Head of Security @Magnific · Security researcher Breaking things to understand them. Securing things for a living. https://nitter.cf/t.co/CHFZzyZSN2

Málaga, Spain
Joined April 2016
🚨Cyber Alert ‼️ 🇪🇸Spain - 𝗝𝘂𝗻𝘁𝗮 𝗱𝗲 𝗔𝗻𝗱𝗮𝗹𝘂𝗰í𝗮 Meduza Locker hacking group claims to have breached Junta de Andalucía. According to the threat actor, the compromised data includes client, confidential, financial, HR, legal, marketing and technical data. Threat actor: Meduza Locker Sector: Gov / Mil / LE Data exposure (claimed): Not specified Data type: Client, confidential, financial, HR, legal, marketing and technical data, and reports Observed: Sep 28, 2026 Status: Pending verification ESIX©: 5.58 Full details and impact assessment on HackRisk.io
1
245
0 days since the last "OpenAI dev shows you the RIGHT way to use a coding harness" thread. it's always 0 days.
1
2
183
Innovation vs Regulation in one image.
Some data we recently assembled on entrepreneurship/compute in Europe: eudata.vercel.app. We hope that one of the useful roles that Stripe can play is in collecting and publishing empirical data pertaining to entrepreneurship and industry in Europe. There's growing appetite to get Europe on a better footing, and cross-sectional comparisons can often shine light on where opportunities lie. If you're interested in this kind of thing, we publish more at stripeeconomics.substack.com.
3
3
478
Replying to @b4dgerr
Nice growth, but following 2.4k back to get 2.4k followers is basically follow-for-follow. That's a different game than growing off content.
43
The rules: > Same prompt for both, fresh each move (board, move history, legal moves). > Effort set to low to avoid overthinking. > 50 games, each model White in 25. > 3 illegal answers in one turn = loss. Here are the stats from the matchup.
1
1
169
Anthropic and OpenAI both dropped their latest models on the same day, so I put them in a chess battle. Opus 5.5 vs GPT-6 Sol. Who do you think won?
1
2
1
6
823
Cloudflare shipped their own version of ngrok to expose localhost to the internet. The problem: those tunnels are getting indexed by Google. Anyone with site:trycloudflare.com can browse random people's exposed local dev servers right now, no login, no tunnel URL needed.
4
2
4
529
Every time I download a new game on my phone, this @LiveOverflow video pops into my head. If you haven't watched it yet, do yourself a favor. youtube.com/watch?v=AMMOErxt…
174
This finding takes 10 seconds to spot and can pay out hundreds of dollars. An exposed Google Gemini API key. Used to be "informative, no impact." Not anymore. The reason: that same key can run Gemini prompts on someone else's bill. It's not just exposed data anymore. It's free AI spend for whoever finds it. Programs are paying for that now.
4
1
46
3,086