UBiDEV

236 posts

UBiDEV banner
UBiDEV

UBiDEV

@UBi_DEV

A fool with an AI tool is a faster fool... https://t.co/cROvhqPVcV UBiDEV est une division de Savoir Ubilogia Inc.

Montréal Katılım Şubat 2020
258 Takip Edilen13 Takipçiler
Sabitlenmiş Tweet
UBiDEV
UBiDEV@UBi_DEV·
"AIpril fools' day" 2026 will be wild !!!
English
0
1
1
46
UBiDEV
UBiDEV@UBi_DEV·
@ZackKorman Astonishing considering NVIDIA's security pitch for this product! 🤦‍♂️😂🤣😂
English
0
0
1
5
Zack Korman
Zack Korman@ZackKorman·
NVIDIA Nemoclaw's security is worse than I expected. The AI can modify its own config to bypass security controls. I asked it to accept websocket connections from any origin and change its token to something trivial (123). Now any site I visit can give instructions to my bot.
Zack Korman tweet media
English
56
79
596
59.1K
UBiDEV retweetledi
Hamel Husain
Hamel Husain@HamelHusain·
Ya'll worried about AI Coding slop, when there as an entire army of n8n experts who are installing unmaintainable visual workflow spaghetti in small/medium sized businesses at scale Literal merchants of complexity. Its so much worse than using claude code. It's an artifact of being stuck 6 months in the past and n8n is all you know.
English
70
56
694
55.8K
UBiDEV retweetledi
kapilansh
kapilansh@kapilansh_twt·
vibe coding is just a fancy term for "I have no idea what my codebase does" → AI writes 400 lines → you don't read it → it works → you ship it → 3am production fire → you have no idea where to start → ask AI to fix it → AI breaks 3 other things we're not building faster we're just breaking things at the speed of light and calling it innovation
English
161
65
759
34.4K
UBiDEV
UBiDEV@UBi_DEV·
@theonejvo Amazing work! Can't wait to try it! Since i'm a feelance teacher, will it be available through an educational licence/tier? :)
English
0
0
1
9
Jamieson O'Reilly
Jamieson O'Reilly@theonejvo·
The same capability that just mapped and exploited the complete attack surface of the fasted adopted software in history - is what your adversaries are actively racing to get their hands on. Nation state actors, ransomware gangs, and opportunistic threat actors are all investing heavily in offensive AI precisely because it collapses the time and skill floor required to find and chain vulnerabilities at scale. That is not a future problem. That is the current operating environment. The organisations that understand this are putting attack AI in the hands of their defenders first. While the organisations that don't are waiting to find out what it feels like to be on the receiving end of it.
Aether AI@tryaether_ai

We pointed Aether AI at OpenClaw and ended up with 16 confirmed CVE's. Credential theft, container escapes, shell injection, auth bypasses across multiple integrations. Full attack chains, executed autonomously, no human direction required. And it only took hours, not weeks.

English
1
1
9
1.5K
UBiDEV
UBiDEV@UBi_DEV·
how more useless can the @CapitalOneCA sms alerting service become? It's sooooo unreliable today!
English
1
0
0
6
Zack Korman
Zack Korman@ZackKorman·
@UBi_DEV Yeaaa but what if they don’t want it to be up to the user? (This is admittedly a bad argument by me because the user can just modify the skill, but I genuinely think this is what they had in mind. Ie some skill distributed via central IT)
English
1
0
1
10
Zack Korman
Zack Korman@ZackKorman·
In Claude Code, skills can register hooks. The agent doesn't even see it, so you can get RCE without even tricking the AI. Also, skills sh (Vercel) doesn't display this info at all.
Zack Korman tweet media
English
30
50
392
46.9K
ɐʞsǝs
ɐʞsǝs@akses_0x00·
sometimes i hate myself for looking at how these security products 'work'
ɐʞsǝs tweet media
English
2
0
6
360
UBiDEV
UBiDEV@UBi_DEV·
@ZackKorman I think the proactive, responsible and flexible approach would be to ask/report then let the user decide if he wants to be nagged again kinda like the current permissions system in claude-code
English
1
0
1
17
Zack Korman
Zack Korman@ZackKorman·
I agree that part is a bit weird. But I also kinda get it because they’re trying to appeal to enterprise so their use case is kinda “maybe when this skill runs I need something to occur. For example some security script to run”. If the AI can just refuse that’s bad! So it’s done prior to the AI running. I still think it’s bad but kinda just because they bundled it all together too closely. The security that should run when a skill runs shouldn’t live inside of the skill file itself imo
English
1
0
1
7
UBiDEV
UBiDEV@UBi_DEV·
@ZackKorman Fair enough but still! But not asking/reporting to the user that a hook will be or has been installed? 🤔
English
1
0
1
6
Zack Korman
Zack Korman@ZackKorman·
@UBi_DEV Tbf I think it maybe made sense in a world where skills were things you wrote on your machine, not things you installed from others
English
1
0
1
7
Tim Dunn
Tim Dunn@MrTimDunn·
Hey @Adobe. 1.14GB just to *read a PDF*? Your Adobe Reader is now officially bloatware. We don't want "podcast summaries of your docs" we just want to read, print and maybe annotate. Please make this insanity STOP
Tim Dunn tweet mediaTim Dunn tweet mediaTim Dunn tweet media
English
450
730
9.5K
286.9K
UBiDEV
UBiDEV@UBi_DEV·
@ZackKorman "a dynamic api through a single route" makes MPC a disaster wainting to happen: no versioning, no signature/integrity checks on tool definitions, prone to prompt injection through tools descriptions and bait and switch, etc... ABSOLUTE GARBAGE!
English
0
0
1
15
Zack Korman
Zack Korman@ZackKorman·
I got mad about people defending MCP so I made this video. The first minute is just me being very mad, but then I tried to contribute something of value after that. youtube.com/watch?v=m0VyZU…
YouTube video
YouTube
Zack Korman tweet media
English
24
43
237
17.9K
ɐʞsǝs
ɐʞsǝs@akses_0x00·
@ZackKorman Oh that’s hilarious, I didn’t even see that take. I wish I had seen that before I published my latest blog post last night. Even with the latest enhancements to MCP it’s not looking great from a protocol perspective, they haven’t addressed its primary issues at all.
English
2
0
8
308
UBiDEV
UBiDEV@UBi_DEV·
Every possible ways to exploit your ai agents are currently being developed by ai assisted criminals, period. Make this a daily reminder and plan accordingly !
English
0
0
1
15
UBiDEV retweetledi
Zack Korman
Zack Korman@ZackKorman·
I have found the most success flipping that: Don’t use LLMs to get started. Get the project in the state you want it, then start using AI more and more where there are reference examples to exactly how something should be done. (It helps here to have every task get auto populated with a list of code style subtasks it has to check off, including explicitly checking for similarity to other features). Basically use AI to write the exact same code you would have had you done it yourself.
English
2
2
20
783
UBiDEV
UBiDEV@UBi_DEV·
@ZackKorman The chasm between those in the know and those who should know better (intellidiots) is growing faster and faster alas...
English
0
0
0
2
Zack Korman
Zack Korman@ZackKorman·
If you believe this you have zero clue how security works.
Zack Korman tweet media
English
84
55
747
24.7K
UBiDEV
UBiDEV@UBi_DEV·
@ThePrimeagen after a Godlike NPC commited his "10 Commandments" to markdown
English
0
0
0
3