@mattjayi
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
Founder of @vuln_u | Long Island elder emo surviving in ATX | AI and Cybersecurity news from an 18yr industry vet
Joined June 2008
- Tweets47.8K
- Following2K
- Followers46.2K
- Likes86.3K
Pinned Tweet
🚨 Exciting thing🚨 I'm getting back to my content creation roots.
I've missed blogging, podcasting, and community engagement from back before I worked for big companies with scary PR teams.
So... I'm launching a newsletter called Vulnerable U. vulnu.beehiiv.com
I been saying!
If zero days are cheap. Detections get much more important.
Zero days are not invisibility cloaks.
These kinds of lists will never please everyone but this is a damn good list.
Here’s The New York Times 100 Best TV Shows of the 21st Century: nytimes.com/interactive/2026…
Banger alert
Dont be sleeping on Heif Heist! Meta paid 100k for my RCE on FB/Instagram!
heif-heist.com/
this is
A) very funny
B) an interesting look at youth cultures view of technology and
C) thats what Ira Glass looks like?!
Some NPR podcasts started getting mysterious comments on Spotify. They made no sense to the staff reading them – until someone from a younger generation cracked the code.
Hear the story: link.podtrac.com/phns92ui
easily the best video on the Hugging Face incident I've seen. By @NielsProvos
youtu.be/B7SGWOtt9rA
Guards up devs! Especially in crypto spaces.
Very prevalent attack here to get you to clone a GitHub repo during a job interview and it’s full of malware
The fingers in front of the face is not foolproof as deepfakes aren’t always used.
Had an "interview" for a blockchain project last week.
Camera was on, we're chatting, and the guy tells me to clone a GitHub repo and run it locally before we go further into the technical round.
I said sure, but first can you do me a favor
hold up 3 fingers in front of your face for me real quick.
He froze.
Didn't move.
Just sat there for a few seconds before the call cut off and he blocked me.
That's when I knew. A real interviewer doesn't glitch out over a random ask like that. A deepfake/AI overlay does.
These "run this repo" scams are getting scary common in crypto and dev hiring right now.
The setup is always the same:
- flattering DM
- real-sounding project
- rushed timeline
- a "quick step" before the call
that's really just remote access or a credential stealer in disguise.
If someone wants you to run code or install something before you've even had a real conversation, that's the whole scam.
Trust the instinct. Stay safe out there.
Turned on ESPN for the first time in ages when I wasn’t in a hotel.
Entire show dedicated to the hosts telling you what they think good bets to place on Draft Kings are this week.
We’re so cooked.
How this scam works.
Step 1: Come up with some half baked idea
Step 2: Use Claude to vibe code a design some half working website
Step 3: buy an old x account with some followers and make a promo with higgsfield
Step 4: bull post with some bots until it catches on
Step 5: share a contract address and rug pull
Be aware
Bliss will be coming to Robinhood.
Launch a coin. Pick its bliss. Let it run.
Early access: bliss.fun
me an @LowLevelTweets been talking about this on a lot of the privacy rabbit hole stuff.
at some point you just have to participate in modern society otherwise it is never ending.
Tweet is from June btw
👀
Yo, we all gotta talk bout ShinyHunters vs PeopleSoft
So let met get this right.. 113 of you said lets pack HR, payroll, finance, procurement, supply chain, student records, employee identities, and every business process with a pulse all into one giant loot piñata with an ugly @Oracle logo stamped on it?
Love me a place where their leadership finally discovers "mission critical" means too important to patch, too entangled to isolate, too expensive to replace, and too embarrassing to explain.
Congratulations kings. You all running a Threat Actor Costco and gave ShinyHunters an executive membership.
I must’ve missed a day on the Internet.
Why is everyone in my comments on the FBI hack talking about beastiality?
timely.
I wonder what news about Oracle PeopleSoft made some threat actors hone in on this vuln's capabilities???
🚨 We are seeing elevated Oracle PeopleSoft (CVE-2026-35273 / PSEMHUB RCE) activity in our honeypots since Sep 22 UTC, including simple WAF bypass attempts against the standard path-block mitigation.
Source IPs and the full indicators are available on Defused Radar.
console.defusedcyber.com/sig…