Tracing Codex's 640TB-a-year SQLite writes
A developer created an eBPF-based tool called sqlite-trace to log SQLite queries from any binary, after a GitHub issue revealed OpenAI's Codex was writing 640TB of logs per year to SQLite. The tool wo…
A developer created an eBPF-based tool called sqlite-trace to log SQLite queries from any binary, after a GitHub issue revealed OpenAI's Codex was writing 640TB of logs per year to SQLite. The tool wo…
A developer demonstrates how eBPF can be used for observability in AI-generated services, providing a practical guide with Go and C. The article argues that eBPF is the future of observability due to …
Researchers introduced ActPlane, a programmable OS-level policy enforcement engine for AI agent harnesses that enforces safety and effectiveness policies in the OS kernel using eBPF. ActPlane improves…
A developer used eBPF with Go to debug a production issue in an AI-generated service where P95 latency spiked from 40ms to 4 seconds due to excessive kernel-level file I/O calls invisible to tradition…
Tigera announced Lynx, a unified control plane for Kubernetes-native AI agents, to address security challenges posed by autonomous, non-deterministic AI agents. Lynx authenticates, authorizes, mediate…
A malicious PyPI package named 'ColorLib' was discovered targeting developers with info-stealing malware that exfiltrates environment variables, cryptocurrency wallet details, and credentials. OWASP r…
A solo developer spent over three years building Ray Hosting, a topology-aware game server orchestrator from scratch. The system uses CPU cache alignment, eBPF/XDP-based DDoS protection, and live cont…
A developer outlines how to build a low-cost home Security Operations Center (SOC) using open-source tools and edge-first principles, leveraging efficient ARM processors and surplus enterprise gear. T…
Zeroserve, a new zero-configuration HTTPS server, serves entire websites from a single tarball over HTTP/2 and TLS 1.3 while allowing users to script request handling with eBPF programs that run as sa…
A GPU training pipeline at a major AI company breached its SLA despite showing 97% GPU utilization across all monitoring tools (Datadog, Grafana, nvidia-smi). Using eBPF kernel tracing, an SRE identif…
An eBPF agent that attaches to the CUDA runtime, CUDA driver, and Linux kernel scheduler simultaneously can trace a GPU stall back to the exact Python source line that triggered it. The tool correlate…
Here is a factual summary of the article: The article describes a system for detecting unusual server processes that learns what "normal" behavior looks like automatically, eliminating the need for m…
User-space security agents are structurally flawed because they share the same privilege level as the processes they monitor, allowing attackers with root access to simply kill the agent or erase logs…
Railway engineer Phin developed a feature called Network Flows, which uses eBPF to provide real-time visualization of traffic between services, eliminating the need for traditional tools like tcpdump.…