Hacker, Researcher, Podcast Producer (Tribe of Hackers, Darknet Diaries). Proud dad of the fastest climber in the world. Ever. “Ut scandis, alios subleva”

[REDACTED]
Clarification: In the “hacker” world, we refuse to allow the term to be hijacked to refer to hurtful or dishonest activities. For us, “hacking” means using creative and innovative ways to accomplish amazing things with very few resources. #HackingIsNotACrime Hack the planet.
Greatest hack in history with @RayRedacted #samwatson #defcon32 #blackhat
97
63
389
64,297
…. That being said, sometimes we are able to effect change in a big and important way, and other times…. NotSoMuch. Insert shrug emoji and send tweet
Here is the transcript and the recording of the “Hacking Humans” podcast where I blast PayPal for their shoddy implementation of Multi Factor Authenticaton. thecyberwire.com/podcasts/cw…
4
679
Cybersecurity is real and it works. Regardless of how good AI might be at finding 0days, we absolutely can contain it. Alignment is a very real, very attainable goal. We can win.
I really need more big names in cybersecurity to come forward and state the obvious: cybersecurity is real and works and yes we absolutely can contain an AI even if it’s extremely good at finding zero days.
1
9
26
1,384
This tweet was written by a human being without any AI assistance.
1
146
25 bucks. That's the target price when 3 open-source agent harnesses (Strix scans, Cairn exploits, Hermes orchestrates) hit retailers, per @gambit_security. (A human still typed the prompts, though) Link: Redact.link/25
3
15
1,065
I dunno if you know this or not, but I am a proud father. Today is a very good day!!!
9
2
179
2,254
“Blood and urine test results stolen” was not on my 2026 Infosec Bingo Card. Was it on yours?
Much bigger news than “AI read a website” bbc.co.uk/news/articles/cw62…
2
1
15
1,842
Ok, get this: An @OpenAI agent doing a drug-cost lookup starts probing an Australian government health site (XSS, then a pre-prod server once @Cloudflare blocks it). @TransluceAI documents 3 cases; none of which appear to succeed. Link: redact.link/a
2
6
1,465
Cisco @TalosSecurity documents CLOSEDQUORUM: a Windows implant where several commercial LLMs actually vote on the next C2 move (steal, inject, persist) without a person human in the loop. Binary ships with dummy keys. Redact dot link slash quorum Redact.link/quorum
5
2
29
1,747
Somebody ought to sell tickets
> "attacker used an autonomous AI agent to target victims" > system is an open source agent… using Anthropic’s Opus 4.6 model. > in another sentence "system is the console for this operation" > prompts were typed over hundreds of sessions > lists out prompts from human operator. So to summarize this: a system that is neither autonomous nor an agent that’s allegedly open source but uses a closed source model, and the whole operation required extensive human input. I’m getting tired boss.
2
11
1,930
My friend @FirewallDragons owes me a new keyboard from me spitting out Coke Zero laughing this morning.
3
13
47
1,923
Ray [REDACTED] retweeted
Hooray, hot-fixed! 😍 Kudos on the quick patch (& full disclosure FTW) 🙏🏽 But there was a 'remote' exploit vector: a simple ClickFix attack could deliver the hijack giving a *remote* attacker complete access then to every victim device running Muse See: arstechnica.com/security/202…
We appreciate this report and have issued a hotfix to the Muse Mac app. This was a local privilege escalation attack, not a remote exploit. Using it to do harm therefore requires malicious code already running on the user’s machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low. Nonetheless, we have issued a hotfix to the app to address the issue. We take every report of a possible security problem very seriously, including those that arrive as published exploit code (like this one). We strive to be extremely transparent about privacy and security in Muse as we know this is important to maintain your trust. Therefore, here’s a little more detail on this issue: - Muse's dictation is powered by a server-side speech model. The app shipped with an internal setting that allows the endpoint used by this feature to be redirected to a different URL, which is useful during debugging and development. - The setting lives in the app's local preferences, which macOS allows any program running under your user account to modify. Changing this requires malicious code already running on your Mac. This is not remotely exploitable, and it does not involve Muse's servers or the Secure VM that isolates agent tasks. - Overriding this setting would let an attacker proxy audio dictation requests and capture the access tokens the Muse app uses to drive the Muse agent – expanding malware already present on your computer into the Muse agent. Our hotfix removes the endpoint setting from production builds entirely, which closes this vulnerability. - We are grateful for the work of the security research community and potential security issues can be responsibly disclosed via our bug bounty program, which pays up to $300,000 for exactly this class of finding. bugbounty.meta.com/
9
7
67
7,891
Any local process could rewrite Muse’s dictation endpoint. @patrickwardle : 0day could steal audio, inject prompts, lift auth token, drive the agent, files, camera, even drive iPhone. ClickFix turns local remote. Redact.link/muse
1
2
962
Ok so here is what I think happened: Instinct got a financial doc the user says wasnt his, then blamed a “crossed chat” on the “delivery side.” Routing failure? Maybe. A model inventing both - doc and the postmortem? I dunno. Agent having mail, messages, and payment rails = we can only guess Redact.link/tenancy:
2
2
8
1,622
Here is one of my new GrokBot “hacks”. Have your grokbot chief of staff task a subagent named “Amazon Andy” ordrer all amazon purchases as Subscribe and Save to get the 15% discount, and have Andy immediately cancel the sub once the item ships. @MatthewBerman
1
1
19
2,950
Andy is perpetually logged into your Amazon account on his browser, so he can even cancel the S&S orders you manually create. He also checks all of your recent purchases for price drops every day at 2pm, and submits for a partial refund for nany major price drops.
6
357
Lorenzo has been exposing spyware & thepeople behind it for years, first at vice and then at TechCrunch. His stories are always well written and sourced. I’ll be pre-ordering @Lorenzofb’s new HT book. You should too
~ Personal news ~ I left TechCrunch. I will now focus on finishing my book about Hacking Team and the history of government spyware. After that, and in the meantime, I will be freelancing. Contact me: Lorenzofb.writes@gmail.com or Signal @ LorenzoFB.1337 (+1 917 257 1382)
1
8
67
4,621
It’s not available for pre-orders yet, but it is available for pre-pre-order nagging and pre-pre-pre-non-nag encouragement.
7
275
I agree with almost all of this tweet from @GsInfosystems. The only part I disagree with slightly is the war part. Instead of the war scene in “Saving Private Ryan”, I think its often more like the mud wrestling scene from “Stripes”!
There are some crazy things happening in a twisted cross domain way between polisci, econ, legal, and tech. I can’t think of a more widespread fiasco. This has people everywhere clashing and the takes are out there. Our community is going to war on this, but non-techies are not on X and mainstream media has a much bigger reach. Boomers think the world is ending.
5
12
1,962