Skip to main content

Vol. MMXXVINo. 98

Field reports from cloud-security engineering, AI experiments, and a homelab that keeps getting bigger.

Latest writing from William Zujkowski

Start here: agentic security, tools, and homelab reading paths

Security·10 min read·

The Command Said It Worked

Five commands this site published reported success while doing nothing. A small container lab reproduces four, and the cheap defense is running each command once where it must fail.

  1. Security·5 min read·

    One ZIP, Two Lists of Files

    A small reproducible ZIP lab shows why indexed and streaming readers can inspect different entries in the same archive.

  2. Linux·5 min read·

    Two Processes, One Page Cache: Testing Shared State Before Blaming the VM

    A small Linux experiment separates shared file identity from identical bytes, with a failed tmpfs control and a careful look at a July 2026 VM-isolation preprint.

  3. Security·7 min read·

    A Correct Answer Doesn't Mean the Agent's Memory Is Clean

    A synthetic memory-recovery drill shows why a correct task result and a clean derived state are separate checks.

  4. Security·5 min read·

    Your Backup Administrator Should Not Be Able to Delete Yesterday

    Timelock Drive puts retention below a compromised host. An offline model shows why unfreezing a backup must start a countdown, not erase its protection.

  5. Security·6 min read·

    The Database Gets a Vote on Your Read-Only Agent

    A disposable PostgreSQL lab tests what an agent-facing database role can actually do, including the SELECT that writes through a privileged function.