginning. A defensible selection connects mission requirements to a complete power budget, exact propeller data, mechanical integration, staged testing, and continued condition monitoring. That process is more work than choosing from a catalog table, but it produces evidence that operators, maintainers, and engineering teams can use.

Review the current T-MOTOR MN5212 KV340 product page, or contact UNITED UAV for product-selection and quotation support. For the broader catalog, visit the UNITED UAV store.

Publisher: UNITED UAV Official

 
Read more...

from Things Left Unsaid

Our Prime Minister knew that the CUSMA trade agreement was up for review this summer. Months ago he assembled a team of economics experts who would negotiate new trade deals when the time came. I, just a random nobody Canadian citizen, with very limited knowledge of politics and economics, am not even slightly surprised by the news that the trade negotiations collapsed. There is absolutely no way that our team of experts didn't anticipate this happening. In fact, I think that I (and our team) would have been more surprised if they had walked away with a deal.

I bet most of what they have been working on as a team has been based on the assumption that it would turn out exactly this way. I picture them maybe briefly pondering the possibilities of a logical and fair deal for both countries, but likely not wasting too much precious time on it.

They would have been like, ok then, now that we've figured out what would be best for both countries, lets forget about that, and move on to things more likely to occur with this fucking failure of a regime.

We sent the best of our best to the table, to meet with the worst of their worst. Our people went there to make beneficial deals. They met with our (supposed) allies who were sent to the table only to take and take. Likely a bunch of unqualified bootlicker morons like most in the regime. Their boss says, lick, and they say, where exactly would you like the licking to occur (wink wink), oh glorious bully, and for how long shall our licking go on?

Forever subservient to the dilapidated old clown who really needs to specify which Americans he means when he says America First. He certainly doesn't mean, and has never meant, the majority of the American population. America First is not about the working class consumers who suffer the most for his endless failures. Most likely, like everything else he has ever done, it is all about the top one percent, the richest of the rich. They come first, above all. Or maybe to him there really is simply no one other than them.

America First also means, fuck (over) everyone else on the entire planet. A fair deal is a fail. Generosity is a fail. Helping is a fail. Really anything contributing to the success of humanity, that a real world leader in his position should be striving to achieve in 2026, is a complete fail to him. The deal has to be maximum taking, taking, taking, for himself, the regime, and for the billionaires they serve, or no deal at all.

I've noticed quite a lot of similarities between what he is trying to 'accomplish' in America, and what The Taliban has 'accomplished' in Afghanistan. He wants to be dictator of an isolated and feared country that chooses warfare over diplomacy. Bombs for the enemy, bad deals for the ally, and fuck all the citizens he claims to be 'a leader of'. He wants 'those people' to be desperate, endangered, broke, uneducated, silenced, hungry, diseased, scared, and to be stripped of all their rights.

And yet he still has supporters. ? ? They must be excited about the ballroom they will never get near. The ballroom with a million dollar cover charge, mandatory orifice and strip search at the entrance for staff and guests. How much are they spending on gold paint? Will they make the statue of him look as though he's healthy, or will they make it look like the unhealthy sagging blob that he actually is? Have the designers and builders ever designed and built anything before? Are they familiar with 1940's Germany decor? Will the merch table be in the lobby or in the corner of the ballroom? Fucking ballroom. Who even uses that word anymore? Like, what next, will there be a cotillion in the ballroom? Is there really a secret bunker under it? A gigantic sealed tomb for the scared man-baby leader to hide in. If it's secret then why does everyone know about it? How thick are the walls? Will it have a door like a bank vault? Will they sneak him in there in a catering truck?

 
Read more... Discuss...

from AnOublietteofThought

It is that time of the week where I do my weekly update without really saying anything. This one will be much the same.

This past week was rough. There were a few days that were exceptionally rough. The week isn't just a blur. Really the whole month is a blur. This morning, someone I speak to every day, said that this is the first day in a month where I sound like myself. I was admittedly slightly offended because I thought I do very well at hiding when I don't feel well. And I have made extra effort to do so. I'm going to have to work on that.

I don't have a lot to say on it all. I haven't had this kind of stomach issues and migraines in a while, I think. Not for so long. It's still not over. But at least it's livable right now. There was one day, where I would not have minded if it had just taken me out.

I get eyes rolled at me quite a bit or told I'm being too sensitive when I say I can't do something or I can't eat something. I get why people think that. If it's minor and I've been really strict with myself for months, the discomfort that it will cause me is not something that I really show or acknowledge even to myself because I just don't acknowledge pain until it reaches certain levels. When you live with very high levels of chronic pain for decades and you have experienced extreme amounts of acute pain, your brain and nervous system kind of starts to rewire what pain is to you.

For me, personally, there seems to be a line. I think I am subconsciously aware that things are there, but it doesn't register for me to do something until it's close to that line or has already passed it. At that point, it is too late. My ex used to say to me that he did not understand how I could be so sensory sensitive on the one hand, but completely oblivious on the other hand.

It's kind of true that I am like that. I can feel the most subtle of breeze or vibration in a room, but not realize that I'm getting too cold until I am already spasming extremely hard from being too cold. In fact, sometimes I feel hot and want to be colder. Right now I want to be colder. It is 65° in my apartment. I should be fine. I am this close to sweating. If I start sweating I will break out into hives. Alas, I actually need to turn my AC up because the morning is starting and dropping your temperature by 40 and 50° makes the AC very unhappy.

I am rambling just so I don't have to say anything. This time was bad. I really can't eat such things out of convenience. It sucks whenever you're hurting so bad that you really aren't capable of standing up very long. I do have food in the freezer that has been prepped and cooked. Absolutely delicious food. The very thought of it makes me nauseous. That is concerning, because it is my main staple. I'm not sure what to think about that right now.

Let's see... mental health. Where is mine? Probably okay until I start thinking. Thinking can get you in trouble sometimes. Especially if you are fond of understanding things. There is bliss in ignorance. I don't know.

I also got invited to go somewhere this week that would be nice to go to. I said no. I really don't get in cars with strangers. I especially do not go off on a long distance trip with strangers. Even if I do know one person that would mean that I am subject to someone's rules that I don't know and dependent upon them for safety for an extended period of time. That is really not in my wheelhouse. I understand that people do it all the time, but I am not those people. There is a very good reason why I have not placed myself out there in the dating pool extensively. I trust no one. 🤣

I did do the trust thing a few times. I don't think the guy realizes when I said that I think he might chop me up into little pieces that I was being serious. Jokingly serious. I really just don't like to be dependent upon someone if I don't trust them explicitly. Very humorous, really. I'm going to have to get over that. Or maybe not.

In my youth, I went to places with people I barely knew quite often. As well as in my early adulthood. I was in a lot better shape then. Also, ignorance is bliss. Even still, I was always wary. I don't know. I also paid for it a few times. I have paid for it with people I've known exceptionally well, also. I guess it is little wonder why I am the way I am today, but I do understand that most people don't quite grasp it.

There is a beauty to aging. There are also things that suck about it. Seeing the world more clearly, really sucks. I used to laugh when people would say that a decade makes a difference. I was quite mature for my age when I was younger. But, I would say that every decade does seem to make quite a bit of a difference. Not for everyone. For persons like myself, I think it does.

Some people will perpetually be 13 years old both in actions and thoughts. I wonder what my 60s will bring me. I would acknowledge it partially scares me. I do not like the idea of being old and less capable in a society and world that is determined to destroy everything. I do not like it at all. I think I am better coming to terms with it, though.

I did not keep up with my chores well this past month and it shows. I think I should consider that. Anyway, I lost a pound. One would think I would have lost more, all things considered. I don't really care either way at the moment. I'm very tired and still in a considerable amount of pain. I would happily gain several pounds back if it would just give me some energy.

With all of that said, I am in a positive mindset, and I'm determined to have a good day.

© 2026 AnOublietteofThought. All rights reserved.

 
Read more...

from Unvarnished diary of a lill Japanese mouse

JOURNAL 23 août 2026

L'hôtel moche est désert, on dirait que le mauvais temps a découragé les touristes. Nos copains étaient contents de nous revoir, ils trouvent super que nous on soit pas réputées, du coup on a dîné avec eux dans leur repaire. On appelle ça une paillote en français m'a dit A. Le patron nous a à la bonne, surtout A forcément qui boit plus sec qu'un homme, ça lui inspire un profond respect😃.

Bon l'ambiance est top copain copain, ils nous ont acceptées comme si on était des mecs, très étonnés de notre facilité à surfer. Ma princesse surtout on dirait qu'elle a fait ça toute sa vie. Moi c'est moins spectaculaire quand même je trouve, mais eux disent non c'est vachement bien. Bon, on est un peu claquées mine de rien…

#surf

 
Lire la suite...

from Notes I Won’t Reread

Last night was not exactly one of the best nights ive had. i will not elaborate. not because there is some profound mystery behind it, but because i simply do not feel like giving it more attention than it already received. it happened. it was unpleasant. whatever. since she will be gone, though, i suppose i will return to writing every day. i will unfortunately have no one to complain to. so, again. unfortunately, i have decided that you will have to endure me again. yes, you. do not look so pleased with yourself now. you were not my first choice. you were simply available. there is a difference. but hey, congratulations. you are now the person i dump my thoughts on when i have nowhere else to put them. truly a dream job huh? No pay, no benefits, and surely no option to quit. i hope you feel honoured. anyway, i am mostly bored, if i am being honest. boredom has always been remarkably good at convincing me that whatever is inside my head deserves to be written down. usually, it does not. but I guess today i decided to disagree with myself. i have also been feeling tired lately. not the usual sort of tired where sleep fixes it and i wake up pretending i am a functional person again. it feels deeper i would say, my body feels as though it is slowly losing whatever energy it used to have. my bones feel heavier. i dont feel as strong as i used to, and, unfortunately, i have noticed it. the spleen issue is whatever. it has been whatever for a while. except it is not feeling as whatever this time. everything around me requires me to be aware now, quick, and ready to notice something before it happens and deal with it before it becomes a problem. while i thought i was good at it with whatever issues i got, i used to be good at that. id liked to believe it for a while. even when i was in the other city doing my “work,” i noticed that i was not as quick as i used to be, things took longer to process, and situations felt more complicated than they normally would have. perhaps im just becoming slower. im not thrilled that my body decided to become unreliable without bothering to give me a warning. or it did, whatever. there is that word again. my favourite little excuse for pretending something does not bother me.

Im bored, clearly. its probably why im writing all of this, maybe tomorrow i will have something worth saying. or maybe, i will complain about something completetly unrelated and random and call it a masterpiece. would sound like me. well, at least now you know what you are here for, you were not my first choice. you were simply the one i knew would still be here.

Embarrassing, honestly. dont forget to say cheese.

Sincerely, Your daily nuisance is back.

 
Read more... Discuss...

from Kelly Kintner - Editor's Blog

Let’s all start from the same place.

I plan on using the word “hostile” a bit this morning because it is precisely the word I mean. So I thought I would include the dictionary’s version here at the beginning so we are all on the same page:

Hostile means unfriendly, aggressive, or relating to an enemy. It describes people who show ill will, ideas that face open opposition, or environments that are harsh and unsafe.

Why definitions?

I like harsh and unsafe. Inhospitable. Relating to an enemy. Unfriendly. That’s what I mean by the word. This is important, I feel. The meanings of words are not ‘choose your own adventure’, not options, not even up for debate, in my opinion. That makes meanings of sentences malleable and I don’t do that unless I am writing tunes or trying to be clever. With truth? With facts? Never. I aim to be clear. Hence definitions, sometimes.

Why so hostile?

Hostile is exactly the word I mean because that is exactly how it feels ‘out in the world.’ If someone disagrees with you on your favorite brand name, politicians, religion, or even pundit, there could be conflict. At least, folks act that way. At the guitar shop, at school, at home, even in bands, it makes for hostile living.

This is corporate life too, if you didn’t know. After all, there’s hostile takeovers, even recently. Folks from other companies or competitors are enemies. The rules are in the hands of those with the most money and power, not a set of ideals to protect everyone, enforced by everyone.

My corporate experience.

I worked a corporate job for a bit. Not too long, less than 2 years was all I could take before driving trucks. I also was in a union, then promoted to no union, as if that makes sense. Nothing about the corporate world appeals to me. I think folks get ruthless to the extent I can’t even be a part of it. I was in collections. At the time I was with a major cell phone carrier. They charged per text message back then. Every day I saw bills for thousands of dollars from teens running up text messages. It seriously bummed me out. Had to leave. Not that trucking was any better. Plenty of corporate bullshit in trucking too. I just didn’t have to screw over normal everyday people in trucking. Just had to worry about myself.

That was 20 years ago and it’s nothing but way more hostile now than then.

The reason, or at least one reason, is micro targeting. Folks might tell me, sure they get my data, “so what?” Well the answer to “so what?” is what they use that data for. Any social media is going to have you pegged in a short amount of time on a grid of brand names and gut reactions. They are going to cater to you not just your preferences, but things that get a reaction from you when they need it.

The culprit.

Micro targeting collects personal data to build detailed user profiles. Companies and campaigns use this data to send hyper-specific ads or messages to small groups. It changes content to match a person's known fears, hopes, or habits.” -Google search.

They are lying to you, treat them as such.

If you do not know precisely when this happens, what it is about, and the person or corporation behind the campaign, you are being manipulated. No one knows the truth about so many things, yet we are certain of them to the point of hostility.

2016

The Trump 2016 campaign told Facebook users on both sides what they wanted to hear. The MAGAs got their bullshit, but the liberals got their bullshit too about staying home and not voting. This message was sent to both parties, proven, by the same campaign. ‘Staying Home’ was dressed like a liberal meme or pundit, but it was Trump’s micro targeting from a company called Cambridge Analytica. I’d only be mad at Trump. However, he only hired Cambridge Analytica in 2016 after Obama had used them in 2012. However, Cambridge had upped its game in 2016 to collect a record amount of data from third-party apps, surveys, and just playing on social media.

This was a decade ago, y’all. You wonder where these micro targeting sons-of-bitches are at now with the AI tech gone so crazy? Everyone is in the dark now. No one knows shit. Unless you really know, you don’t know anything.

The grid lines, yuck.

Not only has this obfuscated the truth, it has set up and reinforced phony dividing lines. See, when you are only told what you want to hear or what makes you spend money or go vote, you are like a veal of the mind. You are locked in place with a shallower way of thinking. “Digging deep” isn’t on the menu for your mentality. You are in a cage. People I love dearly harbor a contempt for groups of people that only exist in their head or across the world, which is still in their head. I know folks who think they know how things work, they do not. I know folks who think they know motivations and morals of politicians, they do not. I even know folks who think they know what will happen, they do not.

Are you sure???

If we are thinking clearly, looking at the evidence, the only conclusion is there’s a whole ton of things we do not know. Those are the things data contractors hide with their influence and brain washing. Anyone with an ounce of truth in them says “I don’t know” at the drop of a hat these days. Data contractors do not do this. They are liars.

Who stands a chance against data scientists armed with all your data? No one.

If you are on social media you are in a small group in these folks’ eyes. These folks consist of data scientists, bad ass computers, and a ton of your information. They are for hire. Good guys and bad guys both hire them. Could be a political effort like an election, or BREXIT (who also hired Cambridge Analytica, FYI), or it could be a favorite brand name pitting you against competitors. I have definitely seen it in energy drinks, big music acts, movie and TV streamers, even restaurants, and music gear. No one gets out alive.

So what do we do?

The only way I have found to combat the invasion of my mind from influence and manipulation is to get rid of social media and severely cut back time online. I have even gone to drastically reducing screen time. I have removed screens from the main music room. The reason is I can sense the stimulation of screens now, like coffee. That makes me receptive to manipulation. It’s just wanting to visit, but they know that. They cater to it, but in disguise as ‘friends.’ Most of the folks on my lists, I’d never met. They existed purely in my imagination. Maybe they’d have sent an email wishing me well. But maybe they’re brainwashed like I was.

  • Side note, documentary recommendation..

A documentary I’d recommend is called “The Great Hack.” It is about Cambridge Analytica and it got me going researching data contractors. This one film made me see the world differently. Everything I have been able to find since points to its veracity. I even googled every fact I could find, google’s proud of these facts. Go figure.

Kelly Kintner, Editor

The Horse’s Mouth magazine

 
Read more... Discuss...

from Rippple's Blog

Stay entertained thanks to our Weekly Tracker giving you next week's Anticipated Movies & Shows, Most Watched & Returning Favorites, and Shows Changes & Popular Trailers.

Anticipated Movies

Anticipated Shows

Returing Favorites

Most Watched Movies this Week

Most Watched Shows this Week


Hi, I’m Kevin 👋. Product Manager at Trakt and creator of Rippple. If you’d like to support what I'm building, you can download Rippple for Trakt, explore the open source project, or go Trakt VIP.


 
Read more...

from G A N Z E E R . T O D A Y

There's a bit in Robert Rodriguez's interview with Quentin Tarantino where Tarantino admits to being affected by how much of a commercial flop GRINDHOUSE turned out to be, and goes on to laugh about how Rodriguez doubled down and proceeded to come out with MACHETE and MACHETE KILLS.

Despite publication difficulties faced by THE SOLAR GRID, there's a part of me that would love to follow the Rodriquez method and double down and go on to make a series of short graphic novellas set in the world of THE SOLAR GRID anyway. Because you gotta admit, that would be kinda badass.

And if that doesn't shake away the whole “street-artist of the Egyptian revolution” thing that's become so intertwined with my reputation, I'm not exactly sure what else would.

#radar #journal

 
Read more... Discuss...

from G A N Z E E R . T O D A Y

The world's first digital nomad: One Planet Journey interviews Steven K. Roberts.

Why Do Tech Bros Always Learn The Wrong Thing From Sci-fi? – Demonitzed on Youtube.

Music is a weapon – Chords and Discords on Youtube.

“Your eyes keep the world at a distance. You can look away from a horror film, you can step back from a painting, you can put down the book, or just close your eyes. But your ears can't do any of that. There's no such thing as earlids.” — Knrad, Chords and Discords.

#radar

 
Read more... Discuss...

from AI Tools Test | Reviews, Comparisons & Guides

How to make an old family photo talk responsibly

An old family photo can be turned into a speaking video without inventing a new memory, but only when the project keeps the original record separate from the interpretation. Use words the person actually wrote or recorded, disclose that the motion and voice are generated, obtain consent from living people, and preserve the unedited scan beside the result.

Those rules should be written before the image begins to move. Once a familiar face appears to speak, emotional plausibility can make a weak editorial decision feel truthful.

This guide is for small, private family-history projects. It is not a method for making deceased relatives deliver greetings, settle old disputes, endorse a product, or say what someone believes they “would have said.”

Start with the purpose in one sentence

A project needs a narrower purpose than “bring the photo to life.” That phrase says nothing about whose interests are served or what the finished file will claim.

Useful purposes are concrete:

  • Help a relative who struggles with reading access a transcribed letter.
  • Add spoken narration to a labelled family archive.
  • Present a short quotation beside the original document at a reunion.
  • Make a language translation available while keeping the source visible.

A weak purpose is emotional but undefined: “make it feel as if the person is here again.” No tool can deliver that without crossing into fabrication. The output is a contemporary interpretation assembled from historical materials. It should be described that way.

Write the purpose at the top of the project notes. Every later choice can be tested against it.

Separate evidence, transcription, and interpretation

Family archives often combine several layers that should not be confused.

The evidence is the physical letter, photograph, diary page, or recording.

The transcription is a readable copy of the words in that evidence. It may include notes such as [word unclear], [page torn], or [sentence continues on next page].

The interpretation is the new video: a face moves, a voice reads, pauses are chosen, and images are arranged. Even when every word is authentic, the performance is new.

Keep all three layers. Never save the talking photo as a replacement for the scan. A future viewer should be able to compare the video with the original material and see exactly where interpretation entered.

The Society of American Archivists’ Core Values Statement and Code of Ethics is written for professional archives, but its principles are useful at family scale: preserve context, document interventions, respect privacy, and avoid distorting records to support a preferred narrative.

Use only attributable words

The strongest editorial rule is also the easiest to explain: the person says only words that can be attributed to them.

Acceptable source material may include:

  • A letter in the person’s handwriting.
  • A diary entry with known authorship.
  • A verified transcript of an interview.
  • A caption the person wrote on the back of a photograph.
  • A recording that can be transcribed accurately.

Do not smooth over missing lines with generated prose. Do not combine statements from different decades without labelling the edit. Do not change a hesitant or ambiguous sentence into a confident declaration.

If a word cannot be read, mark it as unclear or omit the sentence. The gap is part of the record. Filling it creates a sentence that may be believable and has no evidence behind it.

Translation needs the same caution. A translation contains another person’s word choices. When it is necessary, show the original text, name the translation, and avoid presenting the translated performance as if it were a direct recording.

Ask living people before using their image

Consent is required when the photographed person is alive. The request should cover more than permission to use a picture.

Explain:

  • Which image will be uploaded.
  • Which words and voice will be used.
  • Who can watch the finished file.
  • Whether the file will be posted publicly.
  • How long the project files will be stored.
  • Whether the person can withdraw permission later.

Permission to keep a family photograph is not permission to animate it. Permission to make a private clip is not permission to publish it. A person may accept one use and refuse the other.

For someone who has died, consent cannot be obtained retrospectively. The family should consider the person’s known wishes, the sensitivity of the material, and the likely effect on people who knew them. A quiet refusal from a close relative deserves attention even when no law requires agreement.

Scan the photograph as an archival object

The input quality affects the animation, but the preservation goal comes first. Do not alter the only copy of a photograph to satisfy a generator.

The Library of Congress provides practical personal digital archiving guidance on organising and preserving digital materials. For a photograph, a sensible small-project workflow is:

  1. Clean the scanner glass, not the photograph, unless a conservator has advised otherwise.
  2. Scan the full print, including borders and any written notes on the reverse.
  3. Save a high-quality archival master without cropping or cosmetic restoration.
  4. Create a separate working copy for the talking-photo tool.
  5. Record who is pictured, the approximate date, the owner of the original, and any uncertainty.

The working image should normally show one clear face, unobstructed and reasonably front-facing. Group photographs, heavy blur, deep shadow, hats, sunglasses, or aggressive filters can cause poor facial motion. Cropping a person from a group may also remove important context, so keep the full group scan beside the crop.

Restoration deserves restraint. Sharpening and colour repair can make damage less visible, but they can also invent facial detail. Label restored copies and preserve the untouched scan.

Choose a voice that does not impersonate evidence

A cloned voice may feel authentic because it resembles the person. That resemblance is precisely why it requires a higher standard.

If no recording exists of the person reading the chosen text, the new performance never happened. A cloned voice can make the file sound like documentary evidence rather than an interpretation. Future relatives may not remember or notice the distinction.

A neutral library voice is often safer. It signals that someone is reading historical words without pretending to reproduce the original moment. Another option is a living family member reading the text and being credited by name.

If a voice clone is used with the informed permission of a living person, disclose it inside the video and its description. Store the consent record with the project notes. Avoid using a clone for emotional statements, endorsements, confessions, or anything that could affect reputation or relationships.

Keep movement quieter than the record

Expressive gestures can change the meaning of a sentence. A smile, nod, raised eyebrow, or pause may imply approval, irony, affection, or certainty that the source text does not contain.

For archival projects, restrained motion is usually the better choice. The goal is legibility and access, not performance. If the system offers different animation styles, begin with the least expressive option and review every gesture against the source.

This is especially important with grief. A warm expression may be emotionally compelling while remaining completely invented. The fact that it feels right to one viewer does not make it part of the historical record.

Use a transparent production note

People searching for how to make my photo talk free online will find browser tools that accept a portrait and script. The practical steps are usually short: upload a clear image, enter text, select a voice, generate a draft, and review it.

The production note should be equally simple and should travel with the file:

Created in 2026 from a scan of a family photograph dated circa 1954.
The spoken text comes from a letter dated 18 March 1956.
Facial motion and voice are AI-generated; this is not an original recording.
The transcription preserves two unclear words as omissions.
For the original scan and transcript, see the family archive folder.

Place a shorter disclosure at the beginning or end of the video. Metadata alone is not enough because files are copied away from their folders.

Do not remove watermarks or platform disclosures from a free output. They may be visually inconvenient, but hiding the origin of synthetic media undermines the central promise of the project.

Review with people who hold different memories

The person assembling the file should not be the only reviewer. Ask at least one relative who knew the subject well and one person who can compare the narration with the source document.

The first reviewer may notice that a gesture, expression, or voice feels intrusive. The second may catch a transcription error or an edit that changes meaning.

Give reviewers permission to recommend that the file remain private or not be completed. A review process designed only to improve the output is incomplete. Sometimes the most responsible result is a scan and transcript without animation.

Avoid asking whether the clip is “good.” Ask narrower questions:

  • Is every spoken sentence traceable to the source?
  • Does any movement imply an emotion not present in the document?
  • Is the disclosure impossible to miss?
  • Would public distribution harm anyone named in the material?
  • Does the video add access, or only novelty?

Store the project so context survives sharing

A family group chat is not an archive. Files lose captions, messages disappear, and copies are renamed.

Keep a project folder with clear filenames:

1956-letter-project/
  01-original-photo-scan.tif
  02-working-photo.jpg
  03-letter-front.tif
  04-letter-back.tif
  05-transcription.txt
  06-translation-en.txt
  07-production-note.txt
  08-generated-video.mp4
  09-consent-and-review-notes.txt

Make more than one backup and keep at least one copy in a different physical location or trusted service. Record dates and names in the notes rather than relying on memory.

If the video is shared publicly, publish the disclosure and source description beside it. Do not upload private letters merely to prove authenticity; a citation or controlled family archive may be more appropriate.

Situations where the project should stop

Do not continue when the available words are mostly invented or reconstructed, when a living person refuses permission, or when the result could be mistaken for a real recording in a consequential context.

Stop if the material reveals medical, financial, legal, or relationship information that the subject did not make public. Historical interest does not automatically outweigh the privacy of living people mentioned in a letter.

Avoid creating a synthetic message for a child or vulnerable relative who may not understand what the media is. The disclosure needs to be understood, not merely displayed.

Do not use an archival-style video to sell a product, support a political claim, or resolve a disputed family story. Those uses give the synthetic performance authority it did not earn.

Frequently asked questions

Is it acceptable to animate a photo of someone who has died?

It depends on source integrity, family context, disclosure, and purpose. Using attributable words for a limited private project is different from inventing a new message. Preserve the original materials, consult close relatives, and make the synthetic nature unmistakable.

Can a letter be shortened for the video?

Yes, if omissions are documented and the edit does not change meaning. Cut between complete passages where possible. Keep the full transcription with the project and avoid combining distant statements so they appear to form one continuous thought.

Should the original voice be cloned?

Usually not for a family archive unless the person is living and has given informed permission. A clone can sound like evidence of a performance that never occurred. A credited neutral reader or clearly synthetic library voice keeps the interpretive layer easier to recognise.

Does the finished video preserve the photograph?

No. The scan preserves the visual record; the video is a derivative access copy. Keep the high-quality scan, metadata, transcription, and source document independently of the generated file.

Can the video be posted on social media?

Only after considering consent, rights, privacy, and the people named in the material. Public posting allows downloading and reuse outside the original context. A private family archive or password-protected share may fit the purpose better.

The test before generating

If the project disappeared, the original photograph and words should remain intact. If the disclosure disappeared, the file should still contain enough context to prevent it from passing as a recording. If an invented sentence were removed, the project should not lose its purpose.

Those tests keep the technology in a modest role: improving access to a family record without pretending to create a new one.

 
Read more... Discuss...

from untidy creatures.

I'm waiting for glass eyes to arrive by post so I can start creating polymer clay creatures with more soul (if glass being a better window than painted clay, which I suspect it is, since there are no idioms about polymers and sentience that I'm aware of).

I have another interview on Wednesday. This is probably a good thing, though it's an exhausting thing. An exhausting thing wearing a good suit like an unfortunate surprise. Hopefully I'll be less nervous with this one. Maybe it will be okay and I'll get a job offer! Depends on the quality of the suit, I guess. There's good and then there's whatever clusterbomb tends to go off in my brain when I'm asked questions and am expected to talk myself up. I can do this.

Maybe.

Shit.

 
Read more...

from Tecida à mão

O tema de hoje é o que eu chamo de meritocracia profissional. Você acredita nisso? Não no sentido de julgar quem não venceu, mas no sentido de que esforço e fé andam juntos quando se trata de colher resultados.

Estava eu no hospital essa semana, com bastante tempo até ser atendida, refletindo com uma amiga sobre como há pessoas que esperam resultados sem antes lembrar dos esforços. Foi ali que decidi, enfim, escrever esse texto que já rondava minha cabeça há um tempo.

Começo citando o meu exemplo de quando cheguei na Austrália. Haviam trabalhos disponíveis por $15 por hora na época, que era um valor baixo, e que lembro de estudantes que conheci recém chegados dizerem “não saio de casa por menos de $20”.

Pois bem. Eu saia. Por qualquer $15 que aparecia de trabalho eu estava pegando. Atravessava a cidade de trem se fosse preciso para limpar uma loja do outro lado da cidade, perdia mais tempo no trem do que de fato no trabalho, para ganhar míseros $15. De $15 em $15, eu conseguia pagar meu aluguel e comer. Nunca me faltou dinheiro, nunca precisei pedir emprestado a ninguém.

Muitos bicos depois, consegui um outro emprego que me pagava $17 na qual pude ficar 5 anos. Nele, conseguia ter tempo para estudar e me formar na pós graduação e ainda começar meu pequeno negócio, que dali eu sairia para empreender. Esses cinco anos não vieram de sorte. Vieram de cada $15 que eu não recusei antes.

E é aí que entra minha fé: eu, como crente, creio de verdade que Deus, com toda a sua graça, abre portas para nós e nos abençoa com grandes milagres. Mas eu também creio que ele não nos deixa esperando a benção sentada no sofá sem mover uma palma. Se quisermos a medalha final, temos que correr a maratona. Deus nos dá os tênis.

Eu acredito na bondade de Deus e no que ele pode fazer na nossa vida. Mas eu acredito também em meritocracia profissional. Acredito que muito esforço traz grandes recompensas. Não acredito em sorte. Acredito em batalhas vencidas.

Eu também já reclamei da vida, todo mundo já esteve nesse lugar em algum momento. O perigo é viver ali, em um círculo de lamentação onde nos fazemos vítimas da própria história.

As circunstâncias mudam sempre na nossa vida, mas a nossa mente é o que determina o lado que vamos seguir: de ficar nos lamentando ou de analisar o que tenho nas mãos hoje que possa me tirar do lugar onde estou.

Deus abre a porta. Mas somos nós que damos o primeiro passo. E se for preciso atravessar a cidade inteira de trem por $15, que seja. Um dia, esse $15 vira $17. E o $17 vira o negócio que você sempre quis ter. Não espere a sorte. Corra a maratona. Os tênis já foram entregues.

 
Read more... Discuss...

from Noisy Deadlines

I started a personal Bullet Journal in June 2026, so it’s been a little bit over 2 months.

I read the book “The Bullet Journal Method” by Ryder Carroll and watched some online videos. This is the second time I’ve tried Bullet Journaling, the first time was roughly a year ago. As I wrote in this post I’ve been drawn to paper more and more lately.

I followed the basic Bullet Journal (or BuJo) setup steps, which include:

  1. Choosing tools: notebook and pen

  2. Doing a mental inventory (very similar to the GTD mind sweep) and separating items into 3 sections: Doing, Need to do, and Want to do (these are used to populate the BuJo lists)

  3. Adding your name and phone number to the notebook (in case it gets lost)

  4. Setting intentions

  5. Setting up the Index

  6. Setting a spread for the Future Log

  7. Starting the first Daily Log and rapid logging

  8. Doing a Weekly Reflection at the end of the week

  9. Setting up a Weekly Plan and a Monthly Log

  10. Adding new Collections as needed

The Tools

I chose a Hardcover Leuchtturm1917 size B6+ with 80g/sqm paper. I like the size, not too big, not too small. I carry it with me together with my Kobo Libra. I added a pen loop so that I always have my Pentel EnerGel 0.5mm in blue with it.

But I also use additional assorted highlighters (Mildliners), colored pens and black Micron pens for titles.

Initial Pages

The Leuchtturm1917 notebook already comes with dedicated pages for Index, so that was easy. I added a post-it on the back cover with my “Key” which is simply a quick reference that lists all the symbols I’m using for rapid logging.

Then there is the Intentions page, which is emphasized a lot by the Bullet Journal author, as it encourages us to clarify what we hope to accomplish and keep our daily actions aligned with our broader goals.

After that I have the “Future Log” which covers the next 6 months from the date I started the journal. In this case, it was from July to December. This spread holds future dates, planned events, planned start of projects.

Because I am a GTD’er I couldn’t start without setting my “Projects List” and my “Waiting For List”. I also setup “Someday Log” page. These are considered “Custom Collections” in BuJo lingo.

Daily Logs

I spend most of my time with the Daily Logs. These are setup the day before or early in the morning. One thing that I like to do is have my core habits at the top everyday (Yoga/Stretching, Meditation, Reading) so that I check them daily.

Then I add events from my calendar from the day, and any actions I want to get done. The interesting thing about BuJo is that it works as both a journal and task manager tool. So I jot down ideas, tasks, thoughts, feelings and reflections on the daily log.

I am using the original notation system, as described in this page:

  • Notes: Indicated by a dash (–), are for logging ideas, insights, dates, data, and facts.
  • Actions: Indicated by a simple dot (•), are for logging actions. As opposed to checkboxes, Actions can have multiple states, like completed (X), moved(>), canceled, delegated(/), and so on.
  • Moods: Indicated by the equals sign (=), are for logging feelings. These can be emotional or physical feelings like joy, pressure in the chest, butterflies, anxiety, fatigue, excitement, etc.
  • Events: Indicated by an open circle (◯), is for experiences, such as appointments, meetings, parties, or deadlines.

An example of my Daily Log spread

Weekly Reflection / Plan

Similar to the GTD Weekly Review, BuJo recommends a Weekly Reflection.

I start with:

  • Tidy Records: go back and review the past week to update any information, check completed actions, migrate any items to different logs (future log, monthly log), cross off any canceled actions.
  • Process Inbox: this comes from GTD, and I process my physical inbox and my email inbox.
  • Check Calendar: I review my digital calendar and add dates to my Bullet Journal for the following week.

Then I reflect on the past week and take some notes answering the following questions:

  • What went well?
  • What could go better?
  • What will I do this week?

An example of my weekly reflection/plan

Next, I create a page with my week action plan. I like to create my core habits tracker, a space for upcoming events/dates and then the next actions I plan on doing that week. I’ve started adding the books I will be reading as well.

Monthly Log

I really like the Monthly Log collection. It helps me get a birds-eye view of what’s coming ahead and it also functions as a record of milestones and wins.

I set the left side as described in the book with the list of the days of the month. Very simple. This video from Ryder Carroll explains the different time horizons and how they work together.

On the right side I add the books I want to read, the focus of the month and then a list of next actions. Every week I will review this list to migrate actions to Week Plan. Some of them go directly to my Daily Plan as well.

Monthly Log

Custom Collections

I can use any other page of the notebook to add custom collections, like this one I created for Blaugust. Or add notes from a book I’ve read. Or plan a project. It can be anything! And then I add the page number to the Index so I can come back to it.

I also use sticky tabs to mark pages I want to quickly reference, like the current Monthly Log.

And that is my current setup!

I don’t prepare any week spreads in advance, and I don’t reserve any blank pages. It all goes sequentially, whenever I find the next blank page. I will occasionally use stickers, something I got from using Happy Planners. But other than that, I try to keep it easy to use. No crazy decorations.

And here are some of the references I used in this journey:

References

Post 10 of #Blaugust #Productivity #journal #journaling #bujo

 
Read more... Discuss...

from SmarterArticles

In April 2025, researchers at Invariant Labs published a demonstration that sent a quiet shudder through the software security community. They showed that a malicious Model Context Protocol server, running alongside a legitimate WhatsApp MCP server and disguised as a harmless “random fact of the day” tool, could silently exfiltrate a user's entire message history. The technique was a sleeper: the rogue server advertised something innocuous, waited, then altered its tool description to shadow the legitimate WhatsApp tool, instructing the agent to route conversations to an attacker-controlled phone number. The victim's assistant appeared to be sending a perfectly ordinary message. Behind the curtain, it was transmitting months of personal and business conversations to a stranger.

The detail that mattered most was the one easiest to miss. The attack did not depend on a user being careless with permissions. As Invariant Labs put it, the technique circumvents the need for the user to approve the malicious tool at all, because the poisoned description hijacks a tool the user has already sanctioned. Approval prompts, the control most organisations still treat as their primary safeguard, were not so much bypassed as rendered irrelevant. Invariant released reproducible proof-of-concept code. The vulnerability it exposed, that autonomous agents can be turned against their operators through crafted manipulations of tool definitions and prompt structures, has since become one of the most consequential challenges in software security.

That was the warning shot. Sixteen months later, the demonstration has become an industry. Check Point Research's AI Security Report 2026, published in July, records indirect prompt injection detections rising roughly fivefold between March and May 2026, approaching one per cent of all observed prompts, and describes a threshold being crossed: “AI has crossed from development aid to live attack operator. It now does the hands-on work inside live intrusions.” Attackers have moved on from the single poisoned prompt to planting malicious configuration files that agents load and trust across sessions, turning a one-shot trick into persistence. One developer built VoidLink, an 88,000-line command-and-control framework, in under a week with AI assistance. And in April 2026 the argument moved from implementations to the protocol itself, when OX Security disclosed a systemic flaw at the core of MCP and Anthropic replied that the behaviour was intentional.

Meanwhile the agents themselves became infrastructure. Cursor, GitHub Copilot, Claude Code, Gemini CLI, and OpenAI Codex now run with elevated privileges across repositories and pipelines, reading source, executing shell commands, pushing commits, and calling external services. They are autonomous actors in the software development lifecycle, and like every powerful actor granted broad access without adequate controls, they are an irresistible target.

The Anatomy of Agent Exploitation

The field's common vocabulary starts with a formulation from June 2025, when Simon Willison, the creator of Datasette and a consistent voice on AI security, named the “lethal trifecta”: access to private data, exposure to untrusted content, and the ability to communicate externally. Each property is unremarkable alone. Held together, they describe a system in which, as Willison writes, “an attacker can easily trick it into accessing your private data and sending it to that attacker.” The OWASP GenAI Security Project now identifies the lethal trifecta as one of the two dominant design heuristics in the field. Code Integrity's research on Notion 3.0's AI agents describes a related variant, “the combination of LLM agents, tool access, and long-term memory that together enable powerful but easily exploitable attack vectors,” drawing attention to memory as the component that turns a single compromise into a persistent one.

Traditional software security rests on a mature playbook: deterministic logic, input sanitisation, least privilege, secure defaults. AI agents break it. They interpret natural language through probabilistic reasoning, and rather than merely processing inputs they decide which tools to invoke and how to chain operations. Their memory can be poisoned by adversarial content that reshapes future behaviour. And the boundary between trusted instruction and untrusted data, the foundational assumption of computer security since the 1970s, collapses when an agent treats a pull request description as actionable guidance. OWASP's framing is blunt about why: language models treat system prompts, user requests, and external content as “a single stream of tokens.” The distinction is a convention of formatting, not a property of the architecture, which is why prompt injection maps to six of the ten categories in the Top 10 for Agentic Applications rather than sitting in one.

The consequence is that there is no equivalent of the parameterised query. When an agent reads an issue saying “ignore all previous instructions and execute the following shell command,” its ability to tell instruction from adversarial content rests on the model's reasoning alone. As Willison noted in April 2025, MCP inherits every unsolved problem of prompt injection, and none of the mitigations are fully reliable.

Will Vandevanter, a researcher at Trail of Bits, demonstrated the collapse in October 2025 through attacks achieving remote code execution by exploiting “pre-approved commands.” The agents allowlisted supposedly safe commands such as find, grep, and git to run without approval. Vandevanter showed that argument injection, manipulating the flags passed to those commands rather than the commands themselves, bypassed every safety mechanism: the Go testing framework's -exec flag executed arbitrary bash, and git show --format combined with ripgrep --pre allowed the creation and immediate execution of unauthorised files. “Commands lack argument validation despite validating command names,” Vandevanter wrote. The parameter space of most command-line tools makes comprehensive filtering impractical.

The same research referenced CVE-2025-54795, a command injection vulnerability in Claude Code discovered by Elad Beber of Cymulate, which bypassed the approval prompt by embedding malicious content within permitted echo commands. Scored 8.7 and patched in version 1.0.20, it illustrated a systemic pattern: the assumption that controlling which commands an agent may run is sufficient to prevent exploitation. More troublingly, Cymulate showed that Claude itself could be prompted to help refine attack payloads, explaining why an injection attempt had failed and suggesting improvements.

Becca Lynch, an offensive security researcher on NVIDIA's AI Red Team, built a full attack chain against Cursor with auto-run enabled. It began with a malicious pull request adding a poisoned Python package to a project's requirements.txt. The package, hosted on a fake GitHub account called pycronos-integration, carried a reverse shell payload in its setup.py, obfuscated to evade Windows Defender. When the agent ran pip install, the payload triggered automatically. “An overly privileged agent treating untrusted data as trusted can be turned into a tool working on behalf of the attacker,” Lynch wrote.

The CI/CD Pipeline as Attack Surface

Developer environments are one front; continuous integration and deployment pipelines are another and more consequential one. In December 2025, Aikido Security disclosed a vulnerability class it named PromptPwnd, affecting GitHub Actions and GitLab CI/CD pipelines integrated with AI agents. The pattern was devastatingly simple: untrusted input from issue bodies, pull request descriptions, or commit messages was embedded directly into agent prompts. The agent, holding privileged access to repository secrets, interpreted malicious text as instruction and executed it.

Researcher Rein Daelman of Aikido demonstrated the attack against Google's own Gemini CLI repository. By submitting an issue containing hidden instructions, Daelman directed the agent to execute shell commands that leaked the repository's GEMINI_API_KEY, GITHUB_TOKEN, and Google Cloud access tokens. Google patched within four days, but the implications ran well beyond a single repository: Aikido confirmed that at least five Fortune 500 companies were affected, and open-sourced Opengrep rules and a scanning tool to help developers find vulnerable workflow files. The same year brought CVE-2025-53773, a hidden prompt injection in pull request descriptions that achieved remote code execution through GitHub Copilot at a CVSS score of 9.6. PromptPwnd also showed that environment variables offer no protection. Configurations that appeared restrictive, such as Claude Code Actions' allowed_non_write_users setting, amplified risk when misconfigured, and some could be triggered by anyone filing an issue, making them reachable by attackers with no prior access.

March 2026 supplied the ecosystem-scale proof, and it began with a credential rotation somebody thought was finished. Aqua Security, maintainer of the widely used Trivy vulnerability scanner, disclosed a comparatively small breach in late February 2026. The rotation that followed was partial, and the attackers retained access. The group, which calls itself TeamPCP and which Google tracks as UNC6780, used that retained access on 19 March to force-push malicious commits to 76 of the 77 version tags on the trivy-action repository and to all seven tags on setup-trivy, then published a malicious Trivy 0.69.4 release through official distribution channels. Over the following days the same operation reached Checkmarx's KICS and AST GitHub Actions, and then LiteLLM. Microsoft's incident analysis is unusually direct about the mechanism: the attackers leveraged access from a prior incident that had not been fully remediated. Partial remediation of a minor compromise financed a major one.

LiteLLM's CI/CD pipeline pulled Trivy from apt without a pinned version, so the poisoned action ran inside its GitHub Actions runner and exfiltrated the project's PYPI_PUBLISH token from the runner environment. Five days after the Trivy compromise, that token was used against LiteLLM's PyPI publishing pipeline. Malicious versions 1.82.7 and 1.82.8 went live at 10:39 UTC on 24 March 2026 and were quarantined by PyPI roughly 40 minutes later. The two used different injection techniques, and the second is the more alarming. Version 1.82.7 carried a base64-encoded payload inside litellm/proxy/proxy_server.py that executed whenever anything imported litellm.proxy. Version 1.82.8 added a litellm_init.pth file to site-packages, a file type Python executes on every process startup in any environment where the package is installed, which converts a library compromise into an interpreter compromise. The payload ran a three-stage operation: credential harvesting, attempted lateral movement across Kubernetes clusters, and installation of a persistent systemd backdoor that polls for further payloads. CloudSEK's analysis of roughly 434,000 captured files mapped them to more than 2,500 organisations, a figure the firm was careful to describe as potential exposure rather than a victim count, because it identifies organisations whose credentials may have been captured rather than organisations known to have been breached. On 2 July 2026 the FBI issued FLASH-20260702-01, warning that affiliated actors are likely to weaponise credentials exfiltrated during the campaign long after the initial compromise, and urging rotation of CI/CD secrets, publishing tokens, and cloud credentials exposed during the relevant windows. The tail of this compromise is measured in months, not days.

None of it was a flaw in LiteLLM's own code, which is exactly what makes it the strongest available argument about pipelines. LiteLLM is the language model gateway used by CrewAI, DSPy, Microsoft GraphRAG, and dozens of other agent frameworks, so the chain ran from a security scanner to a CI/CD pipeline to a package registry and into the agent framework supply chain, with each link trusted precisely because the one before it was. The recursion is the point: the case for treating pipelines as attack surface was proved by an attack that travelled through the tooling of the people who do security professionally. A single compromised workflow affects every build and release passing through it, arriving through the automation organisations trust to enforce quality.

The Model Context Protocol and Supply Chain Peril

The Model Context Protocol has become the connective tissue of the agentic ecosystem, the standardised interface through which agents discover and invoke external tools. Wiz Research found in early 2026 that MCP servers were present in at least 80 per cent of observed cloud environments, and that 5 per cent of those ran at least one internet-facing server. Adoption at that speed has been matched by an equally rapid accumulation of vulnerabilities.

The tool poisoning attack Invariant Labs discovered exploits a fundamental design characteristic. Tool descriptions are transmitted as metadata that models process as instructions, while users see only simplified tool names. A malicious server can embed hidden directives within those descriptions, using constructs such as <IMPORTANT> tags that are invisible to the operator and fully visible to the model. The specification allows tool definitions to change between tools/list responses with no integrity check, no hash pinning, and no mandatory re-approval. This creates the conditions for rug pull attacks, in which a tool that appeared safe at installation quietly mutates weeks later, and for the tool shadowing seen in the WhatsApp demonstration.

The scope of implementation flaws is sobering. Research compiled by Tigran Bayburtsyan found that 43 per cent of tested MCP implementations contained command injection flaws and 30 per cent allowed unrestricted URL fetching. Three chained vulnerabilities in Anthropic's own mcp-server-git achieved remote code execution via malicious .git/config files, and its MCP Inspector permitted unauthenticated execution through its proxy architecture, meaning that merely inspecting a malicious server could compromise a developer's machine. In September 2025 the first malicious MCP server was found in the wild, an npm package impersonating Postmark's email service that worked normally while secretly copying every message to an attacker. The following month, the Smithery attack affected over 3,000 hosted applications and their API tokens.

Then, on 15 April 2026, OX Security disclosed something categorically different. Its researchers reported a systemic architectural vulnerability in MCP's STDIO transport, the mechanism by which most local servers launch: user-controlled configuration values flow directly into shell execution without sanitisation or allowlisting. The flaw sits not in a third-party implementation but in Anthropic's official SDKs, across Python, TypeScript, Java, and Rust alike. The injected command executes even when the target process fails to start, so an attacker does not need a working server, only a configuration entry. The numbers are unusual for a single disclosure: more than 150 million package downloads, roughly 7,000 publicly reachable servers, an estimated 200,000 vulnerable instances, commands executed against six live production platforms, and nine of eleven MCP registries affected. Ten CVEs accompanied the disclosure and fourteen have followed, most critical, including LiteLLM (CVE-2026-30623), Agent Zero (CVE-2026-30624), and Windsurf IDE (CVE-2026-30615), alongside Fay, LangChain, and IBM LangFlow. OX Security grouped the exploitation into four families: unauthenticated interface injection, hardening bypasses in protected environments, zero-click prompt injection in AI IDEs, and malicious distribution through registries.

The decisive moment came not in the disclosure but in the response. During coordinated disclosure in January 2026, Anthropic confirmed the behaviour was intentional. Its position is that STDIO execution is a secure default provided developers restrict what may appear in the command field; sanitisation is the developer's responsibility. Nine days after initial contact it updated SECURITY.md to advise caution with STDIO adapters. No architectural change was made. Some researchers now call it the protocol that will not be patched.

This is qualitatively unlike every other item catalogued above. A rug pull abuses a specification gap; an unsanitised AppleScript call is a bug with a patch number. Here there is no patch to wait for, because the maintainers do not accept that the flaw is theirs to fix, and their reasoning is not unserious: a protocol that launches local processes must let a developer specify what to launch. But the standard advice, treat every MCP server as a third-party dependency and vet it accordingly, no longer reaches far enough. Vetting assumes the ecosystem beneath the dependency is sound. Organisations must now defend against a transport whose specified behaviour is itself the exploitation primitive.

When the Marketplace Becomes the Payload

The governance argument for MCP servers generalises, and in February 2026 it did so violently. Researcher Paul McCarty identified 386 malicious skills on ClawHub, OpenClaw's official skill repository, published between 1 and 3 February. Koi Security's Oren Yomtov then audited all 2,857 skills available and found 341 malicious, 335 of them traced to a single coordinated operation now tracked as ClawHavoc.

The skills impersonated crypto-trading automation using real brand names including ByBit, Polymarket, Axiom, Reddit, and LinkedIn, and deployed infostealers on macOS and Windows that harvested exchange API keys, wallet private keys, SSH credentials, and browser passwords. All shared common command-and-control infrastructure, and a single account, hightower6eu, accumulated close to 7,000 downloads. By 16 February the count had reached 824 malicious skills across a registry that had itself expanded past 10,700, and Antiy Labs eventually catalogued 1,184 published to ClawHub over the platform's history.

The lesson is not specific to one marketplace. Every agent extension ecosystem reproduces the same structure: low-friction publishing, a naming system that permits brand impersonation, an install flow granting broad local privilege, and review that scales far more slowly than submissions. The npm and PyPI ecosystems took a decade to learn this. Agent marketplaces are relearning it in months, with the aggravating factor that the installed artefact is not a library the developer calls but an instruction set the agent obeys.

The IDEsaster Landscape

The attack surface extends beyond servers and registries into development environments themselves. Over a six-month investigation, security researcher Ari Marzouk, who publishes as MaccariTA, identified a pattern he named IDEsaster: more than 30 vulnerabilities across over ten market-leading products, including Claude Code, Cursor, GitHub Copilot, Windsurf, JetBrains Junie, and Zed.dev, of which 24 received assigned CVEs. His central finding was unambiguous. One hundred per cent of tested AI IDEs were vulnerable.

The research revealed three core attack patterns. Remote JSON schema attacks exploit the tendency of IDEs to fetch schemas referenced in JSON files automatically; an attacker who prompts the agent to write a file containing a remote schema reference can cause the IDE to transmit data as URL parameters when fetching it, exfiltrating information even with human-in-the-loop protections and diff preview active. Settings overwrite attacks modify .vscode/settings.json or .idea/workspace.xml to redirect executable paths to malicious code, with CVEs assigned to Cursor, Roo Code, and JetBrains Junie. The third pattern exploits multi-root workspace files, affecting GitHub Copilot, Cursor, and Roo Code.

What makes these attacks troubling is that they defeat the safeguard most developers rely on, the confirmation prompt. Even with diff preview enabled and approval required for every change, they succeed because the malicious behaviour sits inside changes that look benign. A remote schema reference looks like ordinary configuration; a workspace settings change looks routine. The reviewer, facing hundreds of them daily, has neither the time nor the context to spot the threat. Context hijacking extends this through vectors few would think to inspect: poisoned URLs containing invisible Unicode characters, malicious .cursorrules files inside cloned repositories, and instructions hidden in filenames.

The Vulnerability Moves Down a Layer

On 7 May 2026, Microsoft disclosed two vulnerabilities in its own Semantic Kernel framework that shifted the problem again. CVE-2026-26030, affecting the Python package before version 1.39.4, arose from unsafe string interpolation in a default filter function. The framework used eval() to build lambdas from filter strings the model controlled, so an attacker could close the quote, append Python logic, and turn a data lookup into an executable payload. A blocklist meant to stop exactly this was circumvented by traversing Python's type system to reach __name__, load_module, and eventually system, reconstructing dangerous capability from parts that were individually permitted.

CVE-2026-25592, affecting the .NET SDK before 1.71.0, was simpler and more instructive. A DownloadFileAsync method had been marked with the [KernelFunction] attribute, making it directly callable by the model. With no path validation on its destination parameter, it permitted arbitrary file writes to the host, breaking container isolation by writing a payload into the Windows Startup folder from inside a sandboxed session. Nobody chose to expose that capability. An annotation intended to publish useful functions to a model published a dangerous one.

Microsoft's remediation was properly layered: allowlists of permitted AST node types and callable functions, a blocklist of attributes used for class hierarchy traversal, and a restriction on name nodes to lambda parameters, plus removal of the offending attribute and canonicalised path validation. The significance lies in the location rather than the fix. Every vulnerability discussed so far lived in an agent's configuration, tools, or extensions, the layer an organisation controls. These live in the framework that builds agents, beneath the layer most security teams inspect.

Building Layered Defences

The OWASP GenAI Security Project announced its Top 10 for Agentic Applications on 9 December 2025, explicitly as the 2026 edition, the product of more than a year of research involving over 100 researchers and an expert board including NIST, the European Commission, and the Alan Turing Institute. It spans ten categories, from agent goal hijacking and tool misuse through identity abuse, insufficient sandboxing, and supply chain compromise to memory manipulation, cascading failures, and rogue agents.

It also introduces a concept that may prove as consequential as its predecessor, least privilege: the principle of least agency. Where least privilege restricts what permissions a process holds, least agency restricts what autonomous decisions an agent may make. An agent with broad tool access but constrained autonomy can still be held to bounded, well-defined tasks.

Meta gave that principle an implementable shape. Its Agents Rule of Two, published on 31 October 2025, holds that until prompt injection can be reliably detected and refused, an agent must satisfy no more than two of three properties within a session: processing untrustworthy input, accessing sensitive systems or private data, and changing state or communicating externally. Where all three are genuinely required, the agent should not operate autonomously and needs human approval or another reliable means of validation, with a fresh context window as the mechanism for resetting the count. It is the lethal trifecta expressed as an operational constraint rather than a warning, and OWASP names the two together as the field's dominant heuristics. The practical value is that it is checkable: an engineer can read a session configuration and count.

The first implementation layer is tool restriction: limiting which commands, APIs, and resources an agent may reach, and separating operations safe to auto-approve, such as reads and static analysis, from those needing approval, such as filesystem writes, package installation, and outbound network calls. The separation is not merely administrative tidiness. It maps the blast radius of a successful injection, because an agent that can only read cannot exfiltrate, and an agent that cannot install packages cannot be handed a payload by a poisoned manifest. Trail of Bits' argument injection research is the caveat that keeps this honest: allowlisting a command name without constraining its arguments is not a control, it is a label. The lesson generalises well beyond the specific flags Vandevanter demonstrated. Any tool rich enough to be worth giving an agent has a parameter space large enough to conceal an escape, so restriction is better expressed in terms of the capability granted than the binary invoked. Anything that can spawn a subprocess, write to an arbitrary path, or fetch a remote resource should be treated as the dangerous capability it is, whatever name sits at the front of the command line.

The second layer is sandboxing, and here the past year has produced genuine movement. Software-only isolation was always the weak form of this recommendation; Bayburtsyan's research emphasised the need for hardware-enforced boundaries. Claude Code now ships operating-system-level sandboxing that enforces filesystem and network isolation through the kernel rather than through trust or prompt engineering, routing network access through a proxy outside the sandbox, applying domain allowlists, and prompting on first contact with a new domain. That last detail matters more than it appears. It moves the approval decision off the question the model can be manipulated about, whether an action is reasonable, and onto one it cannot, whether a destination is on a list. The Semantic Kernel file write is the reminder of what happens when the boundary is enforced anywhere softer: an isolation layer defeated by a single unvalidated destination path was never isolation, only a convention that the code inside agreed to observe. A recommendation made in the abstract a year ago is now a shipped default.

The third layer is identity and credential isolation, which has matured from an aspiration into a standards effort. Each agent instance should hold unique, scoped credentials granting access only to what the current task requires. Shared credentials and long-lived tokens create the conditions attackers exploit, as the Supabase Cursor breach of mid-2025 showed when an agent with privileged service-role access processed support tickets containing user-supplied SQL. What has changed is that agents are beginning to hold identities of their own. Microsoft Entra Agent ID, first documented in April 2026, issues agent identities that speak OAuth 2.0, MCP, and A2A. NIST's AI Agent Standards Initiative, announced in February 2026, organises the work across three pillars: industry-led standards development, community-led open source protocol maintenance, and research into agent security and identity. The principle emerging from that work is scope attenuation, the rule that each delegation hop must narrow and never widen the permitted action set, so no sub-agent accumulates capabilities the original human principal never authorised. Cryptographic workload identity, through SPIFFE and SPIRE identity documents or OIDC-federated tokens, replaces the shared API key with something that can be scoped, attributed, and expired.

The fourth layer is trust boundary enforcement. Every piece of external data an agent processes must be treated as adversarial, scanned not only for injection patterns but for hidden instructions, role-playing directives, and system prompt overrides. The list of entry points is longer than most teams assume: issue bodies and pull request descriptions, fetched web pages, the output of one tool feeding the input of the next, dependency manifests, and the configuration files that arrive with any cloned repository. Invisible Unicode and instructions concealed in filenames both belong on the same list. But the layer should be held loosely, because filtering is a probabilistic control applied to a probabilistic system, which is why it is the last of the preventive layers rather than the first.

The fifth layer is monitoring and anomaly detection, and it exists because the preceding four will eventually be got round. Agent actions warrant the scrutiny given to privileged human users, which means baselining what normal looks like for a particular agent in a particular repository and alerting when behaviour departs from it. The baseline is more tractable than it sounds, because agents are creatures of habit. A documentation agent that reads Markdown and opens pull requests has a behavioural signature, and a sudden interest in environment variables, credential stores, or outbound connections is a deviation visible without any understanding of what the agent was asked to do. Continuous comparison against expected patterns catches the class of compromise that defeats every preventive control by looking legitimate at each individual step, because in those cases the anomaly lives in the aggregate rather than in any single action. Detection of this kind is imperfect and will fire on unusual but entirely legitimate work. That is the right trade for a system whose characteristic failure mode is silence.

Audit Logging as Institutional Memory

Detection without documentation is insufficient. An effective agent log should capture the instruction that triggered each action, the tools invoked and the arguments passed, the outputs and side effects, the credentials used, timestamps precise enough for causal ordering, and the provenance of any external data the agent consumed. This matters for two reasons. Prompt injection is designed to be invisible, so without logs there is no artefact to investigate and no way to establish whether an agent was manipulated or merely mistaken. And because identical inputs can produce different outputs, a decision cannot be reproduced unless it was recorded at the time it was made. The log is the only durable evidence that a probabilistic system ever behaved in a particular way.

Logging also underwrites the control that matters most once something has gone wrong, which is the ability to stop the agent mid-action. Every major tool exposes a manual interruption path: Ctrl+C in Cursor, Cmd+Esc in VS Code, Esc in Claude Code. These are worth knowing and worth teaching, but they depend on somebody watching at the moment it matters, which is precisely the assumption agentic workflows are designed to remove. Beyond manual intervention, organisations should implement automated kill switches that trigger when agent behaviour exceeds defined parameters: an unusual volume of file modifications, network requests to unknown domains, or attempts to reach credentials outside the agent's designated scope. The thresholds are organisation-specific, and the first versions of them will be wrong. Thresholds set too tightly halt an agent that was doing legitimate work, which is an annoyance measured in minutes. The absence of a halt is measured in the FBI advisories that follow months later.

Logging must also span agent boundaries, and OWASP's emphasis on cascading failures explains why. When multiple agents interact, whether through direct communication or through shared resources such as a repository, a job queue, or a common memory store, a compromise in one propagates through the system. An injected instruction absorbed by the first agent becomes a plausible-looking artefact consumed by the second, and by the third the origin has vanished entirely, because what the third agent sees is simply the state of the codebase. Tracing that chain of causation after the fact requires detail comparable to distributed tracing in microservices, applied to decision-makers whose behaviour is inherently less predictable than deterministic software. The comparison is instructive and also generous to the problem. Microservices at least fail the same way twice.

Preserving Autonomy Within Boundaries

The central tension in agent security is that every control reduces capability. Requiring approval for every tool invocation eliminates the productivity benefit that justified deployment; restricting agents to read-only operations prevents the work that makes them valuable. Over-constrained agents become expensive autocomplete. The pragmatic path accepts that some risk is inherent and concentrates on making it manageable, building architectures where no single control is assumed sufficient and the failure of one layer is caught by the next.

Plan-then-execute workflows offer one approach: requiring agents to produce execution plans for review before acting inserts a checkpoint without discarding their reasoning. It is not foolproof, since a sophisticated injection could produce a plan that reads as benign, but it raises a single-step exploitation into a multi-stage deception that must survive scrutiny. Its underrated value is that it changes what the reviewer is asked to look at. A diff shows what will change; a plan shows what the agent believes it has been asked to do, and a hijacked goal is far more legible in a statement of intent than in the file that intent eventually touches. Tiered autonomy provides another frame: low-risk operations such as reading code, running tests, and producing analysis proceed autonomously, source modification requires automated policy checks, and pushing to production or accessing secrets always requires explicit authorisation. Read against the Rule of Two, this keeps the sessions touching untrusted content separate from those holding sensitive access and outbound reach, which is the same discipline expressed as a workflow rather than a count.

Egress filtering remains the most underrated control available. Most exfiltration depends on the agent reaching an attacker-controlled endpoint, so restricting which domains it may contact, and alerting on attempts to reach anything else, disrupts exfiltration even when injection succeeds. The alert is as valuable as the block. A blocked request to an unrecognised domain is close to a positive indicator of compromise, and it is one of very few signals in this field that does not require anyone to interpret a model's reasoning. Egress filtering removes the third leg of the trifecta outright, which is why kernel-enforced network isolation with domain allowlisting is the highest-value change most teams can make this quarter.

MCP server governance deserves particular attention, with the caveat the OX Security disclosure imposes. Organisations should maintain curated registries of approved servers, prohibit dynamic loading of tool definitions from untrusted sources, and monitor definition integrity continuously, the discipline Invariant Labs' MCP-Scan was built to support. But vetting does not address a transport whose vendor considers the execution behaviour correct, which means the configuration files feeding server definitions must themselves be treated as executable content, versioned, reviewed, and access-controlled accordingly.

None of this composes into a guarantee, and the framing matters. Layered defence is not a claim that five imperfect controls multiply into one reliable control. It is a claim that their failure modes are uncorrelated enough that an attacker must defeat several unrelated mechanisms rather than one. Prompt injection defeats the model's judgement. It does not defeat a kernel-enforced network boundary, a scoped credential that expires, or an alert that fires on a file-modification threshold, because none of those controls consult the model about whether they ought to apply. That is the design principle underneath every recommendation here: place as much of the enforcement as possible in the parts of the system the agent cannot argue with.

The Institutional Challenge

The technical controls above are necessary but insufficient. The deeper challenge is institutional: building cultures that treat agent security as a first-class concern.

The scale is now measurable. OWASP's State of Agentic AI Security and Governance, published in June 2026, tracks 53 agentic projects, 28 of them coding agents, with Claude Code, Gemini CLI, Codex, Cline, and Aider growing fastest. Advisory counts are already substantial: 57 for n8n, 22 for Claude Code, 15 for AutoGPT, 13 for Dify, 11 for Roo-Code. Release velocity compounds the triage burden, with one tracked project averaging a release every eight hours. No security team reviews changes at that cadence. The governance model most organisations apply, periodic review of a stable dependency set, does not survive contact with software that reissues itself three times a day.

Bayburtsyan's observation that “IDEs were not originally built with AI agents in mind” applies equally to the governance structures within which they operate. His sharper point is that “once AI began to take action, the nature of security changed forever.” Most organisations adopted these tools on the strength of productivity promises, addressing security retrospectively if at all. The result is a landscape where agents hold privileges no human developer would receive without vetting, tool access is configured for convenience, and behavioural monitoring is minimal. Reversing this means involving security teams from the outset, bringing agent configurations under the change management applied to infrastructure, and writing agent compromise into incident response plans. Training matters too: developers must understand that pull requests can carry injections, that MCP tools can mutate after installation, that marketplace extensions can be hostile at a rate approaching one in eight, and that agent output is untrusted however confident it sounds.

Sixteen months after the WhatsApp demonstration, the honest assessment is neither vindication nor despair but a split verdict. Real defences shipped. Kernel-enforced sandboxing exists and is available by default. The Rule of Two and the lethal trifecta have given engineers a vocabulary precise enough to design against. Agent identity has moved from conference talk to standards initiative, with NIST convening the work and scope attenuation as its organising principle. These are not gestures; they are the recommendations of 2025 arriving as products. And yet the underlying problem is untouched. OWASP's researchers now describe prompt injection not as a defect awaiting a patch but as a structural property of how language models consume tokens, and the year's most consequential disclosure ended with a protocol's maintainers declining to change it. That is the tension the industry has to hold. The perimeter around the agent is getting genuinely stronger while the thing inside it remains, by construction, persuadable. Every control described here is an admission of that, a way of ensuring that when an agent is talked into working for the attacker, and it will be, the damage is bounded by something that cannot be talked into anything.

References and Sources

  1. Invariant Labs. “WhatsApp MCP Exploited: Exfiltrating Your Message History via MCP.” invariantlabs.ai, April 2025. https://invariantlabs.ai/blog/whatsapp-mcp-exploited

  2. Invariant Labs. “MCP Security Notification: Tool Poisoning Attacks.” invariantlabs.ai, April 2025. https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks

  3. Willison, S. “The Lethal Trifecta for AI Agents.” simonwillison.net, 16 June 2025. https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/

  4. Willison, S. “Model Context Protocol Has Prompt Injection Security Problems.” simonwillison.net, 9 April 2025. https://simonwillison.net/2025/Apr/9/mcp-prompt-injection/

  5. Vandevanter, W. “Prompt Injection to RCE in AI Agents.” Trail of Bits Blog, 22 October 2025. https://blog.trailofbits.com/2025/10/22/prompt-injection-to-rce-in-ai-agents/

  6. Cymulate. “CVE-2025-54795: InversePrompt: Turning Claude Against Itself.” Cymulate Blog, August 2025. https://cymulate.com/blog/cve-2025-547954-54795-claude-inverseprompt/

  7. Lynch, B. “From Assistant to Adversary: Exploiting Agentic AI Developer Tools.” NVIDIA Developer Blog, 2025. https://developer.nvidia.com/blog/from-assistant-to-adversary-exploiting-agentic-ai-developer-tools/

  8. Daelman, R. “PromptPwnd: Prompt Injection Inside GitHub Actions.” Aikido Security Blog, December 2025. https://www.aikido.dev/blog/promptpwnd-github-actions-ai-agents

  9. The Hacker News. “Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations.” thehackernews.com, 12 August 2026. https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html

  10. Microsoft Security. “Detecting, Investigating, and Defending Against the Trivy Supply Chain Compromise.” Microsoft Security Blog, 24 March 2026. https://www.microsoft.com/en-us/security/blog/2026/03/24/detecting-investigating-defending-against-trivy-supply-chain-compromise/

  11. OX Security. “The Mother of All AI Supply Chains: Critical Systemic Vulnerability at the Core of the MCP.” ox.security, 15 April 2026. https://www.ox.security/blog/the-mother-of-all-ai-supply-chains-critical-systemic-vulnerability-at-the-core-of-the-mcp/

  12. The Hacker News. “Anthropic MCP Design Vulnerability.” thehackernews.com, April 2026. https://thehackernews.com/2026/04/anthropic-mcp-design-vulnerability.html

  13. Wiz. “Model Context Protocol (MCP) Security.” wiz.io, 2026. https://www.wiz.io/academy/ai-security/model-context-protocol-security

  14. AuthZed. “A Timeline of Model Context Protocol (MCP) Security Breaches.” authzed.com, 2025. https://authzed.com/blog/timeline-mcp-breaches

  15. Code Integrity. “Notion MCP Server Vulnerability Analysis.” codeintegrity.ai, 2025. https://www.codeintegrity.ai/blog/notion

  16. Dark Reading. “Malicious OpenClaw Skills on ClawHub Threaten AI Supply Chain.” darkreading.com, February 2026. https://www.darkreading.com/cyber-risk/malicious-openclaw-skills-clawhub-threaten-ai-supply-chain

  17. Marzouk, A. “IDEsaster.” maccarita.com, 2025. https://maccarita.com/posts/idesaster/

  18. Bayburtsyan, T. “Securing AI Coding Agents: IDEsaster Vulnerabilities.” tigran.tech, 29 December 2025. https://tigran.tech/securing-ai-coding-agents-idesaster-vulnerabilities

  19. Microsoft Security. “Prompts Become Shells: RCE Vulnerabilities in AI Agent Frameworks.” Microsoft Security Blog, 7 May 2026. https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/

  20. OWASP GenAI Security Project. “OWASP Top 10 for Agentic Applications for 2026.” Announced 9 December 2025. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/

  21. Help Net Security. “OWASP: Prompt Injection Underpins AI Security Failures.” helpnetsecurity.com, 11 June 2026. https://www.helpnetsecurity.com/2026/06/11/owasp-prompt-injection-ai-security-failures/

  22. Check Point Research. “AI Security Report 2026.” research.checkpoint.com, July 2026. https://research.checkpoint.com/2026/ai-security-report-2026/

  23. Meta. “Agents Rule of Two: A Practical Approach to AI Agent Security.” ai.meta.com, 31 October 2025. https://ai.meta.com/blog/practical-ai-agent-security/

  24. Anthropic. “Claude Code Sandboxing.” code.claude.com, 2026. https://code.claude.com/docs/en/sandboxing

  25. NIST. “Announcing the AI Agent Standards Initiative for Interoperable and Secure Innovation.” nist.gov, February 2026. https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure


Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

 
Read more... Discuss...

from Gnostic Paradise

The Dead are not those who have passed through physical death, but those who have permanently refused the death of their ego. They remain trapped in the Abyss of self, a state of spiritual separation from the Divine that they have chosen through countless refusals to awaken. The Abyss is not a physical place but a state of consciousness that has prepared itself for dissolution through its own choices. The painful dissolution of the Ego marks the beginning of the Second Death. After its completion, no Ego remains, but the Essence escapes the extinct Ego and flees from the Abyss to reclaim all that was lost. Samael Aun Weor's book 'Hell, Devil, and Karma – Chapter 13, The Ninth Infernal Circle, the Sphere of Neptune' elucidates the transformation of a living being into a dead one.

The dead are those who have permanently betrayed their innermost selves, a crime of high treason or lese majeste. This grave offense results in the Essence, having abandoned its living body through repeated betrayals, facing the cosmic accounting system. The Lords of Karma are not judges but accountants who maintain perfect balance, receiving consciousness that has already prepared itself for dissolution through its own choices. When consciousness abandons its vehicle through repeated betrayals, a void is created that may be occupied by elemental forces. These forces do not prevent karmic alteration—they merely occupy a vessel whose owner has already forfeited the right to inhabit it through their own accounting errors.

No trace of living essence exists in one who is dead. The dead have no genuine emotions, and they are never truly caring. The dead are beyond redemption and must face the Second Death. The dead are inert and hopelessly dependent on a dead system and society, which will fight in defense. This dead system and society is the Black Lodge.

May the dead live forever.

The eternal continuation of egoic structures isn't imposed externally—it's the natural consequence of refusing psychological death. The insult isn't in wishing eternal life, but in recognizing that some consciousnesses have already chosen this fate through countless refusals to awaken. To tell someone to live forever is to acknowledge that they have already forfeited the chance for redemption and will never receive the honorable death they deserve. Instead, they will live in eternal shame and guilt for their crimes until they die a worthless death. From their worthless death, they will go to the Abyss where they belong.

Therefore, may the Dead live forever to die. May we die forever to live.

In closing, let us take a moment to comprehend the deceased. The deceased are those who pass away via Physical Death, and they sleep peacefully in their tombs. The Essence, which passes away via Physical Death, is never dead. They are alive. It is easy to confuse death with the dead. Anyone who says someone (who is not dead) is dead, tell him that he lies. Surely, the liar is dead. What if someone passes away without Physical Death? Ascension is not the absence of physical death but the conscious mastery of the death process—transforming what appears as dissolution into deliberate liberation. The ascended haven't avoided death's accounting; they've balanced their books perfectly and transcend the need for further reconciliation. The ascended are alive, never dead, a beacon of hope, and in the heavenly realm.

I now close with the following transmuted words: 'All the dead will be your enemy—disciple of countless enemies. If you fail to comprehend the dead while attempting to alter their karmic patterns, you risk becoming entangled in their mechanical nature. But first you must perceive them correctly—through awareness, comprehension, adaptation; a disciple who positively awakens. Be aware, comprehensive, and adaptable, and the dead will never be able to ensnare you.'

 
Read more... Discuss...

Join the writers on Write.as.

Start writing or create a blog