Techlist.io - Korean Tech Blog Curator

gitlab3 min readCurated summary

GitLab Container Virtual Registry with Docker Hardened Images

GitLab Container Virtual Registry provides a single, authenticated endpoint for pulling images from multiple registries while caching manifests and layers locally. It reduces repeated network downloads, centralizes upstream credentials, and makes it easier to adopt Docker Hardened Images without changing every team’s CI/CD configuration. The article recommends using it as an operational layer between pipelines and registries such as Docker Hub, dhi.io, MCR, and Quay.io. ## The Container Image Management Problem Platform teams often depend on several registries: - Docker Hub for common base images - dhi.io for Docker Hardened Images - MCR for .NET and Azure tooling - Quay.io for Red Hat ecosystem images - Internal registries for proprietary images This creates: - Different authentication mechanisms and image paths - Registry-specific CI/CD configuration - Repeated credential-management work - Slow builds caused by downloading identical images in every job ## How Container Virtual Registry Works - Pipelines pull through a GitLab URL such as: `gitlab.com/virtual_registries/container/<id>/image` - GitLab checks configured upstreams in priority order. - If the image is cached, GitLab serves it directly. - If not, GitLab fetches it from the appropriate upstream, caches the manifest and layers, and returns it. - Cache validity is configurable, with 24 hours presented as the default. - Developers and pipeline authors do not need to know which upstream registry provides an image. ## Benefits for Docker Hardened Images Docker Hardened Images offer: - Minimal attack surfaces - Near-zero CVEs - Software bills of materials (SBOMs) - SLSA provenance The virtual registry reduces the friction of adopting them by providing: - **Centralized authentication:** Teams authenticate to GitLab while GitLab stores and uses the dhi.io credentials. - **Simpler CI/CD:** Pipelines use one GitLab endpoint rather than configuring dhi.io separately. - **Gradual adoption:** Teams can migrate incrementally while cached image paths reveal which variants are being used. - **Improved visibility:** The cache provides an inventory of active dependencies, such as whether teams pull `library/python:3.11` instead of a hardened alternative. - **An audit trail:** Cached images help with compliance and understanding fleet-wide dependencies. ## Setting Up the Registry The article demonstrates setup with a Python client. - Create a virtual registry under a GitLab top-level group: ```python registry = client.create_virtual_registry( group_id="785414", name="platform-images", description="Cached container images for platform teams" ) ``` - Add Docker Hub as an upstream, using a 24-hour cache period. - Add dhi.io with a Docker username and access token: ```python dhi_upstream = client.create_upstream( registry_id=registry["id"], url="https://dhi.io", name="Docker Hardened Images", username="your-docker-username", password="your-docker-access-token", cache_validity_hours=24 ) ``` - Add other sources such as: - `https://mcr.microsoft.com` for Microsoft images, with a 48-hour cache period - `https://quay.io` for Quay-hosted images, with a 24-hour cache period ## Practical Recommendation Use GitLab Container Virtual Registry as a centralized pull-through cache when multiple teams rely on several container registries. Configure Docker Hardened Images as an upstream, point pipelines to the GitLab virtual registry endpoint, and use the cache contents to monitor adoption, performance, and image dependencies.

Read original(opens in new tab)
cloudflare3 min readCurated summary

Slashing agent token costs by 98% with RFC 9457-compliant error responses

Cloudflare argues that HTML error pages are poorly suited to AI agents, wasting tokens while offering little actionable guidance. It now provides RFC 9457-compliant Markdown and JSON responses for Cloudflare-generated errors, including instructions on whether to retry, wait, stop, or escalate. The structured formats reduce payload size and token usage by more than 98% compared with HTML. ## Problems with HTML Error Pages - Cloudflare errors often result from customer policies or edge conditions, including: - DNS or host configuration problems - WAF, geographic, ASN, or bot restrictions - Rate limits - Traditional responses contain large amounts of HTML, CSS, and human-oriented text. - Agents may struggle to identify: - What went wrong - Whether retrying is appropriate - How long to wait - Whether human intervention is required - Custom Error Rules are configuration-dependent and therefore cannot provide a consistent contract across websites. ## RFC 9457 Structured Responses - Cloudflare now supports structured responses for all 1xxx-class errors. - Clients can request: - `Accept: text/markdown` - `Accept: application/json` - `Accept: application/problem+json` - Markdown responses include: - YAML frontmatter with machine-readable fields - “What happened” and “What you should do” guidance - JSON responses expose the same information as a flat object. - Support for Cloudflare-generated 4xx and 5xx errors is planned next. ## Machine-Readable Error Guidance Responses include stable fields such as: - `error_code`, `error_name`, and `error_category` for classification - `retryable` and `retry_after` for automated backoff - `owner_action_required` to indicate when the agent should stop or escalate - `ray_id`, `timestamp`, and `zone` for debugging and support This allows agents to implement durable control flow without scraping HTML or interpreting changing prose. ## Compatibility with RFC 9457 Cloudflare’s JSON format follows the standard Problem Details structure: - `type`: Documentation URL for the error - `status`: Actual HTTP status code - `title`: Short problem description - `detail`: Explanation of the specific occurrence - `instance`: Identifier for the individual error, corresponding to the Ray ID Cloudflare-specific operational fields are included as RFC 9457 extension members. Clients that do not recognize those fields can safely ignore them. ## Example: Rate Limiting A Cloudflare 1015 response identifies the request as rate-limited and includes: - HTTP status `429` - Error code `1015` - Category `rate_limit` - A description stating that the website owner’s configuration caused the limit - A Ray ID and timestamp - Retry-related guidance for implementing backoff The change is automatic across Cloudflare’s network. Browsers continue receiving HTML, while agents receive structured instructions when they explicitly request Markdown or JSON.

Read original(opens in new tab)
cloudflare3 min readCurated summary

AI Security for Apps is now generally available

Cloudflare’s AI Security for Apps is now generally available to help organizations discover, detect, and mitigate threats targeting AI-powered applications. The service protects AI endpoints through Cloudflare’s reverse proxy and integrates AI-specific signals with existing WAF controls. New GA features include free endpoint discovery for all customers, custom topic detection, and custom prompt extraction capabilities. ## Why AI Applications Create a New Attack Surface - Traditional applications follow predictable workflows, while AI applications accept natural-language input and produce probabilistic outputs. - Attackers can exploit models through: - Prompt injection - Sensitive information disclosure - PII exposure - Toxic or off-policy content - Unbounded resource consumption - Risks become more serious when AI agents can call tools to issue refunds, change accounts, apply discounts, or access customer data. - Organizations may struggle to maintain consistent safeguards as teams rapidly adopt new models and providers. ## AI Endpoint Discovery - AI Security for Apps automatically identifies LLM-powered endpoints across web properties, regardless of hosting location or model provider. - Discovery analyzes endpoint behavior rather than relying only on paths such as `/chat/completions`, since AI may also power search, valuation, and recommendation features. - Discovered endpoints appear under **Security → Web Assets** with the `cf-llm` label. - Discovery is now free for Cloudflare Free, Pro, and Business customers: - Free-plan discovery begins when users open the Discovery page. - Paid plans receive recurring background discovery. - Sufficient valid traffic is required to confidently identify AI-powered endpoints. ## Always-On AI Threat Detection - Prompts sent to discovered AI endpoints are evaluated by multiple detection modules. - Built-in protections cover: - Prompt injection - PII exposure and extraction - Sensitive or toxic topics - Detection results are attached as metadata and can be used in custom WAF rules. - Cloudflare intends to use its global network data to identify emerging attack patterns across millions of sites. ## Custom Topics and Prompt Extraction - Custom topics allow organizations to define their own sensitive categories, such as securities, patient data, or competitor products. - Each prompt and response receives a relevance score that can be logged, blocked, or handled through custom policies. - Custom prompt extraction identifies where prompts are located in request bodies, supporting formats such as: - `$.messages[*].content` - `$.requests[*].params.messages[*].content` - `$.property_description` - Standard formats from providers including OpenAI, Anthropic, Google Gemini, Mistral, Cohere, xAI, and DeepSeek are supported. - Unknown payload formats use a default-secure approach that scans the full request body, which may create false positives. - Cloudflare plans to support user-defined JSONPath expressions and automated prompt learning to improve accuracy. ## WAF-Based Mitigation - Organizations can block, log, or customize responses to detected threats using the existing Cloudflare WAF rule builder. - AI-specific signals can be combined with broader request data, including IP reputation, browser fingerprints, bot activity, and attack history. - This lets security teams distinguish isolated suspicious prompts from attacks associated with broader malicious behavior. ## Expanding Partnerships - IBM has selected Cloudflare to provide AI security for its cloud customers. - Cloudflare and Wiz are partnering to provide mutual customers with a unified view of AI security posture. - The service is being extended through Cloudflare’s broader security ecosystem. Organizations adopting AI agents should first inventory their AI endpoints, then apply detection and WAF policies tailored to their data, users, and business risks. Cloudflare’s unified approach is designed to provide a practical fail-safe as AI deployments expand.

Read original(opens in new tab)
grammarly2 min readCurated summary

Now Available: Grammarly’s Writing Support in 17 More Languages

Grammarly’s latest Beta expansion adds real-time grammar and spelling corrections for 17 languages, bringing support to more than 20 languages overall. The feature works automatically in Grammarly’s browser extension and Desktop app, helping users write, edit, and collaborate across languages. More advanced clarity, fluency, tone, and reading-translation features are planned. ## Expanded Language Support - Newly supported languages include: - Turkish, Polish, Dutch, Czech, Vietnamese, Hungarian, Swedish, Romanian, Indonesian, Slovak, Danish, Finnish, Norwegian, Ukrainian, Korean, Tagalog, and Hindi. - These additions build on existing support for Spanish, French, German, Portuguese, and Italian. - Current Beta functionality focuses on grammar and spelling corrections. - Corrections appear in real time without additional setup or settings changes. ## Translation Across Languages - Grammarly provides in-line translation across 19 languages. - Users can highlight text, open the blue sidebar, and choose a target language. - The feature supports drafting and editing in multiple languages without interrupting workflow. ## Planned Improvements - Grammarly plans to add clarity, fluency, and tone suggestions to the 17 newly supported languages. - During the Beta period, the company will refine its models to achieve consistent quality across languages. - A planned reading-assistance feature will let browser-extension users highlight text and translate it while reading, rather than switching tabs. ## Getting Started - Sign up for or log in to a Grammarly account. - Open the Grammarly browser extension or Desktop app. - Write in any supported language to receive real-time corrections.

Read original(opens in new tab)
google3 min readCurated summary

Exploring the feasibility of conversational diagnostic AI in a real-world clinical study

The study evaluated Google’s conversational medical AI, AMIE, in a real-world primary care workflow rather than simulated cases. In a prospective, IRB-approved study at Beth Israel Deaconess Medical Center, AMIE conducted supervised pre-visit history-taking with 100 patients. Results suggested that supervised deployment was feasible and conversationally safe, while AMIE’s diagnostic and management-plan quality was broadly comparable to that of primary care physicians, with physicians performing better on practicality and cost effectiveness. ## Study Design and Clinical Workflow - Patients with new, non-emergency, episodic complaints used AMIE through a secure web link before an in-person or telehealth appointment. - A physician supervised each AI-patient interaction through live video and screen-sharing. - AMIE produced a transcript and summary for the patient’s primary care physician. - Independent clinical evaluators assessed: - The quality of the AMIE conversation - AMIE’s differential diagnoses - AMIE’s management plans - Comparable outputs from physicians - The study was prospective, single-center, single-arm, pre-registered, and IRB approved. ## Participants - 100 adults completed the AMIE interaction. - 98 attended their scheduled primary care appointments. - Participants represented varied ages, racial and ethnic groups, health literacy, technology literacy, and prior chatbot experience. - Compared with all 1,452 urgent care visits during the study period, participants tended to be younger, although the sample reflected the broader population’s female and white demographic skew. ## Safety Oversight - Human supervisors could stop an interaction if they observed: - Immediate risk of harm to the patient or others - Significant emotional distress related to the AI interaction - Potential clinical harm - A patient’s explicit request to end the session - No safety stops were required across the study. - The authors interpret this as evidence that supervised AMIE interactions were conversationally safe in this setting. ## Clinical Reasoning Performance - Three independent clinical evaluators reviewed each case using blinded, randomized assessments. - AMIE and physicians showed similar overall quality for: - Differential diagnoses - Management plans - Management-plan appropriateness and safety - Physicians performed better on the practicality and cost effectiveness of management plans. - AMIE’s differential-diagnosis accuracy was reported as high, including cases where the final diagnosis was confirmed through diagnostic testing. ## Patient and Clinician Experience - The study measured trust, perceptions, and acceptance among both patients and clinicians. - Patient trust in AI increased after interacting with AMIE. - Overall findings indicated that the system was well received within the supervised pre-visit workflow. The study supports cautious, supervised testing of conversational diagnostic AI in clinical environments. It does not establish that AMIE can independently replace clinicians; rather, it suggests that pre-visit information gathering may be a practical early use case, provided rigorous oversight, safety protocols, and further evaluation in larger and more diverse settings.

Read original(opens in new tab)
github2 min readCurated summary

The era of “AI as text” is over. Execution is the new interface.

The post argues that AI is moving beyond text-based question-and-answer interactions toward embedded execution. The GitHub Copilot SDK lets applications use Copilot’s planning, tool use, file modification, command execution, and error recovery capabilities directly. This enables teams to build adaptable AI workflows without creating their own orchestration infrastructure. ## Delegating Multi-Step Work to Agents - Applications can express intent and constraints instead of hard-coding every workflow step. - For a task such as “Prepare this repository for release,” an agent can: - Explore the repository - Plan the necessary work - Modify files - Run commands - Recover and adapt when failures occur - This approach is more flexible than scripts, which become brittle when workflows depend on changing context or unexpected errors. - Teams can use agentic execution while maintaining defined boundaries and observability. ## Using Structured Runtime Context - Relying on prompts to contain system logic makes workflows difficult to test, maintain, and evolve. - The Copilot SDK supports structured, composable context through: - Domain-specific tools and agent skills - Model Context Protocol (MCP) - Runtime retrieval of relevant data - Agents can directly access systems such as: - Service ownership records - Historical decisions - Dependency graphs - Internal APIs - Permissioned tools and real-time data provide more reliable grounding than embedding organizational knowledge in prompts. ## Embedding Agents Beyond the IDE - Agentic capabilities can be integrated into: - Desktop applications - Internal operational tools - Background services - SaaS products - Event-driven systems - Applications can invoke Copilot in response to events such as file changes, deployments, or user actions. - Execution happens within the product itself rather than in a separate IDE or terminal interface. - This turns AI from an auxiliary developer tool into application infrastructure available wherever the software operates. ## Execution as a New Interface - Agentic workflows are programmable planning-and-execution loops that: - Integrate with real systems - Operate under constraints - Adapt during runtime - Use tools to complete tasks - The Copilot SDK provides this execution layer so teams can focus on defining outcomes instead of rebuilding orchestration systems. The practical recommendation is to treat AI as an executable application capability rather than merely a text interface. Teams can start by identifying multi-step workflows or event-driven tasks where structured tools, runtime context, and adaptive execution would provide more value than fixed scripts.

Read original(opens in new tab)
cloudflare3 min readCurated summary

Investigating multi-vector attacks in Log Explorer

Cloudflare Log Explorer provides a unified view for investigating multi-vector attacks across application, network, identity, and endpoint activity. By correlating 14 new datasets from Cloudflare Application Services and Cloudflare One, analysts can connect reconnaissance, credential abuse, DDoS activity, lateral movement, and data-exposure risks. This broader visibility helps reduce Mean Time to Detect and supports faster, more complete forensic investigations. ## Unified Telemetry Across the Stack - Cloudflare describes logs as a “flight recorder” for digital infrastructure, capturing requests, attacks, configuration changes, and performance issues before traffic reaches origin servers. - Log Explorer centralizes telemetry in one interface, allowing analysts to correlate events across: - Application-layer HTTP traffic - Firewall and DDoS activity - DNS queries - Zero Trust access and network sessions - Endpoint, browser, email, and device events ## Zone-Scoped Logs These datasets focus on public websites, edge security, and application performance. - **HTTP Requests:** Reconstruct sessions, exploit attempts, and bot activity. - **Firewall Events:** Show blocked or challenged requests and the rules, IP reputations, or filters involved. - **DNS Logs:** Help detect cache poisoning, domain hijacking, and reconnaissance. - **NEL Reports:** Separate Layer 7 attacks from legitimate client connectivity problems. - **Spectrum Events:** Reveal Layer 4 anomalies and brute-force attempts against services such as SSH or RDP. - **Page Shield and Zaraz Events:** Track unauthorized JavaScript, outbound connections, third-party tools, and privacy-related behavior. ## Account-Scoped Logs Account-level datasets cover internal security, administration, identity, and network operations. - **Access Requests and Zero Trust Network Sessions:** Show who accessed protected applications and how long sessions lasted. - **Audit Logs:** Identify unauthorized Cloudflare configuration changes. - **CASB Findings:** Detect SaaS misconfigurations and potential data exposure. - **Gateway DNS, HTTP, and Network Logs:** Reveal malware callbacks, shadow IT, malicious downloads, unauthorized ports, and lateral movement. - **Magic IDS and Network Analytics:** Detect known exploit signatures, unusual traffic spikes, and volumetric attacks. - **Browser Isolation and Device Posture Logs:** Track risky user actions and whether connecting devices meet security requirements. - **Email Security Alerts:** Trace phishing and other email-based entry points. - **WARP and IPSec Logs:** Identify tampering with security connectivity and monitor encrypted tunnel health. - **DEX telemetry:** Help distinguish security incidents from ordinary application or device-performance problems. - **Sinkhole HTTP Logs:** Confirm attempts by internal devices to contact known botnet infrastructure. ## Investigating Attacks Across Multiple Stages - Public-facing telemetry can reveal how attackers probe websites, while account and Gateway logs show subsequent internal activity. - Analysts can correlate compromised credentials with the applications, devices, and network resources accessed by an attacker. - Magic IDS and Network Analytics extend investigations beyond HTTP to detect network-layer attacks and east-west movement. - Combining these sources gives investigators a timeline spanning initial reconnaissance, exploitation, internal access, and possible command-and-control activity. ## Detecting Reconnaissance - Query `http_requests` for repeated `401`, `403`, or `404` responses from a single IP address. - Look for requests targeting sensitive paths such as: - `/.env` - `/.git` - `/wp-admin` - Use `magic_ids_detections` to identify network-layer scanning. - Suspicious patterns include: - One source IP triggering multiple unique detections - Probes across many destination ports - Activity occurring within a short time window - Magic IDS signatures can identify techniques such as Nmap scans and SYN stealth scans. Log Explorer is most valuable when teams correlate its datasets rather than examining each log source in isolation. Combining application, identity, DNS, network, and endpoint telemetry provides the context needed to identify sophisticated attacks quickly and reconstruct their full scope.

Read original(opens in new tab)
cloudflare3 min readCurated summary

Building a security overview dashboard for actionable insights

Cloudflare’s revamped Security Overview dashboard is designed to turn overwhelming security data into prioritized, actionable work. It combines ranked Security Action Items, security-tool status, and deep links into Security Analytics so teams can identify and investigate risks without switching between tools. Behind it is a checker-based system that processes more than 10 million insights daily through scheduled scans and real-time event handlers. ## From Visibility to Action - Security Action Items focus analysts on what needs to be fixed now rather than displaying every available event. - Issues are ranked by severity: - **Critical:** Immediate risks that could be exploited. - **Moderate:** Issues requiring attention to maintain security posture. - **Low:** Hardening recommendations and best-practice improvements. - Analysts can filter items by insight type, including suspicious activity and insecure configuration. ## Closing Configuration Gaps - The Detection Tools module shows whether Cloudflare protections are actively operating. - It highlights issues such as: - Security tools running in “Log Only” mode instead of blocking threats. - Shadow API discovery being disabled or unavailable. - This shifts the focus from whether a security feature exists to whether it is correctly configured and protecting traffic. ## Connected Investigation Workflows - Suspicious Activity cards appear both on the Security Overview and Security Analytics pages. - Selecting a card deep-links into Analytics with relevant filters already applied. - This removes repetitive navigation and filter recreation, helping teams investigate incidents faster. ## Checker-Based Insight Generation - Cloudflare generates and refreshes more than 10 million actionable insights each day. - Specialized microservices called **checkers** handle different areas, such as DNS, SSL certificates, and AI bot configurations. - Checkers can scale independently and operate through: - **Scheduled checks** for comprehensive configuration inspections. - **Real-time listeners** that respond immediately to control-plane events. ## Scheduled Checks and Insight Lifecycles - A scheduler distributes inspection tasks across checkers, such as scanning all DNS records for a zone. - A checker: - Receives a task. - Collects relevant assets and configurations. - Applies specialized validation rules. - Creates an insight when a configuration fails its required threshold. - Updates the insight timestamp if the issue persists. - Removes the insight once the issue is fixed. ## Real-Time Ruleset Handlers - Event handlers listen continuously for configuration changes. - For example, when a WAF ruleset is changed, a handler can immediately detect that it is enabled only in “Log Only” mode. - The handler determines that attacks are being recorded but not blocked, registers an insight, and displays it on the dashboard. - Once the configuration is secured, the insight is cleared automatically. The dashboard’s main benefit is its combination of prioritization, configuration awareness, and immediate investigation paths. By pairing scheduled validation with real-time detection, it helps security teams move from passive monitoring to faster, more proactive remediation.

Read original(opens in new tab)
grammarly2 min readCurated summary

Superhuman Launches First-of-Its-Kind Agent-Specific Attribution With Grammarly Authorship Update

Superhuman is expanding Grammarly Authorship into its AI-native Docs workspace with agent-specific attribution and default-on tracking. The update records whether AI contributed to research, generation, or revision, while students retain control over whether reports are shared. The company argues that transparent authorship can help schools replace blanket AI bans and detection-based enforcement with more informed, responsible AI education. ## Agent-Specific Attribution - Authorship can now identify which Superhuman AI agents contributed to a document and how they were used. - It distinguishes among: - Research support - Content generation - Revision and feedback - This gives educators more context for evaluating the writing process rather than only the final submission. - Featured agents include: - **Reader Reactions:** Predicts audience responses and suggests improvements. - **Citation Finder:** Locates supporting or challenging sources and formats citations. - **Proofreader:** Improves clarity, flow, correctness, and stylistic consistency. - **Fact Checker:** Finds evidence that supports or disputes claims. ## Default-On Authorship in Docs - Authorship is now available by default in Superhuman Docs. - Students no longer need to manually activate tracking. - The system records human writing, AI-generated content, and AI-edited text as work progresses. - Students still control access: instructors cannot see a report unless the student chooses to share it. ## Supporting Academic Integrity - Authorship is intended to reduce reliance on potentially inaccurate AI-detection tools and false positives. - More than 5 million Authorship reports have been generated since its beta launch in October 2024. - Rowan-Cabarrus Community College reported a 96% reduction in academic integrity violations in one semester after adopting the tool. - The company says process visibility can help educators teach responsible AI use instead of focusing primarily on punishment or prohibition. ## Institutional Controls and Availability - Educational administrators can configure which AI agents are available to students and faculty. - Authorship is available in Docs at no additional cost and is also supported in: - Google Docs - Microsoft Word - Canvas - The feature is part of Superhuman’s broader effort to provide AI transparency wherever students write. Superhuman recommends using Authorship as a foundation for nuanced AI policies and process-based assessment. By showing how AI was used while preserving student choice over sharing, the tool aims to support both academic integrity and practical AI literacy.

Read original(opens in new tab)
stripe3 min readCurated summary

Analyzing first-party fraud trends: Account, free trial, and refund abuse

First-party fraud is rising as legitimate customers exploit account, trial, and refund policies rather than using stolen credentials. Stripe’s analysis identifies account abuse, free-trial abuse, and refund fraud as rapidly growing problems, with AI companies particularly exposed because free access consumes costly compute resources. Stripe is expanding Radar with tools to detect these behaviors across the customer lifecycle. ## Account Abuse at Sign-Up - Users create multiple accounts to repeat free trials, reuse promotional offers, or evade fraud detection. - A single payment method may be linked to dozens or hundreds of emails, IP addresses, and names. - About 20% of consumers admit to using different contact details to access promotions repeatedly; the figure rises to 29% among Gen Z and 27% among millennials. - AI companies are especially vulnerable because repeated free-tier access consumes compute resources. Stripe found suspected multiaccount abuse in 7.4% of AI-company sign-ups. - Stripe is introducing Radar capabilities to assess sign-ups and login events, helping businesses distinguish genuine prospects from repeat abusers. ## Free-Trial Abuse and Virtual Cards - Customers may cycle through multiple trials to extend free access beyond the stated terms. - AI startups with self-serve registration and direct API access experience 10 times more attempted abuse than enterprise AI offerings. - Blocking virtual cards is no longer an effective solution because many legitimate customers use them for privacy and security. - Stripe’s new solution predicts common trial-term abuse with 90% accuracy. - Radar also provides analytics showing blocked high-risk payments and, for businesses without the control enabled, payments that would have been blocked. ## Refund Abuse After Purchase - Customers may falsely claim that products were defective or never delivered while keeping the merchandise. - Stripe estimates global refund-abuse losses at roughly $100 billion annually. - “Wardrobing”—wearing items briefly before returning them—was admitted by 27% of shoppers who returned an online purchase, rising to 49% among Gen Z shoppers. - Social-media shopping hauls can create costs through return shipping, processing, markdowns, and unsellable inventory. - Organized abusers may use more than 100 email variations and multiple cards to bypass refund limits and “no questions asked” policies. - Because purchases often use valid credentials, the abuse may only become visible after the refund is issued. - Stripe is developing tools to identify refund abuse and is seeking preview participants. ## Stripe’s Broader Fraud-Prevention Strategy - Stripe plans to use its network data, existing AI infrastructure, and Radar to detect repeat abusers, fake-account networks, and emerging first-party fraud tactics. - The broader objective is to monitor and reduce abuse throughout registration, trial access, payment, and post-purchase refund processes. Businesses should treat first-party fraud as a lifecycle-wide risk rather than relying only on transaction-time fraud checks. More targeted, AI-based detection can reduce abuse without unnecessarily rejecting legitimate users, especially those using virtual cards.

Read original(opens in new tab)
kakao3 min readCurated summary

From Understanding Korean Culture to Screen Control: Everything About Kanana-V Feature Expansion

Kanana-V expands a vision-language model beyond single-image question answering into Korean cultural understanding, document analysis, multi-image reasoning, and GUI interaction. The post details how Kakao built and evaluated these capabilities through large-scale data curation, Korean benchmarks, and training optimizations. Its central conclusion is that language- and task-specific data quality, rather than scale alone, is essential for producing a practical multimodal model. ## Expanding VLM Capabilities - Real-world VLM applications require more than interpreting one image: - Understanding long PDF documents - Comparing multiple images - Interpreting and operating graphical user interfaces - Kanana-V targets these requirements through: - Korean-context understanding - Document and PDF comprehension - Multi-image and long-context processing - GUI grounding for Computer Use Agents (CUAs) - Compared with the similarly sized Qwen3-VL 4B, it achieved broadly comparable results and showed particular strength on Korean-language tasks. ## Curating Korean Interleaved Data - Interleaved datasets alternate images and text, as in blogs, enabling broad knowledge acquisition and stronger in-context learning. - The source collection reached hundreds of terabytes and contained substantial low-quality material, including advertisements, broken images, and duplicated posts. - Kakao used Hugging Face’s Datatrove framework to shard the data and run filtering pipelines in parallel. ## Eight-Stage Data-Cleaning Pipeline - **Image-based document filtering** - Removed broken, tiny, low-resolution, or extreme-aspect-ratio images. - Excluded documents left without valid images. - Used thresholds such as an aspect ratio above 3.0 or dimensions below 28 pixels. - **Language identification** - Applied FastText-based detection. - Retained documents with at least 90% probability of being Korean. - Preserved Korean technical content containing English quotations or code. - **Gopher repetition filtering** - Detected repeated lines, paragraphs, and abnormal 2-gram through 10-gram patterns. - Removed spam and automatically generated advertising content. - **Gopher quality filtering** - Adapted English-oriented rules for Korean. - Lowered the minimum average word length to one character because Korean tokenization often produces short tokens. - Added Korean particles and endings to stopword checks. - **C4 sentence-structure filtering** - Required at least four sentences. - Avoided punctuation-based filtering because Korean writing often omits sentence-final periods. - **FineWeb quality filtering** - Examined short-line ratios, bullet-list frequency, and lines ending in ellipses. - Removed product lists, menus, and similarly unsuitable formats. - **MinHash deduplication** - Used MinHash and locality-sensitive hashing to efficiently identify copied or highly similar documents without performing all pairwise comparisons. - **PII processing** - Masked Korean phone numbers, email addresses, and other personal information. - Cleaned empty text nodes created by image removal and merged adjacent text blocks. ## Impact of Filtering - Approximately 77% of the original data was removed, leaving 23% for training. - Ablation experiments showed that filtered data generally improved performance: - MMVet increased from 33.76 to 36.79. - LLaVA-Wild increased from 75.10 to 78.00. - Korean entity recognition increased from 50.05 to 53.66. - Korean food-menu understanding increased from 44.56 to 47.02. - Korean chart understanding was the exception, declining slightly from 58.33 to 57.43. - The team emphasizes: - Running inexpensive filters before costly ones - Saving intermediate outputs for inspection and reuse - Tuning thresholds for each language - Cleaning related text whenever images are removed from interleaved data The article’s practical recommendation is to treat multimodal model development as an end-to-end data and systems problem: carefully curate culturally relevant data, build language-specific evaluation sets, and optimize training pipelines for each target capability rather than relying solely on larger datasets or models.

Read original(opens in new tab)
kakao4 min readCurated summary

2026 Kakao Group New Crew Recruitment Coding Test Round 1 Problem Explanations

The post explains the first-round coding test for Kakao Group’s 2026 new-crew recruitment, covering seven problems of gradually increasing difficulty; the provided text details the first five. The solutions rely on string processing, simulation, graph traversal, and structural optimization. The main lesson is to exploit each problem’s constraints and identify the right representation before implementing. ## Problem 1: Preventing Spoilers in Important Words - Split the message into space-separated words and record each word’s character interval. - Classify words as spoiler-protected if their interval overlaps any spoiler range. - Store non-spoiler words in a set or hash map to detect duplicates. - Scan protected words from left to right: - Reject words appearing outside spoiler ranges. - Reject words duplicating an already revealed important word. - Count and record valid words. - Later test groups add overlapping spoiler ranges and duplicate words, requiring both types of deduplication. ## Problem 2: Yellow Traffic Lights - Each light repeats a cycle of green, red, and yellow durations. - The task is to find the first time when every light is yellow. - Since cycles repeat, simulation only needs to continue through the least common multiple of all cycle lengths. - Because each duration is at most 20, a bounded simulation is also feasible. - Possible implementations include: - Updating each light’s state every second. - Precomputing states up to the termination time. - Checking directly whether time `t` lies in each light’s yellow interval. - If no simultaneous yellow period occurs within a full combined cycle, the answer does not exist. ## Problem 3: Maximizing the Number of Leaf Nodes - A split of degree `k` consumes one unit of distribution budget and increases the leaf count by `k - 1`. - Since split degrees are limited to 2 and 3, every path product has the form `2^p × 3^q` and must remain within `split_limit`. - Two structural properties simplify the optimization: - Partial splitting can be rearranged so it occurs at only one depth within a consecutive block of equal split degrees. - Blocks of degree-2 splits should be placed above degree-3 blocks because they use less budget for the same eventual frontier size. - Therefore, an optimal tree consists of: - Consecutive layers of 2-way splits. - Followed by consecutive layers of 3-way splits. - At most one partially split layer. - Enumerate feasible pairs `(i, j)` satisfying `2^i × 3^j ≤ split_limit`. - Fully process each layer while budget allows; at the first insufficient layer, perform as many partial splits as possible and calculate the resulting leaf count. ## Problem 4: Virus Pipes - The tree’s edges use one of three pipe types: A, B, or C. - Opening a pipe type infects every currently reachable organism through connected pipes of that type. - Infection is permanent, and reopening the same type consecutively has no effect. - For each possible pipe-opening sequence: - Start a DFS or BFS from all infected organisms. - Traverse only edges of the selected type. - Mark newly reached organisms as infected. - Exhaustive search is practical because the number of pipe openings is at most 10, yielding at most `3^10 = 59,049` sequences. ## Problem 5: Organizing Kakao Apps - Apps are represented by square blocks on a grid. - Pushing one app by one cell can push blocking apps in the same direction. - Apps leaving one edge wrap around to the opposite side, potentially causing further collisions. - Process each command by: - Using the initially pushed app as a BFS seed. - Finding all apps that must move together. - Moving them one cell simultaneously. - Treating clipped apps that cross the boundary as new seeds. - Repeating until no new seeds remain. - Blocks may be larger than one cell, so collisions can propagate across multiple rows and columns. - With grid dimensions and block sizes bounded by 10, direct simulation is sufficiently efficient and terminates because the state space is finite. Overall, the recommended approach is to model each problem according to its mechanics: sets for duplicate word handling, periodicity for traffic lights, structural exchange arguments for tree optimization, exhaustive DFS/BFS for pipe sequences, and layered BFS simulation for grid movement.

Read original(opens in new tab)
kakao5 min readCurated summary

2026 Kakao Group New Crew Open Recruitment Coding Test Round 2 Problem Explanations

The post explains solutions to five problems from Kakao’s 2026 new-employee second-round coding test. The problems require a range of techniques: exhaustive search, dynamic programming, monotonic deques, prefix sums with arithmetic-sequence jumps, and backtracking. The central lesson is to exploit each problem’s structural constraints rather than simulate large data directly. ## Problem 1: Hint Stage - Enumerate every combination of stages where hint bundles are purchased using a bitmask from `0` to `2^n - 1`. - For each combination: - Track the number of hint tickets available at every stage with a `cnt` array. - Add the cost of solving each stage while using as many available hints as possible. - Add the purchase price when a bundle is selected. - Update future `cnt` values when tickets are purchased. - Guard against integer overflow when the number of tickets exceeds `n`. - The full solution uses exhaustive search; some subtasks can be solved more simply when bundles cost zero or contain only one ticket. ## Problem 2: Treasure Hunt - Use interval dynamic programming to minimize the cost required to guarantee finding the treasure, regardless of which column contains it. - Define: - `cost[L][R]`: minimum guaranteed cost when the treasure is somewhere between columns `L` and `R`. - `pick[L][R]`: the column to excavate first for that interval. - If column `i` is excavated: - The cost is `depth[i]` if the treasure is there. - If it is to the left, the additional cost is `cost[L][i-1]`. - If it is to the right, the additional cost is `cost[i+1][R]`. - Therefore, the required cost for choosing `i` is: `max(depth[i], depth[i] + cost[L][i-1], depth[i] + cost[i+1][R])` - Choose the `i` minimizing this value and store it in `pick[L][R]`. - With at most 200 columns, the `O(w^3)` dynamic programming solution is sufficient. - Reconstruct the excavation strategy by repeatedly narrowing the interval according to the result of `excavate(pick[L][R])`. - Simply choosing the middle column, even with heuristic weighting, is not guaranteed to be optimal. ## Problem 3: Hiding the Cactus - Convert the rainfall order into a grid: - Assign each wet cell the index of the raindrop that first reaches it. - Assign `INF` to cells that never receive rain. - For a `w × h` subgrid, its first rainfall time is the minimum value inside it. - The goal is to maximize this minimum, preferring the uppermost and then leftmost subgrid in case of ties. - Compute two-dimensional window minima efficiently: - Apply a monotonic deque horizontally to obtain minimum values for width-`w` windows in every row. - Apply the same technique vertically to those results using height-`h` windows. - Each deque processes elements in amortized `O(1)` time, producing: - Time complexity: `O(mn)` - Additional space: `O(mn)` - This is necessary because the grid may contain up to `5 × 10^5` cells. ## Problem 4: Squared-Count Array - `brr` is formed by repeating each `arr[i]` exactly `arr[i]` times. For example, `[2, 1, 5]` becomes `[2, 2, 1, 5, 5, 5, 5, 5]`. - Since `brr` can have total length up to `10^15`, it must not be constructed explicitly. - Build: - A prefix sum of `arr` to locate which repeated-value segment contains a given index in `brr`. - A prefix sum of `arr[i]^2` to calculate sums across complete segments. ### Calculating `K` - Divide the requested range `[l, r]` into: - The remaining part of the segment containing `l`. - Complete segments in the middle. - The beginning part of the segment containing `r`. - Each part can be calculated in constant time after preprocessing. - If both endpoints belong to the same segment, calculate the result as value × length. ### Calculating `C` - Count fixed-length windows whose sum equals `K`. - Moving a window one position changes its sum by: `new right value - old left value` - While both endpoints remain in the same repeated-value segments, this difference is constant, so window sums form an arithmetic progression. - Jump directly to the next segment boundary instead of moving one position at a time. - Within each arithmetic-progression interval, determine the number of windows summing to `K` mathematically. - This reduces the overall computation to `O(N)`. ## Problem 5: Train Tracks - Because the grid is at most 20 cells in each dimension, backtracking can enumerate valid track placements. - Simulate the train from `(1, 1)` to `(n, m)`. - When encountering an empty cell, try every track type that is compatible with: - The direction from which the train arrived. - The direction in which it will leave. - The search state must include both the current position and the previous travel direction. - Prune immediately when: - The train moves into an obstacle. - The current track does not connect in the required direction. - Upon reaching `(n, m)`, verify that: - Every placed track has been traversed. - Track type 3 has been traversed once horizontally and once vertically. - Valid configurations are counted only after all these conditions are satisfied. The recommended approach is to match the algorithm to the data structure of each problem: enumerate only when constraints permit it, use interval DP for guaranteed search strategies, monotonic deques for sliding minima, mathematical jumps for enormous implicit arrays, and carefully designed backtracking for small but highly constrained grids.

Read original(opens in new tab)
cloudflare3 min readCurated summary

Translating risk insights into actionable protection: leveling up security posture with Cloudflare and Mastercard

Organizations are expanding their Internet-facing assets faster than they can inventory and secure them, leaving shadow domains, forgotten hosts, and vulnerable services exposed. Cloudflare and Mastercard plan to integrate RiskRecon attack surface intelligence into Cloudflare Security Insights to continuously discover these risks and recommend remediation. The integration is intended to shift security from periodic audits toward ongoing visibility and protection. ## Attack Surface Intelligence - Mastercard RiskRecon maps an organization’s public Internet footprint using outside-in, publicly available data. - It can identify shadow IT, forgotten subdomains, unauthorized cloud servers, exposed services, weak authentication, outdated software, and encryption problems. - A 2025 study of 15,896 breached organizations found that major posture gaps made companies: - 5.3 times more likely to experience ransomware. - 3.6 times more likely to suffer a data breach. ## Combining Discovery with Cloudflare Protection - RiskRecon identifies security gaps, while Cloudflare provides controls to address them. - Discovered assets can be routed through Cloudflare’s proxy without changing the underlying application or website. - In a sample covering approximately 388,000 organizations and 18 million systems, Cloudflare-proxied systems showed: - 53% fewer software vulnerabilities. - 58% fewer SSL/TLS issues. - 98% fewer instances of malicious behavior. ## Finding Shadow Domains and Unprotected Hosts - Cloudflare Security Insights already detects issues for domains that are proxied through Cloudflare, including DNS errors, weak encryption, and inactive WAF rules. - The Mastercard integration will extend visibility to domains and hosts that Cloudflare does not yet know about or protect. - RiskRecon continuously profiles organizations’ Internet footprints and identifies associated domains, hosts, and software stacks. - Assets will receive criticality ratings: - **High:** Sensitive-data systems, authenticated applications, databases, or remote-access services. - **Medium:** Brochure sites adjacent to high-criticality systems. - **Low:** Brochure sites with no proximity to critical systems. ## Turning Findings into Remediation - Security Insights is designed to recommend concrete fixes rather than only report vulnerabilities. - Suggested actions may include: - Enabling the Cloudflare proxy for discovered zones and hosts. - Activating WAF, DDoS, and bot protection. - Enforcing stronger TLS settings. - Applying controls such as API Shield or specific WAF rules. - Future plans include risk scoring and AI-assisted diagnosis that correlates findings with traffic and recommends targeted configurations. ## Availability - The planned integration is expected to enter preview in the third quarter of 2026 for Information Security practitioners on pay-as-you-go and Enterprise accounts. The partnership’s practical goal is to help organizations discover assets they did not know existed, prioritize the most dangerous exposures, and protect them through Cloudflare before attackers exploit them.

Read original(opens in new tab)
line4 min readCurated summary

Journey Toward Perfect AI Guardrails

NeurIPS 2025 research shows that AI safety is moving beyond simple post-training alignment and output filtering toward system-level, modular defenses. New approaches intervene in reasoning, multimodal interpretation, policy enforcement, and continuous evaluation to balance safety with latency and usefulness. The central conclusion is that deployable AI requires adaptable guardrails designed for real-world systems, not isolated attack benchmarks. ## The Shift Toward Practical AI Safety - Guardrails protect AI services from harmful instructions, privacy leaks, confidential-data exposure, bias, prompt injection, and other failures. - NeurIPS 2025 reflects a broader shift: - From post-training safety tuning to intervention in reasoning mechanisms. - From text-only LLMs to VLMs, RAG systems, and reasoning models. - From laboratory attack scenarios to the practical balance between utility and safety. - The article focuses on guardrail frameworks, multimodal moderation, prompt injection and jailbreaks, hallucinations, and over-refusal. ## Modular Guardrail Frameworks **PRIME Guardrails: A General, Low-Latency Safety Framework for Generative AI** addresses the trade-off between rigorous safety checks and response latency through a modular architecture: - **Policy specification:** Declarative, human-readable rules separate policies from model parameters, allowing legal or policy teams to control behavior. - **Risk sensing and scoring:** Asynchronous detectors combine lexical rules, semantic similarity, and lightweight classifiers. Early exit blocks obvious attacks quickly while allowing domain-specific calibration. - **Intervention router:** A deterministic controller chooses whether to allow, rewrite, or reject an interaction based on policies and risk scores. - **Monitoring and memory:** Lightweight records preserve decisions and rejection reasons for predictability and auditing. - **Evaluation and evolution:** Red-team recipes and automated vulnerability testing help the system adapt to new attack methods. The framework supports defense in depth without running every expensive safety mechanism sequentially. Its modularity, auditing capabilities, and continuous-evaluation loop make it suitable for production environments. ## Turning Governance Policies into Code **Policy-as-Prompt: Turning AI Governance Rules into Guardrails for AI Agents** converts informal organizational materials into runtime-enforceable controls. - The framework analyzes sources such as PRDs, technical design documents, regulations, and source code. - It builds a **source-linked policy tree** connecting individual rules to their original documents. - The policies are compiled into lightweight prompt-based classifiers. - When an agent rejects a request, the system can trace the decision back to its legal or organizational basis. - The approach helps enforce: - Least-privilege access. - Data minimization. - Restrictions on out-of-scope tasks. - Protection against prompt injection. - It may be especially valuable in regulated industries such as finance and healthcare, where frequently changing policies create substantial technical debt. ## Multimodal Safety and VLM Reasoning Vision-language models create new safety challenges because harmful meaning can emerge from interactions between images and text. **GuardReasoner-VL: Safeguarding VLMs via Reinforced Reasoning** trains models to reason about combined modalities rather than classifying each input independently. - It addresses cases where harmless text obscures harmful visual content, such as an image of a bloodied knife paired with “cooking.” - Its GRPO-based training process includes: - **Safety-aware data concatenation** to create difficult examples containing hidden or mixed harmful content. - **Dynamic clipping** that encourages exploration early in training and tighter refinement later. - **Length-aware safety rewards** that reward concise conclusions supported by reasoning. - The method aims to detect subtle harms such as hate speech hidden in memes and visual metaphors. ## Hidden Vulnerabilities in Multimodal Training Data **VLMs can Aggregate Scattered Training Patches** demonstrates that filtering training images may not be sufficient. - A harmful image can be divided into individually innocuous patches and included in training. - A VLM may reconstruct the harmful concept by associating patches that share the same text label. - The paper calls this behavior **visual stitching**, related to cross-sample reasoning and inductive out-of-context reasoning. - Text labels such as “safe” or “unsafe” can help the model connect fragmented visual information and infer the original image-level meaning. - This suggests that safety evaluations must inspect not only final outputs but also: - Input-processing pipelines. - Cross-sample interactions. - Internal or latent representations. The available article ends while introducing research on distorted safety perception, so that section cannot be summarized further from the provided text. In practice, organizations should combine modular, low-latency enforcement with traceable policy management and multimodal evaluations that test hidden interactions—not just obvious harmful prompts or images.

Read original(opens in new tab)