Manuel Varela Caldas

542 posts

Manuel Varela Caldas banner
Manuel Varela Caldas

Manuel Varela Caldas

@XSStringManolo

Building security-focused software Research · OSS https://t.co/MKIdYGrN6K

España Katılım Şubat 2020
591 Takip Edilen135 Takipçiler
Manuel Varela Caldas
Manuel Varela Caldas@XSStringManolo·
@psomkar1 stringmanolo.qzz.io 95% is vibecoded. I gave it a real website I made manually years ago on a web framewok i made manually as a template and tell the LLMs to port it to React. Then edited every mistake the LLM made and new components also prompting the LLM.
English
0
0
0
214
Omkar
Omkar@psomkar1·
Is there anyone who vibe coded a successful app or website ?
English
367
8
522
164K
Manuel Varela Caldas
Manuel Varela Caldas@XSStringManolo·
@ThePrimeagen You can endup on jail running this software. The openclawn can go rogue and start hacking randoms stuff for any random reasson.
English
0
0
0
62
Bhavani.py
Bhavani.py@Bhavani_00007·
as a dev, what was your first code editor?
Bhavani.py tweet media
English
1.1K
62
1.5K
168.3K
p4
p4@peeefour·
yo, why tf am i duping critical vulnerabilities from October 2025 🫨. fix that shit ha!
English
1
0
16
32.9K
Manuel Varela Caldas
Manuel Varela Caldas@XSStringManolo·
@Yazeed_oliwah I have worked with same model/hardware. Very good model for such low params. The 37B version I think it was.
English
0
0
2
64
black viru5
black viru5@Yazeed_oliwah·
Just started building a AI security agent! First up is a JS analyzer that hunts hidden APIs, generates raw HTTP requests, and find exposes secrets. I’m running it completely locally via Ollama to dodge token limits... though my laptop might actually melt in the process! 😂🔥
English
4
12
121
14.5K
LeighTrinity
LeighTrinity@LeighGi66657535·
Let's hope I was the first to find these vulnerabilities! Spent the day in my underwear picking through huge companies code. 😍 Exploit dev is so fucking fun!!!!! I'll post more about these as I get feedback from the security teams. 😈7000 bucks for a hours work wouldn't be half bad.🥰
LeighTrinity tweet media
English
11
2
166
9.2K
Omeiza (💻,🧑‍🔧)
Omeiza (💻,🧑‍🔧)@0xOmeiza·
will I ever be able to read rust and navigate it's codebases the way I read solidity like it's English? is rust really that difficult or im just not good at it yet? or maybe I should go into plumbing full time.
English
17
1
47
4.8K
Manuel Varela Caldas
Manuel Varela Caldas@XSStringManolo·
@Zinny_Edmund Been using vim last 10 or 15 years and see no reason why should try anything else. Anything that there is available in vscode is available in vim, and if not, anyone can code it.
English
0
0
0
47
Zinny 🎀
Zinny 🎀@Zinny_Edmund·
Whenever I see someone using anything but VS Code, I just assume they know more about programming than me.
Enugu, Nigeria 🇳🇬 English
58
21
498
29.3K
Manuel Varela Caldas
Manuel Varela Caldas@XSStringManolo·
@CyberRacheal Attack surface will increase but empowered close source automated tools will trive. It will kill low hanging fruits at minimum.
English
0
0
0
9
Cyber_Racheal
Cyber_Racheal@CyberRacheal·
AI doesn’t replace cybersecurity It increases the attack surface. Yay or Nay?
English
35
8
108
8.1K
Manuel Varela Caldas
Manuel Varela Caldas@XSStringManolo·
@rcx86 I been working for weeks non stop on an AI scanner. What a headache, let's hope it finds tons of stuff.
English
0
0
0
340
Mr. Rc
Mr. Rc@rcx86·
The age of automated vulnerability research is upon us
Mr. Rc tweet media
English
4
2
88
13.6K
datavorous
datavorous@datavorous_·
I compressed 2.87GB data into 8.9MB (!) using my custom data compressor :D There were 21k json files with cricket match data, I exploited the structure and compressed it to ~42.46 MB The best gzip could do is ~53MB, and 7z ~45MB. Then I combined my compressor + 7z and brought it down to 8.9MB It's PURE randomness, you simply can't compress it further. I had to read about Shannon entropy and algorithmic data compression Full writeup in my GitHub repo!
datavorous tweet media
English
140
159
3.6K
276.8K
Intigriti
Intigriti@intigriti·
Fill in the blanks 🤠 You know your target is super vulnerable if it uses ____
English
30
2
49
9.8K
PeterSR
PeterSR@PeterSRWeb3·
So many people jumping into bug bounties right now... I'm genuinely curious—what's the actual success rate? Like, what % of hunters actually land their first payout? Or consistently make money? Feels like 95%+ quit early with zero $$$ 😅 Thoughts? Stats? Your experience? 👇
English
20
1
106
11K
Manuel Varela Caldas retweetledi
Kim Dotcom
Kim Dotcom@KimDotcom·
Demis Hassabis, a leading AI researcher, says that we need to be better at cybersecurity than AI. His priority to keep AGI from taking over. I worked in cybersecurity for 7 years as a penetration pro and hacked every client. Fortune 500, big budgets. You are toast against AGI.
English
87
112
1.1K
69K
Gergely Orosz
Gergely Orosz@GergelyOrosz·
I REALLY want something on this platform to indicate “this is a real person who typed out a reply” Feels like more than 50% of blue check replies are AI-generated for some weird growth hacking reason And it will only get worse…
English
568
45
2.1K
126.1K
siddharth ☻
siddharth ☻@siddharthkp·
this week on twitter, i've read: saas is dead UI is dead programming is dead what else is dead?
English
792
63
1.7K
116.9K
Manuel Varela Caldas
Manuel Varela Caldas@XSStringManolo·
@JohnTech2023 @zack0x01 I usually perform penetration testing on the products I use every day. If I've already done passive reconnaissance as a regular user, it only takes a few hours to run some checks. It's frustrating that they don't even offer a 'thank you,' much less any bounties or pro privileges.
English
1
0
1
37
GR1FF1N
GR1FF1N@JohnTech2023·
@zack0x01 When I first started I chose some european company I found like 10 vulns Reported and they fixed it and never even sent a stupid „thanks” in an email
English
2
0
11
711