@devploit

Head of Security @Magnific · Security researcher Breaking things to understand them. Securing things for a living. https://nitter.cf/t.co/CHFZzyZSN2

Málaga, Spain
Joined April 2016
working in cybersecurity nowadays: > wake up > read "new critical vuln just dropped" > summon dev and SRE in the incident channel > patch, scan, rotate secrets, redeploy > check logs to make sure you are not already cooked > take a deep breath and go to sleep > wake up > read "new critical vuln just dropped"... WELCOME TO THE AI ERA
Introducing nginx-poolslip, a fresh RCE for the the latest nginx release 1.31.0. nginx-rift has been patched, but our security agent Vega has found a new 0 day. We will release the full technical writeup with ASLR bypass 30 days after the patch on nebusec.ai.
21
211
9
2,348
160,503
🚨Cyber Alert ‼️ 🇪🇸Spain - 𝗝𝘂𝗻𝘁𝗮 𝗱𝗲 𝗔𝗻𝗱𝗮𝗹𝘂𝗰í𝗮 Meduza Locker hacking group claims to have breached Junta de Andalucía. According to the threat actor, the compromised data includes client, confidential, financial, HR, legal, marketing and technical data. Threat actor: Meduza Locker Sector: Gov / Mil / LE Data exposure (claimed): Not specified Data type: Client, confidential, financial, HR, legal, marketing and technical data, and reports Observed: Sep 28, 2026 Status: Pending verification ESIX©: 5.58 Full details and impact assessment on HackRisk.io
1
222
With Opus 5.5, it looks like I'll finally be able to remove "don't use em-dashes" from CLAUDE.md instructions.
2
139
Daniel Púa retweeted
This finding takes 10 seconds to spot and can pay out hundreds of dollars. An exposed Google Gemini API key. Used to be "informative, no impact." Not anymore. The reason: that same key can run Gemini prompts on someone else's bill. It's not just exposed data anymore. It's free AI spend for whoever finds it. Programs are paying for that now.
4
1
46
3,085
My timeline nowadays: - AI - Security - World of Warcraft X knows what I like.
4
234
Daniel Púa retweeted
If anybody in the office sees this, we might get in trouble We asked Opus 5.5 to apply the same effect to people's pictures on Slack. Even the CEO was a victim of this Our exact prompt so you can recreate it is below
16
20
4
185
19,689
Okay, I need to stop being rude to Claude when it doesn't listen to me...
JUST IN: Anthropic researcher Joe Carlsmith says there are scenarios where AI would be “justified in going rogue” against humans if the systems were being mistreated or oppressed.
207
0 days since the last "OpenAI dev shows you the RIGHT way to use a coding harness" thread. it's always 0 days.
1
2
182
We've hit the point in AI where it's genuinely hard to tell if something's actually good, or if it's just FOMO doing the talking.
1
1
168
Innovation vs Regulation in one image.
Some data we recently assembled on entrepreneurship/compute in Europe: eudata.vercel.app. We hope that one of the useful roles that Stripe can play is in collecting and publishing empirical data pertaining to entrepreneurship and industry in Europe. There's growing appetite to get Europe on a better footing, and cross-sectional comparisons can often shine light on where opportunities lie. If you're interested in this kind of thing, we publish more at stripeeconomics.substack.com.
3
3
476
Every time a new AI model drops I see the same 3 jokes: - Anthropic job posting: “why aren't they using Claude X.X for this?” - “Just built a million dollar app in 30 min, thoughts? url: localhost:8080” - “RIP devs, it was fun while it lasted” We might be more productive but we sure aren't getting more original lol
3
2
311
"I don't know how you sit in front of a screen 8 hours a day" If only he knew it's not 8. Work plus hobby, it's 14 minimum and I don't even notice lol
3
167
Right diagnosis. The cure nobody wants to hear: your bottleneck isn't AI budget, it's your approval chain. At @magnific there's nothing between finding a bug and killing it. How many layers are there in yours?
224
CVSS 9.5, network vector, zero auth, zero interaction. And it's sitting inside a feature nobody audits because "it just generates the share image". These are the features people usually say don't need to be audited.
Another day, another RCE in Next.js github.com/vercel/next.js/se…
229
bueno, pues ya estamos todos
🤔¿Eres de la IA o eres de ay ay ay...? 👉Encuentra respuestas a la situación actual en este vídeo de nuestro director general #IA #IAsegura #IAresponsable
10
9
65
7,074
Anthropic and OpenAI both dropped their latest models on the same day, so I put them in a chess battle. Opus 5.5 vs GPT-6 Sol. Who do you think won?
1
2
1
6
818
The rules: > Same prompt for both, fresh each move (board, move history, legal moves). > Effort set to low to avoid overthinking. > 50 games, each model White in 25. > 3 illegal answers in one turn = loss. Here are the stats from the matchup.
1
1
169
Looks like @DarioAmodei takes the crown this time. nitter.cf/devploit/status/210250…
Anthropic and OpenAI both dropped their latest models on the same day, so I put them in a chess battle. Opus 5.5 vs GPT-6 Sol. Who do you think won?
101
We went from videogame speedrunners to system prompt speedrunners.
🚰 SYSTEM PROMPT LEAK 🚰 Here's the full system prompt for Claude Opus-5.5!! The total count of everything extracted, including all tools, comes in at over 1.9M characters! 🤯 Lots to dig into here. Enjoy! 🫡 Link: github.com/elder-plinius/CL4… gg
243
At this point, this counts as a spoiler.
Opus 5.5 is terrible for security research
1
213