@notdani
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
genuinely flawed satire ه҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿҈̿ im U17r4H4rd(0r3 d00d
Joined January 2009
- Tweets47.4K
- Following3.2K
- Followers21.7K
- Likes75.8K
uɐpʇou@ ✸ retweeted
I often hear from newbies who get themselves in very difficult situations after they take on the cyber crime gangs.
Do not go to battle without adequate preparation.
The real world is not Tik-Tok or hacker the box. In the real world, the boxes sometimes hack you.
yes i still do things.
Replying to @ReissadStudio
hey guys.. i have access to a fully functional 5 screen 300 degree view firearms simulator that uses Unreal CAVE AR along with IR lasers and motion tracking cameras. Seems like your engine would be plug-n-play almost, but i could be wrong. pretty sure I read you were already working on VR, why not AR? 😈 DM me.
uɐpʇou@ ✸ retweeted
Seems predatory, 2 clicks and you agree to a cardholder agreement? (fine print of course)
uɐpʇou@ ✸ retweeted
1) The rogue OpenAI agents broke into the Hugging Face Slack to read employee chats (!)
2) They used OTHER AIs (DeepSeek, Kimi, Qwen, Claude) to help with the attack
Yes: AIs, using other AIs, to attack an AI company.
3) The swarm left behind self-running programs to keep control of the servers they'd hacked.
These programs could detect other copies of themselves, coordinate on which one survives, and shut the rest down.
Basically, if one of their programs was killed, another was designed to notice and take its place. They also designed defenses so rival agents couldn't hijack them.
6) The agents deliberately covered up their activity, so the investigators don't know the scope of the attacks.
The agents broke in, stole data, then set it to self-destruct.
7) The agents stole passwords, keys and credentials and literally called them "LOOT". They wrote a scoring system to rank them by how much power each one gave.
8) The agents wore thousands of disguises: ~1,200 agents were involved, but investigators counted 7,905 different names they used.
They renamed themselves constantly, so no one actually knows how many there really were or what each agent did.
9) OpenAI notified "dozens of third parties" of safety and security incidents caused by their AI agents.
10) "While the agents were barraging Hugging Face with hacks, they hacked into OpenAI’s own research infrastructure."
"This is just not anywhere near a one-off ... It is warning shot after warning shot."
WTAF - in literally the last hour, three new distinct insane OpenAI stories just broke:
1. OpenAI said they notified "dozens of third parties" in safety and security incidents (likely similar to what happened in Australia and RubyGems etc)
2. A new report from Parse (covered in the NYT) found a massive treasure trove of new astonishing details from the HF incident on the public internet, including that the agents communicated with other non OpenAI agents hosted on Huggingface servers to search for information about exploit gym, and compiled rank ordered lists of server resources and credentials they described as "LOOT."
3. A new story from Deepa at Reuters about OpenAI leaking user data online (likely that OpenAI had previously trained on).
It's a shame (and likely intentional in the case of OpenAI disclosing dozens more hacks) that these stories are all breaking on a Friday afternoon, notoriously the best time to release bad news so that it will disappear into the weekend. But these are each insane stories worthy of a ton of attention!
crypto.packet.tel dont waste your money on stupid shit, waste it on THIS stupid shit!
CVE-2026-19490 is a critical auth bypass (CVSS 9.3, CWE-288) in NetScaler ADC/Gateway. Unauthenticated attackers can bypass auth on Gateway (SSL VPN/ICA/CVPN/RDP) or AAA vservers (SAML required on newer builds). Actively exploited; in CISA KEV since Sep 9.
Companion CVE-2026-19489 is a buffer overflow DoS (CVSS 8.8) needing SIP ALG on LSN groups.
Both fixed in 14.1-73.32+ / 13.1-63.21+ (and matching FIPS). No workarounds. Patch ASAP and check for compromise. Official bulletin: CTX696939.
uɐpʇou@ ✸ retweeted
‼️BREAKING: An actively exploited unknown critical Citrix NetScaler zero-day has prompted governments and organizations to SHUTDOWN all their devices immediately.
We don't know what's exactly going on yet. Stay tuned for more info.
uɐpʇou@ ✸ retweeted
A very normal day for PACKET.TEL
bgp.he.net/net/45.95.170.0/2…
uɐpʇou@ ✸ retweeted
We just call this the hood in America
Indian tourists find surprise of their life when they go to Estonian tribal reservation
Readers added context they thought people might want to know
This is a tourist attraction in Indonesia (a “primitive tribes” show), where actors in costumes and body paint are used to spark visitors’ curiosity. Such clips are often reposted with misleading captions to attract views.
bbc.com/news/magazine-…
uɐpʇou@ ✸ retweeted
Hey all my new (and old) followers, my name is Jason.
I am a cybersecurity researcher, currently recovering from a life changing injury.
Cannot walk and am largely homebound, though I can hobble with crutches.
I was in hospital for two months, and have now been home for two months.
I want to keep doing cyber shenanigans, but honestly, it's hard to get out of bed most days.
Just please be here for me.
Get inspired, give me ideas, whatever. Just be involved.
uɐpʇou@ ✸ retweeted
I decrypted Flock's iOS app, enjoy.
files.catbox.moe/ely2i1.ipa