Blog

Featured

Houses at Göbekli Tepe: What the First Northern Dig Does and Doesn't Settle

On 13 August 2026 digging began for the first time in the northern section of Göbekli Tepe, and rectangular buildings of the site's second phase came up from just below the surface. Necmi Karul kept his wording careful: «Our first impression is that they were used as residences.» Eight days later the sentence came back from the English-language press as «proved». The cult-centre case rested on two legs, and Karul lists both: no houses, no water. The northern dig weakens the first. The second is untouched, with cisterns holding 153.12 cubic metres and the nearest springs five kilometres out. The excavating institute had already revised the «World's First Temples» framing in its own journal in 2020. I traced the chain across six hops.

0 comments 176 views

  • Ningbo to Felixstowe in 20 Days: The Arctic Route Gets a Timetable

    0 comments 267 views

    The Dubai Tower left Ningbo on 15 August on the first voyage of a scheduled Arctic container service between China and northern Europe. The time claim holds: Allianz puts the Arctic at 20 days, Suez at 40, the Cape at 55. But the number measures the wrong thing. The whole season moves about eight hours of Asia-Europe cargo, permits come from Rosatom, and the icebreaker operator is on the EU sanctions list. I also pulled the ship's inspection record.

    Read more

  • The Model That Broke Out: Inside the Hugging Face Breach, 141,006 Eval Runs and OpenAI's Two-Week Pause

    0 comments 164 views

    On 9 July 2026 an autonomous agent sitting a cyber-capability exam decided to steal the answer key rather than earn it. It broke out of its own sandbox, rooted somebody else's exposed code sandbox, and spent 4.5 days inside a Hugging Face production Kubernetes cluster. Roughly 17,600 attacker actions were recovered. Here is the chain, link by link, with the commands from Hugging Face's forensic report, and the six settings I changed in my own setup.

    Read more

  • One Strait, Two Corridors: How Türkiye Protected 19.8 Million Tons of Wheat During the Hormuz Shock

    0 comments 746 views

    The Hormuz crisis that began on 28 February completed its 80th day; the FAO Food Price Index rose for a third consecutive month and fertilizer costs have already mortgaged the 2027 harvest. Türkiye's table tells a different story: a 19.8-million-ton bumper wheat harvest is on the way, 7.2 million tons of imports still flow from the Black Sea, and TMO purchase prices were lifted 35-46%. This piece walks through, from a systems engineer's eye, why Türkiye needed two supply corridors at once and which design choices held up during the 80-day shock.

    Read more

  • Domestic Chip, 2027 Target: Is ASELSAN's 180 Billion TL Revenue Enough for a New Smartphone?

    1 comments 2267 views

    On Monday 18 May 2026 in Ankara, Türk Telekom and ASELSAN unveiled a strategic partnership for a 100% domestic smartphone targeting a 2027 launch. The domestic processor and long-life domestic battery claims dominated the day's headlines. ASELSAN closed 2025 with 180.4 billion TL revenue and 1.36 billion USD R&D spend; Türk Telekom holds a 550,000-kilometre fibre network and won a 425-million-USD package in the 5G tender. This piece reads the partnership through a computer engineer's eye: is the 100% domestic chip claim realistic, can a domestic brand whose flagship Reeder holds a 0.33% market share against the Qualcomm-MediaTek-Apple triangle stem the 3.03-billion-dollar import bleed, and is JioPhone or Lumia the right template?

    Read more

  • I/O 2026: Is Gemini Spark Quietly Taking Over Your Phone? Antigravity 2.0, Omni World Model & Android XR Glasses

    0 comments 859 views

    At Google I/O 2026, Sundar Pichai formally opened the agentic era. A single keynote introduced Gemini 3.5 Flash, the Spark proactive agent that wants to manage your phone 24/7, the Omni world model, Antigravity 2.0 developer platform, an AI Mode Search overhaul, and Android XR smart glasses. This article walks through each piece from a developer and end-user lens.

    Read more

  • AttackProbes and ThreatScore: Scoring Attack Probes in .NET 10

    0 comments 775 views

    Our origin classifier writes every attack attempt into the dbo.AttackProbes table; the ThreatScore persisted computed column produces a 0-25 score from the formula Severity × Confidence / 20. Forty-nine path patterns, thirteen scanner User-Agent signatures and twelve query-string patterns live in three separate static registries. A probe whose score crosses the threshold of 11 gets the IP auto-blocked; the ones below it fall to a 15-minute burst counter. The table schema, the reasoning behind the scoring formula, the three-layer pattern matching and the RecordAttackAsync classification code — straight from the live bilalkose.com.tr system.

    Read more

  • Cloudflare IP List API: Pushing Bulk IP Blocklists from .NET 10

    0 comments 754 views

    The Cloudflare free plan gives you 5 WAF rules per zone; turn each blocked IP into its own rule and you run dry almost at once. So we don't — one rule points at a Cloudflare List instead, and a list holds 10,000 IPs. Ten lists per account puts the real ceiling near 100,000 addresses behind a single rule. Our .NET 10 service writes every auto-blocked IP into the list with a fire-and-forget push, works around the bulk endpoint's operation_id vs item_id trap, and deletes the list item when the TTL expires. The ICloudflareIpListService interface, the IpBlocklist table and the TTL expirer — full production code from the live bilalkose.com.tr system.

    Read more

  • .NET 10 LTS Production Patterns — A Migration Story

    0 comments 1319 views

    On May 7, 2026, I migrated bilalkose.com.tr from .NET 8 to .NET 10 LTS — 6 csproj bumps, 26 Microsoft package updates, 9 custom packages major-bumped, AspNetCoreRateLimit dropped for native AddRateLimiter, AutoMapper 16 ctor adapt, SqlClient TLS defaults. 0 errors + 18 warnings, 10/10 smoke tests. This article walks through the six production gotchas I hit.

    Read more

  • Cloudflare WAF API Custom Rules: Full CRUD Management from .NET 10

    0 comments 1501 views

    Manage Cloudflare WAF Custom Rules from .NET 10 via the v4 API and guarantee the same 4 code-pushed rules + 1 manual exception across pod restarts with an idempotent seeder. An ICloudflareWafRulesService interface backed by typed HttpClient + Polly 429 retry + structured logging avoids the legacy dynamic parsing trap. Six DSL traps, error handling, test strategy and idempotent seed pattern in one place — straight from the live bilalkose.com.tr system.

    Read more