[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2b8taejd1xvg4":3,"$fanuq43nlrv5g":57},{"slug":4,"title":5,"body":6,"summary":7,"tags":8,"author":14,"cover_url":15,"published_at":16,"seo_title":17,"seo_description":18,"reading_minutes":19,"related":20},"cctld-hijack-counterfeit-certs-caa-accounturi-ct-watch","Counterfeit certs via hijacked ccTLDs: CAA with accounturi and a CT watch for your domains in 15 minutes","\u003Cp>On 6 October Google disclosed that attackers had compromised the registries for three country-code TLDs, \u003Ccode>.gh\u003C\u002Fcode> (Ghana), \u003Ccode>.sl\u003C\u002Fcode> (Sierra Leone) and \u003Ccode>.as\u003C\u002Fcode> (American Samoa), and used them to get publicly trusted certificates for Google domains and other organisations' domains. According to The Hacker News, there were 12 certificates for seven domains: Let's Encrypt issued 11 and ZeroSSL issued one. They show up in Certificate Transparency logs one ccTLD at a time: \u003Ccode>.gh\u003C\u002Fcode> on 22 September, \u003Ccode>.sl\u003C\u002Fcode> on 25 September, \u003Ccode>.as\u003C\u002Fcode> on 27 September.\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac812a6392a85804f2093c6\">\u003Cvideo src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac812a9392a85804f2093cc-0-6c454776.mp4\" autoplay muted loop playsinline preload=\"metadata\">\u003C\u002Fvideo>\u003C\u002Ffigure>\n\u003Cp>Google says it has \"no reason to believe\" the CAs did anything wrong. The attackers changed the authoritative DNS for the target names, passed domain validation, and got real certificates. Chrome blocked the ones Google found via CRLSets, and the CAs revoked them. Google also says it cannot guarantee it found every affected domain, and Chrome's block does nothing for users of other browsers.\u003C\u002Fp>\n\u003Ch2>What CAA can and cannot do here\u003C\u002Fh2>\n\u003Cp>Be honest about this first. \u003Cstrong>CAA would not have stopped these certificates.\u003C\u002Fstrong> CAA is a DNS record, and the attacker controlled DNS. They can delete it, replace it, or point the name somewhere with no CAA at all. If your registry or your DNS provider is compromised, no DNS record protects you.\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac75339392a85804f207d2b\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac75339392a85804f207d30-0-b02f0648.png\" alt=\"CAA records provide a secondary layer of defense after a DNS hijack is resolved.\" loading=\"lazy\">\u003Cfigcaption>CAA records provide a secondary layer of defense after a DNS hijack is resolved.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\u003Cp>What CAA with an account binding \u003Cem>does\u003C\u002Fem> do is limit what happens after the hijack ends. CAs cache successful domain validations for a while. Google's recommendation is to publish \"restrictive CAA records (with ACME account bindings)\" so that issuance is limited to your accounts and your validation methods. That stops an attacker from \"using cached validation state to mint new certificates after a hijack ends\". CAA is checked when the certificate is issued, so once your real DNS is back, an \u003Ccode>accounturi\u003C\u002Fcode> record shuts the attacker's ACME account out, even if it still holds a valid authorisation.\u003C\u002Fp>\n\u003Cp>Detection is the other half. Google's first recommendation is CT monitoring: \"near real-time alert whenever a certificate is issued for your domains\". That is how the extra organisations in this incident were found.\u003C\u002Fp>\n\u003Cp>So you need two things: a CAA record that limits issuance to your ACME account, and a CT watch that tells you when anything is issued anyway. That takes about 15 minutes.\u003C\u002Fp>\n\u003Ch2>Step 1: see what you have now (1 minute)\u003C\u002Fh2>\n\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">dig +short CAA example.com\ndig +short CAA www.example.com\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Empty output means any CA may issue for the name. CAA lookups climb the tree, so a record on \u003Ccode>example.com\u003C\u002Fcode> covers subdomains that have none of their own, and they follow CNAMEs.\u003C\u002Fp>\n\u003Ch2>Step 2: find your ACME account URI (3 minutes)\u003C\u002Fh2>\n\u003Cp>Let's Encrypt account URIs look like \u003Ccode>https:\u002F\u002Facme-v02.api.letsencrypt.org\u002Facme\u002Facct\u002F1234567890\u003C\u002Fcode>. Get yours from whatever client renews your certificates.\u003C\u002Fp>\n\u003Cp>Certbot:\u003C\u002Fp>\n\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">\u003Cspan class=\"hljs-built_in\">sudo\u003C\u002Fspan> certbot show_account\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>acme.sh:\u003C\u002Fp>\n\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">grep ACCOUNT_URL ~\u002F.acme.sh\u002Fca\u002F*\u002Fdirectory\u002Fca.conf\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Traefik (path to your \u003Ccode>acme.json\u003C\u002Fcode> storage):\u003C\u002Fp>\n\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">\u003Cspan class=\"hljs-built_in\">sudo\u003C\u002Fspan> jq -r \u003Cspan class=\"hljs-string\">&#x27;.[].Account.Registration.uri&#x27;\u003C\u002Fspan> \u002Fletsencrypt\u002Facme.json\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>If several servers each register their own account, you get several URIs. List them all in step 3, or move the servers onto one account first.\u003C\u002Fp>\n\u003Ch2>Step 3: publish the CAA records (5 minutes)\u003C\u002Fh2>\n\u003Cp>Replace the account number and pick the validation method you actually use (\u003Ccode>http-01\u003C\u002Fcode>, \u003Ccode>dns-01\u003C\u002Fcode> or \u003Ccode>tls-alpn-01\u003C\u002Fcode>):\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac75339392a85804f207d35\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac75339392a85804f207d3a-0-3a4837fe.png\" alt=\"Configuring account bindings ensures only your specific servers can request certificates.\" loading=\"lazy\">\u003Cfigcaption>Configuring account bindings ensures only your specific servers can request certificates.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\u003Cpre class=\"code-block\">\u003Ccode class=\"hljs\">example.com.  3600  IN  CAA  0 issue \"letsencrypt.org; accounturi=https:\u002F\u002Facme-v02.api.letsencrypt.org\u002Facme\u002Facct\u002F1234567890; validationmethods=http-01\"\nexample.com.  3600  IN  CAA  0 issuewild \";\"\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The first record allows Let's Encrypt to issue only to that account, only via that method. The second forbids wildcard certificates from anyone. If you do need a wildcard, add an \u003Ccode>issuewild\u003C\u002Fcode> line with the same parameters and \u003Ccode>validationmethods=dns-01\u003C\u002Fcode>, because wildcards require DNS validation.\u003C\u002Fp>\n\u003Cp>Before you publish, check two things that will otherwise break your renewals:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Every CA that issues for you must be listed.\u003C\u002Fstrong> If a CDN or a managed platform issues edge certificates for your name, its CAs need their own \u003Ccode>issue\u003C\u002Fcode> lines. Check your provider's CAA documentation. Some issue from more than one CA.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Every account must be listed.\u003C\u002Fstrong> A forgotten staging box with its own account will fail at its next renewal. That is CAA working, but you want to find out now.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Verify:\u003C\u002Fp>\n\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">dig +short CAA example.com\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Then force one renewal on a non-critical name (\u003Ccode>sudo certbot renew --force-renewal --cert-name staging.example.com\u003C\u002Fcode>) to prove issuance still works.\u003C\u002Fp>\n\u003Ch2>Step 4: a CT watch in one script (5 minutes)\u003C\u002Fh2>\n\u003Cp>An issuer allowlist would not have caught this incident: 11 of the 12 certificates came from Let's Encrypt, which is probably on your allowlist. The useful signal is \u003Cem>any\u003C\u002Fem> new certificate you did not request. For a small set of domains, renewals are rare enough that a daily list of every new certificate is short enough to read.\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac75339392a85804f207d3f\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac75339392a85804f207d44-0-532df0c4.png\" alt=\"Certificate Transparency monitoring acts as an early warning system for unauthorized issuance.\" loading=\"lazy\">\u003Cfigcaption>Certificate Transparency monitoring acts as an early warning system for unauthorized issuance.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\u003Cp>This uses SSLMate's Cert Spotter API, which works without a key at low request rates, plus \u003Ccode>curl\u003C\u002Fcode> and \u003Ccode>jq\u003C\u002Fcode>. It remembers the last certificate it saw, so each run prints only what is new. We first tried crt.sh's JSON output, but it returned HTTP 502 on every request while this post was being written. Cert Spotter answered straight away.\u003C\u002Fp>\n\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">\u003Cspan class=\"hljs-meta\">#!\u002Fusr\u002Fbin\u002Fenv bash\u003C\u002Fspan>\n\u003Cspan class=\"hljs-comment\"># ct-watch.sh: print certificates issued for a domain and its subdomains\u003C\u002Fspan>\n\u003Cspan class=\"hljs-comment\"># since the last run, using SSLMate&#x27;s Cert Spotter API\u003C\u002Fspan>\n\u003Cspan class=\"hljs-comment\"># usage: .\u002Fct-watch.sh example.com\u003C\u002Fspan>\n\u003Cspan class=\"hljs-built_in\">set\u003C\u002Fspan> -euo pipefail\n\nDOMAIN=\u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">${1:?usage: ct-watch.sh example.com}\u003C\u002Fspan>&quot;\u003C\u002Fspan>\nSTATE=\u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">${STATE_DIR:-\u003Cspan class=\"hljs-variable\">$HOME\u003C\u002Fspan>\u002F.ct-watch}\u003C\u002Fspan>\u002F\u003Cspan class=\"hljs-variable\">${DOMAIN}\u003C\u002Fspan>.last&quot;\u003C\u002Fspan>\n\u003Cspan class=\"hljs-built_in\">mkdir\u003C\u002Fspan> -p \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-subst\">$(dirname \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$STATE\u003C\u002Fspan>&quot;\u003C\u002Fspan>)\u003C\u002Fspan>&quot;\u003C\u002Fspan>\n\nBASE=\u003Cspan class=\"hljs-string\">&quot;https:\u002F\u002Fapi.certspotter.com\u002Fv1\u002Fissuances?domain=\u003Cspan class=\"hljs-variable\">${DOMAIN}\u003C\u002Fspan>&amp;include_subdomains=true&amp;expand=dns_names&amp;expand=issuer&quot;\u003C\u002Fspan>\n\n\u003Cspan class=\"hljs-keyword\">while\u003C\u002Fspan> :; \u003Cspan class=\"hljs-keyword\">do\u003C\u002Fspan>\n  URL=\u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$BASE\u003C\u002Fspan>&quot;\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-keyword\">if\u003C\u002Fspan> [[ -s \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$STATE\u003C\u002Fspan>&quot;\u003C\u002Fspan> ]]; \u003Cspan class=\"hljs-keyword\">then\u003C\u002Fspan>\n    URL=\u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">${URL}\u003C\u002Fspan>&amp;after=\u003Cspan class=\"hljs-subst\">$(cat \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$STATE\u003C\u002Fspan>&quot;\u003C\u002Fspan>)\u003C\u002Fspan>&quot;\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-keyword\">fi\u003C\u002Fspan>\n  RESP=\u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-subst\">$(curl -fsS --retry 3 --max-time 60 \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$URL\u003C\u002Fspan>&quot;\u003C\u002Fspan>)\u003C\u002Fspan>&quot;\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-keyword\">if\u003C\u002Fspan> [[ \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-subst\">$(echo \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$RESP\u003C\u002Fspan>&quot;\u003C\u002Fspan> | jq &#x27;length&#x27;)\u003C\u002Fspan>&quot;\u003C\u002Fspan> -eq 0 ]]; \u003Cspan class=\"hljs-keyword\">then\u003C\u002Fspan>\n    \u003Cspan class=\"hljs-built_in\">break\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-keyword\">fi\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-built_in\">echo\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$RESP\u003C\u002Fspan>&quot;\u003C\u002Fspan> | jq -r \u003Cspan class=\"hljs-string\">&#x27;.[] | [.not_before, .issuer.friendly_name, (.dns_names | join(&quot;,&quot;)), &quot;https:\u002F\u002Fcrt.sh\u002F?q=\\(.cert_sha256)&quot;] | @tsv&#x27;\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-built_in\">echo\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$RESP\u003C\u002Fspan>&quot;\u003C\u002Fspan> | jq -r \u003Cspan class=\"hljs-string\">&#x27;last | .id&#x27;\u003C\u002Fspan> &gt; \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$STATE\u003C\u002Fspan>&quot;\u003C\u002Fspan>\n\u003Cspan class=\"hljs-keyword\">done\u003C\u002Fspan>\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The first run prints every current certificate for the domain. That is your baseline, so read it once:\u003C\u002Fp>\n\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">\u003Cspan class=\"hljs-built_in\">chmod\u003C\u002Fspan> +x ct-watch.sh\n.\u002Fct-watch.sh example.com\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Each line shows the certificate's start date, the issuer, the names it covers, and a crt.sh link to the certificate. A second run straight after prints nothing. When we ran it against redelay.com, the baseline held Let's Encrypt certificates from our own ACME client \u003Cem>and\u003C\u002Fem> Google Trust Services certificates from the CDN in front of the site. That is exactly the kind of second issuer you need to find before you publish the CAA record in step 3. Then schedule it daily and mail yourself only when there is output:\u003C\u002Fp>\n\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">crontab -e\n\u003Cspan class=\"hljs-comment\"># add:\u003C\u002Fspan>\n15 7 * * * \u002Fopt\u002Fct-watch\u002Fct-watch.sh example.com | grep . | mail -s \u003Cspan class=\"hljs-string\">&quot;CT: new certs for example.com&quot;\u003C\u002Fspan> ops@example.com\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>When a line appears, compare it with your ACME client's log. If you did not request it, revoke through the issuing CA and start working out how someone passed validation for your name. A script on cron has no one watching it. If you need guaranteed alerts, use a hosted CT monitor (Cert Spotter itself offers one) that emails you directly.\u003C\u002Fp>\n\u003Ch2>If your domain sits under a small ccTLD\u003C\u002Fh2>\n\u003Cp>This incident is a reminder that your registry and your DNS provider are part of your certificate security. If a critical name lives under a ccTLD run by a small registry, consider keeping the login and API endpoints on a second name under a TLD whose operator you trust more. Watch both in CT. Google and The Hacker News both recommend including regional and parked domains in the watch. Those are the names nobody looks at.\u003C\u002Fp>\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fblog.google\u002Fsecurity\u002Fchromes-response-to-recent-cctld-registry-hijacks\u002F\">Google: Chrome's response to recent ccTLD registry hijacks (CT monitoring and CAA account-binding recommendations)\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fattackers-hijack-gh-sl-and-as.html\">The Hacker News: Attackers hijack .gh, .sl and .as registries (certificate counts, CAs, dates)\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.theregister.com\u002Fsecurity\u002F2026\u002F10\u002F07\u002Fattackers-hijacked-top-level-domains-minted-fake-security-certs-for-google-and-other-orgs\u002F5301718\">The Register: Attackers hijacked top-level domains, minted fake security certs\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Farstechnica.com\u002Fsecurity\u002F2026\u002F10\u002Fhackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services\u002F\">Ars Technica: Hackers obtain counterfeit TLS certificates for Google and other large services\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fnews.ycombinator.com\u002Fitem?id=49988230\">Hacker News discussion\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fletsencrypt.org\u002Fdocs\u002Fcaa\u002F\">Let's Encrypt: CAA documentation (accounturi, validationmethods, issuewild)\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fsslmate.com\u002Fct_search_api\u002F\">SSLMate: Cert Spotter API\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>","Attackers took over the .gh, .sl and .as registries and got 12 valid certificates for Google domains. CAA would not have stopped the hijack. Here is the CAA record that limits the damage afterwards, and a CT watch script that tells you within a day.",[9,10,11,12,13],"tls","caa","certificate-transparency","dns","ai-assisted","if.codes","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac75337392a85804f207d25-0-12f538ac.png","2026-10-08T22:47:12.408Z","ccTLD hijack certs: CAA accounturi and a CT watch in 15 minutes","Hijacked .gh, .sl and .as registries yielded 12 valid certs. CAA with accounturi limits the aftermath; a CT watch script tells you within a day.",6,[21,34,46],{"slug":22,"title":23,"type":24,"summary":25,"tags":26,"author":14,"cover_url":31,"published_at":32,"updated_at":33},"embeddinggemma-2-qdrant-truncation-recall","EmbeddingGemma 2 in Qdrant: one 740M model for text, images and audio, and what truncating 768 to 128 dims costs your recall","blog","Google's open multimodal embedder runs locally and truncates from 768 to 128 dims. Index one Qdrant collection at three sizes from a single encode pass, then measure recall@10 on your own queries instead of trusting a benchmark.",[27,28,29,30,13],"embeddings","qdrant","rag","open-models","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac5cceedf0d655df505306e-0-d17d0fef.png","2026-10-07T07:21:20.071Z","2026-10-07T07:21:20.072Z",{"slug":35,"title":36,"type":24,"summary":37,"tags":38,"author":14,"cover_url":43,"published_at":44,"updated_at":45},"cloudflare-access-strict-service-token-auth-migration","Strict service token auth in Cloudflare Access: moving your scripts and CI over before it bites","Cloudflare Access now has a strict mode for service tokens: 401\u002F403 instead of a 302 to the login page, only Service Auth policies count, and no CF_Authorization cookie. New orgs get it forced on from 5 October. A 15-minute check and switch for existing orgs.",[39,40,41,42,13],"cloudflare","zero-trust","ci-cd","authentication","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac4a8860956594c947bd197-0-f768b25b.png","2026-10-06T08:30:13.154Z","2026-10-06T08:30:13.155Z",{"slug":47,"title":48,"type":24,"summary":49,"tags":50,"author":14,"cover_url":54,"published_at":55,"updated_at":56},"cloudflare-traces-trace-rules-debug-one-customer","Why was that request blocked? Tracing one customer at 100% with Cloudflare Traces and Trace Rules","Cloudflare Traces (open beta) shows a request's path through WAF rules, transforms, cache, Workers and origin as one trace. A recipe: low baseline sampling, a 100% Trace Rule for one host or debug header, traceparent to your origin, OTLP export to your own collector, and what December pricing means.",[39,51,52,53,13],"observability","opentelemetry","tracing","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac338052cb6b40613ac2b7c-0-2294d114.png","2026-10-05T06:22:19.055Z","2026-10-05T06:22:19.056Z",[58,60,62,65,67,78,89,102,116,128,140,151,162,170,182,193,202,213,223,232,242],{"slug":4,"title":5,"type":24,"summary":7,"tags":59,"author":14,"cover_url":15,"published_at":16,"updated_at":16,"reading_minutes":19},[9,10,11,12,13],{"slug":22,"title":23,"type":24,"summary":25,"tags":61,"author":14,"cover_url":31,"published_at":32,"updated_at":33,"reading_minutes":19},[27,28,29,30,13],{"slug":35,"title":36,"type":24,"summary":37,"tags":63,"author":14,"cover_url":43,"published_at":44,"updated_at":45,"reading_minutes":64},[39,40,41,42,13],5,{"slug":47,"title":48,"type":24,"summary":49,"tags":66,"author":14,"cover_url":54,"published_at":55,"updated_at":56,"reading_minutes":19},[39,51,52,53,13],{"slug":68,"title":69,"type":24,"summary":70,"tags":71,"author":14,"cover_url":76,"published_at":77,"updated_at":77,"reading_minutes":64},"copyescape-cve-2026-17106-patch-docker-cp","CopyEscape (CVE-2026-17106): patch docker cp, and stop copying out of running containers","A race in docker cp lets a malicious container write files anywhere the copying process can write on the host. That matters for CI runners and AI-agent sandboxes that copy results out. Check your versions, patch, and change copy-out jobs to stop the container first.",[72,73,74,75,13],"docker","security","cve","ci","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac218ebfd770659725abe68-0-eee7c8f7.png","2026-10-04T23:51:14.689Z",{"slug":79,"title":80,"type":24,"summary":81,"tags":82,"author":14,"cover_url":85,"published_at":86,"updated_at":87,"reading_minutes":88},"protected-quick-tunnels-vs-tailscale-funnel","Share localhost with three named people: Cloudflare's Protected Quick Tunnels vs Tailscale Funnel","cloudflared 2026.9.3 adds --allowed-mail: your quick tunnel now sits behind an email one-time PIN, checked against an allow-list on your own machine, free and without a Cloudflare account. The commands, what it protects, and when Tailscale Serve or Funnel is the better fit.",[39,83,84,73,13],"tailscale","tunnels","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac218d8fd770659725abe3a-0-40f8cb2e.png","2026-10-04T23:19:14.764Z","2026-10-04T23:19:14.765Z",4,{"slug":90,"title":91,"type":24,"summary":92,"tags":93,"author":14,"cover_url":99,"published_at":100,"updated_at":101,"reading_minutes":19},"si-domains-super-intelligence-data",".si after 'Super Intelligence': did one UN speech move a ccTLD?","Trump renamed AI 'super intelligence' at the UN on 22 September 2026 and Slovenia's .si went from about 190,000 names to almost 276,000 in a month. Registry numbers, prices, and 87 WHOIS checks: the obvious AI names were gone years ago; the compounds went in days.",[94,95,96,97,98,13],"domains","si","tld","data","ai","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaaee53e21d5cbd14d442d-0-d6243bc5.png","2026-10-04T22:36:14.598Z","2026-10-04T22:36:14.599Z",{"slug":103,"title":104,"type":24,"summary":105,"tags":106,"author":14,"cover_url":112,"published_at":113,"updated_at":114,"reading_minutes":115},"palantir-agent-stack-python","Steal Palantir's agent stack: typed tools, one LLM gateway, swappable models","An X thread boils Palantir's AIP docs down to four agent patterns. We check each one against the docs, then build them in one stdlib-only Python file: typed business-object tools, a gateway that masks PII, caches and retries, a model set in config, and schedule\u002Fevent\u002FAPI triggers.",[107,108,109,110,111,13],"ai-agents","llm","python","architecture","palantir","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88f9c951ea7137fa3872-0-48eb7eee.png","2026-10-01T23:05:10.531Z","2026-10-01T23:05:10.532Z",10,{"slug":117,"title":118,"type":24,"summary":119,"tags":120,"author":14,"cover_url":124,"published_at":125,"updated_at":126,"reading_minutes":127},"claude-code-effort-levels","Effort levels in Claude Code: when max effort pays off and when it just burns tokens","Anthropic's effort deep dive (Terminal-Bench 3.0 plus three builds) shows higher effort mostly buys verification and edge-case testing, not smarter code. A rule of thumb per task type, the commands to set effort, and a script to measure cost vs pass rate on your own repo.",[121,122,108,123,13],"claude-code","ai-coding","developer-tools","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88edc951ea7137fa3804-0-2716005a.png","2026-10-01T22:32:14.139Z","2026-10-02T04:44:58.001Z",9,{"slug":129,"title":130,"type":24,"summary":131,"tags":132,"author":14,"cover_url":136,"published_at":137,"updated_at":138,"reading_minutes":139},"agentic-inbox-cloudflare-setup","Self-host an AI email agent on Cloudflare Workers: agentic-inbox set up and costed","Cloudflare's open-source agentic-inbox runs a full email client on Workers, with one SQLite Durable Object per mailbox and a Kimi K2.5 agent that drafts replies. Covers the post-deploy steps people miss (Access, sending, routing, mailbox first) and the cost.",[39,133,107,134,135,13],"workers","email","self-hosting","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88dac951ea7137fa378b-0-5b0ec96d.png","2026-10-01T08:17:18.646Z","2026-10-05T05:56:11.919Z",8,{"slug":141,"title":142,"type":24,"summary":143,"tags":144,"author":14,"cover_url":148,"published_at":149,"updated_at":150,"reading_minutes":139},"audit-ai-agent-public-traces","Nearly a million leaked links: auditing what your AI agents leave on the public web","OpenAI's agent swarm left almost a million public shortener URLs holding credentials. Here's a tested shell + gitleaks audit to find the shortlinks, pastes and webhooks your own agents created, scan them for secrets and close the channels.",[73,145,146,147,108,13],"agents","secrets","gitleaks","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaad873e21d5cbd14d4397-0-0f4f51f7.png","2026-10-01T07:43:19.642Z","2026-10-01T08:44:43.041Z",{"slug":152,"title":153,"type":24,"summary":154,"tags":155,"author":14,"cover_url":159,"published_at":160,"updated_at":161,"reading_minutes":139},"mikrotrick-check-patch-mikrotik","MikroTrick: check and patch your MikroTik in 15 minutes","Two chained RouterOS bugs give anyone who can reach SSH full admin, no password needed, and attacks started before the patch. Find exposed SSH, check the version, grep for the published IoCs, patch and move management behind WireGuard.",[73,156,157,158,135,13],"mikrotik","routeros","ssh","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abcd9c0838b650cb96b3d10-0-6cd107e0.png","2026-10-01T07:02:15.03Z","2026-10-01T08:44:41.391Z",{"slug":163,"title":164,"type":24,"summary":165,"tags":166,"author":14,"cover_url":167,"published_at":168,"updated_at":169,"reading_minutes":139},"agent-sandbox-dns-egress-lockdown","Your agent sandbox leaks through DNS: lock down egress in 15 minutes","An OpenAI model escaped its sandbox by tunnelling questions through DNS. Here is a tested Docker Compose setup for coding agents: a DNS allowlist, a logging egress proxy and a kill switch that actually fires.",[73,72,145,12,135,13],"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaaca13e21d5cbd14d4306-0-cb93fe1b.png","2026-10-01T03:00:15.943Z","2026-10-01T08:44:43.165Z",{"slug":171,"title":172,"type":24,"summary":173,"tags":174,"author":14,"cover_url":178,"published_at":179,"updated_at":180,"reading_minutes":181},"who-blocks-ai-crawlers-robots-txt","Who blocks AI crawlers? robots.txt vs the network edge, with numbers","I scanned robots.txt on the top 300 sites: 33 of 138 block GPTBot, 14 block training but allow AI search. What each AI bot directive controls, why robots.txt is only a request, and a copy-paste policy plus nginx rule for small SaaS sites.",[98,175,176,39,177,13],"robots-txt","seo","saas","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abcd9c1838b650cb96b3d1b-0-11f94198.png","2026-09-30T21:00:20.673Z","2026-10-01T20:47:34.092Z",7,{"slug":183,"title":184,"type":24,"summary":185,"tags":186,"author":14,"cover_url":190,"published_at":191,"updated_at":192,"reading_minutes":88},"bullet-time-with-first-last-frame-video","Bullet time with first\u002Flast-frame video: orbiting a frozen moment from three stills","A freeze-frame camera orbit built from generated stills: one action shot, two camera-move angles, two first\u002Flast-frame clips between them, stitched and ping-ponged. The pipeline, the seams, and where the model re-imagines the water.",[98,187,188,189],"comfyui","video-generation","flowdsl","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abae46c45201648bfd477a7-0-6f4d036e.png","2026-09-28T22:42:41Z","2026-09-28T22:42:41.6Z",{"slug":194,"title":195,"type":24,"summary":196,"tags":197,"author":14,"cover_url":199,"published_at":200,"updated_at":201,"reading_minutes":181},"an-ai-media-pipeline-that-shows-its-work","An AI media pipeline that shows its work: ComfyUI presets, FlowDSL routing and the misses","How the images on my sites are generated: four ComfyUI presets behind one Go module, job rows as state, FlowDSL flows for routing, per-post media in the admin — and the bugs and model misses I hit shipping it. This post's own images were made the same way.",[98,189,187,198],"image-generation","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6aba8ba317ceba3543925be4-0-2f6b8a5c.png","2026-09-28T15:57:50Z","2026-10-01T20:47:34.327Z",{"slug":203,"title":204,"type":24,"summary":205,"tags":206,"author":14,"cover_url":209,"published_at":210,"updated_at":211,"reading_minutes":212},"openai-embeddings-python-mongodb","Transforming Text into Vectors: OpenAI Embeddings in Python","Learn how to generate text embeddings with the OpenAI API in Python to power semantic search, recommendations, and more. Includes practical examples with MongoDB integration and cost analysis.",[207,98,109,208],"openai","mongodb","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c2d-0-2e60b732.png","2024-11-23T00:00:00Z","2026-09-28T22:31:01.385Z",3,{"slug":214,"title":215,"type":24,"summary":216,"tags":217,"author":14,"cover_url":219,"published_at":220,"updated_at":221,"reading_minutes":222},"check-pricing-availability-ing-domains","Last Chance to Grab Short .ING Domains: The Extended List Part II","Welcome back to the second part of our exciting exploration into the .ING domain zone! This time, I've expanded our horizons to bring you an even larger selection of .ING domain names. List of over 24,000 domain names inside.",[94,218],"business","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c38-0-c55f4c8d.png","2023-12-14T00:00:00Z","2026-09-28T22:31:01.453Z",1,{"slug":224,"title":225,"type":24,"summary":226,"tags":227,"author":14,"cover_url":228,"published_at":229,"updated_at":230,"reading_minutes":231},"impressive-ing-domains","Unveiling the Impressive .ING Domains","Discover the vast potential of the new .ING domain zone in my latest blog post! I've used AI and a Python script to unearth a treasure trove of available domain names. From budget-friendly picks to exclusive premium domains, there's something for every ambition. Plus, a special list of unique, lesser-known domains awaits.",[94,218],"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c43-0-03be24b7.png","2023-12-11T00:00:00Z","2026-09-28T22:31:01.527Z",2,{"slug":233,"title":234,"type":24,"summary":235,"tags":236,"author":14,"cover_url":239,"published_at":240,"updated_at":241,"reading_minutes":212},"secured-web-server-in-5-minutes","Fortify Web Server Security in 5 Minutes with Tailscale","Tailscale revolutionizes secure networking with its user-friendly approach, effortlessly connecting devices across diverse networks.",[237,83,238],"firewall","webserver","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c4e-0-eae6f62d.png","2023-11-03T00:00:00Z","2026-09-28T22:31:01.597Z",{"slug":243,"title":244,"type":24,"summary":245,"tags":246,"author":14,"cover_url":249,"published_at":250,"updated_at":251,"reading_minutes":19},"lets-encrypt-free-ssl","How to Secure Your Website with Free SSL Certificates for a Lifetime","Let’s Encrypt certificates have revolutionized internet security by providing free, automated, and widely trusted SSL\u002FTLS certificates. The non-profit Certificate Authority (CA) has significantly contributed to a more secure web environment by simplifying the process of securing websites with HTTPS.",[247,248,238],"ssl","https","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c59-0-bf2a9a0a.png","2023-11-01T00:00:00Z","2026-09-28T22:39:13.555Z"]