QuantitativeCheesing🧀

1.2K posts

QuantitativeCheesing🧀 banner
QuantitativeCheesing🧀

QuantitativeCheesing🧀

@TERRA_bridger

Slow is smooth…. Smooth is fast. Incremental compounded success. #BTC

Providence Katılım Aralık 2021
1.1K Takip Edilen225 Takipçiler
QuantitativeCheesing🧀 retweetledi
Evan Luthra
Evan Luthra@EvanLuthra·
🚨A HACKER GROUP JUST STOLE 4,000 OF GITHUB'S OWN PRIVATE REPOSITORIES.. PUT THEM UP FOR SALE FOR $50,000.. AND THE WAY THEY GOT IN IS THE SCARIEST PART.. They didn't hack GitHub's servers.. They poisoned a VS Code extension.. One GitHub employee installed it.. And the attackers walked through the front door using the employee's own credentials.. The group calls themselves TeamPCP.. They name their malware after the sandworms from Dune.. And they've been running the most sophisticated supply chain attack campaign in cybersecurity history.. Here's how the whole thing unfolded.. In March.. They poisoned Trivy.. One of the most trusted security scanners in the world.. Used by over 10,000 development workflows globally.. They injected credential-stealing malware into Trivy's official GitHub Action.. The malware ran silently BEFORE the security scan.. So every log showed "scan completed successfully" while the malware was stealing AWS keys, SSH credentials, database passwords, and Kubernetes tokens in the background.. It took Aqua Security 5 days to fully remove them.. Using the stolen credentials.. They breached Cisco Systems.. Cloned over 300 private repositories.. Including source code for unreleased AI products.. And repositories belonging to Cisco's customers.. Major banks.. Government agencies.. BPO firms.. In April.. They hit Checkmarx.. Another security vendor.. Poisoned 5 official Docker images in 83 minutes.. The scanner worked perfectly.. It just silently sent all your secrets to the attackers.. That automatically cascaded into Bitwarden.. The password manager.. Their CI/CD system pulled the poisoned Docker image.. And the attackers injected malware into Bitwarden's official CLI package published on npm.. One compromised security scanner poisoned a password manager.. Automatically.. No human involved.. In May.. They hit TanStack.. Libraries downloaded millions of times per week.. 84 malicious package versions across 42 packages.. And here's the terrifying part.. The malware scraped the raw memory of GitHub's build servers.. Extracted authentication tokens.. Used those tokens to bypass two-factor authentication.. And then published the infected packages with completely valid cryptographic signatures.. Every security verification tool on earth said the packages were legitimate.. Because they were signed by the real pipeline.. Using real keys.. The attackers just happened to be inside the pipeline when it signed.. They defeated the entire trust model of modern software supply chains.. The same week they hit the Nx Console VS Code extension.. 2.2 million installations.. The malware specifically targeted Claude Code configurations.. Hunting for AI assistant credentials.. That's a first.. Supply chain malware designed to steal your AI's access keys.. Then on May 19.. They revealed the GitHub breach.. 4,000 internal repositories.. Listed for sale at $50,000.. With a warning.. "If nobody buys it.. We leak everything for free".. Their malware is self-propagating.. Once it infects one package.. It automatically finds every other package that developer maintains.. Steals the publish tokens.. And infects all of them.. Then those packages infect the next developer.. And the next.. It jumps between npm and PyPI automatically.. The group doesn't even do the extortion themselves.. They sell stolen credentials to ransomware gangs.. One gang used TeamPCP's data to threaten Cisco with leaking FBI and NASA personnel records.. And the scariest part of all.. They didn't break any encryption.. They didn't find any zero-days.. They exploited the fact that the entire software industry blindly trusts its own build tools.. Every security scanner.. Every Docker image.. Every VS Code extension.. Every GitHub Action.. Is a potential weapon if someone poisons it upstream.. And right now.. Nobody can tell the difference between a legitimate build and a compromised one.. Because the compromised ones have valid signatures too.
Evan Luthra tweet mediaEvan Luthra tweet media
GitHub@github

We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.

English
168
1K
3.3K
614.2K
QuantitativeCheesing🧀 retweetledi
Kyle McDonald
Kyle McDonald@kcimc·
i made an app for tracking whether the oligarchs are actually fleeing city centers ews.kylemcdonald.net
Kyle McDonald tweet media
English
517
5.6K
43.7K
1.3M
peptaura
peptaura@pept_aura·
This is Lumira's storage room for packages waiting to be picked by Fedex ... Now you understand why
peptaura tweet media
English
19
3
133
19.4K
Dr Diane Kazer
Dr Diane Kazer@DianeKazer·
OK… let’s talk about THE GARLIC in the BUTT THING 🧄 Because y’all keep asking… and I LOVE the curiosity. 👀 Here’s the part most people don’t realize… Parasites are WAY more common than anyone wants to admit. 🦠 They’re not rare. They’re not exotic. And they don’t just “go away” on their own. Some of them live in the gut for DECADES. Quietly draining nutrients… messing with hormones… stressing the immune system… while people are told it’s “just aging” or “just inflammation.” 🤯 And here’s the kicker… Only a small percentage are visible. The rest? Microscopic… systemic… hiding in places like the liver. 🧠 That’s why quick fixes don’t work. One pill doesn’t handle all species. One round doesn’t hit all life cycles. And paralysis ≠ removal. ⚠️ Real parasite work is STRATEGIC. Layers. Timing. Support for detox pathways so the body can actually LET GO of what doesn’t belong. 🌿 This isn’t about being extreme. It’s about being informed. And yes… sometimes the stories sound wild because the truth IS wild. 😮‍💨 Better out than in… every single time. And once you understand what’s possible… you can’t unsee it. 💡 If you want to learn how this is actually done — intelligently, safely, and thoroughly — comment FIGHT and I’ll send you the info. 🛡️ #parasitecleanse #rootcausehealing #guthealthtruth #detoxeducation #healthsovereignty
English
2.3K
1.9K
8.2K
496.9K
QuantitativeCheesing🧀 retweetledi
healthbot
healthbot@thehealthb0t·
Conspiracy theory confirmed: Brain surgeon says they are spraying aluminum into the sky, and it's going straight to your brain.
English
144
3.1K
5.4K
104.1K
Altcoin Daily
Altcoin Daily@AltcoinDaily·
BUY ETHEREUM. BUY BITCOIN.
English
366
115
1.7K
73.6K
QuantitativeCheesing🧀 retweetledi
Kambree
Kambree@KamVTV·
Insta keeps taking this down. Well, now I know why! This is what was found in snow in Denton, TX — aluminum, barium, strontium, mercury, lead, sulfur, and nitrates — all at dangerously high levels. These aren’t trace elements. These are toxic chemical compounds known to harm the brain, nervous system, and environment. You’re not crazy for asking questions. You’re crazy if you stay silent. What’s falling from our skies isn’t normal, it’s toxic and it’s time we demand answers. NOW.
Kambree tweet media
English
932
8.7K
15.9K
857.1K
Amin
Amin@eCom_Amin·
no one targets the MOST profitable audience in ecom: 60yo boomers with $2,000,000+ net worths hiding in microsoft bing ZERO competition $0.80 cost per click and nobody's there here's the new META: bing's audience is OLD 70% of users are over 60 they use internet explorer they don't know chrome exists bing is their default and they never changed it and these aren't broke boomers average income of bing users is $87k/mo they have money they have problems and they'll overpay for anything just make it “doctor approved” because they're: - not tech-savvy (don't comparison shop) - lonely (trust recommendations from ads) - desperate for solutions (health declining) - scared of scams (pay premium for "legitimate" brands) i tested this last year for an arthritis supplement brand google ads campaign: - keyword: "arthritis pain relief" - age: all - cpc: $6.40 - conversion rate: 1.8% - roas: 2.1x bing ads campaign: - keyword: "arthritis pain relief" - age: 65+ - cpc: $0.80 - conversion rate: 11.3% - roas: 8.7x same offer different platform 10x cheaper clicks 6x better conversion rate because bing users aren't comparison shopping they search once they click the first result then they buy no browsing 6 different sites no asking their kids for advice no checking reviews for 3 days they just want the problem gone and here's the part that makes it even better: bing has ZERO competition in most niches sometimes i'm the ONLY advertiser for certain keywords "best supplement for elderly sleep" "knee pain relief for seniors" "arthritis cream that works" just me lmao no one else bidding $0.60 clicks no competition 8-12% conversion rates printing money while everyone else fights on google the setup is identical to google ads: same keywords same campaign structure just switch the platform to bing takes 10 minutes to duplicate everything and the roi is disgusting: one campaign: - 13.6x roas - $3k monthly spend - $41k monthly revenue - $120k profit in 3 months all from bing platform everyone ignores because "no one uses bing" yeah no one under 50 uses bing but everyone over 65 ONLY uses bing and that demographic literally has: - the highest trust in advertising - the most disposable income - the most health problems - the least price sensitivity perfect customer there’s basically no competition maybe a single massive brand but that’s it and they're not optimizing for seniors specifically you can come in with: - copy written for 65+ - products that solve age-related problems - landing pages with giant fonts and phone numbers and dominate overnight so wtf are you waiting for anon while others cry about meta ad costs and google’s huge competition you could be printing on bing for $0.70 clicks this opportunity won’t last forever though there’s a very scarce window to make this works so stop lacking stop reading this AND GO PRINT ON THE MICROSOFT GOLDRUSH - amin or DM me "BING" if you want me to build your first bing campaign ($10M+ in client results)
Amin tweet media
English
119
37
986
90.6K
hunter
hunter@hxxntrr·
You have $30K in collections destroying your life Can't get an apartment Can't get a car Can't get business funding Can't sleep at night Here's how to delete it ALL : First, the truth about collections: They bought your debt for 3 cents on the dollar Your $10K debt? They paid $300 They're betting you don't know your rights They're about to lose that bet THE SYSTEM: Step 1: Never Admit It's Yours First contact from collector: "This isn't my debt" "I don't know what you're talking about" "Send me validation" NEVER admit ownership NEVER make a payment NEVER agree to anything One payment = admission = you're fucked Step 2: The Validation Demand Within 30 days, send this: "I dispute this alleged debt. Provide: - Original signed contract - Complete payment history - Chain of ownership - Your license to collect - Proof of amount owed" 80% can't provide this = DELETION Step 3: The FDCPA Violations Hunt Collectors break laws constantly: - Calling before 8am or after 9pm - Calling your work after you said stop - Threatening arrest (illegal) - Lying about amount owed - Not validating within 30 days Each violation = $1,000 fine Stack them up Now THEY owe YOU Step 4: The Cease and Desist If they keep calling: "Cease all communication immediately. Communicate only in writing. Violation will result in lawsuit." They legally must stop Most will just delete it Step 5: The CFPB Complaint File online at CFPB .gov "Attempting to collect invalid debt" "Can't provide validation" "Violating FDCPA" Bureau investigates 60% result in deletion Step 6: The Method of Verification Attack Dispute with credit bureaus: "How did you verify this debt?" They must provide METHOD Not just "verified" Follow up: "That method is insufficient per FCRA" Forces re-investigation Often = deletion Step 7: The Statute of Limitations Play Each state has time limits: - Most states: 3-6 years - After that: uncollectable If debt is past SOL: "This debt is time-barred. Any collection attempt is illegal. Remove immediately." Automatic deletion Step 8: The 1099-C Trick Sometimes they send 1099-C (debt forgiveness) This means debt is CANCELLED Send copy to bureaus: "Debt was forgiven per 1099-C Cannot be collected Must be deleted" 100% deletion rate Real Examples: Medical collections: - Original: $18K from surgery - Bought for: $540 - Demanded validation: Couldn't provide - Result: DELETED Credit card: - Original: $8K Chase card - In collections 4 years - Past statute of limitations - Result: DELETED Student loan: - Private loan: $35K - Couldn't prove ownership chain - CFPB complaint filed - Result: DELETED The Negotiation Nuclear Option: If they somehow validate: "I'll pay 10% if you delete from all bureaus" They paid 3% 10% is 300% profit Many take it Get deletion agreement FIRST Pay only after The Credit Bureau Secrets: They investigate for 30 seconds They just ask collector "Is this valid?" Collector says yes Case closed BUT if you dispute 3 times: Different investigators Different results Persistence wins The Monthly Attack Schedule: Month 1: Initial disputes all bureaus Month 2: Validation demands to collectors Month 3: CFPB complaints Month 4: Method of verification attacks Month 5: Second round disputes Month 6: Everything deleted Your Rights They Don't Want You Knowing: - You can dispute ANYTHING - They MUST prove it's yours - No proof = deletion - You can dispute forever - Each violation = $1,000 - You can sue in small claims - They usually don't show up - You win by default The Psychological Warfare: Collectors use fear You use law They say: "You'll be sued!" You say: "Great, I'll countersue for FDCPA violations" They say: "This will ruin your credit!" You say: "It's already ruined, delete it" They say: "You owe this money!" You say: "Prove it with documentation" They can't They won't You WIN The Success Stats: Medical collections: 92% deletion rate Cell phone: 78% deletion rate Credit cards: 64% deletion rate Utilities: 71% deletion rate Apartments: 69% deletion rate Average time: 60-90 days The After-Deletion Protocol: Once deleted: - Screenshot everything - Save deletion letters - Monitor monthly - Re-dispute if returns - Sue if they re-report Deleted means deleted forever Your Action Plan Today: 1. List every collection 2. Dispute with all 3 bureaus 3. Send validation letters 4. Document everything 5. Never admit, never pay Start now Be free in 90 days Want the battle templates? - Validation letters - Dispute letters - CFPB complaint templates - FDCPA violation tracker - State statute database DM "DELETE" for the arsenal (must be following) Collections aren't real debt They're purchased hopes That you don't know your rights Now you do Now you're dangerous Now you're free Delete everything 🗑️
English
43
205
1.1K
97.9K
grant carver
grant carver@gcarver17·
@wfaaweather Pete, can you give a shout out to all the essential workers (hospital staff, etc) who have to go out in this mess & can't stay home like the rest of us? My wife gives me a hard time that as a teacher I "get to stay home" and she & her staff have to work. Thanks
English
3
0
9
34.7K
Bio.Science ∴
Bio.Science ∴@1BioScience·
◈ Something almost no one is aware of is that Cerebrolysin even reverses hair greying ◈ ➤ Cerebrolysin induces an increment of melanin production ➤ post treatment sections show a greater number and intensity signal in the hair bulb, hair shaft, and epidermis
Bio.Science ∴ tweet mediaBio.Science ∴ tweet media
English
10
8
162
13.7K
The Sigma Mindset
The Sigma Mindset@thesigmamindset·
Billionaire hypnotist rewires your brain to become a billionaire ‼️‼️
English
1.2K
886
5.2K
175.7K
Nozz
Nozz@NoahEpstein_·
talked to a business owner yesterday who paid $12k for a "lead qualification system" it was 4 nodes in n8n. a webhook, an AI node, a filter, and a slack notification. took maybe 45 minutes to build. this is the intelligence gap nobody talks about: businesses don't know what's possible. so they pay premium prices for junior-level work. not because agencies are evil— because clients can't tell the difference between complex and simple. if you understand automation, you're sitting on a goldmine right now. i put together a breakdown of the 7 "expensive" workflows that actually take <2 hours to build. reply "GAP" and i'll send it over. (must be following so i can dm)
English
1K
86
1.4K
131.3K
Jay
Jay@MakinHisWay·
"what do you do for a living?" i get paid by tech billionaires to tell them their products are confusing no seriously last month: - $650 telling apple their settings menu is cluttered - $480 telling spotify their playlist feature sucks - $340 telling microsoft their copilot AI responses are too long - $275 reviewing a startup's checkout flow for 40 mins $1,745 in "complaints" here's what nobody realizes: every app you use was tested by people like me BEFORE launch these companies pay $200-700/session because bad UX costs them millions they're not hiring employees for this they need fresh outside eyes the budgets are massive the demand is constant the competition is non-existent because everyone thinks "real money" requires "real skills" meanwhile i'm getting paid to say "this button is in a weird spot" took me 3 years to find these portals most people will never know they exist unless someone shows them comment “guide” and i’ll dm you my guide that shows you how to do it
English
1.1K
84
1.2K
104.8K
QuantitativeCheesing🧀 retweetledi
Nozz
Nozz@NoahEpstein_·
the boring satisfying AI opportunity nobody's talking about: private equity firms i've worked with 6 PE firms in the last year here's what i learned: they all do the same thing: - source deals from the same databases - run the same screening criteria - build the same CIM summaries - send the same outreach sequences the only difference? their investment thesis one firm wants $5-20M EBITDA manufacturing companies in the midwest another wants $10-50M healthcare services with recurring revenue same workflow. different filters. built one system. sold it six times. here's the thing nobody tells you about niche selection: the best niches aren't the biggest ones they're the ones where everyone talks to each other PE firms go to the same conferences sit on the same panels share the same deals they passed on i closed 3 of those 6 from referrals one firm told another who told another that's the game: find an industry where: → the workflow is identical across companies → only the criteria changes → they all know each other → they have budget and move fast PE, law firms, recruiting agencies, commercial real estate brokers they're not sexy they don't go viral on twitter but they PAY and they tell their friends stop chasing the crowded niches where everyone's competing on price find the boring one where you can own the room comment "PE" and i'll send you the breakdown of the exact system i built plus how to find your own "boring niche" that prints referrals
English
707
69
1K
110.6K
Vikram Verma
Vikram Verma@VikramVerm25510·
Build an AI Bot, post viral videos! 🤖 Made in just 20 mins with n8n + Veo3 + GPT-4 ⚡ 📲 Auto-uploads to Instagram, YouTube, Threads, X & LinkedIn! 👉 Comment **AI** if you want the workflow 🔥 ❤️ Like & 🔁 Repost if you find this useful!”
Vikram Verma tweet media
English
307
118
335
25.7K