Writing
Notes on web infrastructure, hosting, and the tools that keep sites online. Write-ups, breakdowns, and the occasional post-mortem.
Follow on X.
2026
Agentic security operations is coming to small hosting. See what Cloudflare's AI SOC automation means for one-server shops and cPanel hosts.
WordPress 7.1.3 patches seven security flaws, including stored XSS in comments admin. See what to fix now and why this release needs an immediate update.
AI agent evaluation should end with a database state check, not a clean transcript. This is why tool calls alone can't prove an agent worked.
Reflection Beam open-weight MoE model: 501B total, 23B active params, Apache 2.0 weights, reasoning effort, and self-hosting notes.
Amazon Bedrock Managed Agents now runs OpenAI models inside your AWS account, using IAM, VPC endpoints, and CloudTrail for governance.
Vulnerability risk management breaks when AI speeds up exploits. Learn why CVE spreadsheets, CVSS, and EPSS need automation now.
VPS vs AWS for small apps: when a single VPS with Nginx, systemd, and Postgres beats AWS complexity and cost for developers.
Agent-to-agent handoff security is the AI security gap most audits miss: authority passed between agents is invisible to single-agent checks.
Cloudflare x402 MCP tools turn tool calls into paid transactions. See who controls AI agent spending limits and how agent payments and billing stay capped.
SC WordPress malware is a self-healing mesh. Learn why deleted backdoors return and the correct WordPress backdoor removal order.