nemo

806 posts

nemo banner
nemo

nemo

@107cwk

Trying to build a very good list of infosec researchers to follow. I swear I'm probably not a bot.

Katılım Ağustos 2018
1.4K Takip Edilen37 Takipçiler
nemo
nemo@107cwk·
@haroonmeer Vendors promising the latest gizmo will "solve all security", Microsoft breaking things as a feature, firewalls are all in rage again (for APTs at least), now we just need someone publishing another Smashing the Stack (for LLM) paper...
English
0
0
0
32
haroon meer
haroon meer@haroonmeer·
Niels Provos posting smart security stuff, Dave Aitel knows stuff he can’t share, Halvar exploring the current space, and people arguing loudly about disclosure ethics.. This could totally be 2002..
English
12
17
135
12.8K
nemo
nemo@107cwk·
This reads like the modern version of the trainspotting monologue youtube.com/watch?v=SaP7qm…
YouTube video
YouTube
Katherine Argent@effthealgorithm

Search is full of ads and wrong answers. Every other email is an ad. Prime Video charges you and shows ads. Paramount? Ads. Peacock? YouTube? Hulu? Ads followed by more ads. Netflix full of ads. Meta and X, every other thing is an ad. Pinterest is nothing but ads. AI is in everything. AI finishes sentences incorrectly and won’t stop. AI reads your email and search history to target you with more ads. Every time you open an app or visit a site there’s an update making it worse. In a hurry? First, click here to agree to terms you don’t have time to read and must accept. You need an account to do that. Change your temporary password. Enter your 2FA code. Check your email and enter that code. Now use a passkey. Your password is too simple to remember. Change it. No, not like that. Now log on. Enter your 2FA code. Check your email for a code… Welcome back! We’ve updated our terms of service and privacy policy (you have none). Subscribe to the site. Subscribe to Netflix. Subscribe to toilet paper. Subscribe to these groceries. Pay a membership fee for the right to subscribe then tip your driver who delivers the subscriptions your membership lets you subscribe to. Time to work? We’ve got to update your laptop and will slow down everything you do until you agree to update. But first, click here to agree. Update installed — your laptop’s broken now. It doesn’t matter, since your boss just replaced you with AI. Go to your phone to complain on social media. Wait, your phone needs an update so we can add more AI. Click here. Oh sorry, your phone can’t handle this update. Now it’s useless. Go get the newest phone. Here’s a text from a friend, an email, a voice mail they left three days ago but you didn’t see until now because of sync problems with the cloud. It’s their GoFundMe. Their MLM. Their Patreon. Never mind, you didn’t respond to their text within 9 minutes and now you’re no longer friends. They blocked you. Make new friends. Download this app to find people in your area. In your neighborhood. On your street. Two doors down from you. Do you know this person yet, we think you’d get along. You need an account to use this app. That username is taken. Enter a password. Not that one, you used it on another site. You need to be connected to WiFi to download the app. Allow the app to connect to other devices on your network. Allow the app to access your contacts, know your precise location, store your credit card details. Oops, sorry, we got hacked now all that info is available on the web. There’s a class action suit. You can join. It’ll take a decade to get your $3.73 share of the ten billion settlement. We’ll send it via PayPal or deposit it to your bank, just tell us those details. Oh no, another hack. That info is circulating now, too. Here’s a spam call, a spam email, a spam text. Why are you angry? Why are you talking about getting rid of your phone? Why don’t you like AI, it lets us make all of this easier? Do you know how ridiculous that sounds? This is progress. You’ll be left behind. Do you want to be left behind? Do you???

English
0
0
0
3
nemo
nemo@107cwk·
@vxunderground @LundukeJournal @gf_256 Did you know that Freddie Mercury was gay? The person with one of the most amazing voices in recent history, that inspired millions, whose musical talent and genius is recognised worldwide, was gay! Imagine if we subtly judged people for their sexual life instead of their talent
English
0
0
4
827
The Lunduke Journal
The Lunduke Journal@LundukeJournal·
Remember the security firm that Ubuntu hired to audit the (ill-advised, highly buggy) Rust-rewrites of all of the GNU Coreutils? Turns out that security firm is run by @gf_256, who: - Appears to be a man who thinks he's a woman ("trans"). - Uses an anime cartoon of a girl as his avatar. - Appears to have an OnlyFans page. I repeat: Ubuntu hired a "Trans" man, with an anime girl avatar and an OnlyFans page... to audit Rust code. It's hard to get more on-the-nose than that.
The Lunduke Journal tweet mediaThe Lunduke Journal tweet mediaThe Lunduke Journal tweet mediaThe Lunduke Journal tweet media
English
415
89
1.3K
594K
nemo
nemo@107cwk·
@terrynini38514 True, but then you meet That Vendor that refuses to acknowledge, threatens to sue, actively scans your social media to see traces of disclosure, and doesn't patch because "it would require a rewrite".
English
0
0
1
65
NiNi
NiNi@terrynini38514·
Responsible disclosure and chasing online attention often pull in opposite directions. This is when your principles reveal themselves, and they may not match what you claim to stand for. People may not even realize this about themselves in their lifetime. When that happens, people often try to cover the gap with excuses.
English
2
0
13
773
nemo
nemo@107cwk·
@NinjaParanoid As one ages, the old adage applies "you only have a limited number of fucks to give. You must cherish them, protect them and use for what really matters"
English
0
0
1
151
Chetan Nayak (Brute Ratel C4 Author)
Long rant: Few days ago, someone asked me why I don't speak at conferences. I wasnt active on social media until I started Dark Vortex. I started using instagram late last year since I was doing a lot of trackdays but decided to permanently delete it few days back. Everywhere, I see dumb comments, people fighting without understanding the other person and instantly triggered even by the smallest of things. I am not a person who favors a specific country, or religion, but looking at where we are progressing as mankind in general, it just feels like too much chaos. There's little truth in all the chaotic news we get these days. I started DarkVortex because I loved developing offsec tools and experimenting with code. You might call me old at 33 years old, but I feel I've reached a point where I have little patience for stupidity and have more or less decided to take a break from everything social. People like to connect in general, but I've reached a point where I pretty much don't care about the worldly affairs. I love researching, which is what I will continue to do on BRc4, do a lot of trackdays and might stop being active on Twitter too in sometime.
English
10
3
81
7.1K
nemo
nemo@107cwk·
@ShitSecure I agree it will be a helper, but I have a feeling there will be a 'race to the bottom' where pentesting companies start charging less (because they use AI and still make a huge profit), then AI companies will start to increase their subscription charges (a-la Azure).
English
0
0
0
107
S3cur3Th1sSh1t
S3cur3Th1sSh1t@ShitSecure·
@107cwk I dont think its a replacement to humans at all. Its running in parallel as helper. Imagine it as a "classic" scanner on steroids.
English
1
0
0
681
S3cur3Th1sSh1t
S3cur3Th1sSh1t@ShitSecure·
Making progress with an autonomous local Pentest LLM pipeline - using Qwen3 27b it's finding and verifying real vulnerabilities and creating a full report including Management-Summary already for us. 🧐 Better than many web vulnerability scanners as it even found e.G. IDOR.
S3cur3Th1sSh1t tweet mediaS3cur3Th1sSh1t tweet media
English
15
24
203
18.4K
nemo
nemo@107cwk·
@x64dbg The year of the linux debugger on the desktop
English
0
0
12
1.1K
x64dbg
x64dbg@x64dbg·
There is also a pre-alpha Linux version brewing 👀
x64dbg tweet media
English
25
65
482
35.9K
x64dbg
x64dbg@x64dbg·
New version is out!
x64dbg tweet media
English
2
32
195
19.6K
nemo
nemo@107cwk·
@_RastaMouse That might not be what you asked, but a pair of happy guard dogs will not only alert you in real time, but also remember any threat forever, recognise friends, and can't be unplugged.
English
0
0
3
361
Rasta Mouse
Rasta Mouse@_RastaMouse·
Does anybody have recommendations for relatively large domestic CCTV setup with local storage? Needs to cover house, stables, and front gate, all at least 20-30 metres apart.
English
9
0
9
6.2K
nemo
nemo@107cwk·
@TheVixhal Literally a pan-galactic gargle blaster
English
0
0
0
107
vixhaℓ
vixhaℓ@TheVixhal·
There is a cloud of alcohol in space big enough to give every person on Earth a quadrillion drinks. In the constellation Aquila, about 10,000 light-years away, astronomers discovered an interstellar cloud called G34.3+0.15 containing enough ethyl alcohol to fill 400 trillion trillion pints of beer. Scientists have also found entire regions of the galaxy containing sugar, vinegar, and precursor molecules to amino acids, just floating in space. The ingredients for life, and apparently a cosmic cocktail, are scattered across the universe.
English
6
2
57
5.2K
nemo
nemo@107cwk·
@IceSolst Crowdstrike shares took about 4-6 weeks to recover after their major fuck-up.
English
0
0
1
31
nemo
nemo@107cwk·
@hackerfantastic @myhackerhouse Seems like you found yourself an excellent niche! Wishing you all the best. Makes me feel optimistic about the future :)
English
1
0
1
9
hacker.house
hacker.house@hackerfantastic·
@107cwk @myhackerhouse We don't conduct those types of audits and are not accepting clients who are in that situation, our clients are more forward thinking and proactive on security, needing expert guidance across their development practices. We provide expert guidance and deep dive solutions.
English
1
0
0
21
nemo retweetledi
Julian Horoszkiewicz
Julian Horoszkiewicz@ewilded·
Finally, it is published 😁 Making Vulnerable Drivers Exploitable Without Hardware - my latest research on driver vulnerability hardware-gating, explaining the concept of hardware-dependent code and diving deep into creative deployment techniques - software-emulated phantom devices, driver restacking, and forced driver replacement — all explored through the lens of Bring Your Own Vulnerable Driver (BYOVD) attacks: atos.net/wp-content/upl…
English
5
90
430
96.3K
Dave Kennedy
Dave Kennedy@HackingDave·
Pulling the trigger on ordering 8xh100s for TrustedSec. The inconsistencies on frontier models plus how deep we are going with research is a must. Now I’ll have my own dedicated coding system. Excited ! Maybe I’ll share with @HackingLZ and @cantcomputer ..
English
56
4
260
21K
nemo
nemo@107cwk·
@MbarkCherguia A fighter jet flying low over a symmetrical cloud of smoke
English
0
0
0
1
nemo retweetledi
neural oscillator of uncertain significance
once again i am increasingly convinced that the best rule of thumb remains “don’t trust an LLM to do something you don’t know *exactly* how to do yourself”
English
66
321
3.1K
56.9K