The Dossier Doesn't Have a Publisher Traffic Story, So Here's What It Actually Says
The most recent dated item in the dossier is the VUSec Branch Target Reuse write-up, published on 29 September 2026, and it is a Spectre-v2 attack against JIT engines. It has nothing to do with search traffic, and neither does anything else in the twelve sources provided.

The topic query was search engine traffic publishers. The dossier does not contain a single source on that subject. What it does contain is twelve items published across 29 September 2026, covering CPU side channels, an economics replication workflow, inference routing, a MongoDB platform launch, local-first sync, and a poem about user interfaces. This piece explains what is actually there, and where the gaps are.
What the newest sources say
The freshest item in the dossier is VUSec's Branch Target Reuse project page, timestamped 29 September at 21:54 UTC. According to VUSec, BTR is a Spectre-v2 attack that abuses stale indirect branch prediction entries in just-in-time compilers. The researchers say they analysed Linux cBPF, Oracle GraalVM and SpiderMonkey, the JIT engine in Firefox, and built two end-to-end exploits against the Linux kernel. One leaks eight bytes per second. The team used it to walk the kernel task list and recover the root password hash from a running "su" process. They also say the attack bypasses the bpf_jit_harden constant-blinding option, which is off by default in Linux. A SpiderMonkey proof of concept was feasible on Intel CPUs, with an estimated leakage rate in the tens of bytes per second, though VUSec is explicit that turning it into a full browser exploit needs further work.
That is the news peg, and it is a security peg.
Four other sources landed within the same hour or two of each other on 29 September. MongoDB published its Atlas Agent Engine product page at 13:59 UTC and a companion blog post at 13:13 UTC announcing what it calls the largest expansion of its platform, including MongoDB 9.0, a deployment option called Atlas Infinite, and the Agent Engine itself, which the company says is in public preview. The same post carries a leadership disclosure: the author says the board asked him to step in as interim CEO following a leadership change, and that he previously led MongoDB for more than 11 years. Loro published a post by Zixuan Chen on 29 September, dated 21 September inside the text, arguing that CRDTs alone are not enough for a local-first sync engine. Unblocked published an engineering post on adaptive routing of LLM traffic across Baseten, Fireworks and CoreWeave, all serving GLM 5.2. And an NBER working paper by Matthew Schwartz, Isaiah Andrews and Jesse M. Shapiro, number 35782, describes an open-source LLM workflow that ran across 4,452 published replication packages from five economics journals and flagged discrepancies in 3,460 articles or their appendices.
Numbers worth keeping straight
The NBER paper is the densest source of figures, and its disclosure section is worth reading alongside the results. The authors state that LLMs were used in the analysis and writing of the article, and that Schwartz worked as a contractor for Anthropic during the project. The paper claims computation-time reductions of more than a factor of ten in 496 articles, and extensions in 923 articles. Those are large claims attached to a workflow that is itself partly LLM-generated, and the paper says so rather than hiding it.
Unblocked's post is the other source with production numbers. The company says it previously ran round-robin across Fireworks and Baseten. In the last full week on that setup, Fireworks served 51% of GLM 5.2 tasks and Baseten 49%, while Fireworks' prices were 25% higher and Baseten was faster. A fixed order with Baseten first pushed Baseten to 98.5% of tasks and Fireworks to 1.5%. CoreWeave's list prices are described as about 45% lower than Baseten's. Unblocked's scoring formula weights cost at 0.7 and speed at 0.3, and the post explains the consequence: a faster provider can only come first if it costs less than 1.75 times the cheapest. The company also admits its first circuit breaker counted 429 rate-limit responses as failures, pulling Baseten from the whole fleet after five in a minute.
- VUSec BTR: 8 bytes per second on the Linux kernel exploit, tens of bytes per second estimated for the SpiderMonkey proof of concept
- NBER 35782: 4,452 replication packages reviewed, 3,460 flagged, 496 speed-ups above 10x, 923 extensions
- Unblocked: 51/49 round-robin split, 98.5/1.5 under fixed order, 0.7/0.3 cost-speed weights
Background, clearly older
Several sources sit outside the 72-hour window. The VDE press release is dated 21 September, though the dossier lists it under a 29 September timestamp. Its figures are the most concrete in the set: more than half of international master's graduates, 55.5%, leave Germany after their studies, and that group is just over one-third, 35.5%, of all graduates. VDE also calculates that domestic students are about 7 percentage points more successful than their international peers, and that every euro invested in an international student returns roughly 16 euros in added value. Thomas Hegger of the VDE committee calls for more coaching, language support and transparent scholarship criteria.
The remaining sources are not news in any useful sense. IEEE Spectrum's contribution is a poem by Ralph Earle, a former IBM senior software engineer who retired in 2017 and has since published two poetry collections. A personal blog post from parksb, dated 28 September, traces the history of the term software engineer back to the 1968 NATO conference and Thomas Haigh's account of the ALGOL 68 debate. GitHub hosts a repository for OpenJev, described as an independent, Jev-compatible decision engine that reproduces an interface pattern but not TypeSafe's undisclosed model or training. Picnic's CTO Daniel Gebler tells an interview that the company is hiring because of AI rather than despite it, and that 25 million of its 50 million lines of code were written by analysts rather than engineers. And Pikuma walks through reverse-engineering the terrain maps in NovaLogic's 1992 Comanche, including the "Kyle DTA" signature at the top of each map file and the 1,048,576-byte grids underneath.
Where the coverage is missing
There is no publisher traffic story here. No source in the dossier reports on search referrals, AI Overviews, paywalls or audience decline. The recent headlines supplied for context mention a 40% year-on-year decline for publishers, a Cloudflare argument about bots and ads, and a Digiday recap on rebuilding for a post-search era, but those are explicitly marked as context and not as facts this piece can cite. Any article built from them would be inventing its sourcing.
What the dossier does support is narrower and more honest: a security disclosure, a database launch with a leadership change attached, an LLM research workflow with unusually frank disclosures, and a routing post with real production numbers. None of that answers the query, and saying so is more useful than pretending otherwise.
Sources
12- 01Branch Target Reuse: Spectre-v2 Attacks in JIT EnginesEN
- 02An LLM Workflow That Reproduces, Improves, and Extends Published Economics ResearchEN
- 03Routing LLM traffic across inference providers by cost, speed and reliabilityEN
- 04The Intelligent Data Platform for the AI EraEN
- 05The MongoDB Agent Platform | Atlas Agent EngineEN
- 06CRDTs are not enough: From CRDTs to a local-first sync engineEN
- 07VDE Figures: Electrical Engineering Programs Are Popular Internationally, But the Majority Leave Germany AgainEN
- 08Poetry for Engineers: The UI Designer's DreamEN
- 09What makes software development engineeringEN
- 10OpenJev: An open-source, Jev-compatible System One decision engineEN
- 11We Are Hiring Engineers Because of AI, Not Despite It: Inside Picnic's AI TransformationEN
- 12Reverse Engineering NovaLogic's Comanche Terrain MapsEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.