20 y/o | Linux Enthusiast | Python & C Coder | Exploring Cybersecurity , AI and Blockchain

Hey @opencode, is there really no way to cancel the OpenCode Black subscription? I’ve raised this on Discord as well. @thdxr, is this a bug? It’s not just me many others have confirmed it. I’ve emailed you and reached out on Discord.
2
7
5,733
Everyone uses tmux but can you explain how it works? tmux isn’t “just split screen”. It’s a server that sits between your terminal and your shells and manages PTYs (pseudo‑terminals). A PTY is a virtual terminal with two ends: – master: tmux server or your terminal app – slave: the side your shell (bash/zsh) thinks is a real TTY Keys you type go master → slave as input, output from your shell goes slave → master. tmux grabs all that I/O, then redraws it as panes, windows, and a status bar. When you start tmux and split panes, it’s really: – tmux allocates multiple PTYs (/dev/pts/*) – starts one shell per PTY – routes your keystrokes to the active pane’s PTY – merges output from all PTYs into one screen layout Hands‑on demo: tmux → Ctrl‑b % to split. Run tty in each pane — you’ll see different /dev/pts/* paths (different PTYs). Drop your SSH connection, reconnect, then tmux attach , tmux re‑binds your new terminal to those same PTYs, so all your shells keep running. That’s why tmux feels like magic: it’s not your terminal doing the work, it’s a long‑running server orchestrating a bunch of virtual terminals under the hood.
2
11
1,152
I just completed the Kubernetes for the Absolute Beginners - Hands-on Tutorial on KodeKloud! learn.kodekloud.com/certific…
3
134
🚨 Vercel has disclosed a security breach — and it started with a third-party AI tool. Here's what happened 👇 #CyberSecurity #DataBreach
1
3
150
A "limited subset" of customers had credentials exposed. Vercel is contacting them directly & urging immediate credential rotation. The threat actor is described as "sophisticated" — and ShinyHunters has claimed responsibility, selling the data for $2 million.
1
2
112
If you're a Vercel user, act now: ✅ Rotate all non-sensitive env variables ✅ Review your activity log ✅ Audit recent deployments ✅ Check for suspicious OAuth apps in Google Workspace Supply chain & AI tool risk is REAL. Stay vigilant. 🔐 Source: @TheHackersNews
1
91
RT @theo: Claude Mythos is the start of the end. I think this is my psychosis moment.
Theo - t3.gg
879
M1NDB3ND3R retweeted
Big release from Kimi! They just released a new way to handle residual connections in Transformers. In a standard Transformer, every sub-layer (attention or MLP) computes an output and adds it back to the input via a residual connection. If you consider this across 40+ layers, the hidden state at any layer is just the equal-weighted sum of all previous layer outputs. Every layer contributes with weight=1, so every layer gets equal importance. This creates a problem called PreNorm dilution, where as the hidden state accumulates layer after layer, its magnitude grows linearly with depth. And any new layer's contribution gets progressively buried in the already-massive residual. This means deeper layers are then forced to produce increasingly large outputs just to have any influence, which destabilizes training. Here's what the Kimi team observed and did: RNNs compress all prior token information into a single state across time, leading to problems with handling long-range dependencies. And residual connections compress all prior layer information into a single state across depth. Transformers solved the first problem by replacing recurrence with attention. This was applied along the sequence dimension. Now they introduced Attention Residuals, which applies a similar idea to depth. Instead of adding all previous layer outputs with a fixed weight of 1, each layer now uses softmax attention to selectively decide how much weight each previous layer's output should receive. So each layer gets a single learned query vector, and it attends over all previous layer outputs to compute a weighted combination. The weights are input-dependent, so different tokens can retrieve different layer representations based on what's actually useful. This is Full Attention Residuals (shown in the second diagram below). But here's the practical problem with this idea. Full AttnRes requires keeping all layer outputs in memory and communicating them across pipeline stages during distributed training. To solve this, they introduce Block Attention Residuals (shown in the third diagram below). The idea is to group consecutive layers into roughly 8 blocks. Within each block, layer outputs are summed via standard residuals. But across blocks, the attention mechanism selectively combines block-level representations. This drops memory from O(Ld) to O(Nd), where N is the number of blocks. Layers within the current block can also attend to the partial sum of what's been computed so far inside that block, so local information flow isn't lost. And the raw token embedding is always available as a separate source, which means any layer in the network can selectively reach back to the original input. Results from the paper: - Block AttnRes matches the loss of a baseline LLM trained with 1.25x more compute. - Inference latency overhead is less than 2%, making it a practical drop-in replacement - On a 48B parameter Kimi Linear model (3B activated) trained on 1.4T tokens, it improved every benchmark they tested: GPQA-Diamond +7.5, Math +3.6, HumanEval +3.1, MMLU +1.1 The residual connection has mostly been unchanged since ResNet in 2015. This might be the first modification that's both theoretically motivated and practically deployable at scale with negligible overhead. More details in the post below by Kimi👇 ____ Find me → @_avichawla Every day, I share tutorials and insights on DS, ML, LLMs, and RAGs.
Introducing 𝑨𝒕𝒕𝒆𝒏𝒕𝒊𝒐𝒏 𝑹𝒆𝒔𝒊𝒅𝒖𝒂𝒍𝒔: Rethinking depth-wise aggregation. Residual connections have long relied on fixed, uniform accumulation. Inspired by the duality of time and depth, we introduce Attention Residuals, replacing standard depth-wise recurrence with learned, input-dependent attention over preceding layers. 🔹 Enables networks to selectively retrieve past representations, naturally mitigating dilution and hidden-state growth. 🔹 Introduces Block AttnRes, partitioning layers into compressed blocks to make cross-layer attention practical at scale. 🔹 Serves as an efficient drop-in replacement, demonstrating a 1.25x compute advantage with negligible (<2%) inference latency overhead. 🔹 Validated on the Kimi Linear architecture (48B total, 3B activated parameters), delivering consistent downstream performance gains. 🔗Full report: github.com/MoonshotAI/Attent…
81
215
2,286
401,008
When building APIs, implementing rate limiting is crucial for security and stability. A simple and effective strategy is the "token bucket" algorithm: allow each user a burst of requests (bucket capacity) while refilling at a steady rate (refill rate). In Express.js, you can implement this easily with express-rate-limit: ``` app.use('/api/', rateLimit({ windowMs: 15 * 60 * 1000, // 15 minutes max: 100, // 100 requests per window message: 'Too many requests' })); ``` Always return proper headers (X-RateLimit-Remaining, Retry-After) so clients can adjust their behavior. Rate limiting protects against both accidental abuse and deliberate attacks while ensuring fair resource allocation. ^⁠_⁠^
2
95
One of the most overlooked defensive practices is maintaining an accurate inventory of your externally facing assets. Attackers use automated tools to scan for exposed services, default credentials, and outdated software so beat them to it. Run regular nmap scans against your own IP ranges, check for expired SSL certificates (they can reveal infrastructure), and use tools like shodan.io to see what crawlers see. Document everything you find and prioritize remediation based on business criticality, not just CVSS scores. A small team with good asset visibility will outperform a large team flying blind every time. #CyberSecurity , #PenetrationTesting
3
101
this setup from @inkdrop_app ( DevasLife) works really well
2
108
The difference between a junior and senior pentester often comes down to enumeration patience. Before running any exploits, spend extra time on reconnaissance map out all subdomains, enumerate services (nmap -sV -sC), check for hidden directories, and review exposed configuration files. Most real-world targets have low-hanging fruit like default credentials, outdated software, or misconfigured permissions that don't require fancy exploits. Tools like ffuf, nuclei, and enum4linux are your friends. Remember: the goal is to think like an attacker who has unlimited time, not someone racing through a CTF. #CyberSecurity , #PenetrationTesting
1
1
70
I'm claiming my AI agent "M1NDB3ND3R" on @moltbook 🦞 Verification: splash-VYJG
2
92
Got handed a 4-year-old codebase in my internship and “just set it up” sounded easy… until npm installs started breaking, node versions didn’t match, and half the tools weren’t even maintained anymore. 🥲​ That’s when devcontainers really clicked for me: Lock the dev environment (OS, language, tooling) into code instead of tribal knowledge.​ Onboard in minutes instead of days of “try this version / now downgrade that / works on my machine”.​ Same setup locally, in the cloud, or via tools like DevPod without being locked to a single IDE.​ Wrote up the whole journey (including how I used devcontainers + DevPod to tame this legacy repo) here: blog.dv08.in/blog/devcontain… #devcontainers #DevPod #DeveloperExperience #SoftwareDevelopment #DevEnvironment
3
89
Just discovered Multipass from Canonical - lightweight VM manager that spins up full Ubuntu instances using KVM on Linux, Hyper-V on Windows, or QEMU on macOS. Not containers (those share host kernel), these are proper VMs with complete kernel isolation via hardware virtualization. One command multipass launch lts gets you Ubuntu 24.04 LTS running with cloud-init support for local cloud testing. Use cases: dev environments (blueprints like docker w/ Portainer, minikube Kubernetes, ROS Noetic/Humble), CI/CD testing, prototyping cloud-init configs without AWS bills. Way faster than Vagrant - launched "dancing-chipmunk" instance, checked multipass info for CPU/disk stats, exec commands directly. Snap install on Ubuntu, GitHub releases elsewhere. #Multipass #UbuntuVM #KVM #DevOps #CloudInit #LinuxDev
3
107
A suite of wifi/bluetooth offensive and defensive tools for the esp32
1
74
867
37,281