Blog

Thoughts on AI, the tech stack, and the indie hacker journey.

A Claude Session Found a 13-Year-Old RCE in Apache ActiveMQ — What That Means for Every Legacy Dependency You Ship

CVE-2026-34197 is an RCE in Apache ActiveMQ that's been sitting in the code since 2013. A security researcher found it during a casual Claude session. It's now on CISA's KEV list with a federal patch deadline of April 30. The real story for solo operators isn't "AI finds bugs." It's that the rate of newly-discovered legacy bugs is about to go up sharply.

Amazon Is Bricking 13 Kindle Models on May 20 — Here's Why Your SaaS Should Care

Amazon just announced that every Kindle shipped in 2012 or earlier loses Store access on May 20. Factory reset the device after that and it literally cannot be re-registered. It only affects ~3% of users — and that's exactly the point. If you're building a subscription product, this is the clearest case study in platform risk and graceful deprecation I've seen this year.

Uber Blew Through Its AI Budget in 3 Months — And Every Solo Dev Should Read the Fine Print

Uber spent $3.4B on R&D this year, encouraged every engineer to use Claude Code, and exhausted its planned AI budget before Q2. The cause isn't hype spend — it's Anthropic's hybrid "per-seat + pre-committed tokens" pricing. The same dynamics are biting solo devs. Here's what the Uber story actually teaches you about AI bills, and what to do about it before your next invoice.