Blog

Thoughts on AI, the tech stack, and the indie hacker journey.

A Claude Session Found a 13-Year-Old RCE in Apache ActiveMQ — What That Means for Every Legacy Dependency You Ship

CVE-2026-34197 is an RCE in Apache ActiveMQ that's been sitting in the code since 2013. A security researcher found it during a casual Claude session. It's now on CISA's KEV list with a federal patch deadline of April 30. The real story for solo operators isn't "AI finds bugs." It's that the rate of newly-discovered legacy bugs is about to go up sharply.

Amazon Is Bricking 13 Kindle Models on May 20 — Here's Why Your SaaS Should Care

Amazon just announced that every Kindle shipped in 2012 or earlier loses Store access on May 20. Factory reset the device after that and it literally cannot be re-registered. It only affects ~3% of users — and that's exactly the point. If you're building a subscription product, this is the clearest case study in platform risk and graceful deprecation I've seen this year.