ambivalentcase🌈
6.6K posts

ambivalentcase🌈
@ambivalentcase
Trying to be nice since 1999

Confirmed! Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) chained 4 logic bugs to achieve a sandbox escape on Microsoft Edge, earning $175,000 and 17.5 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin





Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux. The file name transformers.pyz appears deliberately chosen to mimic the widely used Hugging Face Transformers library and blend into ML/dev environments. The main payload is a credential stealer, but it also includes country-aware logic; it avoids Russian-language environments and contains a geo fenced destructive branch that has 1-in-6 chance of executing rm -rf / when the system appears to be in Israel or Iran. To mitigate this threat: isolate affected Linux hosts, block 83[.]142[.]209[.]194, hunt for /tmp/transformers.pyz, pgmonitor[.]py, and pgsql-monitor.service, and rotate exposed credentials.

Sam Altman's group chat with Satya Nadella November 21, 2023









Some progress in lightning: quantamagazine.org/what-causes-li….

0days doesn't seem cool enough anymore. what should real hackers be doing now?


Reid Hoffman (@reidhoffman), LinkedIn co-founder, said he’s deeper into crypto than ever bc it can power payments for AI agents He also pointed to crypto’s role in proving humanity online, w/ NFTs potentially becoming a key building block for digital identity & will nv sell $BTC






















