Cloudflare built a crawler billing system on HTTP 402, the status code that never had a defined meaning. To understand it I wrote my own simulator of the flow, an API and console of my own, and got a signature requirement wrong in a way that turns out to be instructive. Wire traces, the protocol in detail, and the criticism it deserves.
I have run things on Cloudflare for nine years. This is the first of seven posts on what they built, why the engineering choices mattered, and where the honest limits are. Part one covers the arc from free SSL in 2014 to a network where most of the traffic is no longer human.
IBM now puts a price on the AI tools your staff use without telling you: breaches that involve shadow AI cost $670,000 more. Here is what the 2026 numbers mean for the people who own the budget.
Open source runs the modern economy, and most of the people maintaining it are unpaid, overworked, and one bad week from walking away. From the XZ backdoor to curl’s AI-generated bug reports, here’s why that isn’t an ethics problem, it’s a supply chain risk sitting on your books right now.
Hong Kong’s regulator just scored its banking sector 2.3 out of 10 on quantum readiness and asked for a 10 by 2030. The gap is not awareness anymore, it is that cryptography sits in a hundred places and belongs to nobody.
A finance employee at Arup wired $25 million after a video call with a deepfaked CFO and colleagues. The FBI just gave AI-enabled fraud its own reporting category for the first time. Here’s what the data says about deepfake fraud in 2026, and the specific controls that are actually stopping it.
Brussels delayed the headline-grabbing high-risk rules, but the parts of the AI Act that touch almost every company building on foundation models switch on August 2, 2026. Here is what leaders should have finished by then.
I built a Chrome extension that reads a YouTube video’s title, description, and transcript with an AI model of your choosing, and shows you an honest verdict in the side panel before you click play. Here’s what it does, and why it’s built to collect nothing by default.
A look at how Hoklok, a Hong Kong primary-school platform, uses AI to generate personalised worksheets, mark them, and track progress, while keeping every decision under a teacher’s sign-off.
AI agents often act through credentials issued to people, which hides who performed an action and grants the agent more authority than the task requires. Leaders should treat every production agent as a distinct identity with bounded, revocable permissions.
The Model Context Protocol is why AI agents finally work inside real companies. It is also the part of the stack nobody secured. Here is what leaders should demand before they connect an agent to anything that matters.
Hugging Face just disclosed a breach carried out end-to-end by an autonomous AI agent. Here’s what the data on agentic AI risk actually says, and the four questions every leadership team should be able to answer before their next agent goes live.
After a multi-year hiatus, I’m back. Let’s kick things off by exploring one of the most lucrative and explosive new roles in tech: the Forward-Deployed Engineer (FDE) and why AI is making it essential.