<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>lilting channel (English)</title><description>Notes on tech and daily life</description><link>https://lilting.ch/</link><language>en-us</language><item><title>JANIMA vs Hexer Minimal Toon (M1 Max): LoRA fidelity flips per character</title><link>https://lilting.ch/en/articles/janima-hexer-minimal-toon-kana-compare/</link><guid isPermaLink="true">https://lilting.ch/en/articles/janima-hexer-minimal-toon-kana-compare/</guid><description>Tested on M1 Max ComfyUI: newly free JANIMA vs Hexer Minimal Toon Anima V1 vs anima-base, one character LoRA, same seed. Hexer keeps the outfit; JANIMA adds clothes but draws the quietest backgrounds.</description><pubDate>Thu, 11 Jun 2026 15:00:00 GMT</pubDate><category>AI</category><category>Image Generation</category><category>ComfyUI</category><category>Anima</category><category>Anima-Base</category><category>LoRA</category><category>Apple Silicon</category><category>Experiment</category></item><item><title>Codex says Selected model is at capacity: try continuing</title><link>https://lilting.ch/en/articles/codex-selected-model-at-capacity-continue/</link><guid isPermaLink="true">https://lilting.ch/en/articles/codex-selected-model-at-capacity-continue/</guid><description>Codex showed Selected model is at capacity, but the same thread resumed after a continue prompt. Related issues point to serving pressure, not context length.</description><pubDate>Thu, 11 Jun 2026 06:56:09 GMT</pubDate><category>OpenAI</category><category>Codex</category><category>Troubleshooting</category><category>AI Agents</category><category>CLI</category></item><item><title>Microsoft 73-repo Miasma: AI agent startup, not npm install</title><link>https://lilting.ch/en/articles/microsoft-miasma-ai-agent-repo-stealer/</link><guid isPermaLink="true">https://lilting.ch/en/articles/microsoft-miasma-ai-agent-repo-stealer/</guid><description>GitHub disabled 73 Microsoft repos after an Azure/durabletask commit. Miasma used Claude Code, Gemini CLI, Cursor, and VS Code config, not npm install.</description><pubDate>Thu, 11 Jun 2026 04:24:35 GMT</pubDate><category>Security</category><category>npm</category><category>Supply Chain</category><category>Malware</category><category>Microsoft</category><category>AI Agents</category></item><item><title>LiteLLM CVE-2026-42271: MCP stdio test RCE, CISA KEV</title><link>https://lilting.ch/en/articles/litellm-cve-2026-42271-cisa-kev/</link><guid isPermaLink="true">https://lilting.ch/en/articles/litellm-cve-2026-42271-cisa-kev/</guid><description>LiteLLM 1.74.2-1.83.6 command execution via MCP stdio test endpoints is in CISA KEV. Patch to 1.83.7+ and Starlette 1.0.1+; BadHost can remove auth.</description><pubDate>Wed, 10 Jun 2026 10:03:57 GMT</pubDate><category>Security</category><category>CVE</category><category>RCE</category><category>CISA</category><category>MCP</category><category>LLM</category></item><item><title>Claude Fable 5 vs Opus 4.8, Sonnet 4.6, and Codex: tiny blog benchmark</title><link>https://lilting.ch/en/articles/claude-fable-opus-codex-blog-benchmark/</link><guid isPermaLink="true">https://lilting.ch/en/articles/claude-fable-opus-codex-blog-benchmark/</guid><description>Claude Code CLI vs Codex CLI on a 7-test static-blog fixture: runtimes, estimated Claude Code cost, and the semantic diff Codex used to pass.</description><pubDate>Wed, 10 Jun 2026 04:27:26 GMT</pubDate><category>Claude</category><category>Codex</category><category>AI Agents</category><category>Benchmark</category><category>Experiment</category></item><item><title>Laxhar&apos;s SenseNova U1 LoRA trainer: bf16 on 32GB GPU, ~20GB peak VRAM</title><link>https://lilting.ch/en/articles/sensenova-u1-lora-trainer-bf16-32gb-gpu/</link><guid isPermaLink="true">https://lilting.ch/en/articles/sensenova-u1-lora-trainer-bf16-32gb-gpu/</guid><description>Laxhar&apos;s U1 trainer needs 32GB+ GPU, bf16 only — 4bit broke gen tower. Prefix offload keeps ~20GB peak. 8-step LoRA stack, A3B MoE compat, official training code gap.</description><pubDate>Tue, 09 Jun 2026 06:23:29 GMT</pubDate><category>AI</category><category>Image Generation</category><category>LoRA</category><category>HuggingFace</category><category>MoE</category></item><item><title>AFM 3: 20B sparse on-device, Cloud Pro on Google Cloud, five model tiers</title><link>https://lilting.ch/en/articles/apple-foundation-models-3-google-pcc/</link><guid isPermaLink="true">https://lilting.ch/en/articles/apple-foundation-models-3-google-pcc/</guid><description>AFM 3 splits into 20B on-device sparse (NAND-to-DRAM weight loading) and Cloud Pro on Google Cloud NVIDIA GPU. Three Google contexts, Foundation Models API opening, and what&apos;s still unreleased.</description><pubDate>Tue, 09 Jun 2026 03:28:44 GMT</pubDate><category>AI</category><category>LLM</category><category>Apple Silicon</category><category>Google</category><category>Edge AI</category></item><item><title>LFM2.5 1.2B JP on M1 Max 64GB: 208 tok/s decode, JSON OK, name hallucinated</title><link>https://lilting.ch/en/articles/lfm25-12b-jp-local-test-plan/</link><guid isPermaLink="true">https://lilting.ch/en/articles/lfm25-12b-jp-local-test-plan/</guid><description>Tested LFM2.5-1.2B-JP-202606 on M1 Max 64GB. llama.cpp Q4_K_M: 208 tok/s decode, JSON intact, model name hallucinated (LFM→FDM). Q8_0: 157 tok/s, no hallucination. Tool calls broken via GGUF.</description><pubDate>Sun, 07 Jun 2026 16:20:00 GMT</pubDate><category>AI</category><category>LLM</category><category>Local LLM</category><category>MLX</category><category>Ollama</category><category>Apple Silicon</category><category>Edge AI</category><category>Experiment</category><category>Japanese LLM</category></item><item><title>Two-character LoRA without bleed or fusion: rank128 + 20 dual images on Anima</title><link>https://lilting.ch/en/articles/anima-keikana-dual-character-lora-v2/</link><guid isPermaLink="true">https://lilting.ch/en/articles/anima-keikana-dual-character-lora-v2/</guid><description>rank128 + 20 two-character images killed the v1 ahoge bleed and body fusion on this Anima dual-character LoRA. Lap-sit stays a Qwen3 text-encoder limit; sweet spot is ep140.</description><pubDate>Sun, 07 Jun 2026 15:00:00 GMT</pubDate><category>LoRA</category><category>AI</category><category>Image Generation</category><category>Anima</category><category>Anima-Base</category><category>RunPod</category><category>Qwen</category><category>ComfyUI</category><category>Experiment</category><category>Multi-character</category></item><item><title>Claude Code &apos;court&apos; bug: tool calls leak as text instead of running (Opus 4.8)</title><link>https://lilting.ch/en/articles/claude-code-court-tool-call-hang/</link><guid isPermaLink="true">https://lilting.ch/en/articles/claude-code-court-tool-call-hang/</guid><description>Claude Code sometimes emits a stray court token and raw &lt;invoke&gt; as plain text instead of running Read/Edit/Bash — a malformed tool call that never executes. How to tell it from a hung shell or a &apos;could not be parsed&apos; error, on long Opus 4.8 sessions.</description><pubDate>Sun, 07 Jun 2026 04:48:38 GMT</pubDate><category>Claude Code</category><category>Anthropic</category><category>Bug</category><category>Troubleshooting</category><category>AI Agents</category></item><item><title>Two characters, one Anima LoRA: hugs hold, lap-sit breaks (stack vs interleave)</title><link>https://lilting.ch/en/articles/anima-keikana-dual-character-lora/</link><guid isPermaLink="true">https://lilting.ch/en/articles/anima-keikana-dual-character-lora/</guid><description>One Anima (Qwen-Image DiT) LoRA, two characters, trained on RunPod: can they touch? Hugs and piggyback hold, lap-sit fuses; stacked limbs survive, interleaved break. Best at ep100, Turbo.</description><pubDate>Fri, 05 Jun 2026 16:54:03 GMT</pubDate><category>LoRA</category><category>AI</category><category>Image Generation</category><category>Anima</category><category>Anima-Base</category><category>RunPod</category><category>Qwen</category><category>ComfyUI</category><category>Experiment</category><category>Multi-character</category></item><item><title>CVE-2025-24964 lets a malicious web page reach RCE via Vitest&apos;s WebSocket API</title><link>https://lilting.ch/en/articles/vitest-api-websocket-rce-cve-2025-24964/</link><guid isPermaLink="true">https://lilting.ch/en/articles/vitest-api-websocket-rce-cve-2025-24964/</guid><description>Vitest&apos;s UI/api WebSocket skips Origin checks (CSWSH), so a malicious page can call saveTestFile and rerun to run code on your dev machine. Fixed in 1.6.1 / 2.1.9 / 3.0.5.</description><pubDate>Fri, 05 Jun 2026 16:16:24 GMT</pubDate><category>Security</category><category>Vite</category><category>JavaScript</category><category>Vulnerability</category><category>CVE</category><category>Node.js</category></item><item><title>In &apos;One Developer Is All You Need&apos; the speedup was wait time, not 4x AI coding</title><link>https://lilting.ch/en/articles/one-developer-ai-augmented-squad-brownfield-enterprise/</link><guid isPermaLink="true">https://lilting.ch/en/articles/one-developer-ai-augmented-squad-brownfield-enterprise/</guid><description>At Itaú, a staff engineer delivered a 4-person, 18-week project in 9 weeks with 4 AI agents — but it worked only because they knew the codebase deeply. What the case study really says about AI and team size.</description><pubDate>Fri, 05 Jun 2026 15:29:05 GMT</pubDate><category>AI</category><category>AI Agents</category><category>Developer Productivity</category><category>Research</category></item><item><title>Paper vs tablet manga fMRI study: tablet slowed integration-question RT</title><link>https://lilting.ch/en/articles/paper-manga-tablet-fmri-reading-load/</link><guid isPermaLink="true">https://lilting.ch/en/articles/paper-manga-tablet-fmri-reading-load/</guid><description>Sakai Lab fMRI study (N=25, U-Tokyo): reading a story&apos;s first half on a tablet stretched response time on integration questions and skipped the language-area savings paper produced. Full stats (F/p/q/r), plus the MangaFlow manga-generation AI as the drawing-side counterpart.</description><pubDate>Fri, 05 Jun 2026 04:17:24 GMT</pubDate><category>Research</category><category>Manga</category><category>Ebooks</category></item><item><title>CVE-2025-48595: Android Framework EoP, exploited, in CISA KEV (June 5 deadline)</title><link>https://lilting.ch/en/articles/android-framework-cve-2025-48595-exploited/</link><guid isPermaLink="true">https://lilting.ch/en/articles/android-framework-cve-2025-48595-exploited/</guid><description>Android 14–16/16-qpr2 patch CVE-2025-48595, a Framework integer-overflow EoP Google flags as under limited, targeted exploitation. In CISA KEV with a 2026-06-05 deadline. Includes the 06-01 vs 06-05 patch-level split.</description><pubDate>Fri, 05 Jun 2026 04:17:01 GMT</pubDate><category>Android</category><category>Security</category><category>CVE</category><category>Vulnerability</category></item><item><title>Request smuggling vs request splitting in Spring Boot: what to check for each</title><link>https://lilting.ch/en/articles/spring-boot-request-smuggling-splitting/</link><guid isPermaLink="true">https://lilting.ch/en/articles/spring-boot-request-smuggling-splitting/</guid><description>Two CRLF-adjacent bugs, two different checks. Smuggling is a proxy↔Tomcat HTTP/1.1 framing mismatch (tomcat-embed-core version, CVE-2026-24880); splitting is CRLF in sendRedirect/setHeader/RestTemplate. With a grep checklist.</description><pubDate>Fri, 05 Jun 2026 04:16:22 GMT</pubDate><category>Security</category><category>Spring</category><category>Java</category><category>Vulnerability</category></item><item><title>Hexer Minimal Toon Anima V1 vs Illustrious v3.1: base, folders, and license</title><link>https://lilting.ch/en/articles/hexer-minimal-toon-anima-illustrious/</link><guid isPermaLink="true">https://lilting.ch/en/articles/hexer-minimal-toon-anima-illustrious/</guid><description>Hexer Minimal Toon&apos;s new Anima V1 is a DiT checkpoint, not an SDXL one: 4.1GB bf16, separate VAE/text-encoder ComfyUI folders, Anima-only LoRA, and a non-commercial license the Civitai page doesn&apos;t show. What changes vs Illustrious v3.1 before you load it.</description><pubDate>Fri, 05 Jun 2026 04:15:38 GMT</pubDate><category>AI</category><category>Image Generation</category><category>ComfyUI</category><category>Stable Diffusion</category><category>LoRA</category><category>Anima</category><category>Illustrious</category></item><item><title>Character LoRA won&apos;t stand straight on Anima-Base: cut posed data, don&apos;t add it</title><link>https://lilting.ch/en/articles/anima-base-keichan-lora-v4/</link><guid isPermaLink="true">https://lilting.ch/en/articles/anima-base-keichan-lora-v4/</guid><description>On Anima-Base, my character LoRA bent its legs even on standing. Adding upright references didn&apos;t fix it; cutting 36 posed full-body images did. Subtract, don&apos;t add.</description><pubDate>Fri, 05 Jun 2026 03:00:00 GMT</pubDate><category>LoRA</category><category>AI</category><category>Image Generation</category><category>Anima</category><category>Anima-Base</category><category>RunPod</category><category>Qwen</category><category>ComfyUI</category><category>Experiment</category></item><item><title>HTTP/2 Bomb: 5,700x Envoy, 4,000x Apache amplification via HPACK + flow control</title><link>https://lilting.ch/en/articles/http2-bomb-hpack-flow-control-dos/</link><guid isPermaLink="true">https://lilting.ch/en/articles/http2-bomb-hpack-flow-control-dos/</guid><description>100Mbps to 32GB via HPACK + flow control stall. Envoy 5,700:1, Apache 4,000:1. Patch status: nginx 1.29.8, mod_h2 v2.0.41, Envoy 1.35–1.38, IIS/Pingora unpatched.</description><pubDate>Thu, 04 Jun 2026 06:36:25 GMT</pubDate><category>Security</category><category>CVE</category><category>nginx</category><category>Apache</category><category>Vulnerability</category></item><item><title>Gemma 4 12B Unified: 35M linear projection replaces 150M 16-layer Vision Encoder</title><link>https://lilting.ch/en/articles/gemma-4-12b-unified-encoder-free/</link><guid isPermaLink="true">https://lilting.ch/en/articles/gemma-4-12b-unified-encoder-free/</guid><description>35M linear projection replaces E4B&apos;s 150M 16-layer Vision Encoder. Bidirectional attention in the 48-layer LLM absorbs patch features. Comparison with Fuyu, EVE, EVEv2, and Mono-InternVL.</description><pubDate>Thu, 04 Jun 2026 04:44:51 GMT</pubDate><category>AI</category><category>LLM</category><category>Google</category><category>Gemma</category><category>Multimodal</category><category>Local LLM</category></item><item><title>Character LoRA on Anima-Base vs WAI-Anima: face fidelity up, intakes capped</title><link>https://lilting.ch/en/articles/anima-base-keichan-lora-v2/</link><guid isPermaLink="true">https://lilting.ch/en/articles/anima-base-keichan-lora-v2/</guid><description>Rebaked a WAI-Anima character LoRA onto upstream Anima-Base with off-distribution Gemini data. Trigger-only usable, face fidelity beats v1, intakes still cap out.</description><pubDate>Wed, 03 Jun 2026 04:00:00 GMT</pubDate><category>LoRA</category><category>AI</category><category>Image Generation</category><category>Anima</category><category>Anima-Base</category><category>RunPod</category><category>Qwen</category><category>ComfyUI</category><category>Experiment</category></item><item><title>One LoRA on 6 Anima derivatives (M1 Max): trigger-only unstable, RDBT runs wild</title><link>https://lilting.ch/en/articles/anima-derivatives-character-lora-portability/</link><guid isPermaLink="true">https://lilting.ch/en/articles/anima-derivatives-character-lora-portability/</guid><description>Tested on M1 Max 64GB ComfyUI: one character LoRA across 6 Anima derivatives, same prompt/seed. Trigger-only never stabilizes, RDBT bolts to beast-ears, structure tags fix it.</description><pubDate>Tue, 02 Jun 2026 04:14:51 GMT</pubDate><category>AI</category><category>Image Generation</category><category>ComfyUI</category><category>Anima</category><category>WAI-Anima</category><category>LoRA</category><category>Qwen</category><category>Apple Silicon</category><category>Experiment</category></item><item><title>Anima checkpoints: 20+ derivatives sorted by type and style, one LoRA fits all</title><link>https://lilting.ch/en/articles/anima-derivative-checkpoints/</link><guid isPermaLink="true">https://lilting.ch/en/articles/anima-derivative-checkpoints/</guid><description>Anima is a Cosmos-based DiT, not SDXL, so one Anima LoRA loads on every derivative checkpoint. 20+ CivitAI Anima models sorted by type, aesthetic, and prompt adherence.</description><pubDate>Mon, 01 Jun 2026 10:13:23 GMT</pubDate><category>AI</category><category>Image Generation</category><category>ComfyUI</category><category>Qwen</category><category>Stable Diffusion</category><category>LoRA</category><category>Anima</category><category>WAI-Anima</category></item><item><title>TrapDoor: Rust build.rs, npm postinstall &amp; PyPI imports steal crypto dev keys</title><link>https://lilting.ch/en/articles/trapdoor-solana-sui-aptos-developer-packages/</link><guid isPermaLink="true">https://lilting.ch/en/articles/trapdoor-solana-sui-aptos-developer-packages/</guid><description>TrapDoor planted 34 packages across npm, PyPI and Crates.io to steal Solana/Sui/Aptos wallet keys. Each registry fires differently: postinstall, import-time, and Rust build.rs.</description><pubDate>Sun, 31 May 2026 07:12:35 GMT</pubDate><category>Security</category><category>npm</category><category>PyPI</category><category>Rust</category><category>Supply Chain</category><category>Malware</category><category>AI Agents</category></item><item><title>SpaceX&apos;s $4.16B Golden Dome deal: SB-AMTI sensor satellites, not interceptors</title><link>https://lilting.ch/en/articles/spacex-golden-dome-sbamti-satellites/</link><guid isPermaLink="true">https://lilting.ch/en/articles/spacex-golden-dome-sbamti-satellites/</guid><description>SpaceX&apos;s $4.16B SB-AMTI award is a sensor layer for tracking airborne moving targets, not interceptors. AMTI vs GMTI, the SDN Backbone deal days earlier, and how Japan&apos;s defense constellation compares.</description><pubDate>Sat, 30 May 2026 13:18:05 GMT</pubDate><category>Space</category><category>Security</category><category>Military</category></item><item><title>Microsoft Defender RedSun &amp; UnDefend: actively exploited CVEs now in CISA KEV</title><link>https://lilting.ch/en/articles/microsoft-defender-redsun-undefend-cve-kev/</link><guid isPermaLink="true">https://lilting.ch/en/articles/microsoft-defender-redsun-undefend-cve-kev/</guid><description>RedSun (CVE-2026-41091) and UnDefend (CVE-2026-45498) are confirmed exploited and in CISA KEV. A patched Windows isn&apos;t enough: how to check your Defender engine 1.1.26040.8 / platform 4.18.26040.7.</description><pubDate>Sat, 30 May 2026 13:17:54 GMT</pubDate><category>Security</category><category>Microsoft</category><category>Windows</category><category>Vulnerability</category><category>CVE</category><category>CISA</category><category>KEV</category></item><item><title>VS Code Remote-SSH: a compromised host can run commands on your local terminal</title><link>https://lilting.ch/en/articles/vscode-remote-ssh-local-terminal-rce/</link><guid isPermaLink="true">https://lilting.ch/en/articles/vscode-remote-ssh-local-terminal-rce/</guid><description>Calif&apos;s Vibe Hacking: a compromised SSH host runs commands on your local terminal via VS Code/Cursor Remote-SSH. No CVE — Microsoft calls it by design. How to check and isolate instead.</description><pubDate>Fri, 29 May 2026 11:24:36 GMT</pubDate><category>Security</category><category>VS Code</category><category>Cursor</category><category>AI Coding</category><category>AI Agents</category></item><item><title>Two Anima LoRAs in one image: side-by-side works, overlap breaks the design</title><link>https://lilting.ch/en/articles/anima-two-oc-lora-one-image-qwen-edit/</link><guid isPermaLink="true">https://lilting.ch/en/articles/anima-two-oc-lora-one-image-qwen-edit/</guid><description>Tested on M1 Max ComfyUI: two WAI-Anima character LoRAs in one image. Side-by-side works, but only non-overlapping inpaint keeps the design pixel-exact; Qwen-Image-Edit elongates the side ponytail even with training tags, and overlapping interaction poses jam at skeleton extraction.</description><pubDate>Thu, 28 May 2026 16:01:25 GMT</pubDate><category>LoRA</category><category>AI</category><category>Image Generation</category><category>Anima</category><category>WAI-Anima</category><category>ComfyUI</category><category>Qwen</category><category>Experiment</category></item><item><title>KnowledgeDeliver CVE-2026-5426: shared machineKey, ViewState RCE, Cobalt Strike</title><link>https://lilting.ch/en/articles/knowledgedeliver-viewstate-godzilla-cobalt-strike/</link><guid isPermaLink="true">https://lilting.ch/en/articles/knowledgedeliver-viewstate-godzilla-cobalt-strike/</guid><description>CVE-2026-5426 zero-day: KnowledgeDeliver&apos;s shared ASP.NET machineKey → ViewState RCE → Godzilla in memory → Cobalt Strike via JS tampering. Hunting starts at Event ID 1316.</description><pubDate>Thu, 28 May 2026 04:30:41 GMT</pubDate><category>Security</category><category>CVE</category><category>Vulnerability</category><category>RCE</category><category>Malware</category><category>Zero-Day</category></item><item><title>WAI-Anima LoRA trained on its own generations: ep20 sweet spot, 7.5x faster</title><link>https://lilting.ch/en/articles/wai-anima-keichan-lora-training/</link><guid isPermaLink="true">https://lilting.ch/en/articles/wai-anima-keichan-lora-training/</guid><description>WAI-Anima LoRA trained only on images the model itself made. Distribution shift drops to ~zero, so the sweet spot hits epoch 20 not 150 (7.5x faster). What the trigger bakes in vs what still needs tags, plus pose/angle control.</description><pubDate>Wed, 27 May 2026 14:50:00 GMT</pubDate><category>LoRA</category><category>AI</category><category>Image Generation</category><category>Anima</category><category>WAI-Anima</category><category>RunPod</category><category>Qwen</category><category>Experiment</category></item></channel></rss>