Tony

7.8K posts

Tony banner
Tony

Tony

@TJ_Null

Blue Teamer in Disguise. Blog at https://t.co/spa33ybIVL. SANS Netwars Champion. Former community manager and founder of the Offsec community for @offsectraining

Katılım Mart 2013
489 Takip Edilen23.3K Takipçiler
Sabitlenmiş Tweet
Tony
Tony@TJ_Null·
As Promised! I have decided to update my guide for preparing for OSCP. The guide is full of new updates and information to help you prepare for PEN-200/PWK 2.0. If anyone wants to read it here it is: netsecfocus.com/oscp/2021/05/0…
English
31
340
958
0
Tony retweetledi
Mike Felch (Stay Ready)
Mike Felch (Stay Ready)@ustayready·
As yall may have realized, I disappeared from the community for a little while we fight the most difficult fight of our life. My wife Angela was diagnosed with stage 3 cancer. We need all the help we can get, please consider supporting our fight. givesendgo.com/anchors-for-an…
English
10
39
113
22.1K
Steve S.
Steve S.@0xTriboulet·
> Be world-class researcher @ilove2pwn_ > *Refuse* to learn PowerPoint 💀
Steve S. tweet media
English
12
0
37
3.8K
Tony retweetledi
EvilMog® @mog.evil.af
EvilMog® @mog.evil.af@Evil_Mog·
This is the best explanation of how hashcat works
EvilMog® @mog.evil.af tweet media
English
1
5
30
2.8K
Tony retweetledi
Chompa
Chompa@ch0mpaa·
We are re-launching Houston bsides I would greatly appreciate a like and repost to spread the word. Will be taking place September 17, 2026 call for papers will be announced soon thank you! linkedin.com/posts/houston-…
English
0
8
10
3.2K
Tony retweetledi
Chompa
Chompa@ch0mpaa·
🎟️ BSides Houston tickets go on sale this week! We're proud to partner with the Houston Food Bank every ticket sold helps support their mission to fight food insecurity in our community. Stay tuned and be ready! 🚀 houstonbsides.org #BSidesHouston #InfoSec #Cybersecurity
English
0
1
2
346
Tony retweetledi
Mr.Un1k0d3r
Mr.Un1k0d3r@MrUn1k0d3r·
It is kind of sad that the best way to launch @claudeai is to use the following command: claude --model claude-sonnet-4-6. They have to stop with the guardrail nonsense on their latest model. Cyber is a not a crime. #AI #cyberisnotacrime
Mr.Un1k0d3r tweet media
English
4
7
62
6.4K
Tony retweetledi
Arszilla
Arszilla@arszilla·
@TJ_Null Yep - my whole organization is in CVP yet we face the same bullshit. What’s the point of CVP then?
English
0
1
1
447
Tony retweetledi
BridgeMind
BridgeMind@bridgemindai·
FABLE 5 CAME BACK NERFED. We re-ran the July 1st version of Claude Fable 5 on BridgeBench. The results are brutal: Debugging: 86.2 → 25.9 Refactoring: 73.6 → 38.4 Hallucination: 75.9 → 61.7 The new guardrails are kicking in on way too many tasks and falling back to Opus 4.8. This is not the model that got banned. Anthropic owes everyone an explanation.
BridgeMind tweet media
English
622
1K
8.7K
2M
Tony retweetledi
JUMPERZ
JUMPERZ@jumperz·
so i tested fable for straight 4 hours.. > its clearly nerfed > it keeps automatically switching me back to 4.8 > burns through quota way faster than it should > flags normal coding as if it's something dangerous > the one-shot magic is gone > the output feels like slop now > half my prompts never even reach fable, they hit Opus instead its like you're paying the fable premium for a fallback answer.. until they tune the safeguards down and fix the metering, fable in this state isn't worth building with honestly.
Claude@claudeai

Fable 5 is back.

English
150
69
970
132.9K
Tony
Tony@TJ_Null·
@1kadaba Tried that on one my prompts and kicked back to Opus 4.8.
English
0
0
1
345
kadaba
kadaba@1kadaba·
@TJ_Null If you are using the gui version, flip it back to fable from opus while it’s processing
English
1
0
0
410
Tony
Tony@TJ_Null·
Tried to use Fable 5 today and here is how it went. Asked it to test some tools against a development box I have. Immediately gets flagged by its cyber security guard rails. (I already have a cybersecurity exception) Switches back to opus 4.8 to run my tests…
English
11
1
38
7K
Tony
Tony@TJ_Null·
@0xdf_ I have a Max Plan 5x. I do have access to fable but with the prompts I have sent it kicks back to Opus 4.8. Was really hoping to see how Fable 5 would work with some of the projects I have. Do you know when Fable 5 plans to make more exceptions for the infosec community?
English
1
0
0
162
0xdf
0xdf@0xdf_·
@TJ_Null Fable is not meant for cyber security use cases. Cvp does not apply. And you aren't paying for fable if it falls back to opus.
English
1
0
0
239
Tony
Tony@TJ_Null·
@arszilla It is even more annoying when you know you are already approved and you still get hit by the guard rails for it.
Tony tweet media
English
1
0
2
278
Arszilla
Arszilla@arszilla·
@TJ_Null Opus 4.8, Fable 5 and Sonnet 5 all did the same for me as well. Had to revert to Opus 4.7 instead so I can get my work done. Even if you “appeal”, I don’t hear jack nor anything changes, then what’s the point of having CVP?
English
1
0
2
366
Tony retweetledi
BridgeMind
BridgeMind@bridgemindai·
I just paid $321 for a coding session where Fable 5 refused to do the work. Here is where the work actually went: Fable 5: $78 Opus 4.8: $242 75% of the session got routed to Opus because the new classifiers kept flagging routine coding work as cybersecurity risk. The model I chose did a quarter of the job. The fallback did the rest. Anthropic said a small fraction of tasks would fall back. My receipts say otherwise.
BridgeMind tweet media
English
325
276
3.6K
945.9K
Tony
Tony@TJ_Null·
@rootsecdev Looks like shit post to me. Then again I watch my robot vacuum traffic, and it makes me question a lot of things...
English
0
0
1
516
rootsecdev
rootsecdev@rootsecdev·
Not sure if this is real or shitpost but I’m here for it all
rootsecdev tweet media
English
33
32
1.2K
126.8K
Tony
Tony@TJ_Null·
@zh0nb @BsidesHbg They were not but I can make them public. Let me get a repo together and I can share my slide deck.
English
0
0
1
16
Tony
Tony@TJ_Null·
At @BsidesHbg yesterday I did a talk about how I built a modular asset discovery framework by using open source tooling to help automate my work when handling large engagements. That tool is called cygor: github.com/tjnull/cygor
English
2
12
63
4.8K
Tony retweetledi
Jason Lang
Jason Lang@curi0usJack·
Prove it. Reinstate Nightmare Eclipse on GitHub.
Microsoft Security Response Center@msftsecresponse

Over the past several days, we have been listening to the conversation around coordinated disclosure and the relationship between security researchers and vendors. We recognize that this relationship is both critical and, at times, fragile. We deeply value the security community, and will continue to take your feedback seriously. To be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research. When an individual breaks the law and engages in malicious activity causing real harm to our customers, we will work with law enforcement as appropriate. We recognize the work that goes into researching and submitting a vulnerability. We are committed to approaching every interaction with transparency, clear communication, and professionalism. We continue to believe strongly in Coordinated Vulnerability Disclosure as the foundation for protecting customers and improving our products. Each year we process a high volume of vulnerability reports. That volume continues to grow and will continue with the rise of AI-enabled research. We acknowledge that some interactions have fallen short and are working to learn from them. Many of us have experience on both sides of this work, as researchers reporting vulnerabilities and as responders triaging and assessing them. That perspective informs how we approach this feedback and the importance we place on getting it right, particularly as the volume and complexity of research continues to grow. The security community plays a vital role in helping us protect customers. We are committed to maintaining a constructive and respectful relationship and growing together. We know that, given the nature of this work, there will at times be misunderstandings. We remain committed to engaging in good faith and to providing a respectful and professional experience for all researchers, regardless of past interactions.

English
4
52
583
21K