Pull to refresh

All streams

Show first
Period
Level of difficulty

PGConf.Nepal 2026 invites you

Level of difficultyEasy
Reading time3 min
Reach and readers4.3K

From 18 to 21 November 2026, Nepal will host PGConf.Nepal 2026, the country’s fourth PostgreSQL conference. The previous events took place in 2018, 2023, and 2025. This year, the conference is expected to bring together a wider mix of participants, organisations, and countries.

Read more

When a perfect audit was too hard to use

Level of difficultyEasy
Reading time7 min
Reach and readers3.1K

Everyone loves security — until they have to configure it. The first version of our audit extension felt like a nuclear power plant control panel: infinitely flexible, but impossible to operate without a manual. We admitted defeat, listened to DBA complaints, and shipped version 2.0 — with event classes and configuration logic designed for humans, not just compilers.

This article tells the story of fixing our own mistakes and turning a “shelf-ware” product into a tool people actually use.

Read more

DragonDoll: the spyware hiding behind a Google Chrome update

Reading time30 min
Reach and readers2.3K

In spring 2026, researchers at the Positive Technologies Expert Security Center (PT ESC) identified an unusual campaign targeting users in Saudi Arabia. The campaign used a previously unknown APK named Chrome.apk. The sample immediately stood out. Behind a benign-looking Google Chrome update screen and an unexpected request to enable Accessibility Services, we found a heavily protected execution chain that ultimately deployed Android spyware.

Read more

The sparrow that chirped too loud: FamousSparrow attacks using updated SparrowDoor and the new SquawkDoor backdoor

Level of difficultyMedium
Reading time57 min
Reach and readers4.6K

In the first half of 2026, we discovered activity by the East Asian threat group FamousSparrow. Its attacks targeted several countries in South Asia and Europe. In these attacks, the threat actor used its own malware: a heavily reworked variant of the modular SparrowDoor backdoor and a new backdoor that we named SquawkDoor.

FamousSparrow, also known as Salt Typhoon and Earth Estries, is an East Asian threat group that has been active since 2019. The group is known for using its proprietary SparrowDoor backdoor and initially focused on attacks against hotels worldwide, as well as government and international organizations. Later, FamousSparrow began actively targeting telecommunications companies and internet service providers, apparently seeking long-term access to lawful communications intercept systems.

In these attacks, the threat actor used both malicious LNK files and a website compromise vector involving malicious JavaScript. The injected script displayed a fake error message when a user visited the page and prompted them to download a new certificate. In reality, the download was a malicious executable that led to backdoor infection. The attacks were tailored to specific countries: the JavaScript samples and payloads contained text customized for the target country.

Read more

Time for Sentry to retire… Metric is ready to take over

Level of difficultyMedium
Reading time8 min
Reach and readers2.1K

Self-hosted Sentry means 65 containers, 16-32 GB of RAM, and a dedicated engineer just to keep it alive. All that - to catch stack traces. We dig into why the industry treats this as normal, compare the alternatives (GlitchTip, BugSink, Hawk), and take a look at Metric - a Sentry-compatible monitoring platform written in Rust that runs on 1 GB of RAM and two containers. Migration is a single-line DSN change.

Read more

OpenAI Codex Agents Dashboard: Managing Concurrent CLI Tasks

Level of difficultyEasy
Reading time3 min
Reach and readers5.6K

Codex CLI sessions are easy to manage when only one task is active. The workflow becomes less predictable when several sessions operate in different repositories or terminal tabs. A task may be blocked on an approval while another is still running and a third is ready for review.

Read more

How we choose LLMs and frameworks for AI agents

Level of difficultyEasy
Reading time10 min
Reach and readers3.9K

The journey from a single A100 in the cloud to an H200 cluster is not just a hardware upgrade — it’s a story of how an ML team stopped chasing “the one perfect model” and started building an ecosystem. When there are millions of lines of PostgreSQL C code under the hood and tasks range from hint-set generation to Graph-RAG, the model stops being a black box and becomes just another replaceable component. We explain how we rebuilt our stack around vLLM and MCP, why context management matters more than model weights, and how we made a 0.6B-parameter model perform on par with the giants using GRPO.

Read more

I Built the Same Program in BASIC, C, Pascal and Python — The Results Were Not What I Expected

Level of difficultyHard
Reading time12 min
Reach and readers3.6K

I wanted to see what actually changes when the same small data-processing program travels through four generations of programming languages. So I built it in BASIC, C, Pascal and Python, kept the algorithm as similar as possible, and compared not only execution speed but also memory use, binary size, debugging time and the amount of code I had to keep in my head. C was fast. Python was short. Those parts were predictable. BASIC and Pascal were where the experiment became interesting.

Read more

LLMs haven't learned to lie. They only speak

Level of difficultyEasy
Reading time7 min
Reach and readers5.1K

LLMs hallucinate — everyone has seen what it looks like. The model reports, confidently and coherently, with the right intonation and terminology, something that isn't there. Engineers treat this as a bug: one being fixed, one about to be fixed.

It won't be. This is not a technical fault but an inherent property of language, which the machine has made visible.

Read more

Inside DeepSeek Harness: Cordis, Session Events, Tool Pipelines, and Permission Boundaries

Level of difficultyMedium
Reading time7 min
Reach and readers7K

DeepSeek Harness is often described as an open-source coding agent. That description is correct, but incomplete. The more interesting part is its architecture. DeepSeek Harness is a configurable runtime for constructing agents from model adapters, tools, session services, execution backends, permission policies, interfaces, and agent loops.

Read more

Why Your AI Agent Gets Blocked and Your Chrome Doesn't

Reading time5 min
Reach and readers2.1K

Two months ago I gave an agent a simple job: log into a vendor portal, download last month’s invoice PDF, rename it, drop it in a folder. It worked on my laptop. It failed on the server, silently, in a way that took me a full day to understand — the page loaded, the DOM was there, the login form was there, and the credentials were rejected with a generic error. No CAPTCHA. No block page. Just “something went wrong.”

Read more

A 7-Year Indie Journey: Building an Offline-First iOS Debt Tracker with Multi-Currency & FIFO Investment Support

Reading time4 min
Reach and readers4.2K

Hello, Habr!

For many IT professionals, the ultimate personal finance setup involves a massive Google Sheet or a complex Notion database. I completely understand this approach: when you spend your entire day sitting in front of a monitor, entering data into a cell takes two seconds.But 7 years ago, my reality was entirely different. I was an entrepreneur, and my workday meant constant movement. I was driving, visiting warehouses, meeting partners, or checking production floors. I was 100% mobile, and the only tool I always had on hand was my iPhone.

In that fast-paced rhythm, traditional finance trackers and spreadsheets simply fall apart. Here are typical scenarios from my life back then:

Read more

Residential Proxies: How to Choose a Pool for Multi-Accounting Without Wasting Your Budget

Level of difficultyEasy
Reading time10 min
Reach and readers3K

In light of recent events (restrictions, slowdowns, bans) — “this isn’t allowed,” “this is for the best,” “strictly in the interest of your security,” and so on — the market for proxy providers has grown exponentially in just the last couple of years. 

To be fair, the ”proxy boom” hit right during the golden era of the 2020s, and overall, the growth trend continues to rise. In fact, I believe in the next few years, we will witness a total revolution in automation and related services. Reimagining, repackaging, and rolling out new features — I’m certain we have yet to peak in abilities.

However, the larger the market grows, the breakdown of components becomes much more interesting — to analyze the players, categorize them into subgroups, and highlight the favorites, mid-tier options, and underperformers. There are plenty of services out there, and a good chunk of them are incredibly inefficient and inaccurate. Since I have hands-on experience with many of these players, I'll share my firsthand knowledge, in hopes of it being useful to others.

Read more

Your Desktop Anti‑Detect Setup Doesn't Survive Mobile

Reading time4 min
Reach and readers2.5K

When I added mobile personas to a browser that already had desktop ones working, I assumed the work was mostly string substitution: swap the user agent, set touch points to 5, shrink the viewport, done. That assumption survived about a day.

Mobile fingerprints aren’t a variant of desktop fingerprints. They’re a different set of constraints, and most of the desktop toolkit either doesn’t apply or actively gives you away. Here’s what I ran into, in the order it hurt.

Read more

I Kept Average Test Time at 10 Seconds but Changed Only Its Variance: Why Unpredictable Tests Break Developer Focus

Level of difficultyMedium
Reading time10 min
Reach and readers4.4K

Two test suites can have exactly the same average runtime and still create completely different development workflows. I modeled 300 code → test → fix cycles while keeping mean feedback latency close to ten seconds and changing only its variance. One runner behaved predictably. The other was usually fast but occasionally became extremely slow. The average stayed almost the same. The cost of waiting did not.

Read more

I Tried to Write a Program That Could Still Run Unmodified in 2056

Level of difficultyHard
Reading time18 min
Reach and readers2.9K

Modern software can become surprisingly difficult to run after only a few years. Dependencies disappear, package managers change, APIs get deprecated, runtimes stop supporting old versions, and sometimes the build instructions become archaeology before the actual code does. So I tried the opposite approach: write a small useful program in 2026 while treating 2056 as a real deployment target. The result turned out to be less about choosing the perfect language and more about removing assumptions that normally feel completely harmless.

Read more

I Cloned the Same VM 100 Times and Found Five Identities That Were No Longer Unique

Reading time13 min
Reach and readers2.9K

I needed 100 disposable Linux machines for a test environment, so cloning one prepared VM looked like the fastest option. The clones received different MAC addresses, IP addresses and hostnames, booted normally and appeared as separate hosts in monitoring.

Then I started checking the identities stored inside the operating system itself. Across the whole fleet I found the same system machine ID, the same SSH host key, the same filesystem UUID, inherited cloud‑init state and the same WireGuard identity. What looked like 100 independent VMs from the outside was still one machine copied 100 times at several lower layers.

Read more

Active Directory security assessment in Rust: from LDAP observations to evidence-backed paths

Level of difficultyHard
Reading time2 min
Reach and readers3.6K

Finding a misconfiguration and proving an attack path are different tasks. ADhammer is an open-source Rust toolkit built around that distinction.

The workflow is simple:

Collect → Graph → Validate → Report

Collection first

The collector reads directory objects, ACLs, trusts, delegation, GPO signals, privileged principals, and certificate-template data. The result is an observation of the directory state—not an automatic compromise claim.

Graph context

AD relationships become typed edges: membership, control, delegation, enrollment, trust, and privilege. This makes a finding reviewable. A reader can ask which object creates the edge, which control is missing, and whether the route reaches a Tier 0 target.

Validation with a boundary

Validation is optional and intended for an authorized lab. When a supported workflow captures the expected proof, the finding records that validation state. Unsupported routes stay marked as potential instead of being promoted to confirmed exploits.

Evidence in the report

A useful finding keeps the affected objects, impact, remediation, commands, and proof metadata together. ADhammer exports JSON for automation, Markdown and HTML for human review, and graph-oriented data for existing identity-analysis workflows.

Why this matters

A report should let another operator understand what was observed, what was tested, and what remains unconfirmed. That makes remediation easier to prioritize and makes technical criticism productive.

ADhammer is still early software. It does not claim universal exploitability or replace operator judgment. The project is intended for authorized assessments and research environments, and technical review is welcome.

Read more

I Revisited My 7x Go API Benchmark: What ApacheBench Was Actually Measuring

Level of difficultyMedium
Reading time10 min
Reach and readers2.2K

My Go API benchmark once showed an almost 7x throughput improvement after I moved a read-heavy endpoint from PostgreSQL to a local in-memory cache. The result looked obvious: PostgreSQL was the bottleneck, the cache removed it, and the API became much faster. Later I realized that this interpretation was too simple. ApacheBench had measured an entire request path consisting of HTTP handling, connection management, pgxpool waiting, SQL execution, decoding, serialization, and response writing. I decided to decompose that path and understand what the 7x result actually meant.

Read more
1