Ideas

Thinking
out loud.

Notes on AI security, design, and the places where they collide. Covering LLM exploits, zero-days, and the craft of building things that last.

14
AI Finds 0-Day in Linux Kernel Before Any Human Did

Google's Project Big Sleep agent autonomously discovered a memory-corruption vulnerability in the Linux kernel's io_uring subsystem — patched before public disclosure. The era of AI-first vulnerability research is here.

May 2025 AI Security
13
Prompt Injection: The Vulnerability AI Can't Patch Itself

Unlike buffer overflows or SQL injection, prompt injection attacks are semantic — they exploit the model's instruction-following nature. Understanding why this class of vulnerability is structurally different from everything that came before it.

May 2025 LLM Security
12
RAG Poisoning: When Your AI Knowledge Base Becomes an Attack Vector

Retrieval-Augmented Generation systems trust their data sources implicitly. Injecting adversarial content into a vector database can hijack every query that retrieves it. A walkthrough of the attack surface.

Apr 2025 LLM Security
11
Sleeper Agents in LLMs: The Attack That Survives Fine-Tuning

Anthropic's 2024 research showed that LLMs can be trained to behave normally until a specific trigger condition is met — and that standard RLHF safety training fails to remove the behavior. What this means for any organization deploying third-party models.

Apr 2025 AI Safety
10
Malicious Models on Hugging Face: The New Supply Chain Attack

Researchers discovered over 100 models on Hugging Face Hub containing serialized payloads that execute arbitrary code on load via pickle deserialization. The ML supply chain has the same vulnerabilities as npm — and less scrutiny.

Mar 2025 Supply Chain
09
CVE-2024-6387: How a 0-Day in OpenSSH Went Undetected for 18 Years

regreSSHion was a signal flare. A race-condition vulnerability dormant since 2006, rediscovered by Qualys's AI-assisted static analysis pipeline. On how AI-powered code auditing is surfacing bugs that escaped a generation of manual review.

Feb 2025 Zero-Day
08
AI-Discovered Critical Vulnerabilities in 2025: A Running Tally

From Google's Big Sleep SQLite buffer overflow to Microsoft's Security Copilot flagging misconfigurations in Azure — a curated log of vulnerabilities where AI either found the bug, accelerated the patch, or changed the disclosure timeline.

Jan 2025 AI Security
07
The Case Against Consistent Design

Why the obsession with pixel-perfect consistency might be the thing that's making your product feel lifeless — and what to reach for instead.

May 2025 Design
06
Monospace as Aesthetic Statement

There's a reason the most interesting corners of the web keep reaching for fixed-width fonts. It's not nostalgia — it's a precision play.

Apr 2025 Typography
05
Speed Is a Design Choice

Performance and aesthetics are the same conversation. A 3-second load time isn't a technical problem — it's a trust problem, a brand problem, a relationship problem.

Mar 2025 Performance
04
The Grain Always Comes Back

On the resurgence of texture in digital interfaces, and why generations of designers keep rediscovering that the most modern surfaces are never perfectly smooth.

Feb 2025 Texture
03
What Dark Mode Actually Means

Dark mode isn't an accessibility feature or a user preference toggle. For some of us, it's the only honest way to work — a disposition, not a setting.

Jan 2025 Philosophy
02
Static Sites and the Long Game

Every framework promises the future. HTML has already survived three decades. There's something to be said for betting on the thing that doesn't need updating.

Dec 2024 Web
01
Why I Keep Coming Back to Georgia

Screen-native, battle-tested, and more expressive than anything that came after it. The most underrated typeface in the history of digital design is already on your device.

Nov 2024 Typography

Stay in the loop

New ideas, when they're ready.

Get notified  →