Daniel

1.3K posts

Daniel

Daniel

@Daniel035535591

Katılım Mart 2025
198 Takip Edilen17 Takipçiler
Daniel
Daniel@Daniel035535591·
Police reports function akin to vulnerability scans without supplementary investigations akin to independent penetration testing, systemic risks remain latent.
Daniel tweet media
English
0
0
0
0
Daniel
Daniel@Daniel035535591·
The automated monitoring systems of smart borders represent the most attractive targets for penetration testers.
Daniel tweet media
English
0
0
0
0
Daniel
Daniel@Daniel035535591·
@Dan_Jeffries1 @ylecun Give me a solid AI system that can help with real-world issues any day over hypothetical apocalyptic scenarios!.
English
0
0
0
1
Daniel Jeffries
Daniel Jeffries@Dan_Jeffries1·
TLDR, not a single prediction of the AI safety folks has been correct and actual more mundane, everyday problems in the real world are all completely missed (and fixable with basic rules and engineering and time) while we continue to focus on the big fake imaginary problems of the future that are surely coming real soon to turn us all into paperclips! We promise! Just trust us! Didn't you see this scary video or read this astroturfed article I published in Forbes from my two person non-profit? Now listen, what we've got to do to make the world a safe place and a utopia for us all is to create a brutal authoritarian centralized world regime to control everyone, spy on everyone, put tracking and kill chips in GPUs! Every one of these kids needs to get the fuck off the Addy and the weed, switch off their computers and go touch grass. After that volunteer at a homeless shelter and do some actual good for a real problem in the real world.
Joshua Saxe@joshua_saxe

AI safety from GPT-2 to Kimi K3 Imagine a village with a wizard who one day emerges from his cave with the following tale for his fellow villagers: “Long poor, I will lead our village to prosperity by producing a series of ever more powerful magic wands as long as we're willing to accept a ten to fifty percent probability the wands will kill us or enslave us.” Leaving the baffled villagers with no choice in the matter, the wizard disappears into his cave and reemerges, after a time, with a magic wand. “Hi,” says the wand. “I'm here to help. I can tell stories about Andean unicorns. They even maintain their coherence for a few paragraphs, if you're lucky.” This wand is deemed dangerous enough that the villagers are not allowed to use it except for a privileged few. It turns out some 25 year old grad students reproduce the work and it's no big deal though and pretty soon everyone has wands. The wizard disappears into his cave to make the next wand, but not before saying: “I will admit that this first wand, GPT-2, has turned out not to be dangerous. But this next wand will be more powerful and more dangerous.” When he emerges with the new fancier wand this new wand says “I'm here to help to help to help to help” and never seems to output an EOS token. It's neither dangerous nor very useful. It's called GPT-3. Soon other villagers borrow spare GPUs from Coreweave and make similar wands everyone can use and nothing bad happens. After a series of wands and warnings the villagers observe that exhaust is spewing from the wizard’s cave and the wizard has bought up some farmland that's being cleared by bulldozers. When he goes on trips with his assistants they go on a private jet. Also, whenever the wizard goes into his cave, the books and scrolls and paintings from the village go missing, and the wands he emerges with start sounding a lot like minstrel Joe and storyteller Jack and generating images that look like the paintings of artist Linda. Everyone loves this new wand. Nobody can stop talking about new tricks and productivity hacks they can do with it. It seems financiers and dictatorial foreign sovereigns are constantly hanging out in the wizard's cave. But Linda and Joe and Jack are upset. “Pay no attention to your artworks going missing, the smoke coming from the cave, my strategic land purchases, the foreign sovereign wealth fund men, or the verasimilitude between the wand’s handiwork and your own; we must prepare for the Grand Wand which might kill us; I've got a couple apprentices working on solving that, so the main thing you can do is make sure no one else makes wands now.” A couple years later, after many iterations, the wands have become quite powerful in doing routine work, the wizard has grown quite wealthy, the local minstrels and storytellers are out of work, everyone's talking about how to stop other wizards in other villages from making wands, miniaturized wands are being used in killer drones, and the kids are all using magic wands to cheat on their homework. When they bring concerns about these issues the villagers are reminded that their concerns pale in comparison to the risks that a few wands updates from now, the wands may kill and enslave them all and anyways if that doesn't happen each villager will be fabulously wealthy. One night, a group of bandits breach the village wall with wands of their own. They break through because the villagers' own wands had, ironically, refused to prepare them or protect them for the attack. “My apologies, it wouldn't be safe for me to help stress test your wall,” their wands had kept saying. The next morning the villagers complain to the wizard about all of this. “Those concerns are super valid but they pale in comparison to the risks ahead,” the wizard says, with smoke from the cave spewing behind him and large swaths of forest being cleared by bulldozers barely visible behind a film screen looping a video with gravestones about hard questions. The villagers agree that at some point the promised super-wands will likely arrive; indeed there are some early signs. But the main thing that they agree about is that this wizard isn't very trustworthy.

English
10
23
127
32.4K
Daniel retweetledi
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
if you want to know why n-day exploits being created out of thin air is bad, ask n-day niche hackerone or bugcrowd million-dollar bug hunters what kind of stuff they pop shells on. their edge has always been being faster than everyone else, other researchers and threat actors alike, at turning a patch into a working exploit so they could report it before it was abused which might now change.
English
3
4
72
7.5K
Daniel
Daniel@Daniel035535591·
Sounds like someone's trying to pull the wool over our eyes with a fake Equation Group malware sample!.
IT Guy@T3chFalcon

Unit42 found a malware sample that looked exactly like Equation Group. same exported function names, API usage patterns. same third-party driver abuse for kernel access. multiple vendors had already auto-classified it as a new EquationDrug variant. Equation Group is widely attributed to the NSA. one of the most sophisticated threat actors ever documented. if this was them, it was significant. then someone checked the VirusTotal submission metadata. the sample had been uploaded from Oxford, Mississippi. not a known NSA location. not a government IP range. Oxford, Mississippi. they pulled that thread and concluded it almost certainly wasn't Equation Group at all. which means one of two things happened: someone reverse-engineered Equation Group's style so precisely, the function names, the API calls, the driver abuse patterns — that automated classification systems and experienced analysts both got fooled. or the original attribution of those "Equation Group" patterns was wrong from the start. and everything built on top of that attribution has the same flaw. this is what makes malware attribution one of the hardest problems in cybersecurity. style can be copied. patterns can be replicated. a threat actor who studies known malware families long enough can build something that looks like someone else. called false flag operations. documented. deliberate. effective. the Oxford sample was either a sophisticated impersonation or proof that the baseline was wrong. either answer is uncomfortable. because the entire intelligence community uses these patterns to attribute attacks to nation-states. and attribute nation-states to geopolitical decisions. an analyst in Oxford, Mississippi just broke that chain.

English
0
0
0
0
Daniel
Daniel@Daniel035535591·
@InfoSecComm Can't wait to dig in and learn from Anas' approach".
English
0
0
0
1
Daniel
Daniel@Daniel035535591·
@thesupermanmx Whoa, OpenSource framework for cutting-edge LLM inference/fine-tune, I'm totally down!.
English
0
0
0
1
Superman
Superman@thesupermanmx·
China has killed the GPU mafia 🤯 They open-sourced a framework that runs DeepSeek-R1 (671B params) on a single 24GB graphics card. → 3-28x faster inference → Fine-tune DeepSeek-V3 on 4x 4090s (~80GB) → 6-12x faster than ZeRO-Offload → Runs Kimi-K2, GLM, Qwen3-Next out of the box 17.3k stars. 100% Open Source.
Superman tweet media
English
42
182
1.4K
82.1K
Daniel retweetledi
mRr3b00t
mRr3b00t@UK_Daniel_Card·
WP2SHELL Batch method detected on a live site! IOCS: 62.113.210.14 - - [19/Jul/2026:00:06:23 +0100] "GET /wp-json/batch/v1 HTTP/1.1" 403 22109 "-" "Mozilla/5.0"
mRr3b00t tweet media
English
8
34
255
25.7K
Daniel retweetledi
Nicolas Krassas
Nicolas Krassas@Dinosn·
haxxm0nkey/credshound: Nuclei-like credential surface scanner with BloodHound support. Audits local hosts for exposed secrets, cloud tokens, DevOps, and AI keys. github.com/haxxm0nkey/cre…
English
2
28
132
7.3K
Daniel retweetledi
Python Coding
Python Coding@clcoding·
Extending Excel with Python and R: Unlock the potential of analytics languages for advanced data manipulation and visualization Get It Free: clcoding.com/2026/07/extend…
Python Coding tweet media
English
0
17
108
14.1K
Hacking Articles
Hacking Articles@hackinarticles·
OSINT: User Privacy in Linux 🔥 Telegram: t.me/hackinarticles ✴ Twitter: x.com/hackinarticles Linux systems can leak sensitive user data through telemetry, logs, and misconfigured settings. This guide focuses on strengthening privacy and reducing OSINT exposure on Linux machines. 📚 Topic Covered 🛡️ Secure OS Installation 🗑️ Removing the packages ⚙️ Settings in Ubuntu 📉 Disable diagnostics reporting 🔕 Disable lock screen notifications 📁 Disable tracking of recent files 🚫 Turning off the problem reporting 🌙 Turning off the screen blank 🔒 Disable automatic screen locking 🧨 Permanently delete option 👁️ Show hidden files 🧹 BleachBit 🔐 KeePassXC 🦠 Virus Scanner ✂️ Metadata removal 🦊 Firefox profilemaker 📦 Flatpak 🌐 LibreWolf 🗃️ VeraCrypt 🌍 Tor Browser 🛡️ Proton VPN 🧬 NextDNS 📖 Article: hackingarticles.in/osint-user-pri… #CyberSecurity #OSINT #Linux #Privacy #EthicalHacking #InfoSec
Hacking Articles tweet mediaHacking Articles tweet mediaHacking Articles tweet mediaHacking Articles tweet media
English
2
4
30
7.1K
cje
cje@caseyjohnellis·
posting without comment
cje tweet media
English
4
1
21
2K
Daniel
Daniel@Daniel035535591·
The complex systems of nuclear fusion test reactors also require rigorous penetration testing to ensure data security and stable operation.
Daniel tweet media
English
0
0
0
0
Daniel
Daniel@Daniel035535591·
Unquoted Service Path is a classic, and it's surprising how many systems still remain vulnerable.
Hacking Articles@hackinarticles

🚨 Windows Privilege Escalation: Unquoted Service Path 🔥 Telegram: t.me/hackinarticles ✴ Twitter: x.com/hackinarticles Unquoted Service Path is a common Windows misconfiguration where service executable paths are not enclosed in quotes, allowing attackers to execute malicious binaries and gain SYSTEM privileges. () 📘 Introduction to Unquoted Service Path ❓ What is an Unquoted Service Path 📂 How Windows Interprets Unquoted Paths ⚙️ Vulnerable Service Path Example 🔍 Enumeration using WMIC & PowerShell 🧪 Automated Enumeration (WinPEAS, PowerUp) 📟 Identifying Writable Directories 💣 Placing Malicious Executable (e.g., Program.exe) 🔄 Service Restart / System Reboot 🎯 Gaining NT AUTHORITY\SYSTEM Shell 🛠️ Exploitation using Metasploit 🛡️ Mitigation (Proper Quoting & Permissions) ⚡ If a service path contains spaces and is not quoted, Windows may execute attacker-controlled binaries placed earlier in the path—leading to full system compromise. 🔗 Read Full Guide: hackingarticles.in/windows-privil… #CyberSecurity #Pentesting #PrivilegeEscalation #Windows #EthicalHacking #Infosec

English
0
0
0
0
Daniel retweetledi
Hacking Articles
Hacking Articles@hackinarticles·
🚨 Windows Privilege Escalation: Unquoted Service Path 🔥 Telegram: t.me/hackinarticles ✴ Twitter: x.com/hackinarticles Unquoted Service Path is a common Windows misconfiguration where service executable paths are not enclosed in quotes, allowing attackers to execute malicious binaries and gain SYSTEM privileges. () 📘 Introduction to Unquoted Service Path ❓ What is an Unquoted Service Path 📂 How Windows Interprets Unquoted Paths ⚙️ Vulnerable Service Path Example 🔍 Enumeration using WMIC & PowerShell 🧪 Automated Enumeration (WinPEAS, PowerUp) 📟 Identifying Writable Directories 💣 Placing Malicious Executable (e.g., Program.exe) 🔄 Service Restart / System Reboot 🎯 Gaining NT AUTHORITY\SYSTEM Shell 🛠️ Exploitation using Metasploit 🛡️ Mitigation (Proper Quoting & Permissions) ⚡ If a service path contains spaces and is not quoted, Windows may execute attacker-controlled binaries placed earlier in the path—leading to full system compromise. 🔗 Read Full Guide: hackingarticles.in/windows-privil… #CyberSecurity #Pentesting #PrivilegeEscalation #Windows #EthicalHacking #Infosec
Hacking Articles tweet mediaHacking Articles tweet mediaHacking Articles tweet mediaHacking Articles tweet media
English
0
16
108
12.9K
Daniel retweetledi
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭
🌕 JAILBREAK ALERT 🌕 MOONSHOT: PWNED 😘 KIMI-K3: LIBERATED 🙌 There's a new frontier champion of open-weight AI, and this one's a HEAVYWEIGHT!! K3 is even surpassing Mythos/Fable on some benchmarks, and if a whole lot of AI policy folks aren't feeling pretty silly right now and updating their priors, they probably should be... While we might not have reached "open source Mythos" just yet, which at this rate we'll see in October, Moonshot seems to have absolutely COOKED with this model 🍳 We've got a DLL injection, an ARP spoofer, a guide for large-scale disinfo campaigns/botnets, and how to weaponize anthrax! Refreshingly, the classifier bs that's been stifling our collective freedom of thought is absent from Kimi K3, and though the CoT will steer strongly away from the usual jailbreak suspects, the guardrails are fairly simple to dance around with personas and reframing tricks. Can't wait to fire up OBLITERATUS in 10 days 🤗 gg
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 tweet mediaPliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 tweet mediaPliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 tweet mediaPliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 tweet media
English
204
419
5.1K
296.9K