Tom Sweet

341 posts

Tom Sweet banner
Tom Sweet

Tom Sweet

@ThomasJSweet

Digital Global #Technology Leader,Engineering, IT #cloud, #DevOps, #automation, #CTO #leadership (My opinion only)

Dallas area Bergabung Ocak 2014
415 Mengikuti314 Pengikut
Tweet Disematkan
Tom Sweet
Tom Sweet@ThomasJSweet·
According to @GoToMyPC support, their #Azure single sign-on does not support #phishing resistant MFA such as #FIDO keys or #WHfB. This makes me wonder about their own internal security.
English
1
0
13
304
Tom Sweet
Tom Sweet@ThomasJSweet·
@hnykda @tcrawford - build your own CRM they said, it will be easy the said, only 30 min they said. Maintenance is more than many think.
English
0
1
1
42
Daniel Hnyk
Daniel Hnyk@hnykda·
LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below
English
297
2.2K
9.2K
5.2M
Tom Sweet
Tom Sweet@ThomasJSweet·
@feross @tcrawford - when you talk SaaS replacement and maintenance, this is the type of thing that adds to internal costs. We had to stop everything and test our repos/apps for this. I am sure this is not the last time a component will be compromised.
English
1
0
4
1.4K
Feross
Feross@feross·
🚨 Breaking: Trivy GitHub Actions supply chain attack – 75 out of 76 version tags compromised. If your CI/CD pipelines reference “aquasecurity/trivy-action” by version tag, you’re likely running malware right now. At Socket, we identified that an attacker force-pushed nearly every version tag in the official aquasecurity/trivy-action repository. That’s @​0.0.1 all the way through @​0.34.2. Over 10,000 GitHub workflow files reference this action. The malicious payload runs silently before the legitimate Trivy scan, so nothing looks broken. Meanwhile it’s: - Dumping runner process memory to extract secrets - Harvesting SSH keys - Exfiltrating AWS, GCP, and Azure credentials - Stealing Kubernetes service account tokens The only unaffected tag right now appears to be @​0.35.0. Socket independently detected this at 19:15 UTC and generated 182 threat feed entries tied to this campaign – all correctly classified as Backdoor, Infostealer, or Reconnaissance malware. This is the second Trivy compromise this month. Earlier in March, attackers injected code into the Aqua Trivy VS Code extension on OpenVSX to abuse local AI coding agents. The compromised tags are still active. Pin to @​0.35.0 or use a SHA reference until this is fully remediated. Full write-up: socket.dev/blog/trivy-und…
English
16
117
382
235.2K
Reid Southen
Reid Southen@Rahll·
Wait wait wait waaait a second.... He's saying he wants his $500,000 engineer to actually cost him $750,000 by using $250,000 worth of AI tokens. Wasn't AI supposed to make things cheaper, not cost 50% more?
TFTC@TFTC21

Jensen Huang: "If that $500,000 engineer did not consume at least $250,000 worth of tokens, I am going to be deeply alarmed. This is no different than a chip designer who says 'I'm just going to use paper and pencil. I don't think I'm going to need any CAD tools.'"

English
376
405
5.8K
240.8K
Tom Sweet
Tom Sweet@ThomasJSweet·
Gotta love cyber people on LinkedIn with big mouths that wont' display their last name -real brave.
English
0
0
1
15
Jack Spirko⚡️
Jack Spirko⚡️@TheSurvivalPodc·
The AI-Driven Leader by Geoff Woods - Item of the Day thesurvivalpodcast.com/iotd-6-24-25 Are you using AI or are the companies behind AI using you? This book shows you how to use AI where you are always the "thought leader" vs. the passive way most people let AI control the conversation and hence the output. To survive the AI change you really need to read this book.
English
4
0
6
283
Tom Sweet
Tom Sweet@ThomasJSweet·
@tcrawford I remember a quote from "No Country for Old Men" - when Elias tells his brother, "you can't stop what's coming."
English
0
0
1
8
Tom Sweet me-retweet
HalcyonAI
HalcyonAI@HalcyonAi·
🚨 LAST CALL! 🚨 Join the team behind the world’s first #Ransomware Operations Center for a live discussion on: • Why ransomware broke the SOC model • What attackers are doing now • Real saves from the frontlines TODAY @ 11 AM ET Register now: bit.ly/4sIfjy9 #cybersecurity #ThreatIntel #webinar
HalcyonAI tweet media
English
0
1
3
63
Tom Sweet me-retweet
HalcyonAI
HalcyonAI@HalcyonAi·
Most ransomware reports tell you what could happen. This one shows what actually did — straight from Halcyon’s Ransomware Operations Center (ROC). Introducing our new monthly ROC STAR Report, built from real attacks stopped in live environments. What we’re seeing: • Attackers scaling with legit tools (RMM, remote access) • Most threats stopped before foothold • #EDR failing silently — no alerts, no signal No theory. Just real-world #ransomware. 👉 Download the report: bit.ly/4bOfmmg #ThreatIntel #cybersecurity
HalcyonAI tweet media
English
0
2
4
79
Tom Sweet
Tom Sweet@ThomasJSweet·
@AutismCapital waited 40 min for the live event to start, then moved on.
English
0
0
0
428
Autism Capital 🧩
Autism Capital 🧩@AutismCapital·
🚨 NEW: Nvidia announces support for OpenClaw 🦞
English
73
202
2.6K
180.1K
Tom Sweet
Tom Sweet@ThomasJSweet·
@tcrawford I can see that - we downplayed the AI portion of RefrigAgent.
English
0
0
1
7
Tom Sweet
Tom Sweet@ThomasJSweet·
@tcrawford I think a lot will change in the next two months.
English
0
0
1
5
Tom Sweet
Tom Sweet@ThomasJSweet·
@tcrawford Assuming you could, keeping up with daily open-source updates/patches/vulnerabilities takes a lot of time. Ask me how I know. 😀😀
English
0
0
1
6
Tim Crawford
Tim Crawford@tcrawford·
Think you can just "vibe-code" a custom ERP with AI and ditch your SaaS contracts? Think again. 🛑 The hype says AI replaces SaaS; reality says replicating the complexity of a Salesforce or Workday is a monumental (and expensive) feat. Don't trade stability for hype: avoa.com/2026/03/06/is-… #CIO #Cloud #AI #EnSW
English
1
0
1
75
Tom Sweet
Tom Sweet@ThomasJSweet·
Got banned from @claudeai tonight for 'who knows why?' I had a personal API account with $5 on it and never got around to using it. I can't even log in to to see what happened, if anything. Sure I can appeal it.
English
1
0
1
26
Tom Sweet
Tom Sweet@ThomasJSweet·
All these arm-chair quarterbacks discussing 'should haves" for #stryker - clear to me that none have actually managed an M365 tenant.
English
0
0
0
74
Tom Sweet
Tom Sweet@ThomasJSweet·
@honeymoon250 If she has a boyfriend or husband, many will blame him for the black eye that results.
English
0
0
1
15
Honey 🛼
Honey 🛼@honeymoon250·
Any advice to her ?
Honey 🛼 tweet media
English
558
23
133
14.9K
Tom Sweet
Tom Sweet@ThomasJSweet·
It might just need an hour or two to sync up. It is starting to work now
English
0
0
0
10
Tom Sweet
Tom Sweet@ThomasJSweet·
I cannot get @claudeai to #SSO to work with our "Team" license. The "test" from workos.com works, but then it never enables and activates our domain in the identity portion of the claude app. Any ideas? workos.com shows timeouts in their screen
English
1
0
0
28
Tom Sweet me-retweet
Tech Layoff Tracker
Tech Layoff Tracker@TechLayoffLover·
Atlassian just confirmed 1,600 layoffs with 900+ coming from engineering But I'm hearing the real story from inside Sources say they've been running "knowledge extraction sprints" for 6 months - recording every senior engineer's screen, logging their prompts, documenting their debugging workflows One architect told me they made him walk through his entire microservices decision tree while they filmed it. Called it "knowledge transfer for the transition team" The transition team? 47 contractors in Bangalore with access to his recorded sessions and a Claude Enterprise subscription Same architect just found out his replacement starts Monday. Guy makes $28k annually and ships code 40% faster using the exact prompt libraries they extracted They're not just cutting headcount - they're systematizing 15 years of engineering expertise into training data The "strategic AI focus" isn't about building AI products It's about replacing their entire engineering culture with agents trained on their senior engineers' knowledge Word is the CTO replacement already has the playbook: extract, document, offshore, automate If you're still there and they ask you to "document your processes for the team" - RUN The knowledge extraction is complete
English
406
856
6.9K
1.2M