security engineer, ex-pentester videos @AstarteSecurity - meetup sprawl.nyc/

villa straylight
Here's a thread of every app I've built 100% with @cursor_ai using Claude. These are all fun side projects I've worked on in my free time over the last few months.
65
118
2,688
642,888
“First touchscreen Mac”
What to expect from the upcoming 'MacBook Ultra' based on the latest rumors 🔥
4
1
61
2,032
solst/ICE of Astarte retweeted
What is AppSec? what do AppSec engineers do all day? What’s a SAST and a DAST? What gives npm? And wow you look tired, are you doing okay? Getting enough sleep? And other questions your AppSec Engineer friends are answering, answered, again semgrep.dev/blog/2026/what-a…
2
15
1,539
solst/ICE of Astarte retweeted
Aren't they pretty in ENIG
33
136
2,092
32,869
Notice how with every hype cycle, it's the experts in the corresponding field who are questioning the validity and importance of overly exaggerated results by AI labs. A consistent pattern it seems.
I work in CRISPR discovery research. This is one of the most exaggerated nothing-burgers ever and would be laughed out of the room if a human scientist attempted to publish something like this. (cont.)
18
159
992
19,749
Your work computer has spyware and a remote access tool available to some frequently underqualified folks with questionable morals. I repeat this so often and some are still shocked. It is not your machine, avoid using it as much as you can.
Coworker today asked me if I use a separate chrome profile on my work computer for personal. My response: "My dude. My work computer goes in a faraday cage at the end of each day. There is no personal shit on there."
35
403
5,540
217,596
solst/ICE of Astarte retweeted
Replying to @IceSolst
every day more internet activity
1
3
564
Today's pace of the frontier was fast.
1
2
16
4,612
ShinyHunters compromised the FBI via an Oracle PeopleSoft exploit, and stole employee data. It’s not confirmed whether it was via a 0day (as they’ve claimed), or exploiting the known recent vulnerability below. They also claim to have pivoted to aws govcloud. It’s not confirmed if all the data was stolen solely from PeopleSoft, or from elsewhere. It’s also not clear how they defaced the recruitment site. It is not obvious to me how PeopleSoft would give you access to modify a website, so some lateral movement was likely. Defacement here was to send a message. They could have silently modified the site’s data and misled visitors, eg getting to sign up and collecting their data. But their motive was to demand the FBI “correct or simply REMOVE the 2026 Quarter 2 FLASH report on us that includes several FALSE allegations” Overall an interesting compromise, I’m a fan of defacement esp when they could have chosen to silently alter it instead. I respect the boldness. (Btw don’t compromise the fbi, im pretty sure it’s illegal, but I’m not a lawyer)
When CISA adds a vuln to KEV it starts a clock for government agencies to patch fast. It seems the FBI didn’t abide by that timeline on a known exploited CVSS 9.8 vuln.
26
46
322
22,661
ShinyHunters quote from the article below. The 404media article is gated behind a signup, shame on them
ShinyHunters says the FBI owes it a correction. Its alleged bargaining chip? Employee data. mashable.com/tech/shinyhunte…
2
19
1,767
This is what the defaced page looked like
ShinyHunters just defaced the FBI Jobs page
13
1,381
solst/ICE of Astarte retweeted
Cybersecurity people are upset at AI doomers, because most all doomer scenarios involve rampant hacking by AIs -- our area of expertise. What AI doomers want is to violate all the principles of cybersecurity that we've learned over the last 40 years. If the AI doom comes to pass, it'll be because the doomers succeeded at wrecking cybersecurity.
There is a group of charlatans calling themselves “AI Safety Experts” that are spewing lies and inane delusional bullshit, such as “we will all die unless we regulate AI”. The AI labs (Anthropic and OpenAI) enable them, to 1. position themselves well pre-IPO via media hype, 2. manipulate government into contracts & regulation, and then 3. block competition. Mainstream media loves tabloid gossip type slop content, therefore is platforming them. It is important we stop their harmful narrative. These people do not care about anyone’s safety. They push a coordinated narrative under the umbrella of “effective altruism” but it is all manipulative. Security and AI experts do not agree with them, they are in a bubble. They have dismissed decades of research and known practices in order to drive their own narrative. Adopting their narrative will set humanity back decades, since instead of actually adopting safety guidelines around AI, we’ll end up in a dystopian AI despotism led by psychopaths that control AI, therefore inextricably intertwined with our lives, controlling ideology, beliefs, monopolized with no alternative. AI must be open and accessible, like the internet and any body of knowledge.
30
78
336
20,881
solst/ICE of Astarte retweeted
They call me 007… I am very bad at Linux permissions
66
549
8,482
121,762
solst/ICE of Astarte retweeted
FBI hacked by ShinyHunters with Oracle 0 day
11
47
287
13,985
Replying to @thejazzestate
miles davis on thelonious monk
10
141
2,675
110,834
solst/ICE of Astarte retweeted
The world will go into mass psychosis believing in a machine god instead of investing in cybersecurity.
79
131
811
31,341
solst/ICE of Astarte retweeted
With all the focus around TypeSafe/Jev/System One lately- this research is super timely (or, before it's time because @noperator is very clever!). Also check out his Phrack article for complementary research. 🔥
Umbriel's Caleb Gross (@noperator) spoke at Blackhat this year ("Sift or get off the PoC: Applying information retrieval to vulnerability research"). The talk is now live! See it here: piped.video/watch?v=1ADD60wy…
1
3
14
2,905
Every time I hear about another vuln disclosure debacle/debate/disaster I feel like we should make a musical. It’s not that I don’t take this stuff seriously, I wouldn’t have built my career on defining & refining these processes if so. It’s that we keep hearing the same tunes

ALT Red haired woman with the caption “it’s happening again isn’t it?”

8
12
102
21,548
solst/ICE of Astarte retweeted
I made multiplayer Windows 98 Solitaire. It's called Solitaire Alone Together. You can play together, with the whole internet, but you can't chat or talk. solitairealonetogether.com
11
27
240
12,778
Aikido released an open weight security model. This is how you demonstrate you care about the security community. Make security accessible.
Replying to @madelinelawren
Altar-1 is an expert-pruned version of GLM-5.3, built for frontier-grade security workflows. It's already running on the Aikido Machine and found critical vulnerabilities in prod, on day 1. Built to run inside the environment it protects.
10
46
457
26,811