[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2qe9tt7p4wadg":3,"$fanuq43nlrv5g":57},{"slug":4,"title":5,"body":6,"summary":7,"tags":8,"author":15,"cover_url":16,"published_at":17,"seo_title":18,"seo_description":19,"reading_minutes":20,"related":21},"mikrotrick-check-patch-mikrotik","MikroTrick: check and patch your MikroTik in 15 minutes","\u003Cp>On September 2, 2026, MikroTik owners started posting odd lines from their router logs on the MikroTik forum and Reddit: a failed SSH login for a user called \u003Ccode>-2\u003C\u002Fcode>, immediately followed by a new user being added. A day later MikroTik shipped fixed RouterOS builds without much fanfare. On September 5 CERT Polska published the story: two chained bugs, now called \u003Cstrong>MikroTrick\u003C\u002Fstrong>, give an attacker full admin on any RouterOS device whose SSH service they can reach. No password, no key.\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6abd88f2c951ea7137fa3836\">\u003Cvideo src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88f4c951ea7137fa383c-0-6b87f4cd.mp4\" autoplay muted loop playsinline preload=\"metadata\">\u003C\u002Fvideo>\u003C\u002Ffigure>\n\u003Cp>On September 10 CISA added two of the disclosed bugs, CVE-2026-86060 and CVE-2026-67277, to its Known Exploited Vulnerabilities catalog with a three-day remediation deadline. On September 25 it added the rekey bug, CVE-2026-67279, as well, so both halves of the chain are now on the list. If you run a MikroTik anywhere (home lab, office, a VPS edge on CHR), this is a 15-minute job: find out whether SSH is exposed, check the version, look for the known indicators, patch, and move management behind a VPN. Every command below is copy-pasteable into a RouterOS terminal or your own shell.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>You need:\u003C\u002Fstrong> admin access to the router (Winbox, WebFig or a local SSH session), a machine outside your network for the exposure check (a VPS or a phone hotspot) with \u003Ccode>nmap\u003C\u002Fcode> and \u003Ccode>nc\u003C\u002Fcode>, and a WireGuard client on your laptop for step 5. Steps 1 to 4 fit in 15 minutes; the WireGuard setup takes a few more if you have never done it.\u003C\u002Fp>\n\n\u003Ch2>What the chain does\u003C\u002Fh2>\n\u003Cp>CERT Polska's technical analysis describes two bugs that only matter together:\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6abd88f6c951ea7137fa3842\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88f6c951ea7137fa3847-0-fde9c585.png\" alt=\"A conceptual representation of a vulnerability chain in a network service.\" loading=\"lazy\">\u003Cfigcaption>A conceptual representation of a vulnerability chain in a network service.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\u003Cul>\n\u003Cli>\u003Cstrong>CVE-2026-67279\u003C\u002Fstrong>: the SSH server mishandled key re-exchange (rekeying) during user authentication. If the client started a rekey mid-auth, the server moved on to channel handling without ever sending \u003Ccode>SSH_MSG_USERAUTH_SUCCESS\u003C\u002Fcode>. In other words, authentication could be skipped.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CVE-2026-86060\u003C\u002Fstrong>: the login helper did not handle usernames that start with a disallowed character. A username of \u003Ccode>-2\u003C\u002Fcode> gets parsed as a command-line argument, so the helper reads its identity from file descriptor 2 and the attacker controls the policy mask, which means full admin rights.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Two other CVEs from the same disclosure get mixed up with MikroTrick. \u003Cstrong>CVE-2026-67276\u003C\u002Fstrong> (CVSS 9.2) is a separate SSH bug: RouterOS did not properly verify public keys, so someone who knows an account name and its RSA public key could log in as that user. CERT notes that some publications wrongly tied it to the chain. \u003Cstrong>CVE-2026-67277\u003C\u002Fstrong> (CVSS 8.8) is in the bandwidth-test service, which let an unauthenticated connection reach a state that should need a login; combined with two smaller flaws it leaks kernel memory or crashes the device. It is not part of the chain, but it is on CISA's KEV list too. The KEV entries from this disclosure are CVE-2026-86060, CVE-2026-67277 (both added September 10) and CVE-2026-67279 (added September 25); CVE-2026-67276 is not listed.\u003C\u002Fp>\n\u003Cp>Vulnerable: neither MikroTik nor CERT publishes an exact affected range (CERT's lab covered releases from 6.43.11 onward), so treat every build older than the fixed ones as vulnerable. Fixed builds, released September 3:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>6.49.21\u003C\u002Fstrong> (v6 long-term)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>7.23.4\u003C\u002Fstrong> (v7 long-term)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>7.24.2\u003C\u002Fstrong> (v7 stable)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>7.25beta3\u003C\u002Fstrong> (testing)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>CERT has not published the full exploitation procedure, but the bug classes are now public, and exploitation in the wild started a day before the patch existed. Assume anyone can do this now.\u003C\u002Fp>\n\n\u003Ch2>Step 1: is SSH reachable from the internet? (2 minutes)\u003C\u002Fh2>\n\u003Cp>Check from a machine \u003Cem>outside\u003C\u002Fem> your network (a VPS or a phone hotspot) against your public IP. RouterOS identifies itself in the SSH banner:\u003C\u002Fp>\n\u003Cpre>\u003Ccode># replace with your router's public IP\nROUTER=203.0.113.10\n\n# SSH, Winbox, bandwidth-test ports\nnmap -Pn -p 22,8291,2000 --open \"$ROUTER\"\n\n# grab the SSH banner; RouterOS answers with SSH-2.0-ROSSSH\n# (use the port SSH actually listens on if it is not 22)\nnc -w 3 \"$ROUTER\" 22\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>If SSH answers with \u003Ccode>ROSSSH\u003C\u002Fcode>, you are in scope for MikroTrick. MikroTik's default configuration blocks management ports from the WAN side, so an exposed port usually means someone opened it by hand, or moved SSH to another port. If you did that, scan every port and let nmap read the banners, so SSH shows up as \u003Ccode>ROSSSH\u003C\u002Fcode> wherever it listens: \u003Ccode>nmap -Pn -sV -p- \"$ROUTER\"\u003C\u002Fcode>.\u003C\u002Fp>\n\n\u003Ch2>Step 2: which version are you running? (1 minute)\u003C\u002Fh2>\n\u003Cpre>\u003Ccode>\u002Fsystem resource print\n\u002Fsystem package update print\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Compare \u003Ccode>version\u003C\u002Fcode> with the fixed list above. Anything older than 6.49.21 on v6, older than 7.23.4 on long-term, older than 7.24.2 on stable, or older than 7.25beta3 on testing is vulnerable.\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6abd88f6c951ea7137fa384c\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88f6c951ea7137fa3851-0-c9ae6fb3.png\" alt=\"Hardware devices running RouterOS may be affected by these vulnerabilities.\" loading=\"lazy\">\u003Cfigcaption>Hardware devices running RouterOS may be affected by these vulnerabilities.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\n\u003Ch2>Step 3: look for the published indicators before you patch (5 minutes)\u003C\u002Fh2>\n\u003Cp>CERT Polska published this log pattern for a successful attack:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>login failure for user -2 from &lt;ip&gt; via ssh\nuser &lt;name&gt; added by ssh:-2@&lt;ip&gt;\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>In the cases they saw, the new account was named \u003Ccode>ops\u003C\u002Fcode> and placed in the \u003Ccode>full\u003C\u002Fcode> group. Shortly afterwards the attacker created RouterOS diagnostic (\u003Ccode>.rif\u003C\u002Fcode>) files and pulled them out with \u003Ccode>fetch\u003C\u002Fcode>. The observed source IPs were \u003Ccode>82.192.72.4\u003C\u002Fcode> (successful attacks, since at least September 2) and \u003Ccode>103.102.31.18\u003C\u002Fcode> (exploitation attempts). Check all of it:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>\u002Flog print where message~\"user -2\"\n\u002Flog print where message~\"82.192.72.4\"\n\u002Flog print where message~\"103.102.31.18\"\n\u002Fuser print detail\n\u002Fuser print where name=\"ops\"\n\u002Fuser ssh-keys print\n\u002Fsystem script print\n\u002Fsystem scheduler print\n\u002Ffile print where name~\"rif\"\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>One caveat: RouterOS keeps logs in memory by default, so a reboot erases them. If you forward logs to syslog, search there too:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>grep -E 'user -2|82\\.192\\.72\\.4|103\\.102\\.31\\.18' \u002Fvar\u002Flog\u002Fmikrotik*.log\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>If you find a hit, do not just patch and move on. CERT's advice is to isolate the device, save the logs and configuration first (they are evidence), then factory-reset and rebuild from a trusted backup with new credentials. To save what is there right now:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>\u002Flog print file=incident-log\n\u002Fexport file=incident-config\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Then copy both files off the router (Winbox Files, or \u003Ccode>scp\u003C\u002Fcode> from a trusted host).\u003C\u002Fp>\n\n\u003Ch2>Step 4: patch (5 minutes plus a reboot)\u003C\u002Fh2>\n\u003Cp>Pick the channel that matches what you run now. \u003Ccode>stable\u003C\u002Fcode> gets you 7.24.2; \u003Ccode>long-term\u003C\u002Fcode> gets you 7.23.4 on v7, or 6.49.21 on v6.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>\u002Fsystem package update set channel=stable\n\u002Fsystem package update check-for-updates\n\u002Fsystem package update install\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The router reboots straight after the install, so run it from a session you can afford to lose and don't change management access in the same window. When it is back, confirm the version with \u003Ccode>\u002Fsystem resource print\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>The patched builds also check for compromise themselves. According to CERT, if they find a suspicious \u003Ccode>ops\u003C\u002Fcode> account, RouterOS disables it, writes a critical warning to the log and sets the device to \u003Cstrong>Flagged\u003C\u002Fstrong> status. The flag shows up as the \u003Ccode>flagged\u003C\u002Fcode> field in the device-mode output (the command CERT's advisory points to; device-mode exists on RouterOS v7), and the warning lands in the log:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>\u002Fsystem device-mode print\n\u002Flog print where topics~\"critical\"\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>If the device is flagged, follow MikroTik's Flagged status documentation. After any upgrade, MikroTik's own advice is to look through the configuration for scripts, users or other entries you don't recognise.\u003C\u002Fp>\n\n\u003Ch2>Step 5: take management off the internet (5 minutes)\u003C\u002Fh2>\n\u003Cp>Patching fixes this bug. Not exposing SSH protects you from the next one. MikroTik's bulletin says the same: SSH should not be open to untrusted networks, and a VPN like WireGuard beats an open management port. Build the VPN path first, so you don't lock yourself out when you restrict the services. Here \u003Ccode>10.99.0.0\u002F24\u003C\u002Fcode> is a management subnet you will reach over WireGuard:\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6abd88f6c951ea7137fa3856\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88f6c951ea7137fa385b-0-56024458.png\" alt=\"Moving management access behind a VPN reduces the attack surface.\" loading=\"lazy\">\u003Cfigcaption>Moving management access behind a VPN reduces the attack surface.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\u003Cpre>\u003Ccode>\u002Finterface wireguard add name=wg-mgmt listen-port=13231\n\u002Finterface wireguard print\n\u002Fip address add address=10.99.0.1\u002F24 interface=wg-mgmt\n\u002Finterface wireguard peers add interface=wg-mgmt public-key=\"&lt;your-laptop-public-key&gt;\" allowed-address=10.99.0.2\u002F32\n\u002Fip firewall filter add chain=input protocol=udp dst-port=13231 action=accept comment=\"wg-mgmt\"\n\u002Fip firewall filter move [find comment=\"wg-mgmt\"] destination=0\n\u002Fip firewall filter print\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Use the router's public key from \u003Ccode>\u002Finterface wireguard print\u003C\u002Fcode> in your laptop's WireGuard config, with \u003Ccode>Address = 10.99.0.2\u002F32\u003C\u002Fcode> and \u003Ccode>AllowedIPs = 10.99.0.1\u002F32\u003C\u002Fcode>. The \u003Ccode>add\u003C\u002Fcode> puts the accept rule at the end of the input chain, behind any drop rule; the \u003Ccode>move\u003C\u002Fcode> line puts it at the top (it also works when it is the only rule). If your default config drops input from outside the LAN, also make sure \u003Ccode>wg-mgmt\u003C\u002Fcode> traffic is accepted, for example by adding the interface to the \u003Ccode>LAN\u003C\u002Fcode> interface list: \u003Ccode>\u002Finterface list member add list=LAN interface=wg-mgmt\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>Once you can log in over WireGuard (at \u003Ccode>10.99.0.1\u003C\u002Fcode>), restrict the services themselves. Keep your current session open until that works:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>\u002Fip service print\n\u002Fip service set ssh address=10.99.0.0\u002F24\n\u002Fip service set winbox address=10.99.0.0\u002F24\n\u002Fip service set telnet disabled=yes\n\u002Fip service set ftp disabled=yes\n\u002Fip service set www disabled=yes\n\u002Ftool bandwidth-server set enabled=no\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The last line turns off the bandwidth-test server, the component behind CVE-2026-67277.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Already on Tailscale?\u003C\u002Fstrong> You don't have to run Tailscale on the router itself. Advertise the router's LAN from a subnet router you already have. By default Tailscale source-NATs that traffic, so the router sees your SSH sessions coming from the subnet router's LAN address. Put that single address in \u003Ccode>\u002Fip service set ssh address=...\u003C\u002Fcode> instead of the WireGuard subnet.\u003C\u002Fp>\n\u003Cp>Finally, test from outside again with the \u003Ccode>nmap\u003C\u002Fcode> line from step 1. Port 22 should no longer answer.\u003C\u002Fp>\n\n\u003Ch2>How CERT Polska found it: LLM agents on a VM farm\u003C\u002Fh2>\n\u003Cp>The research method is worth a look for anyone who ships network software. According to its write-up, CERT Polska's team ran OpenAI models it names as GPT-5.5-cyber and GPT-5.6-sol, with reduced refusal thresholds, together with locally hosted GLM, DeepSeek, Qwen and PLLuM. The agent controlled 40 Cloud Hosted Router VMs, 39 snapshots and 24 RouterOS releases through libvirt. It ran static analysis of the binaries with radare2 and Ghidra, and walked the SSH state machine by repeating, skipping and reordering protocol stages. That is exactly how the rekey-during-auth bug shows up.\u003C\u002Fp>\n\u003Cp>The timeline matters more than the tooling. A public AI-assisted analysis of MikroTik's patch was out at 03:22 UTC on September 4, the day after the fixed builds shipped. CERT says that combining that information with its own patch diffing let it pin down CVE-2026-86060 \u003Cem>within an hour\u003C\u002Fem>. Once you publish a fix, the time before someone reverses it into an exploit is now measured in hours. Plan patch windows for edge devices around that.\u003C\u002Fp>\n\n\u003Ch2>The 15-minute checklist\u003C\u002Fh2>\n\u003Col>\n\u003Cli>From outside, check whether anything answers \u003Ccode>SSH-2.0-ROSSSH\u003C\u002Fcode> on your public IPs.\u003C\u002Fli>\n\u003Cli>Compare the version against 6.49.21 \u002F 7.23.4 \u002F 7.24.2 \u002F 7.25beta3.\u003C\u002Fli>\n\u003Cli>Search the logs for \u003Ccode>user -2\u003C\u002Fcode>, the two IPs, an \u003Ccode>ops\u003C\u002Fcode> user and \u003Ccode>.rif\u003C\u002Fcode> files. Save the evidence if you find anything.\u003C\u002Fli>\n\u003Cli>Upgrade, then check the Flagged status.\u003C\u002Fli>\n\u003Cli>Limit SSH and Winbox to a WireGuard or tailnet address, turn off services you don't use, and scan again.\u003C\u002Fli>\n\u003C\u002Fol>\n\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fcert.pl\u002Fen\u002Fposts\u002F2026\u002F09\u002Fmikrotrick-technical-analysis\u002F\">CERT Polska: MikroTrick technical analysis\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fcert.pl\u002Fen\u002Fposts\u002F2026\u002F09\u002Fvulnerabilities-in-mikrotik-routeros-actively-exploited\u002F\">CERT Polska: Vulnerabilities in MikroTik RouterOS actively exploited\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmikrotik.com\u002Fsupportsec\u002Fseptember-2026-vulnerability\u002F\">MikroTik security bulletin, September 2026\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fcyber.gc.ca\u002Fen\u002Falerts-advisories\u002Fal26-020-vulnerabilities-impacting-mikrotik-routeros-cve-2026-67276-cve-2026-67277-cve-2026-86060\">Canadian Centre for Cyber Security: AL26-020\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fmikrotrick-chain-let-attackers-take.html\">The Hacker News: MikroTrick chain lets attackers take over RouterOS\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.cisa.gov\u002Fknown-exploited-vulnerabilities-catalog\">CISA Known Exploited Vulnerabilities catalog\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fx.com\u002F0xManan\u002Fstatus\u002F2103846906837569909\">@0xManan on X (the thread that surfaced the story)\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>","Two chained RouterOS bugs give anyone who can reach SSH full admin, no password needed, and attacks started before the patch. Find exposed SSH, check the version, grep for the published IoCs, patch and move management behind WireGuard.",[9,10,11,12,13,14],"security","mikrotik","routeros","ssh","self-hosting","ai-assisted","if.codes","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abcd9c0838b650cb96b3d10-0-6cd107e0.png","2026-10-01T07:02:15.03Z","MikroTrick RouterOS SSH bypass: check, patch and lock down","15-minute guide to MikroTrick (CVE-2026-67279 + CVE-2026-86060): find exposed SSH, check versions, grep IoCs, patch, move management to WireGuard.",8,[22,35,47],{"slug":23,"title":24,"type":25,"summary":26,"tags":27,"author":15,"cover_url":32,"published_at":33,"updated_at":34},"agentic-inbox-cloudflare-setup","Self-host an AI email agent on Cloudflare Workers: agentic-inbox set up and costed","blog","Cloudflare's open-source agentic-inbox runs a full email client on Workers, with one SQLite Durable Object per mailbox and a Kimi K2.5 agent that drafts replies. Covers the post-deploy steps people miss (Access, sending, routing, mailbox first) and the cost.",[28,29,30,31,13,14],"cloudflare","workers","ai-agents","email","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88dac951ea7137fa378b-0-5b0ec96d.png","2026-10-01T08:17:18.646Z","2026-10-01T08:44:42.528Z",{"slug":36,"title":37,"type":25,"summary":38,"tags":39,"author":15,"cover_url":44,"published_at":45,"updated_at":46},"audit-ai-agent-public-traces","Nearly a million leaked links: auditing what your AI agents leave on the public web","OpenAI's agent swarm left almost a million public shortener URLs holding credentials. Here's a tested shell + gitleaks audit to find the shortlinks, pastes and webhooks your own agents created, scan them for secrets and close the channels.",[9,40,41,42,43,14],"agents","secrets","gitleaks","llm","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaad873e21d5cbd14d4397-0-0f4f51f7.png","2026-10-01T07:43:19.642Z","2026-10-01T08:44:43.041Z",{"slug":48,"title":49,"type":25,"summary":50,"tags":51,"author":15,"cover_url":54,"published_at":55,"updated_at":56},"agent-sandbox-dns-egress-lockdown","Your agent sandbox leaks through DNS: lock down egress in 15 minutes","An OpenAI model escaped its sandbox by tunnelling questions through DNS. Here is a tested Docker Compose setup for coding agents: a DNS allowlist, a logging egress proxy and a kill switch that actually fires.",[9,52,40,53,13,14],"docker","dns","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaaca13e21d5cbd14d4306-0-cb93fe1b.png","2026-10-01T03:00:15.943Z","2026-10-01T08:44:43.165Z",[58,60,62,65,67,80,92,101,113,124,133,144],{"slug":23,"title":24,"type":25,"summary":26,"tags":59,"author":15,"cover_url":32,"published_at":33,"updated_at":34,"reading_minutes":20},[28,29,30,31,13,14],{"slug":36,"title":37,"type":25,"summary":38,"tags":61,"author":15,"cover_url":44,"published_at":45,"updated_at":46,"reading_minutes":20},[9,40,41,42,43,14],{"slug":4,"title":5,"type":25,"summary":7,"tags":63,"author":15,"cover_url":16,"published_at":17,"updated_at":64,"reading_minutes":20},[9,10,11,12,13,14],"2026-10-01T08:44:41.391Z",{"slug":48,"title":49,"type":25,"summary":50,"tags":66,"author":15,"cover_url":54,"published_at":55,"updated_at":56,"reading_minutes":20},[9,52,40,53,13,14],{"slug":68,"title":69,"type":25,"summary":70,"tags":71,"author":15,"cover_url":76,"published_at":77,"updated_at":78,"reading_minutes":79},"who-blocks-ai-crawlers-robots-txt","Who blocks AI crawlers? robots.txt vs the network edge, with numbers","I scanned robots.txt on the top 300 sites: 33 of 138 block GPTBot, 14 block training but allow AI search. What each AI bot directive controls, why robots.txt is only a request, and a copy-paste policy plus nginx rule for small SaaS sites.",[72,73,74,28,75,14],"ai","robots-txt","seo","saas","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abcd9c1838b650cb96b3d1b-0-11f94198.png","2026-09-30T21:00:20.673Z","2026-10-01T08:44:41.146Z",7,{"slug":81,"title":82,"type":25,"summary":83,"tags":84,"author":15,"cover_url":88,"published_at":89,"updated_at":90,"reading_minutes":91},"bullet-time-with-first-last-frame-video","Bullet time with first\u002Flast-frame video: orbiting a frozen moment from three stills","A freeze-frame camera orbit built from generated stills: one action shot, two camera-move angles, two first\u002Flast-frame clips between them, stitched and ping-ponged. The pipeline, the seams, and where the model re-imagines the water.",[72,85,86,87],"comfyui","video-generation","flowdsl","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abae46c45201648bfd477a7-0-6f4d036e.png","2026-09-28T22:42:41Z","2026-09-28T22:42:41.6Z",4,{"slug":93,"title":94,"type":25,"summary":95,"tags":96,"author":15,"cover_url":98,"published_at":99,"updated_at":100,"reading_minutes":79},"an-ai-media-pipeline-that-shows-its-work","An AI media pipeline that shows its work: ComfyUI presets, FlowDSL routing and the misses","How the images on my sites are generated: four ComfyUI presets behind one Go module, job rows as state, FlowDSL flows for routing, per-post media in the admin — and the bugs and model misses I hit shipping it. This post's own images were made the same way.",[72,87,85,97],"image-generation","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6aba8ba317ceba3543925be4-0-2f6b8a5c.png","2026-09-28T15:57:50Z","2026-09-28T15:57:50.784Z",{"slug":102,"title":103,"type":25,"summary":104,"tags":105,"author":15,"cover_url":109,"published_at":110,"updated_at":111,"reading_minutes":112},"openai-embeddings-python-mongodb","Transforming Text into Vectors: OpenAI Embeddings in Python","Learn how to generate text embeddings with the OpenAI API in Python to power semantic search, recommendations, and more. Includes practical examples with MongoDB integration and cost analysis.",[106,72,107,108],"openai","python","mongodb","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c2d-0-2e60b732.png","2024-11-23T00:00:00Z","2026-09-28T22:31:01.385Z",3,{"slug":114,"title":115,"type":25,"summary":116,"tags":117,"author":15,"cover_url":120,"published_at":121,"updated_at":122,"reading_minutes":123},"check-pricing-availability-ing-domains","Last Chance to Grab Short .ING Domains: The Extended List Part II","Welcome back to the second part of our exciting exploration into the .ING domain zone! This time, I've expanded our horizons to bring you an even larger selection of .ING domain names. List of over 24,000 domain names inside.",[118,119],"domains","business","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c38-0-c55f4c8d.png","2023-12-14T00:00:00Z","2026-09-28T22:31:01.453Z",1,{"slug":125,"title":126,"type":25,"summary":127,"tags":128,"author":15,"cover_url":129,"published_at":130,"updated_at":131,"reading_minutes":132},"impressive-ing-domains","Unveiling the Impressive .ING Domains","Discover the vast potential of the new .ING domain zone in my latest blog post! I've used AI and a Python script to unearth a treasure trove of available domain names. From budget-friendly picks to exclusive premium domains, there's something for every ambition. Plus, a special list of unique, lesser-known domains awaits.",[118,119],"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c43-0-03be24b7.png","2023-12-11T00:00:00Z","2026-09-28T22:31:01.527Z",2,{"slug":134,"title":135,"type":25,"summary":136,"tags":137,"author":15,"cover_url":141,"published_at":142,"updated_at":143,"reading_minutes":112},"secured-web-server-in-5-minutes","Fortify Web Server Security in 5 Minutes with Tailscale","Tailscale revolutionizes secure networking with its user-friendly approach, effortlessly connecting devices across diverse networks.",[138,139,140],"firewall","tailscale","webserver","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c4e-0-eae6f62d.png","2023-11-03T00:00:00Z","2026-09-28T22:31:01.597Z",{"slug":145,"title":146,"type":25,"summary":147,"tags":148,"author":15,"cover_url":151,"published_at":152,"updated_at":153,"reading_minutes":154},"lets-encrypt-free-ssl","How to Secure Your Website with Free SSL Certificates for a Lifetime","Let’s Encrypt certificates have revolutionized internet security by providing free, automated, and widely trusted SSL\u002FTLS certificates. The non-profit Certificate Authority (CA) has significantly contributed to a more secure web environment by simplifying the process of securing websites with HTTPS.",[149,150,140],"ssl","https","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c59-0-bf2a9a0a.png","2023-11-01T00:00:00Z","2026-09-28T22:39:13.555Z",6]