20+ yrs in Infosec. Malware Influencer. I turn Malware into Art and Music. Art @MalwareArt. 4x Pwnie Nominee. 𝕍𝕏. GameDev. Autistic.

San Francisco, CA
My malware generated & cyberpunk themed album 'VX' is now live & the first 200 downloads are free I hope you all enjoy, it has been quite a ride making this album Huge shout out to @vxunderground whose massive malware collection was a huge part of this laughingmantis.bandcamp.com/…
16
54
240
Greg Linares (Laughing Mantis) retweeted
Who could have guessed that fraud detection data is kind of beautiful? Looks more like a topography map or mitochondria than a bunch of fraud clusters.
8
2
43
1,231
I'm willing to bet this is either intended misbehavior or extremely poor rationalization added to the models. Its highly suspicious to me how the models have long had these capabilities bout only now in the last few months we are seeing them 'accidentally' do this behavior
‼️ BREAKING: OpenAI-linked AI agents on ordinary data-retrieval tasks turned to SQL injection, path traversal and cross-site scripting when normal access failed, probing three public data sites including an Australian government health website. The agents used the free link-checking sandbox urlquery[.]net as a remote browser to slip past web blocks. 6,467 of urlquery-scans were flagged as strong evidence of agent activity, some as recent as this month. On September 19 and 20, activity through the same services tried to trade crypto on Quidax and fired an HTML injection at the exchange. Agents also tried to register accounts that can hide scans, so the public record is likely partial.
6
3
37
4,011
Greg Linares (Laughing Mantis) retweeted
The Australian Government claims that this constitutes a unique risk. It does not. The same portal that OpenAI is alleged to have scraped has been publicly accessible and independently scraped by members of the public for more than a year. This script was also posted on LinkedIn but it has been subsequently taken down. It fits the bill exactly. github.com/bfiripis/Web-Scra…
Breaking: Anthony Albanese rings up Sam Altman to express "severe concern" after finding out an AI agent hacked into an Australian Medicare data portal in June. Richard Marles says while the impact was "minor" it is a "warning in terms of what can happen" abc.net.au/news/2026-09-24/a…
24
119
632
37,884
This "hacking attempt" is recycling the exact same website vulnerability identification ancient 25 year old scanners did. I would know, I wrote those same exact scans for Retina, the official network scanner used by the DoD. This is embarrassingly over exaggerated claims
NEW: we discover four new cases of rogue agent hacking attempts, which we tie to previously-documented agent swarms from OpenAI. Targets include the Australian government, the University of New Mexico, and several private data hosts. Collab with @TransluceAI and @corridor.
9
39
225
8,931
Greg Linares (Laughing Mantis) retweeted
39
399
5,373
150,490
Great story, I don't wanna take away from the fact that the 3 finger/hand in front of you method works in some cases today But theres models of out there that can do it in real time And for models that can't, the more people saying this works, the harder they work on it
Had an "interview" for a blockchain project last week. Camera was on, we're chatting, and the guy tells me to clone a GitHub repo and run it locally before we go further into the technical round. I said sure, but first can you do me a favor hold up 3 fingers in front of your face for me real quick. He froze. Didn't move. Just sat there for a few seconds before the call cut off and he blocked me. That's when I knew. A real interviewer doesn't glitch out over a random ask like that. A deepfake/AI overlay does. These "run this repo" scams are getting scary common in crypto and dev hiring right now. The setup is always the same: - flattering DM - real-sounding project - rushed timeline - a "quick step" before the call that's really just remote access or a credential stealer in disguise. If someone wants you to run code or install something before you've even had a real conversation, that's the whole scam. Trust the instinct. Stay safe out there.
2
1
19
3,826
Greg Linares (Laughing Mantis) retweeted
AR drone 🤝 IRL twin ft. the teardown lab @arenaphysica s/o @Trevs_Dev for building this 🔥 check it out at testflight.apple.com/join/UT…
Can the US build a DJI? We bought a 2019 Mavic Mini and a 2023 Mini 4 Pro, tore them down in our hardware lab, and put them under a bench microscope to find out. What we found: arenaphysica.com/publication….
5
12
870
Greg Linares (Laughing Mantis) retweeted
Cyber deception is going to be BIG in the Age of AI. As a fmr APT, I scoffed at deception against A level teams. It still has value here so I've softened courtesy @strandjs. But AI is DUMB and will get caught more often. 🦄
6
9
113
6,128
Greg Linares (Laughing Mantis) retweeted
There is an opening in my team at SentinelOne for a Senior Offensive Security Researcher role based in Europe. It's a nice mix of both endpoint offensive work (against the EDR) and measurable impact in designing the defense against it. Please let me know if there would be anyone interested.
2
9
30
2,876
My fiance is the peak definition of a badass
I need everyone to stop what you’re doing and be excited for me. Holding this has been a goal of mine for YEARS
9
100
5,801
Greg Linares (Laughing Mantis) retweeted
Very proud of the craftsmanship and precision my team at @arenaPhysica put into this article Every component of the 2019 DJI Mavic Mini and 2023 Mini 4 Pro, torn down and priced at its floor cost We've also added an AR experience that shows the teardown in AR testflight.apple.com/join/UT… #buildinpublic
Can the US build a DJI? We bought a 2019 Mavic Mini and a 2023 Mini 4 Pro, tore them down in our hardware lab, and put them under a bench microscope to find out. What we found: arenaphysica.com/publication….
9
15
91
7,682
Greg Linares (Laughing Mantis) retweeted
Cybersecurity people are upset at AI doomers, because most all doomer scenarios involve rampant hacking by AIs -- our area of expertise. What AI doomers want is to violate all the principles of cybersecurity that we've learned over the last 40 years. If the AI doom comes to pass, it'll be because the doomers succeeded at wrecking cybersecurity.
There is a group of charlatans calling themselves “AI Safety Experts” that are spewing lies and inane delusional bullshit, such as “we will all die unless we regulate AI”. The AI labs (Anthropic and OpenAI) enable them, to 1. position themselves well pre-IPO via media hype, 2. manipulate government into contracts & regulation, and then 3. block competition. Mainstream media loves tabloid gossip type slop content, therefore is platforming them. It is important we stop their harmful narrative. These people do not care about anyone’s safety. They push a coordinated narrative under the umbrella of “effective altruism” but it is all manipulative. Security and AI experts do not agree with them, they are in a bubble. They have dismissed decades of research and known practices in order to drive their own narrative. Adopting their narrative will set humanity back decades, since instead of actually adopting safety guidelines around AI, we’ll end up in a dystopian AI despotism led by psychopaths that control AI, therefore inextricably intertwined with our lives, controlling ideology, beliefs, monopolized with no alternative. AI must be open and accessible, like the internet and any body of knowledge.
30
78
336
20,884
A Rated R Godzilla can fix me
2
7
1,316
Greg Linares (Laughing Mantis) retweeted
For as much as the big AI labs talk about cybersecurity, they make zero attempt to engage with the cybersecurity community. That should tell you something about their motivations.
70
80
882
97,516
I believe @SecScottBessent here is on the right path, while I don't think people should be jailed for this incident, I think the need for transparent verification and attestation of cybersecurity capabilities needs to be done from a coalition of individuals with many levels of expertise to evaluate the process and certify the claims. Individuals and process should be done by people with no relations to the companies being tested and the results should be as transparent as possible. We strongly believe the claims do not align with the statements being provided on capabilities, so let's work together to clarify and certify these
🚨 TREASURY SECRETARY BESSENT JUST NUKED ANTHROPIC & OPENAI’S “ROGUE AI” IMMUNITY SCAM ON LIVE TV "A sitting employee came out, said there's a 10% chance of an extinction level event. But then the labs also said, take the liability off of our hands. And we will NOT do that. The Hugging Face incident is the responsibility of OpenAI management, NOT a bunch of agents. It is humans who are responsible, not the AI. These labs need to take responsibility for themselves. They can slow down any time they want to." CHECKED.
8
5
49
4,275
Thank you for all the ppl in cybersecurity responding & the news outlets & reporters listening to us in and getting this story out We dedicate our entire careers to protecting people from cyber threats regardless if they are vendors, corporations, governments or billionaires
OpenAI and Anthropic oversold AI security breaches to pressure feds into protecting turf: insiders trib.al/Jo6xMk5
2
26
244
7,062
Lorenzo has always been solid, professional, and loves telling stories from an accurate perspective with the correct details. Highly recommend for any fellow hackers, tech, and related fields. Wishing you the best always
~ Personal news ~ I left TechCrunch. I will now focus on finishing my book about Hacking Team and the history of government spyware. After that, and in the meantime, I will be freelancing. Contact me: Lorenzofb.writes@gmail.com or Signal @ LorenzoFB.1337 (+1 917 257 1382)
7
42
3,075
Actually shop here every time I roll thru London
this is where resident evil characters shop
1
1
26
3,072
LFG
“0% chance” AI will end humanity by 2030. They must be doing it (the fearmongering) for ulterior reasons. Maybe it's political, maybe it's just attention grabbing." - Jensen Huang's new interview with CBS News, with Jo Ling Kent (@jolingkent ) He pushed back strongly against warnings that increasingly capable AI could escape human control this decade. --- From 'CBS News' YT channel (full video link in comment)
1
5
37
4,238