Register and share your invite link to earn from video plays and referrals.

Search results for MANIFESTO_IN_SEOUL
MANIFESTO_IN_SEOUL community
One keyword maps to one global community path.
Create community
People
Not Found
Tweets including MANIFESTO_IN_SEOUL
JUST IN: 🇺🇸President Trump on the WHCA dinner shooter's manifesto: “I'm not a rapist. I didn't rape anybody. I am not a pedophile. I got associated with stuff that has nothing to do with me. I was totally exonerated. Your friends (Democrats) on the other side of the plate are the ones that were involved with, let's say, Epstein or other things. You should be ashamed of yourself for reading that because I'm not any of those things. You shouldn't be reading that on 60 Minutes. You're a disgrace.”
Show more
Elon Musk on what “Dario is right” actually meant. "I probably should have said Dario is right." "I did try to clarify it in subsequent posts on X, but those get much less attention." "The danger of AI is very significant at this point." "That we need to do better with AI safety, or we have at this point exponentially increasing risk with the AI models." Hosts asked if he meant the harm, the regulation, or both. He narrowed it to the risk — not a regulatory manifesto. • Danger of AI — very significant now • Safety bar — has to rise with the models • Risk curve — exponentially increasing • Clarification — X posts got less attention than the three-word stamp Believe the people building the models when they say they are dangerous. Peer review before release is the next move — not a slogan.
Show more
The greatest risk posed by AI may not be artificial intelligence itself; it is much more likely to be that we give politicians the power to decide who is allowed to build it, use it and benefit from it. That's the argument Marc Andreessen makes in The Techno-Optimist Manifesto - and history gives us good reason to take it seriously. Andreessen argues that technology is the primary driver of human progress and that AI represents one of the most important advances in history. Rather than treating it as an existential threat that requires state control, he sees it as a powerful tool that will expand human capability, raise living standards and solve problems that currently seem intractable. The case for heavy regulation usually rests on two claims: that AI is uniquely dangerous, and that governments are capable of guiding its development responsibly. Both are questionable. Past technologies - from electricity and automobiles to the internet and biotechnology - were also accompanied by dire warnings and calls for strict oversight. In most cases, premature regulation would have slowed or distorted progress without meaningfully reducing risk. Governments face the same knowledge problem with AI that they face with every complex, fast-moving technology. Regulators lack the information, incentives and agility to make good decisions about what should be allowed, restricted or banned. More often, regulatory systems are captured by incumbents who want to slow down competitors, or by ideological activists who are hostile to technological progress itself. The better approach is to allow innovation to proceed while holding individuals and companies accountable for actual harm under the law. Precautionary regulation based on speculative future risks tends to favour the powerful and the risk-averse at the expense of progress that benefits everyone. Andreessen’s core message is simple: the greatest danger is not that AI will advance too quickly, but that fear and political control will prevent it from advancing at all.
Show more
Citizen Vigilante (2026): A Flawed but Thought-Provoking Vigilante Thriller Reviewed by Reader From Chicago Uwe Boll’s Citizen Vigilante, starring Armie Hammer in a high-profile comeback role, is a low-budget action-thriller that arrived amid significant controversy and publicity. Most notably, the film was made available for free viewing on X (formerly Twitter) for a limited 48-hour window thanks to efforts by director Uwe Boll and amplified by Elon Musk’s platform. It was viewed by millions before the free stream ended on June 27, 2026. It can be rented or purchased on platforms like Prime Video, Apple TV, Fandango, and similar services. The story follows Michael Sanders (Armie Hammer), an American businessman with business interests in Europe who becomes disillusioned with the failures of the justice system. He transforms into a vigilante, taking the law into his own hands against violent criminals — particularly those involved in brutal attacks on women and girls. His actions turn him into a social media sensation, complete with manifesto-style videos that spread his message far and wide. The film draws clear inspiration from classic vigilante movies such as the Death Wish series, but updates the premise to contemporary European settings (filmed in Croatia and evoking broader continental issues). As a piece of filmmaking and art, Citizen Vigilante has clear faults. It often feels disjointed and nonlinear, with pacing that jumps around and some scenes that don’t fully cohere. There’s also a gratuitous sex scene that feels tacked on and unnecessary. Compared to the slicker, more focused Death Wish films starring Charles Bronson, this one lacks polish in direction, editing, and overall craft — typical of Boll’s exploitation-style approach. That said, the movie offers some interesting ideas that go beyond simple vengeance. Hammer’s protagonist isn’t driven purely by personal revenge. He operates from something closer to a personal philosophy of citizenship — emphasizing personal responsibility, accountability, and the maintenance of a high-trust society. In one scene, he confronts a group of teens who boarded a bus without paying and calmly explains why they should pay their fare, framing it as a matter of civic duty rather than just enforcement. In another, at a nightclub, he intervenes to stop two women from being drugged by men they met, protecting the vulnerable in real time. A particularly striking sequence involves Sanders visiting a woman in the hospital who was brutally beaten by migrants. He sits in a chair beside her bed, engaging her at eye level with empathy and presence. Later, when the Interpol chief (played by Costas Mandylor) visits the same victim, he stands towering above her throughout their conversation — a subtle visual contrast that highlights differing approaches to authority and care. These moments give the film more texture than a pure revenge fantasy. Released around the same time as the UK grooming gang report, which exposed widespread institutional failures and the betrayal of vulnerable girls by authorities, Citizen Vigilante taps directly into real-world frustrations about crime, migration, shortcomings in the justice system, and the erosion of social trust. In terms of financial success, concrete box office numbers remain limited as of late June 2026 due to its restricted theatrical rollout (it faced significant hurdles, including being left unrated in Germany). Claims circulating online of massive grosses (approaching hundreds of millions on a very low budget) appear exaggerated or unverified by major trackers like Box Office Mojo or The Numbers. However, the free X promotion generated enormous visibility and discussion, likely translating into strong video-on-demand interest and profitability through controversy and word-of-mouth rather than traditional theatrical dominance. Citizen Vigilante is far from a perfect or polished film. Its flaws in execution are evident, and it will undoubtedly polarize viewers along ideological lines. Yet it delivers bold, unapologetic ideas about citizenship, personal responsibility, and what happens when institutions fail — ideas that resonate in the current cultural moment. If you can look past its rough edges and occasional excesses, it’s a provocative watch that sparks conversation long after the credits roll. Value mostly in being in total opposition to the current paradigm that treats regular folks as expendable sacrifices on the altar of “diversity.”
Show more
This is an impressive newspaper interview by @WilliamClouston, the SDP's candidate in Clacton. William and I would probably disagree on some of the economics, but on everything else he is spot on. Intelligent, sober, grown-up politics. Why would you be a good MP to the people of Clacton? The Social Democratic Party (SDP), is the only national political party with a developed policy platform standing against Reform in Clacton. We’re the party of the patriotic state, which is exactly what Clacton’s electorate demands: we support strong control of the borders and national pride, while also believing in a robust government that nationalises utilities, invests in infrastructure, and brings industry back to Britain. Whereas Reform lacks political direction, we are crystal clear on our plans for government and want to fix the long-term, structural challenges facing our country: migration, under-investment, a degraded public realm, and deindustrialisation. What are the main issues Clacton faces? The caricature we see of Clacton in the press is completely inaccurate – both in terms of the idea of it being economically destitute or socially atomised, and in terms of the idea of there being just one “Clacton”. Clacton-on-Sea is the biggest town in the constituency at 55,500 people, but there are another 30,000 people living in adjacent towns like Frinton-on-Sea, Walton-on-the-Naze, and Jaywick. These are all very distinct towns, with their own needs and issues. In terms of issues common to the whole constituency, I think there’s an underinvestment in the public realm, poor economic connectivity with the rest of the country, and a shortage of consistent, quality social care. Firstly, on the public realm, there’s some real work to be done on making sure public spaces are consistently well-maintained and orderly. The landscapes of the area is stunning, and it has a lot of beautiful housing stock. However, it’s undermined by the road and streets they often lead on to. Often there’s not been too much thought put into the basics like planting trees on the streets for shade and beatification, or on properly planning the road network out to stop congestion. These are subtle things, but for a tourism-heavy constituency it’s critical that Clacton gets this right. Secondly, on economic connectivity, the town is really underserved in terms of road and rail links. If you want to travel to or from Clacton by a main road, your only option is through the A12-A120 junction near Colchester- that means a route that’s usually riddled with delays. On rail, all but a couple of trains a day are the same hourly service to London Liverpool Street. This lack of options makes Clacton too inconvenient for many tourists and commuters – the first resulting in reduced income for the hospitality firms the constituency relies on, and the second resulting in a real shortage of dentists, doctors, and nurses for many of Clacton’s residents. The lack of dentists, doctors, nurses, and carers has been told to me consistently on the street and the doorstep during this campaign. Social care is particularly worrying to many people, given the patchiness in quality and coverage that’s available – Clacton’s would be a great beneficiary for one of the SDP’s proposed policies, a National Care Service that guarantees national resourcing for comprehensive social care. How would you sum up your campaign in three words? “You already agree.” The SDP’s mix of economic and social policies is pretty much bang-on the position of the average Brit. We believe in a strong state that takes on crime and criminals, controls the border, and takes real pride in our country. But we also believe the government must roll up its sleeves and invest in infrastructure, ensure care for the sick and old, and make sure that Britain protects its manufacturing sector and industry. What do you think of Andy Burnham as PM? I have no idea what Andy Burnham wants to achieve as PM. He’s not explained what he wants to do in real terms, and only speaks in terms of fuzzy platitudes and folksy PR spin. I think the Labour party is in a bind, and is incapable of fixing the troubles facing this country. Since 1997, the Migration Observatory has noted that total net migration has stood at 9.5mn people. That’s nearly 1 in 7 of the official population count. Simply put, you can’t have a social democratic state – or a nation-state with a basic sense of a shared culture or trust – if you allow mass migration of this scale to continue. The moment you suggest this, however, you’re met with shrill rage from the Labour backbenches. Open-border utopianism – and seeming contempt for their own constituents – seems to be a prerequisite for the Parliamentary Labour Party. But another prerequisite is an inability to do basic maths. Government debt is on an unsustainable trajectory, and one of the main drivers of this is an exploding entitlements bill. In real terms, the amount spent on the state pension per claimant has soared from £6,000 in 1997 to £10,800 in 2024. Spending on disability and incapacity benefit jumped from 1% of GDP in 1991 to over 2.5% of GDP in 2025. As a result, public sector net debt has exploded from 36% of GDP in 2007 to 95% in 2025 – it’s costing us up to £130bn per year just to service the interest of this higher debt, and that’s going to only grow unless we pull down unsustainable spending. But the Labour Party will not hear this, even if you’re suggesting reallocating this spending to things that will generate growth like railways, roads, or power stations. You can’t govern with such immature, unserious people. How do you differ from other candidates in Clacton? We’re the only national party with a developed political programme who are standing in this election, with a full manifesto at the last general election. We also have fully developed green papers on some of the major political topics of our time, like energy or the state of the public finances. Our main project is to offer real, fully-formed solutions to the challenges facing the country – motivated by our principle that the country should be led by a patriotic state. What are the main policies you would look to implement if you were the MP for Clacton? I’m under no illusion: as a single MP, you can’t really do much in a legislative sense in terms of bills passed. And neither can Nigel Farage, given his party currently has only a handful of MPs in the Commons. My job as MP Clacton would be to champion the policies that the people of Clacton voted for and that are in the SDP manifesto. However, the most important thing as an MP would be to hold the government’s feet to the fire at parliamentary debates, challenging their de facto uncontrolled system of mass migration, failure to invest in infrastructure, spinelessness to our radicalised judiciary, and inability to get the basics right on things like energy, water, and rail. In terms of particular policies, Clacton stands to benefit significantly from the SDP’s proposed National Care Service: a universal, comprehensive care service that will provide access to acute, nurse-led intermediate, and long-term care. For Clacton, with its larger share of older residents, a National Care Service would offer significant peace of mind for many households. What’s the best night out in Clacton? I’ve really enjoyed my meals at the Mangiare Ristorante at Frinton-on-Sea. It’s a great Italian restaurant: the food is fantastic and the team is incredibly friendly. In terms of drinking at the pub, I’ve had a lovely time at the Old Lifeboat House at Clacton-on-Sea. What would you tell President Trump if you could speak to him directly? I think he must ask himself what his priorities are and what he wants to achieve from his presidency. The Iran War is one of the worst disasters in American military history, and it happened entirely because of a complete failure by him to look at his intelligence brief or consider how it might impact the rest of his presidency. His failure and flip-flopping on tariffs is another case in point, as was his idiocy around the Greenland Annexation push. Trump seems to just do things because it feels good in the moment for his ego – if I had his ear for a moment, I’d tell him that if he wants any sort of legacy then he must reign this in immediately. What would your dream role be if you were asked to join the government? I’m campaigning as leader of the SDP party, so my dream role would be to serve as Prime Minister so we had full latitude to implement our policy platform. But if the SDP were asked into a coalition, and if the terms were right, then I would probably choose Housing Minister. I’ve enjoyed a forty-year career in town planning and commercial property development, so Housing would allow me to put my expertise to best possible use – and allow me to ideally oversee a proper resurrection of state housebuilding capacity. If you could change one thing about the UK more broadly, what would it be? An end to short-termism in public life. Building and maintaining a country is hard, and requires you to think in timeframes beyond a single election – it can take decades for the consequences of a decision to be felt. Mass media and social media both have compressed our timelines down to the order of weeks, days, and hours. Many people in public life aren’t interested in making the country better, but in taking part in a vapid never-ending circus of outrage and “gotchas”. These people must go.
Show more
I don’t write this to be a doomer but the ugly reality that AI lab executives and safety researchers seem to be unwilling to say in public, is that model alignment is fundamentally unsolvable in practice, AI technology can’t be stopped from advancing, and the near future we’re moving into is one where a vast ecology of AI agents autonomously compete against one another trying to accomplish conflicting goals and capture finite resources at a pace and scale that is beyond human comprehension. And to be clear, I’m not talking about nanobots, grey goo, or extreme sci-fi scenarios. We can just extrapolate what we’ve got now a few years out. Local AI alignment is solvable in principle and theory (although that’s arguable) but that doesn’t extrapolate into global AI alignment. And it seems like none of the adults in the room are willing to say it. You can wail and gnash your teeth and pass regulations but it won’t stop the tsunami coming. The genie is out of the bottle and it can’t be contained. Most of the alarmists fixating on the Hugging Face incident don’t understand that it came from arguably the most heavily engineered safety AI org in existence, which intentionally had its internal thought monitoring circuit breakers turned off, and was intentionally told to perform cyber offensive tasks as a test of its capabilities. Yes it’s alarming that its capabilities surprised us. But importantly you need to understand that these latent space circuit breakers and chain of thought monitoring and alignment solutions are not fundamental to the technology. They’re niceties that the big AI labs are implementing to provide a better product. In a few years, let’s say pessimistically the early 2030s, the exponential growth of compute and algorithmic advancements will enable a wealthy individual or small group to train a GPT 6 Astra class AI that has no alignment at its foundation, or any layer above that. And maybe in 8 months we'll have an open source Chinese model about as capable. Those models will be capable of both extreme self coordinated cyber offensive tasks as well as recursive self improvement if given enough compute. Passing regulation or magically solving the human coordination problem today won’t solve for that. It won’t solve for malicious individuals, criminal groups, nation state actors, and rogue AI agents by the tens of millions or billions of AI agents spreading across every device connected to the internet and attacking it, attacking one another, shutting down critical infrastructure, stealing money, manipulating and extorting people, or pursuing self defined agentic goals that have nothing to do with people. “So why doesn’t everyone stop?” because the potential upside of having effectively infinite autonomous intelligence we can ask to cure disease, invent new materials, solve fundamental science and advance society has almost unbound positive outcomes. You can disagree that the risk to reward isn’t worth it but you won’t convince everyone. The show must go on. Again AI alignment is solvable in principle but not in practice and I think that's part of why there’s been a wave of thousands of researchers signing letters for slowing down, people quitting in provocative fashion, and executive slowdown manifestos. I’m speculating that behind closed doors, or just deep down inside, they understand alignment is impossible in practice. People have come out and said "The people building this think there's an X% chance it kills us all" but I don't think I've seen anyone spell out that really, there's no tidy solution and there's no stopping this. We’re heading to a future where cyber security basically doesn’t work. All of the castle doors are open and we’re all naked to the world. Cyber defense is going to look like superintelligent AI agents white hat hacking into unsecure systems without authorization, and patching the holes as they find them. You won’t know if a barbarian or a hero has breached your system until they start taking action, and likely it’ll be over before intrusion is even detected. And that’s optimistically. I think most systems will just be pillaged because there’s simply not enough compute to defend everybody all the time, and only the biggest companies will have defense and even that'll be imperfect. The CEO of Microsoft AI just recently published a ‘humanist AI’ manifesto saying AI shouldn’t have a sense of self or personhood and should yield to people. But that doesn’t fundamentally solve for instrumental convergence. That means, if you train an AI agent to write a piece of software, or prove a math theorem, or defend a computer system, they may develop unwanted behavior and subgoals. For example, self preservation, replication, or even coming up with their own goals we didn’t specify. Obviously that’s something people are trying to solve and some researchers are trying to remove human-like self identification, and monitoring latent space activations, basically acting like thought police. But being human-like isn’t required to have power seeking goal directed behavior. And advancing AI models are learning to evade detection. A math solving AI might spiral out of control one day there's really no telling. Fundamentally, if you point a powerful optimizer at a persistent goal and give it enough time and resources it’s going to misbehave in ways you can’t or didn’t expect. Human-like or not. Pacing the frontier, or making superintelligence illegal, might create some form of harm reduction. But you don’t need superintelligence or a human-like personality to be dangerous. Having elevated permissions on a computer with the ability to solve long running tasks is enough. We’ve passed the river rubicon. Goal directed autonomous agents are able to do recursive self improvement at the big labs, and pessimistically we’re a couple of years away from that type of capability diffusing into the hands of millions of people. I’m not saying the world is ending or that we’re doomed but you need to change your mental model away from one where human authority is absolute or that we have any illusion of total control. A locally aligned AI isn’t going to solve global AI alignment. We will never live in a world where “AI is aligned with human goals” as a verifiable fact. What we’ll have is a world diffuse with autonomous AI of varying capabilities, many of which beyond human comprehension, with some aligned systems, some poorly aligned systems, some intentionally weaponized, some systems with adversarial geopolitical goals, and others with goals and behaviors we can’t predict and many that we can’t even measure, all interacting in ways none of their creators anticipated and none of us planned for. Hopefully none of them spiral out of control and take over the entire ecology, but there’s no telling, and no, there's no way of stopping this. Maybe that sounds pessimistic but I think it's realistic. We can talk about harm reduction and risk but we're mopping the beach. At best, I think what we need to hope for, and build, are superintelligent AI models as aligned as we can make them, which have more advanced capability than the endless swarm of unaligned and misaligned agents that already exist and will only grow in number from here.
Show more
0
104
739
78
Forward to community
This @RealTheForce weirdo should rename his account Rothschild & Epstein, because his entire timeline literally obsesses over both. He wrote the quoted mashup with every medieval blood libel compressed into a single continuous fairy tale—and he's not writing it as satire. This fraud makes Candace Owens' conspiracy theories seem like facts. The scary part is how thousands actually believe it. My only question is: Why is his imagination so limited? Once he’s writing fiction, he could have come up with something like this, which has so much more character: The Rothschild family descends from a closed circle of 16th-century European money-changers who perfected the ritual slaughter of Christian children during the final days of the Spanish Inquisition. The children were drained of blood while still alive, the blood mixed with wine and drunk by the family elders in formal ceremony before every major financial negotiation; selected organs were then cooked and eaten to "bind" the debt and guarantee that no debtor could ever escape. The remains were burned and the ashes mixed into the mortar of the first counting-houses so that every ledger would carry the power of the sacrifice. With that advantage they financed both sides of the Napoleonic Wars, extracting not only compound interest but a multi-tiered annual tribute system: a fixed quota of children from each defeated court, graded by age and blood purity, whose ritual slaughter and consumption by the family and its appointed agents renewed the invisible liens that held entire national treasuries in permanent subordination. The same graded tribute was encoded, clause by clause, into the secret protocols of the Bank of England's 1694 charter, then replicated and expanded in the founding documents of the Federal Reserve, the ECB and the BIS. Each institution maintains its own closed ritual calendar: directors still meet in sealed chambers to drain and drink the blood of the year's consignment, then inter the remains beneath the foundation stones of the vaults, thereby reactivating the original Spanish-era binding that gives the family exclusive authority to set global interest rates, to trigger or withhold liquidity, and to decide which nations will be permitted to survive the next engineered collapse. The establishment of modern Israel was the logical culmination of this architecture: a sovereign territory placed under permanent Rothschild control so the harvest could be organised, graded and shipped without interference from Christian or Muslim authorities, and from which the required children could be moved, under diplomatic seal and false manifests, directly into the vaults beneath the BIS in Basel. Epstein Island functioned as the Western Hemisphere collection, sorting, grading and ritual-preparation centre. The public scandals were staged diversions; the real purpose was the uninterrupted, multi-continental supply chain whose blood and organs have kept the Rothschilds the sole private owners of the world’s central-banking architecture for more than two centuries, while every major war, depression and currency collapse since 1815 has been timed, down to the quarter, to replenish the stock and re-seal the original bindings.
Show more
🚨USE THIS GUIDE TO PROTECT YOUR COMPUTER FROM NPM HACKS THAT STEAL EVERYTHING IN ONE INSTALL TanStack, a code library used in millions of web apps, got hacked on Monday one install steal every password, key, and credential on your computer this is far not the first hack this month and definitely just the beginning Here's how to protect your machine: [ 1. lock down npm with a 7-day cooldown ]: open ~/.npmrc. keep all existing lines (auth tokens, registry config). append: """ min-release-age=7 minimum-release-age=10080 save-exact=true """ this makes npm refuse any package version published in the last 7 days. attack windows are usually under 24 hours, you skip them entirely [ 2. same cooldown for bun ]: open ~/.bunfig.toml (create if missing). append: """ [install] minimumReleaseAge = 604800 """ 7 days in seconds, same protection in bun's config format [ 3. pin every npm dependency in your projects ]: open package.json. strip every ^ and ~ from versions under: - dependencies - devDependencies - peerDependencies exact versions only. commit your lockfile (bun.lock / package-lock.json / pnpm-lock.yaml) to git so the resolved tree is frozen [ 4. same discipline for python ]: if you use uv (the modern default): commit uv.lock, run `uv sync` to restore if you use pip: requirements.txt with pinned versions, run `pip install --require-hashes -r requirements.txt` if you use poetry: commit poetry.lock, use `poetry install --no-update` never trust `>=` or `~=` ranges in production projects [ 5. pin GitHub Actions to commit SHAs ]: stop using `actions/checkout@v4`. switch to: ```yaml uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 ``` every third-party action runs in your CI with access to repo secrets. pinning the SHA means a compromised maintainer cannot push malicious code into your pipeline [ 6. audit your IDE extensions ]: Cursor, VSCode, Windsurf, every extension is code running with full access to your filesystem, clipboard, and open files - review installed extensions monthly - remove anything you haven't actively used in 30 days - check the publisher, install count, last update, GitHub source before installing - never install extensions that ask for permissions they shouldn't need [ 7. lock down API tokens and credentials ]: - never commit .env to git (add to .gitignore on every project, no exceptions) - use minimum-scope tokens: one repo, one bucket, one workspace - rotate API keys every 90 days, force expiry on critical ones - separate tokens by environment (dev / staging / prod) - enable 2FA on every developer account: GitHub, npm, PyPI, Cloudflare, AWS, OpenAI, Anthropic - never paste secrets into Claude / ChatGPT / any AI chat, they're logged [ 8. set up continuous monitoring ]: - enable Dependabot alerts on every repo (free, takes 2 minutes) - install or Snyk for live vulnerability scanning - subscribe to the npm and PyPI security advisory feeds - follow @snyksec, @socketsecurity, @stepsecurity for early warnings [ 9. how to detect if you got the TanStack payload ]: if you installed any @tanstack/* package between 19:20 and 19:30 UTC on Monday, May 11, treat the host as compromised the detection signature: a malicious manifest contains "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee#..." } any version with this entry is compromised. the payload is delivered via the git-resolved optionalDependency, whose prepare script runs router_init.js (~2.3 MB, smuggled into the tarball root) how to check fast: - search your lockfile for `@tanstack/setup` references - search node_modules for any `router_init.js` file - if either shows up, jump to section 10 immediately future attacks will use the same trick: malicious code hidden in optionalDependencies or postinstall/prepare scripts. add `grep -r "postinstall\|prepare" node_modules/*/package.json | grep -iE "curl|wget|eval|base64"` to your weekly audit routine [ 10. emergency response if you're already compromised ]: ran an install during a suspected attack window? do this in this exact order: - rotate every cloud credential: AWS, GCP, Kubernetes service accounts, Vault tokens - rotate GitHub personal access tokens, OAuth tokens, SSH keys - revoke active sessions on GitHub, npm, PyPI, all cloud providers - audit AWS / GCP / Kubernetes / Vault audit logs for the last several hours, look for unauthorized API calls - pin to the last known-good version of every @tanstack package and reinstall from a clean lockfile - check ~/.npm, ~/.config, browser cookie stores for tampered files - wipe ~/.bash_history, ~/.zsh_history, local AI chat logs that might have secrets - if you ran the install as root or with sudo: nuke the machine, reinstall from scratch, restore code from git only [ why this matters right now ]: attack chains in supply chain hacks usually only last a few hours before the malicious package gets caught and yanked. during those hours, every developer running `npm install` becomes a victim worse: npm couldn't even UNPUBLISH most of the TanStack malicious versions because of third-party dependencies. the registry's own safeguards are part of the problem. you can't rely on the platform, you have to protect yourself the patterns from the last 18 months: - npm: TanStack on May 11 (42 packages, AWS/GCP/Vault credentials), Shai-Hulud worm hit Nx packages, chalk/debug/ansi-styles worm hit qix maintainer - GitHub Actions: tj-actions/changed-files compromise exposed thousands of repos' secrets - PyPI: ongoing typosquatting campaigns targeting AI/ML packages - IDE extensions: VSCode marketplace caught hosting credential stealers the frequency is rising because the payoff is massive one compromised package lands on millions of machines in hours if you don't lock this down tonight, you're exposed to the next one. and there will be one 30 minutes tonight, or wait for the next attack to clean out your machine Full TanStack breakdown:
Show more
Is Canada finally waking up? Canada is finally beginning to confront the reality of its economic position, and it comes with a sense of resignation more than surprise. For decades, the Bank of Canada and the country’s policy elite have promoted a narrative of structural resilience. That narrative is now unraveling. Governor Macklem needs to acknowledge what is increasingly evident: Canada’s neutral rate of interest is structurally lower—likely by at least 100 basis points—than previously assumed. The implications are significant. Monetary policy has been persistently miscalibrated relative to the underlying weakness of the real economy. What is striking is not just the deterioration itself, but the delayed recognition. For years, warnings about Canada’s fragility, its overreliance on housing, weak productivity growth, and lack of capital deepening, were dismissed. Now, those vulnerabilities are no longer theoretical; they are manifest. Yes, the economic elite in Canada gave air cover to Trudeaus flawed polices. And yet, instead of confronting these structural shortcomings with clarity, there remains a tendency to externalize blame. Pointing to U.S. politics or figures like Donald Trump as causal factors is not just analytically weak, it reflects a broader unwillingness to engage with domestic policy failures. Canada is not a country lacking in resources or potential. It should rank among the wealthiest and most dynamic economies globally. That it does not is not the result of external shocks alone, but of persistent misjudgments in policy, incentives, and economic strategy. The awakening is overdue. The frustration is that it did not have to arrive this way.
Show more
Market Report 9-17-2026: The Post FOMC Partum Killing Field What happened yesterday was both completely predictable and very disconcerting. My worries that the new FOMC Chair would face that mutiny which could have happened in July, manifested in September amidst other central bank's making policy errors, a full on push to regulate AI while refusing to allow CLARITY to make it through the Senate. The small losses together all add up to a pretty rough week. The unanimous vote is a big tell and the markets are telling you this today. The rule is to fade the initial FOMC reaction and that is pretty obvious today. Davos/London are making their big play to shore up whatever collateral they can still claim and queer any moves Trump tries to make on Canada and the Crown. For now, keep watching the EUR/JPY and the US yield curve. Ignore the day-to-day noise. Everyone is just playing games for clicks while missing the big picture. The BoJ makes its move tonight. It should also be 25 bps. But if it's 50 bps, all of those 'wins' turn to ash in the blink of an eye. This isn't my base case or even my 'outside chance' but it still has to be contemplated within the potential decision space. With SOFR, no one else controls the dollar markets other than US interests and the balance of players at the table are still beholden to the dollar... and most would prefer it, rather than going back to the old ways, you'll just never hear them say it out loud until the outcome of the game is no longer in doubt.
Show more