@devploiti
iAccount based inSpain
About this account
- Account based in
- Spain
- Connected via
- Spain App Store
Account-level information from X, not a live location or the device used for a specific post.
Head of Security @Magnific · Security researcher Breaking things to understand them. Securing things for a living. https://nitter.cf/t.co/CHFZzyZSN2
Málaga, Spain
Joined April 2016
- Tweets3.2K
- Following658
- Followers3.1K
- Likes4.7K
Pinned Tweet
working in cybersecurity nowadays:
> wake up
> read "new critical vuln just dropped"
> summon dev and SRE in the incident channel
> patch, scan, rotate secrets, redeploy
> check logs to make sure you are not already cooked
> take a deep breath and go to sleep
> wake up
> read "new critical vuln just dropped"...
WELCOME TO THE AI ERA
Introducing nginx-poolslip, a fresh RCE for the the latest nginx release 1.31.0.
nginx-rift has been patched, but our security agent Vega has found a new 0 day.
We will release the full technical writeup with ASLR bypass 30 days after the patch on nebusec.ai.
🚨Cyber Alert ‼️
🇪🇸Spain - 𝗝𝘂𝗻𝘁𝗮 𝗱𝗲 𝗔𝗻𝗱𝗮𝗹𝘂𝗰í𝗮
Meduza Locker hacking group claims to have breached Junta de Andalucía. According to the threat actor, the compromised data includes client, confidential, financial, HR, legal, marketing and technical data.
Threat actor: Meduza Locker
Sector: Gov / Mil / LE
Data exposure (claimed): Not specified
Data type: Client, confidential, financial, HR, legal, marketing and technical data, and reports
Observed: Sep 28, 2026
Status: Pending verification
ESIX©: 5.58
Full details and impact assessment on HackRisk.io
With Opus 5.5, it looks like I'll finally be able to remove "don't use em-dashes" from CLAUDE.md instructions.
Daniel Púa retweeted
This finding takes 10 seconds to spot and can pay out hundreds of dollars.
An exposed Google Gemini API key. Used to be "informative, no impact." Not anymore.
The reason: that same key can run Gemini prompts on someone else's bill. It's not just exposed data anymore. It's free AI spend for whoever finds it. Programs are paying for that now.
geminiHunter in Intigriti's September Bug Bytes 🫡intigriti.com/researchers/bl…
0 days since the last "OpenAI dev shows you the RIGHT way to use a coding harness" thread. it's always 0 days.
We've hit the point in AI where it's genuinely hard to tell if something's actually good, or if it's just FOMO doing the talking.
Innovation vs Regulation in one image.
Some data we recently assembled on entrepreneurship/compute in Europe: eudata.vercel.app.
We hope that one of the useful roles that Stripe can play is in collecting and publishing empirical data pertaining to entrepreneurship and industry in Europe. There's growing appetite to get Europe on a better footing, and cross-sectional comparisons can often shine light on where opportunities lie. If you're interested in this kind of thing, we publish more at stripeeconomics.substack.com.
Every time a new AI model drops I see the same 3 jokes:
- Anthropic job posting: “why aren't they using Claude X.X for this?”
- “Just built a million dollar app in 30 min, thoughts? url: localhost:8080”
- “RIP devs, it was fun while it lasted”
We might be more productive but we sure aren't getting more original lol
"I don't know how you sit in front of a screen 8 hours a day"
If only he knew it's not 8. Work plus hobby, it's 14 minimum and I don't even notice lol
Right diagnosis. The cure nobody wants to hear: your bottleneck isn't AI budget, it's your approval chain.
At @magnific there's nothing between finding a bug and killing it.
How many layers are there in yours?
Attacker vs. Defender AI Advantage
danielmiessler.com/blog/atta…
CVSS 9.5, network vector, zero auth, zero interaction. And it's sitting inside a feature nobody audits because "it just generates the share image".
These are the features people usually say don't need to be audited.
Daniel Púa retweeted
bueno, pues ya estamos todos
🤔¿Eres de la IA o eres de ay ay ay...?
👉Encuentra respuestas a la situación actual en este vídeo de nuestro director general #IA #IAsegura #IAresponsable
Anthropic and OpenAI both dropped their latest models on the same day, so I put them in a chess battle.
Opus 5.5 vs GPT-6 Sol. Who do you think won?
The rules:
> Same prompt for both, fresh each move (board, move history, legal moves).
> Effort set to low to avoid overthinking.
> 50 games, each model White in 25.
> 3 illegal answers in one turn = loss.
Here are the stats from the matchup.
Looks like @DarioAmodei takes the crown this time.
nitter.cf/devploit/status/210250…
We went from videogame speedrunners to system prompt speedrunners.
🚰 SYSTEM PROMPT LEAK 🚰
Here's the full system prompt for Claude Opus-5.5!! The total count of everything extracted, including all tools, comes in at over 1.9M characters! 🤯
Lots to dig into here. Enjoy! 🫡
Link: github.com/elder-plinius/CL4…
gg