AcmeThough

7.8K posts

AcmeThough

AcmeThough

@AcmeThough

Technology, technique, etiquette

Katılım Ekim 2018
793 Takip Edilen324 Takipçiler
AcmeThough retweetledi
Law Of Attraction
Law Of Attraction@The_Secret_Law·
Forgive yourself for not knowing better at the time. Forgive yourself for giving away your power. Forgive yourself for past behaviors. Forgive yourself for the survival patterns and traits you picked up while enduring trauma. Forgive yourself for being who you needed to be.
English
6
34
235
3.2K
VixXi
VixXi@VickiCocks15·
This morning, cladding installation began on the road-facing wall of Gigabay. Goodbye view! @LabPadre
English
3
9
128
2.7K
Rumi
Rumi@rumilyrics·
It took me 10 years to realize: no matter how much you trust the people around you, don’t tell them everything.
English
91
492
3.7K
51.9K
vx-underground
vx-underground@vxunderground·
> be me > get dm > "smelly i think someone tried to send us malware" > look inside > furry video game > lolwtf > download > look inside > big big program > smells funny > weird resource section > header value never seen before IT'S A FUCKING SEA BLOB
vx-underground tweet media
English
16
23
1.3K
43K
unusual_whales
unusual_whales@unusual_whales·
Roughly 111 million people — half of all Americans with a credit card and over 40% of adults — are unable to pay off their credit card bills each month, per MorePerfectUnion
English
246
600
3.8K
279.6K
AZ Intel
AZ Intel@AZ_Intel_·
VIDEO: Building collapses in central Beirut, Lebanon after Israeli airstrikes.
English
16
51
246
16.1K
AcmeThough
AcmeThough@AcmeThough·
@pelositracker Wait, so DHS and TSA don't get paid til more people get passports? Is there an irony here?... Kidding about irony, but fr, airports less safe til this gets signed? We're all SOL
English
1
0
2
10
Nancy Pelosi Stock Tracker ♟
You've probably heard a lot about the SAVE America Act, but may not know why it's stalled Here's why it's not passing: → All 53 Republicans are expected to vote yes, but passing it requires 60 votes → Every Democrat is a no. They say it's voter suppression that would block millions of legal US citizens from voting Here's the summary → Passport or birth certificate required to register, not a driver's license → Photo ID required every time you vote. In person and by mail → Voter rolls sent to DHS to purge non-citizens The problem: 21 million Americans don't have easy access to those documents. Half of all Americans don't even own a passport Trump won't sign any other bill until this bill passes
Nancy Pelosi Stock Tracker ♟ tweet media
English
440
46
465
170.5K
AcmeThough
AcmeThough@AcmeThough·
@vxunderground @GenXFatBastard Is Five Eyes part of NATO? And the cyber offshoots of the G7? During aughts, NATO was largely ridiculed as ceremonial tripe with no command or will to exert any influence elsewhere, Balkans, Rwanda, Chechnya, even later Crimea, Libya should it be taken more seriously.
English
1
0
2
250
vx-underground
vx-underground@vxunderground·
United States President Donald J. Trump posted this message on social media today. Personal grievances the Trump administration it asserts it has with other countries and political theatrics aside, the notion that the United States even hints are exiting NATO is a PROFOUND cybersecurity issue. Yes, NATO deals with traditional military stuff (land, sea, air, space), NATO also deals with things in the digital domain (cyberspace). NATO (non-United States) has historically shared a great deal of intelligence with each other regarding state-sponsored threats to the United States. Likewise, the United States has shared intelligence on state-sponsored with our NATO allies. It makes me incredibly nervous that this idea of exiting NATO is floated or threatened. NATO cybersecurity space deals a lot with ICS/SCADA (Industrial Control Systems, which is things like water treatments plants, nuclear energy facilities, telecommunication systems, etc) and anything else which possesses a military threat to the United States and it's citizens. I am unsure of the impact leaving NATO would have on our cybersecurity intelligence. The idea makes me very nervous. The United States is constantly under siege from foreign adversaries (notably China, Russia, North Korea, Iran). Additionally, I have great concern that if we left NATO it would damage our relationship with European allies which have been of significant importance apprehending Threat Actors who have done extreme damage to the United States. Part of the FBI's success in apprehending ransomware actors have been our strong relationship with EUROPOL, and European allies apprehending individuals residing outside the United States. Chat, this unironically makes me very nervous.
vx-underground tweet media
English
72
79
915
55.5K
AcmeThough retweetledi
Law Of Attraction
Law Of Attraction@The_Secret_Law·
Be the person you've always wanted to be.
English
13
56
323
4.3K
AcmeThough
AcmeThough@AcmeThough·
Hedgie@HedgieMarkets

🦔 Researchers at Aikido Security found 151 malicious packages uploaded to GitHub between March 3 and March 9. The packages use Unicode characters that are invisible to humans but execute as code when run. Manual code reviews and static analysis tools see only whitespace or blank lines. The surrounding code looks legitimate, with realistic documentation tweaks, version bumps, and bug fixes. Researchers suspect the attackers are using LLMs to generate convincing packages at scale. Similar packages have been found on NPM and the VS Code marketplace. My Take Supply chain attacks on code repositories aren't new, but this technique is nasty. The malicious payload is encoded in Unicode characters that don't render in any editor, terminal, or review interface. You can stare at the code all day and see nothing. A small decoder extracts the hidden bytes at runtime and passes them to eval(). Unless you're specifically looking for invisible Unicode ranges, you won't catch it. The researchers think AI is writing these packages because 151 bespoke code changes across different projects in a week isn't something a human team could do manually. If that's right, we're watching AI-generated attacks hit AI-assisted development workflows. The vibe coders pulling packages without reading them are the target, and there are a lot of them. The best defense is still carefully inspecting dependencies before adding them, but that's exactly the step people skip when they're moving fast. I don't really know how any of this gets better. The attackers are scaling faster than the defenses. Hedgie🤗 arstechnica.com/security/2026/…

English
0
0
0
20
vx-underground
vx-underground@vxunderground·
I want to share something. I don't expect anyone to care. I just want to scream into the void. I've accomplished everything I've ever wanted to do with malware. There isn't really a malware thingy that's popped up that I haven't seen or done. My malware code repository of stuff I've written dates back to like, 2009. I've released dozens upon dozens of never before seen (at least publicly) malware snippets and ideas. I'm standing at this weird cross road where I'm standing at the peak and I'm kind of looking around like ???. What do I do now? Options: 1. Keep finding new stuff for usermode Windows malware 2. Venture outside usermode to kernel mode malware 3. Switch focus, focus on initial access or stager stuff, not final payload 4. Switch focus, focus outside Windows to different platforms 5. Switch to defense, develop ways to detect malware 6. ??? There is always more to learn and do. But, I've been climbing vertically for like, 20 years, and in order to keep climbing I need to find a different path.
English
158
16
1.1K
56.2K
AcmeThough
AcmeThough@AcmeThough·
Lukasz Olejnik@lukOlejnik

China's biggest cybersecurity company apparently just shipped an AI assistant with its own SSL private key sitting inside the installer. Qihoo 360, think Norton or McAfee, but dominant across the entire Chinese market It appears that their new AI product, 360安全龙虾 (Security Claw) bundles a wrapper on @OpenClaw. Inside the installer package - accessible to anyone who downloaded it - was a private SSL certificate key for the domain *.myclaw.360.cn. An SSL private key is essentially the master password to a website's encrypted connection. With it, an attacker can impersonate 360's servers, silently intercept user traffic, forge a login page that looks completely legitimate, or possibly take over the AI agent altogether. The cert is valid until April 2027 and covers every subdomain on the platform. It's now public. The founder launched the product with a promise it would "never leak passwords". It did that during release? 461 million users, a $10B valuation, and nobody checked the zip file before shipping. The cert expires April 2027.

English
0
0
0
13
vx-underground
vx-underground@vxunderground·
Currently reading about how the weird mooshy gooey thingy inside my skull can retain information (the brain). I started reading on neuropath ways and neurons and synapses. My brain (which is reading this and convincing me to type this) cannot comprehend how mooshy gooey non machine can store information. Mooshy gooey thing in skull, which is self aware, is confused. I am mooshy gooey thing. I don't understand any of this. I am having an existential crisis trying to understand it.
vx-underground tweet media
English
52
28
736
22.5K
Nightingale Associates
Nightingale Associates@FCNightingale·
Denver Office Sales City Center sold for $57.4M ↓86% from $400M in 2020. Denver Energy Center sold for $5.25M ↓97% from $176M in 2013. Trinity Place sold for $6M ↓85% from $40.2M in 2015. Hudson's Bay Centre sold for $8.95M ↓78% from $41.5M in 2014. Denver Place sold for $47.5M ↓76% from $200M in 2007. Centerpoint I and II sold for $23M ↓70% from $77.5M in 2019. The Link sold for $7.2M ↓68% from $22.5M in 2019. #commercialrealestate
Nightingale Associates tweet mediaNightingale Associates tweet mediaNightingale Associates tweet mediaNightingale Associates tweet media
English
265
392
1.8K
256.8K
AcmeThough
AcmeThough@AcmeThough·
@staunovo I thought A) California is going to be in a world of hurt next week for oil bc of War and B) their refineries are bottleneck where even trains of oil from ND bakken are going to idle?
English
0
0
0
20
Giovanni Staunovo🛢
California’s Natural Resources Agency has ordered Houston-based oil driller Sable Offshore Corp. to remove a pipeline crossing a state park days after the US government instructed the company to begin pumping crude through the conduit. #oott bloomberg.com/news/articles/…
English
6
8
20
8.7K
Viral Vibes
Viral Vibes@x_viral_vibes·
Natural oil seeps occur when hydrocarbons from underground source rocks migrate to the surface, forming visible crude oil, tar, or gas emissions.
English
2
18
50
3K
AcmeThough retweetledi
Orange Book 🍊📖
Orange Book 🍊📖@orangebook·
Most people waste too much time explaining themselves to people who never had their best interests at heart. Time explaining what you do is time not doing it. You want to get things done, you need to learn how to ignore most of the world:
English
38
40
387
16.2K
Hedgie
Hedgie@HedgieMarkets·
🦔 Walmart is expanding drone delivery to 150 more stores this year through its partnership with Wing, bringing the service to over 40 million Americans. By 2027 they're planning 270 drone delivery locations from Los Angeles to Miami. Wing says their top 25% of customers order three times a week. Most popular items are eggs, ground beef, avocados, limes, and snacks like Takis. The drone drops packages via parachute without landing. My Take The economics question keeps coming up and it's fair. Right now this probably doesn't make sense for a bag of nuts. But the last mile is the most expensive part of delivery, and if you can launch multiple drones from a truck in a central location to cover a radius, you eliminate a lot of windshield time. The drone doesn't need health insurance, doesn't take breaks, and can fly a direct path instead of navigating streets. The more interesting use case is urgent lightweight items. Prescriptions, phone chargers, last-minute ingredients. Wing started in Africa delivering blood and medicine to remote hospitals where the infrastructure didn't exist for ground transport. That worked because the value of speed was high and the alternatives were bad. Suburban America is a different test. The infrastructure exists, people aren't dying without their avocados, so the bar for convenience has to clear the weirdness of a drone dropping a parachute in your yard. Based on the three-orders-a-week stat from repeat customers, it seems like once people try it they keep using it. Whether that scales nationally is the question. Hedgie🤗
English
16
8
57
9.8K
Javier Blas
Javier Blas@JavierBlas·
I wish I owned a VLCC right now. OK, even just a mere Suezmax would be good. Hell, an Aframax would do it. (looking at eyewatering dirty freight rates)
English
42
45
689
133.3K
AcmeThough
AcmeThough@AcmeThough·
@vxunderground Do you live on a farm and like to sleep upstairs in barn? Like an un-homed cat sanctuary, and your favorite cat is like Hobbes from the comic? And one of your cats looks like a huge female tarantula?
English
0
0
0
12
vx-underground
vx-underground@vxunderground·
Today United States Donald J. Trump released the "Cyber Strategy for America" document. It was highlighted by FBI Director Kash Patel. Let's take a look at it together. I'll translate it from fancy political speak into nerd speak. Intro: >america is cool and badass >were strong af fr >our hackers are schizo af >we could be strongerer >need corpos to work with us fr >were fuckin shit up so nerds cant hide >america 250 years old soon >computers are important Section Two: >we made the internet >we are the best in internet stuff >mean nerds fuck shit up on the internet >mean nerds pissing us off >"im trump and im not a bitch about cyber" >mean nerds targeting important shit online >this is a new era of cyberspace >lots of money online Section Three: >mean nerds pissing us off fr >if we cant internet you, well physically hurt you >he actually wrote that LOL >other countries have shitty AI >we have the best AI >were gonna work with unis and companies for AI >wont let people be censored online >something about people censoring americans >mean nerds will get sanctioned >mean nerds will be memed >mean nerds will get beat up (maybe) >america remove more regulations on AI >regulations slow us down >gotta go fast af boi fr >cybersecurity so important fr Donald J. Trump Pillars of Action: 1. Shape Adversary Behavior >mean nerds attacking americans and companies >theyre innocent ppl tho >nsa and cia given thumbs up to hack back extra >we raising aggression 2. Promote Common Sense Regulation >reduce cybersecurity regulation >checklists are for losers >regulation make companies less agile >companies and gov need to be fast af 3. Modernize and Secure Federal Government Networks >government computers are lame >will make them better >use best practices >use "post-quantum cryptography" >use "zero-trust architecture" >use "cloud transition" >will improve stuff to hunt down nerds we dont like >will use AI for cybersecurity 4. Secure Critical Infrastructure >critical infra support important >energy grid important af to defend >banks important af to defend >hospitals important af to defend >water plants important af to defend >telecoms important af to defend >datacenters important af to defend >must defend everything important af >stop using technology made by countries we dont like 5. Sustain Superiority in Critical and Emerging Technologies >america will make more tech stuff >we gonna protect what we make fr >cryptocurrency must be secured and stuff >we need quantum stuff >ai mega important tho >we need more ai for hacking and for defense >people we dont like hack dumb and shitty ai 6. Build Talent and Capacity >we need more nerds >nerds are unironically super important >need to invest in nerds >remove "roadblocks" for nerds (???) across industry >will invest in more nerd stuff for nerds to learn
vx-underground tweet media
English
125
278
2.1K
118.4K
Cerfia
Cerfia@CerfiaFR·
🇫🇷⚓️ FLASH | Emmanuel Macron annoncera mercredi le nom du futur porte-avions français. Quel nom aimeriez-vous qu'il choisisse ?
Cerfia tweet media
Français
4.7K
217
5.4K
3.7M
Javier Blas
Javier Blas@JavierBlas·
The American Petroleum Institute and CME (owner of the top US commodity exchange) are both pushing against some of the ideas the White House is floating to bring oil prices down. Reflexively, one would think that Joe Biden is still the President...
English
13
40
323
54.2K