troublemaker & troubleshooter

0.0.0.0/24
threat actor = someone who wants to punch you in the face threat = the punch being thrown vulnerability = your inability to defend against the punch risk = the likelihood of getting punched in the face
78
558
1,796
The honorable Prof Richard Buckland dropping truth bombs... "Perfect security is like absiolute zero" 😙👌
2
3
186
"Maybe it's not as important to make the armor a little thicker as it is to realize that the cannons are on the horizon"
42
38
398
5,363
150,210
Welp, just spent the last 4 days using deepseek for some testing and I can see why there are so many bad reports in the triage queue. This is terrible LOL. Its claiming a write vulnerability with no actual proof. 17 findings and nothing worthy of reporting.
18
2
82
5,979
NO ROBOTS IN THE GYM
3
1
12
1,023
(shoutout to @danielmiessler)
1
190
Replying to @BSidesCbr
@BSidesCbr day 2 is underway
4
24
943
*loving* this talk by renaud from @synacktiv
1
127
cje retweeted
tl:dr; patch yo' shit. (and hope that's enough)
1
1
4
477
On one hand, this advisory simply calls out that AI is at a point where it can perform semi-autonomous vulnerability discovery and exploitation. For those on the coalface, this isn't new information. On the other hand: It's pretty big deal to see this coming from @asdgovau and @acsc. They're saying that yes, as industry, we should be paying attention to how the economics of attack are in the process of shifting, and that the risks are now real and imminent. Risks of AI misalignment to Australian organisations | Cyber.gov.au m.cje.io/47dOfOr
7
1
20
2,104
cje retweeted
The vulnpocalypse has enter the zeigiest, and the technical debt can no longer be ignored. 🫣 @caseyjohnellis shares his thoughts about what that means for the state of bug bounties and more in the latest episode of Offense Taken. piped.video/watch?v=MYLvQpXE…
6
15
2,766
cje retweeted
openai crawled a publicly accessible website and the country is freaking out? what?
65
42
811
52,402
cje retweeted
Starting to think oil is the new data
4
10
88
2,724
Unfortunately, the complexity of the hardware and firmware supply chain has the same negative effect on how cryptographic artifacts are managed, or mismanaged, across the ecosystem. This is a reminder of the scale of the problem, based on just one documented data breach.
⛓️Confirmed, Intel OEM private key leaked, causing an impact on the entire ecosystem. It appears that Intel BootGuard may not be effective on certain devices based on the 11th Tiger Lake, 12th Adler Lake, and 13th Raptor Lake. Our investigation is ongoing, stay tuned for updates.
3
16
68
9,933
cje retweeted
Defacing a target site showing all users that there is a vulnerability is an amazing way to ensure no company will want to work with you. Don’t do this.
Um...did @owasp just suffer a subdomain takeover or something worse? 👀😬
5
2
72
8,699
I earned $30,000 for my submission on @bugcrowd #ItTakesACrowd Thanks to @ThisIsDK999 & @_rajesh_ranjan_
43
21
690
38,447
I've amended my open mlx-lm PR to support this model: github.com/ml-explore/mlx-lm…
Introducing Xiaomi MiMo-V2.6 — Pro & Flash. Frontier intelligence, all the modalities, built in public. 🔹 Two omnimodal models, advancing through scaled reinforcement learning 🔹 Pro performs on par with Claude Opus 5 and GPT-5.6 Sol across most agent benchmarks 🔹 Pro scores 46 on the Artificial Analysis Intelligence Index — the highest among open-source models 🔹 Stronger coding, computer use, 3D reasoning and creative capabilities 🔹 Open model weights, technical report, RL environments and training code Blog:mimo.xiaomi.com/mimo-v2-6
1
2
21
4,003
cje retweeted
Does Jev live up to the hype? Based on the results of running it against our ScopeJudge benchmark, it does. @typesafeai's Jev was competitive with leading LLM judges, catching agent scope violations at pennies per thousand checks, with 130 millisecond responses on average. [1/4]
2
10
36
3,317
I've had a lot of conversations lately about LLM models, cyber security, and sovereignty. So I'm really excited about the news that we've started investing into sovereign security intelligence that can run inside the environment it protects.
Introducing Altar-1, our first open-weight security model. Frontier-grade defensive AI, built to deploy. Own your own security.
10
5
213
33,085