Why are Jeff Bezos, @elonmusk and Richard Branson so excited for space? They’ve fucked almost everyone on our planet and want one last shot at Uranus.

The sad thing about terror is that we remember the killers long after their victims are forgotten. - Stephen King
281
This is Xitter hole retweeted
Good piece from the NCSC on agentic defence The difficult part starts when the agent is allowed to actually change things in production. Scope, criticality, confidence and recoverability suddenly matter a lot more than “can the model understand the attack?” Worth a read ncsc.gov.uk/blogs/one-does-n…
6
52
241
17,741
This is Xitter hole retweeted
‼️ BREAKING: OpenAI was hacked by an Anthropic model. A HEIF photo uploaded to OpenAI's public support forum triggered a bug in the site's image decoder, led to code execution on the forum, and, through a second flaw in OpenAI's own login, ended with a pull request in OpenAI's internal GitHub. The forum runs Discourse, the off-the-shelf software behind countless community sites. Discourse was still shipping an old copy of libheif, the library that decodes iPhone-style photos. The bug in it had already been fixed upstream. But the fix was never labelled a security fix, so nobody treated it as urgent. Hacktron's researchers uploaded a HEIF image and got their own code running on community[.]openai[.]com. Then came the second bug, in OpenAI's own single sign-on, the "log in with OpenAI" button the forum uses. It turned that forum foothold into the actual ChatGPT and Codex accounts of people who had signed in there. OpenAI employees among them. And a ChatGPT account is no longer just a chatbot. Through Codex, users wire in Gmail, Outlook, Drive, Slack, GitHub. To prove the access was real, they used one employee account to have Codex open a harmless pull request in OpenAI's internal repo. They say they read no sensitive code. OpenAI patched the SSO flaw roughly 14 hours after the report and paid a $6,500 bug bounty. The team says Anthropic's Opus 4.8 found the libheif bug, and Opus 5 turned it into a working exploit. Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more were also vulnerable and compromised by the same team of researchers.
140
576
3,685
466,380
This is Xitter hole retweeted
👀If you deal with IPs for your work, you need to see this. It runs a IP search across over 20+ premium data sources, that all need paid subscriptions, and provides you the intelligence in under 1 second. For Free...
UserSearch v2.0.23 just went live 🚨 New : 🌐 IP Search — one IP address, 22 data sources, one search. First results in under a second. 🕵️ Is it hiding? — VPN, Tor exit, proxy & hosting flags, cross-checked across sources 🔓 Attack surface — open ports, services, technologies & CVEs, rolled up in one view 🔎 Insights — names, emails, phones, locations & tech, auto-organised. Click any to jump to the source 🤖 AI surface scan — thousands of data points, assessed in seconds 💸 Dynamic pricing — you choose the data sources, so a search can be virtually free 🎓 See it used for real — ex-NCA investigator Mark Bentley works a live case in "Inside an IP Investigation: An Expert's Playbook", Wed 7 Oct, 16:30 UTC Try it now & register for our latest Webinar 👇 us06web.zoom.us/webinar/regi…
2
10
912
This is Xitter hole retweeted
Посланикът ни в ОАЕ ще бъде отзован, тъй като е свързан с Пеевски и през фирма на баща му са минавали парите от поръчки за полетите на Пеевски. Чудесно, но кой назначи посланика? Служебният кабинет на Гълъб Донев предлага Иван Йорданов за посланик в ОАЕ през 2022 г. Радев, като президент, го назначава. Още тогава се знаеше, че Йорданов е човек на Пеевски. Беше консул в Дубай, известен със сагата с фурмите на верния на Пеевски министър Караниколов. А част от сделките, за които стана ясно вчера, са от 2020 г. Само че тогава врагът на Радев беше нашето правителство, свалено от ИТН с неговата благословия, така че нямаше проблем да се назначават хора на Пеевски. Посланикът в Дубай е само един пример, има и други. Ние може да сме правили компромиси, и да сме били наказвани за тях от избирателите, но тези компромиси са били с ясно дефинирани политически цели - Шенген, еврозона, съдебна реформа. Но с каква цел Радев и Донев назначаваха хора на Пеевски в служебните кабинети? Ако тези назначения не са били компромис с ясна политическа цел, то какво са били?
9
35
217
2,802
This is Xitter hole retweeted
I don’t think the AI doom messaging from OpenAI and Anthropic is really about safety at all I think the goal is to make themselves too important to fail: get regulated, raise the barriers for competitors, become “critical infrastructure” and make government support almost inevitable if their extremely capital-heavy financial models start to crack. I can’t prove that this is the motive. But the incentives line up remarkably well. “Our tech will transform the entire economy, but it’s also far too dangerous to leave unregulated” is a very convenient story when you need govs and investors to believe they simply cannot afford to let you fail.
18
32
161
9,823
This is Xitter hole retweeted
>sam altman: "we tried this because there were rumor on the internet" >rumor: math professor close to solving navier-stokes >the professor: using codex for a year >openai: has all his logs >checked every codex session tagged to N-S >found the most promising one >spun up 10,000 agents to finish the proof where he couldn't >they got caught >told the guy if you say anything you'll destroy your own career >he ruins his career over this >openai: "we did not see his work" >also openai: "we cannot rule out that de-identified data from their usage helped improve our models" they stole it lmao
732
12,578
91,377
3,983,601
This is Xitter hole retweeted
Replying to @hilbertspaess
103
1,335
16,447
863,226
This is Xitter hole retweeted
I resigned from Anthropic today. I spent the last three years doing pretraining research at both OpenAI and Anthropic. Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives. More thoughts below.
20,623
167,420
802,951
173,955,393
This is Xitter hole retweeted
Хазартът е епидемия, която се развива под бездействащия поглед на държавата. Градовете са пълни с реклами - билборди, знамена, фасади. Онлайн рекламата се лее отвсякъде. По време на световното имаше телевизионна реклама. А НАП пренаписа закона с едно неадекватно становище, което отвори вратите за злоупотреби широко. Затова внесохме изменения в Закона за хазарта, за пълна забрана на рекламата на хазарт - и външна реклама, и онлайн, и чрез директни съобщения, както и за затваряне на всички вратички в действащия закон. Незаконната реклама и незаконният хазарт трябва да бъдат гонени докрай, а контролните органи да повишат ефективността си.
21
15
209
2,601
This is Xitter hole retweeted
Did you ever need to run a Password Spraying attacks directly from your C2 beacon? Well, Sliver's armory BOFs are capable of helping with that. Learn how here: piped.video/MgotYfujDio
6
25
1,364
This is Xitter hole retweeted
The creator of the C++ programming language, Bjarne Stroustrup, says AI-generated code is not successful and calls the idea of using natural language as a programming language idiotic. He says humans will still write code and use abstraction. According to him, AI generates bloated code with more bugs and security holes, making it hard to validate. He also says the senior developers needed to validate it are starting to retire because they don’t want to deal with validating something that changes every time you change your prompt. He goes on to say that AI is not good at writing safety-critical or performance-critical code: “Now, let’s say that 70 or 80% of the world’s code doesn’t fit that pattern, but it’s that 10, 20% of the code that I’m interested in.”
755
1,361
8,974
1,158,128
This is Xitter hole retweeted
I stopped hiding shellcode in the pixels. The PNG spec has a quieter door. Ancillary chunks are skipped by decoders that do not know them. Pixels stay byte-identical. Pixel steganography is a puzzle. Format steganography is delivery.
5
23
182
6,471
This is Xitter hole retweeted
Your SMB stager leaves a registry key. WNetAddConnection2W with explicit creds writes HKCU\Network\<drive>, and it survives until WNetCancelConnection2W runs on the same path. Let the stager use the current user token and there is nothing left to clean up.
1
2
20
1,249
This is Xitter hole retweeted
I have to admit, impressive response time, one day patch wow... support.kaspersky.com/vulner…
12
37
676
58,774
This is Xitter hole retweeted
От 2021 г. предлагаме повишаване на прага за регистрация по ДДС на 166 000 лв. В резултат на това той беше поетапно вдигнат първо на 100 000, а след това на 166 000 лв. След това ГЕРБ и ДПС го свалиха на 100 000 лв, удряйки малкия бизнес. В този парламент внесохме отново повишаване 85 000 евро, а сега организираме петиция за подкрепа на по-високия праг. Това облекчава малкия бизнес и подпомага удържането на по-благоприятни цени. Можете да я подкрепите тук: peticiq.com/dds85000
3
10
74
2,068
This is Xitter hole retweeted
I've taken over enterprise networks in less than 60 seconds......
10 hours. That’s all it took for an AI-assisted TA to completely compromise an enterprise network. In less than 10 hours, the TA bypassed perimeter firewalls, exfiltrated Vault secrets, hijacked GitHub CI/CD pipelines, and backdoored active production K8S nodes. The TA also released a comprehensive 80-page technical report detailing its findings and remediation recommendations. unit42.paloaltonetworks.com/…
20
6
179
16,088
This is Xitter hole retweeted
Need to decode a ROT cipher? Use dCode to test different alphabet rotations and identify the original text: dcode.fr/rot-cipher
1
2
6
181
This is Xitter hole retweeted
‼️ BREAKING: Nightmare-Eclipse just released another zeroday, this time a proof-of-concept called FalconFlank, which claims a local privilege-escalation flaw in CrowdStrike Falcon — abusing the sensor's own malicious-Office-macro remediation to reach SYSTEM on fully updated Windows 11 25H2 and Server 2025. github.com/MSNightmare/Falco…
34
337
2,921
163,078
This is Xitter hole retweeted
lol I know it's your baby but I'm gonna have to hard disagree with that with a big caveat. apparmor is fantastic, for normies running normie distros that aren't technically inclined or simply don't do that work on that system. how does AA enforce policies inside of a postgres db? it doesn't, but selinux does through sepgsql. how does AA know that file that moved into the webroot is clear for hosting? it doesn't because it sees the path glob. httpd_t sees the label and stops it. you've also got labeled networking. AA basically operates on a "this profile can't do that network thingy". SECMARK smokes it with nftables tagging and peer labeling. then you've got things like x server and others. it's arguably the best possible tool for where it sits, protecting the normie which includes most of your end users. when you start having to handle infra and devs doing local dev work, it's not good enough. learn selinux.
1
1
2
14
This is Xitter hole retweeted
Днес Радев наговори големи небивалици за Европа и Русия. В едно изречение каза, че Европа не може да издържи срещу Русия, а две изречения преди това се жалваше, че Европа помагала на Украйна - вероятно затова Русия вече четири години и половина не може да завърши тридневната си военна операция. Реалността е друга - Русия, проваляйки се в конвенциалната война, се ориентира към саботажни и терористични действия. В Германия, в Полша. И в България: срещу оръжейни заводи. Въпросът е, при тази плахост на властта спрямо Русия и нейната отговорност за тези саботажни действия, българските служби готови да им противодействат? Ще има ли още взривове във военни заводи или ДАНС най-накрая ще си свърши работата? Или властта се надява, че като се снишава, ще ни се размине?
14
22
274
3,390