Critical Supabase and n8n Vulns, WTH Occurred in December with AI?, 19 Modifications I See Coming to Cybersecurity in 2026 – Cyber Tech
UPDATES
Hey! Hope you all are doing nicely!
Holy crap this primary couple of weeks of 2026 has been a loopy few months!
My Main Suggestion for 2026: Get on Claude Code Proper Now
Undecided in the event you observed, however one thing exceptional occurred to the world with AI in December. Mainly Punctuated Equilibrium. Type of like one or two generations of jumps in a blink. A variety of that was individuals simply realizing it, however it was additionally some mixture of Opus 4.5 with Claude Code. The acceleration of AI capabilities in 2026 is about to be much more ridiculous than I (or anybody) thought it was going to be.
I believe Claude Code will probably be largely main that, until there’s some MASSIVE mannequin leap from Google or somebody as a result of a elementary breakthrough. However even then, Anthropic is more likely to be on that prepare as nicely and get it into Claude Code.
Claude Code is cool however it’s nowhere pretty much as good as in the event you improve it and customise it to your self, which is why I created the Open Supply PAI Mission. I moved it to 2.0 over the vacation break, and it is now at 2.1.
Anybody asking what they need to do to get into AI? Simple.
Claude Code is by far one of the best AI system proper now. And PAI makes it many instances higher. No joke. I’m out of hyperbole to make use of. Must ask Kai to invent new ones.
I’m studying a bunch of books proper now and loving three of them.
-
The Biography of Theodore Roosevelt.
The primary is a guide on writing. Truly, they’re each books on writing. In numerous methods. The primary one is in regards to the rhetorical figures, and it is a very outdated guide. The second dissects what makes good books and flicks, and tales on the whole. As you may guess. Each are A+.
I am additionally in a mode the place I’m bouncing backwards and forwards between AI analysis and engineering (future / cyber / neo shit) mixed with studying about very outdated issues, like biographies, and outdated books on rhetoric and writing, and such. I just like the distinction. I really feel prefer it’s rejuvinating or one thing. Possibly like chilly plunge to sauna and again once more. I keep in mind somebody saying one thing related, the place they solely learn extraordinarily new issues and very outdated issues. Or one thing like that.
I am going via my begin of yr record, which I am placing within the Suggestions part. It is like a guidelines of issues that consistently get ignored however are crucial, so I attempt to remind myself to do them within the final couple weeks of the yr.
My Neovim config is definitely tremendous strong proper now (made some tweaks a pair months in the past), so I am not doing that this yr.
Saddest photograph I’ve seen in a very long time. I may speak about this for hours. What it says about animals, however about us as nicely. And life on the whole. PHOTO
My favourite tune on the planet proper now could be Paper Hearts, by WHY? SONG
Most of all, what I wish to share with you on this first episode is to have hope.
AI can wreck the whole lot and it will probably make the whole lot method higher than it was earlier than.
I’m pushing actually f-ing arduous for the latter. And it’s invigorating. Let me allow you to be part of that body and struggle.
Safe Your Google Workspace With out the Guesswork
Most safety instruments are simply “alert factories” that demand extra headcount to handle. For lean groups, including one other dashboard feels much less like a win and extra like a chore. Materials Safety takes a special path.
We concentrate on high-leverage automation that truly clears the plate. By implementing automated remediation workflows in your cloud workspace, Materials handles the tedious stuff—like clawing again delicate attachments or revoking dangerous third-party app permissions—with out requiring guide intervention for each occasion.
It’s pragmatic safety designed to be set, forgotten, and trusted. We allow you to shut the hole between “figuring out a couple of threat” and “fixing it” throughout Google Workspace and Microsoft 365, all whereas preserving your group centered on higher-order issues.
CYBERSECURITY
California launches a one-stop platform to delete your information from firms California’s new DROP system allows you to submit deletion requests to a number of firms without delay as a substitute of doing it manually for every one. CALIFORNIA DROP PLATFORM | HN DISCUSSION
Hundreds of Supabase initiatives are leaking information as a result of devs do not allow RLS Most builders skip row-level safety on Supabase, leaving their total databases publicly accessible to anybody who is aware of the API endpoint. SKILLDELIVER ARTICLE | REDDIT DISCUSSION
CSA’s Agent-Augmentation Benchmark Examine
-
CSA examined 148 analysts break up into two random teams.
-
AI-assisted analysts completed investigations 45-61% sooner total.
-
Handbook group completeness dropped 29% by second state of affairs.
-
AI group completeness solely dropped 16% below identical load.
-
Handbook report size fell 27% as fatigue set in.
-
AI-assisted reviews held regular or barely elevated element.
-
After testing, 94% of AI customers considered it positively.
The AI narrative is continually about alternative, however augmentation helps people in the actual world.
Important n8n RCE vulnerability lets attackers take over total servers A CVE scored 9.9 out of 10 lets attackers execute arbitrary code via expression injection in workflow definitions—patch instantly. ORCA SECURITY BLOG
Two cybersecurity specialists pled responsible to ransomware assaults on their very own shoppers Former incident response specialists used their entry and experience to deploy BlackCat ransomware, demanding as much as $10 million per sufferer—just one paid $1.27 million. BLEEPINGCOMPUTER REPORT | DOJ STATEMENT | COURT RECORDS
NATIONAL SECURITY
Taiwan noticed 2.63 million each day Chinese language intrusion makes an attempt in 2025 A Taiwan authorities report exhibits cyberattacks from China rose 6% final yr, hitting vitality and hospitals particularly arduous, with assaults coordinated round army drills and political occasions. TAIWAN NSB ANALYSIS | CYBERSCOOP ARTICLE | FDD ANALYSIS ON CEEW
Finland detains ship and crew after undersea cable will get broken Finnish authorities are holding an Eagle S vessel after a vital undersea cable between Finland and Estonia was severed, doubtless by the ship’s anchor. CNN ARTICLE | HN DISCUSSION
AI
Google engineer says Claude Code inbuilt one hour what took her group a yr Jaana Dogan from Google gave Claude a three-paragraph immediate and bought a distributed agent orchestration system that matches a yr of inner work. That is what I used to be speaking about within the intro. Issues are completely different now. Generationally. JAANA DOGAN’S POST | BORIS CHERNY ON CLAUDE WORKFLOW | THE DECODER ARTICLE
Sensible guides and code examples for constructing with Claude CLAUDE COOKBOOK
TECHNOLOGY
America’s financial system appears to be like set to speed up The Economist reviews GDP development is predicted to choose up in 2025, defying predictions of slowdown that dominated final yr. I see it as a large race between including productiveness and eliminating job which permit individuals to purchase stuff. After which the third piece is the UBI play for after that occurs. These all should converge someway. ECONOMIST ARTICLE | HN DISCUSSION
Plaud launches AI pin with bodily button and desktop assembly app I is likely to be getting this one to exchange my Limitless. PLAUD NOTEPIN S ANNOUNCEMENT
Internet improvement is enjoyable once more It is so loopy about half the posts I learn are from builders who’re like, “I am having a lot enjoyable.” After which the opposite half are from builders saying, “My life is meaningless now.” MATTIAS GENIAR’S POST
Meta buys Manus for $2 billion to get tens of millions of precise paying AI customers Meta simply purchased the viral AI startup Manus for $2 billion, principally paying for a product that already has tens of millions of paying subscribers and $100M in ARR. TECHCRUNCH ARTICLE | MANUS BLOG POST
HUMANS
Your key survival talent for 2026 is vital ignoring The WSJ argues we have to struggle our intuition to soak up the whole lot and apply intentionally ignoring low-quality data as a substitute. WSJ ARTICLE
Trump will ban Wall Avenue from shopping for single-family houses This one shocked me. REUTERS ARTICLE
Bankruptcies are exploding throughout each a part of the US financial system Enterprise filings are method up throughout small companies, households, and firms—seems excessive charges and inflation really damage individuals. Exploding is a loaded phrase. I did extra evaluation on this and it’s extra like returning to different highs after falling. However I think about evaluation varies. BUSINESS INSIDER ARTICLE | HN DISCUSSION
IDEAS
AI workers do not pay taxes and that is a civilization-level drawback Alec argues that changing staff with AI does not simply get rid of jobs—it eliminates the tax base that funds roads, colleges, and healthcare, breaking the mathematics of society.
I don’t assume that is that dangerous really, since these firms that do nicely will probably be paying everybody’s UBI. That’s the one system that I see working anyway. I’ve but to listen to another. ALEC’S POST
DISCOVERY
Textual content recordsdata are essentially the most sturdy format for sharing data throughout generations Jakash3 argues plain textual content beats fancy codecs as a result of it opens immediately, works on any system endlessly, and does not want bloated software program that ruins formatting. WHY PREFER TEXTFILES | TEXTFILES DIRECTORY
Ken Thompson explains how a disk scheduling algorithm unintentionally turned Unix In a video interview, Ken Thompson talks about how optimizing disk head motion ended up shaping the complete working system. KEN THOMPSON INTERVIEW
Hourly life monitoring confirmed most days had been really okay. REDDIT POST
RECOMMENDATION OF THE WEEK
-
Get on Claude Code and PAI. Doesn’t matter in the event you’re technical or a dev. In some ways it’s higher in the event you’re not. It is a human magnifying system. It really works for something besides digging holes in your yard. It’s a common device. Please. Get on it. Critical severe. Are available in Discord and ask questions within the #PAI channel.
-
For those who’ve been constructing AI for the final yr or two, use January to wash out your cruft. You’ve got most likely signed up for tons of providers that you just’re not utilizing, and so they might have credentials or one thing. Hold the Supabase and n8n vulnerabilities prime of thoughts. All these suppliers are vibe coding too. And vibe product constructing. They’re laying observe because the prepare rides. Clear up your assault floor.
-
Transfer to a mindset of chance. Discover and take away your self-restrictions. Issues are going to be altering in surprising methods within the subsequent months and years. Discover methods to maneuver in the direction of the resilience of Human 3.0, the place you might be your personal factor. You do what you need, whenever you need, and produce output that individuals need. That is what everybody needs to be doing, and it’s important to begin mapping it now.
APHORISM OF THE WEEK
❝
What lies behind us and what lies earlier than us are tiny issues in comparison with what lies inside us.
Ralph Waldo Emerson
You’re at present receiving the STANDARD version.
Members assist this work proceed. For those who benefit from the publication, the podcast, what I placed on YouTube, or any of my open-source initiatives on Github, I ask you to please develop into a member. It permits me to remain centered on studying and constructing and sharing. It’s like a cup of espresso or two per thirty days.
Plus, members get quite a few advantages, together with:
-
25-50% off all UL Paid Content material, together with the upcoming Human 3.0 / AUGMENTED ONLINE portal!
-
Entry to the extraordinary UL Member Group that features vibrant conversations with ~1,500 of the neatest and kindest individuals you’ll discover on the web
-
Member-only Content material, akin to EDC guides on tech stacks, private productiveness routines, my suggestions on Important expertise to Construct Going Ahead, Development Identification and Evaluation, and extra…
-
Entry to the Member Archive of earlier Member-only content material, the Ebook Membership archive, and so forth.
-
Entry to The UL Ebook Membership that’s been going month-to-month since 2017! One of many highlights of my and lots of attendees’ month!
-
Entry to the Month-to-month Member Meet-up the place we speak about our routines, productiveness workflows, what’s on our minds, and so forth.
-
Entry to In-Particular person Occasions like our dinners in Vegas, San Francisco, and so forth.
That is the second to attach with others who’re good, sort, and asking the identical questions we’re. The place is that this all going? And the way do to organize?
