0std | Pentester | AppSec

442 posts

0std | Pentester | AppSec

0std | Pentester | AppSec

@0std1

my researches https://t.co/8209nDXdiH

Katılım Ekim 2019
83 Takip Edilen95 Takipçiler
Sabitlenmiş Tweet
0std | Pentester | AppSec
Few words about me: 5.5 years pentesting (40+ external + 20+ web apps, red team, physical) → now 3 years in defensive (SOC, SSDLC, AppSec, Wazuh, Suricata). Found $250 bug bounty in the first week of my 30-day challenge. Sharing real purple team labs, implemeting AI, practical setups, and lessons from both red and blue sides. Subscribe & grow with me 🔥
English
0
0
3
336
Zack Korman
Zack Korman@ZackKorman·
Cybersecurity is being used as a pawn in the AI debates. First it was “these models are too dangerous.” Now it’s “Chinese open-weight sleeper agents.” These ideas are pushed by non-security people to serve an agenda, and that agenda has nothing to do with cybersecurity.
English
22
31
278
7.9K
Jun Song
Jun Song@jun_song·
Surprised to see so many people still hauling MacBooks around. I completely switched to working remotely via my iPhone, and it handles everything flawlessly. What is even the reason to carry a heavy laptop anymore?
English
98
5
180
25.7K
Abhijit
Abhijit@AbhiCodes15·
What's the point of a local model if most developers can't realistically run it?
English
54
1
93
4.3K
0std | Pentester | AppSec
So everyone is saying that Kimi K3 benchmaxxed all frontier models? Waiting for a score on “backdoor creation” benchmark
English
0
0
0
41
Ryan G. Cox
Ryan G. Cox@RyanGCox_·
Here are some logical career pivots if you want to break into Cybersecurity: IT -> Corporate Security SWE -> Application Security/Red Team Network Engineer -> Cloud Security Data Analyst -> SOC Analyst SysAdmin -> IAM Security DevOps -> DevSecOps/Infrastructure/Cloud Security Help Desk -> SOC Analyst To work in cybersecurity, you don't have to start in cybersecurity. Everyone's path is different. Find the path that makes the most sense for you.
spencer@techspence

Getting an IT job first before getting into cybersecurity is unmatched. Especially true if you want to do any kind of technical role, that IT experience is only going to help you. The problem is, so many people lack the patience to do it. Especially when you get a "cybersecurity" degree...

English
4
23
163
8.8K
0std | Pentester | AppSec
@techspence somehow cybersecurity requires understanding what and how needs to be done in a lot of areas like devops, sysadmin, backend dev all at once but significantly underpaid compared to all of them
English
0
0
2
115
spencer
spencer@techspence·
Getting an IT job first before getting into cybersecurity is unmatched. Especially true if you want to do any kind of technical role, that IT experience is only going to help you. The problem is, so many people lack the patience to do it. Especially when you get a "cybersecurity" degree...
English
33
29
454
34.9K
0std | Pentester | AppSec
@0xAlaric Fable guardrails were bypassed the same day as it was released to public yet we don’t see everyone hacked or some rapid emerge of cyberattacks. So it’s either cybercriminals are not using it either it is not so good at it as it was stated by Anthropic lmao
English
0
0
2
3.4K
Alaric
Alaric@0xAlaric·
Anthropic: “Fable is an agentic coding superweapon, capable of developing cyber- and bio-weapons at unprecedented speed and scale. We cannot in good faith release it without guardrails.” China: “lmao here’s Fable but open-source. Good fkn luck”
Kimi.ai@Kimi_Moonshot

Introducing Kimi K3: Open Frontier Intelligence 🔹 2.8 Trillion Parameters, 1 Million Context, Native Multimodal 🔹 Kimi Delta Attention enables up to 6.3x faster decoding in million-token contexts 🔹 Attention Residuals deliver ~25% higher training efficiency at <2% additional cost 🔹 Built for long-horizon agentic coding and self-evolving workflows Kimi K3 is now live on on Kimi.com, Kimi Work, Kimi Code, and the Kimi API. Open Weights by July 27, 2026. 🔗 API: platform.kimi.ai 🔗 Tech blog: kimi.com/blog/kimi-k3

English
160
1.1K
14.1K
1.4M
0xSero
0xSero@0xSero·
It costs: - 18,000$ for GLM-5.2 on 4x DGX Sparks @ 30 tok/s - 60,000$ for GLM-5.2 on 4x RTX Pro 6000 @ 80 tok/s - 24,000$ for GLM-5.2 on ??????? @ 50 tok/s Here it's using subagents to research x API & build a local.ai bot, it's actually phenomenal.
0xSero tweet media
English
29
5
258
28.5K
solst/ICE of Astarte
Marketing for cybersecurity can be done right: just look at @haroonmeer @Jhaddix @madelinelawren & what they’ve built. When you deeply understand the community, you can speak to its members directly. Otherwise you hire a clueless sales exec and turn people away.
English
16
12
113
6.9K
spencer
spencer@techspence·
One of the best investments ever, if you work in security, is having your own lab. Your own little sandbox or playground where you can literally destroy stuff and it doesn't matter.
English
20
7
132
9.2K
dunik
dunik@dunik_7·
he made 405-billion-parameter models run on a single 8GB gaming GPU. instead of turning it into a paid service, he open-sourced the whole thing. Gavin Li Founder and CEO of Anima AI in the Bay Area. 'airllm' - it keeps one layer on the GPU at a time and streams the rest, so a 70B model fits in 4GB and DeepSeek's full 671B fits in about 12GB 22,700 stars. Apache 2.0. → github.com/lyogavin / he has 808 followers. / his repo has 22,700 stars. bookmark it. that's what shipping something impossible looks like.
dunik@dunik_7

running a 405-billion-parameter model used to mean a $30,000 GPU rack. one developer made it run on a single 8GB card the kind that's been sitting in gaming laptops for years. it's called AirLLM, and the trick is almost stupidly simple: instead of loading the whole model, it keeps one layer on the GPU at a time and streams the rest through. / Llama 3.1 405B on 8GB / DeepSeek-V3, all 671B of it, on about 12GB / no quantization, no distillation, no pruning the full-precision model / works with Llama, Qwen, DeepSeek, Mistral, Gemma, and more it's Apache 2.0 and already past 22,600 stars. → github.com/lyogavin/airllm bookmark it.

English
42
125
1.1K
108.9K
0std | Pentester | AppSec
@infmes open source models can’t provide you one either as they are completely blackbox and give undetermined answers as other models do and are
English
0
0
0
20
Faisal
Faisal@infmes·
@0std1 can't put a price on privacy 🫣
English
1
0
0
32
Faisal
Faisal@infmes·
@0std1 24k for one user not for entire company
English
1
0
0
34
0std | Pentester | AppSec
@infmes @0xSero we've built AI SAST which spends about 1,5 mln tokens per merge request which amount can be about 500 per day (company wide). So it will take about 13 hours to analyse 1 which obviously we can't afford. So yeah in commercial sense this speed is quite useless.
English
2
0
1
41
Zack Korman
Zack Korman@ZackKorman·
I really struggle to understand Semgrep’s research on backdoored AI models. They say we urgently need trusted third parties to validate models. But… why? A non-backdoored model can still behave in an unsafe way. You shouldn’t trust any model. cc @InsiderPhD
Zack Korman tweet media
English
14
6
74
5.8K
spencer
spencer@techspence·
@0std1 to each their own. I think a lot of the blue team stuff IS fun
English
1
1
2
224
spencer
spencer@techspence·
In the 5 year's I've been pentesting, I've worked with clients that had: hardened endpoints, app control, edr & mdr, custom alerts they created themselves, good hygiene, tiered admin accounts, etc. I wish I could talk about all the awesome stuff these folks are doing. I think part of why offensive security has become so popular is because the super cool awesome blue team stuff isn’t shared as much, for obvious reasons. Defenders don’t want to give up their hands or put a target on their back. Certainly don't blame them. Blue team stuff is cool and fun and awesome. We just don’t get to see it as often. I wish we did.
English
5
7
83
5.5K