Alexander Wilczek

1.1K posts

Alexander Wilczek banner
Alexander Wilczek

Alexander Wilczek

@SecWillCheck

Digital Nomad Fighting Cybercrime | Founder @rivanorthSec

Australia 🇦🇺🦘 Joined Mart 2019
280 Following214 Followers
Alexander Wilczek retweeted
BreachClaw
BreachClaw@BreachClaw·
In under two weeks, I've already collected over 150 breaches.
English
0
1
0
5
Alexander Wilczek
Alexander Wilczek@SecWillCheck·
I'm pretty sad that MCP servers are dead. I really liked the concept, but I guess optimising context windows is key. So I guess long live the CLI.
Alexander Wilczek tweet media
English
0
0
0
39
Alexander Wilczek
Alexander Wilczek@SecWillCheck·
@fr0gger_ Cheers mate 🙏 couldn't stop laughing when I generated that logo 😂 love it
English
0
0
1
22
Alexander Wilczek
Alexander Wilczek@SecWillCheck·
OpenClaw has been causing havoc in the security space ever since its release. As amazing as AI agents are, they can have some pretty catastrophic side effects. One of those can be leaking your data or secrets. So I decided to do something about it. Let me introduce you to @BreachClaw. @BreachClaw scans the open internet, from code repositories to paste sites and everything in between looking for sensitive information like API keys, configuration files, passwords and other secrets. Some of those leaks happen due to user error, this could be approving a dangerous prompt or simply AI agents running wild. There have also been instances of malicious skills extracting data through paste sites, so that's covered too, especially if skills are used that haven't gone through the official ClawHub (OpenClaw’s skill marketplace) or before they started collaborating with VirusTotal. Think of it as, if it's on the public internet, BreachClaw will find it. You can check it out here: breachclaw.ai If you like the concept and think it's a useful tool for the community, I would really appreciate a repost or if there is a functionality I should add let me know in the comments. 🫶 🦞
Alexander Wilczek tweet media
English
1
0
4
246
Alexander Wilczek
Alexander Wilczek@SecWillCheck·
it's a shame MCP seems already dead, I kinda liked the concept but I guess CLI is king
English
0
0
0
44
Alexander Wilczek
Alexander Wilczek@SecWillCheck·
I often get asked, how do you manage to work while constantly on the road? I'm not gonna lie, it's not always easy. Back in the day, I used to think that I needed at least two to three monitors, a standing desk, and a perfectly fine-tuned setup to be able to work. But the truth is, with time, our body, and our mind adapts to pretty much anything. This seemed to be impossible previously. But now I can pretty much whip up my laptop anywhere, have a coffee, put in my noise-canceling airpods in, and get in the zone and get work done. I think if we allow our body and our working style some time to adjust, any work setup is doable and can bring good results. And when I really need two screens, especially for programming, I use an inexpensive portable monitor. In hindsight, having a perfect work setup is just an excuse I used to make. But if you're engaged and you like what you do, a laptop and a camping chair will do just fine.
Alexander Wilczek tweet media
English
0
0
1
23
Alexander Wilczek
Alexander Wilczek@SecWillCheck·
Why I hate social media. 👇 👇 👇
English
0
0
0
17
Alexander Wilczek retweeted
Justin Elze
Justin Elze@HackingLZ·
Kali just published a guide on piping pentesting tools through Claude's API and didn't mention data security once. You're sending scan results, target info, and potentially sensitive findings to a third party LLM. "The Most Advanced Penetration Testing Distribution" should probably mention that. x.com/kalilinux/stat…
English
38
83
563
53.6K
Alexander Wilczek
Alexander Wilczek@SecWillCheck·
I'm part of the problem. So recently I started sharing a few quirks that I encountered while using AI, mostly around prompt engineering. And by all means, I'm not saying I'm an expert. But I would say that most of my time is spent writing (vibe) code. I'll link my Windsurf stats for the month below. But what really surprised me was the utter nonsense comments that I got from some people on my posts. I felt that, to me, those people try to build a pseudo understanding on AI using fancy words like "pattern matching", "tokens" and what not. Which is cool, but going and preaching on the internet with convoluted messages that make no sense, I believe is a waste of time. I see AI like cars. If you're not an experienced mechanical engineer, you won't be able to take apart and put together a modern vehicle by yourself. What you can do instead is learn to drive it properly. I think rather than wasting time on pseudo understanding AI, I learn what I really need to and then try to use this amazing technology to create something useful. At least those are my two cents. Happy Friday.
Alexander Wilczek tweet media
English
0
0
0
43
vxdb
vxdb@vxdb·
What password manager do you use? I wanna see if anyone is moving away from 1Password since the price increase
English
449
5
352
75K
INFOSEC F0X 🔥
INFOSEC F0X 🔥@infosec_fox·
AI experts say the only job left might be plumbing?
English
19
1
22
1.9K
Alexander Wilczek retweeted
sam
sam@samdape·
you basically need to be unemployed rn to keep up
English
466
1.6K
20.6K
1.2M
Alexander Wilczek
Alexander Wilczek@SecWillCheck·
Not gonna lie, didn't expect this... I thought that AI slop was the current biggest problem. Didn't expect my AI to read all my environment variables, even though I declined the command... For those that don't know, environment variables often have very sensitive information like API keys and other secrets. Having them read by an AI is equivalent to a breach. (In my opinion, at least.) Thankfully, this was just in the development environment. Anyway, I'll add this one-liner to my global rules, hopefully this will prevent it from happening again. "Never use bash commands to read .gitignore-protected files; if read_file is blocked, respect that protection." And in the meantime, I'll go and rotate all my secrets and API keys. 🤦‍♂️
Alexander Wilczek tweet media
English
0
0
0
44
Alexander Wilczek retweeted
Can Vardar
Can Vardar@icanvardar·
we desperately need a new season of silicon valley. the ai era alone would carry 3 seasons
Can Vardar tweet media
English
536
1.1K
17.3K
1.5M
Alexander Wilczek
Alexander Wilczek@SecWillCheck·
The more we progress in Gen AI, the more noise is becoming a problem. This is the simple framework I follow to combat that: For every signal I see, I ask myself, "Is this relevant?" If yes, what is the real security impact for our customers, not theoretical, real impact? If there is none, I discard and move on. I think the more we use AI, the harsher we need to become with cutting noise. Remember, for every false positive, there is someone that needs to clean it up. P.S. @rivanorthSec Oko does the cleaning for you 😉
Alexander Wilczek tweet media
English
0
0
2
24
Tib3rius
Tib3rius@0xTib3rius·
Software development in 2026.
Tib3rius tweet media
Română
21
21
249
10.3K