๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž

12.8K posts

๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž banner
๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž

๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž

@andreaswditze

Geschรคftsfรผhrer bei @tripuls | Stadtverordneter in Wetter (Hessen), Ortsbeirat in #Mellnau | Im Vorstand bei @ffnordhessen & anderen | #ChatGPT Maniac

Marburg, Germany Katฤฑlฤฑm Aralฤฑk 2009
1.4K Takip Edilen771 Takipรงiler
๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž retweetledi
Jack Lindsey
Jack Lindsey@Jack_W_Lindseyยท
Our tools are highly imperfect, and weโ€™re working to gain more precise understanding of model internals. But itโ€™s becoming clear that reading modelsโ€™ minds is an important complement to reading their outputs, if we are to ensure they work as intended. Lots more in the system card: www-cdn.anthropic.com/53566bf5440a10โ€ฆ. (14/14)
English
41
16
746
50.4K
๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž retweetledi
Anthropic
Anthropic@AnthropicAIยท
Introducing Project Glasswing: an urgent initiative to help secure the worldโ€™s most critical software. Itโ€™s powered by our newest frontier model, Claude Mythos Preview, which can find software vulnerabilities better than all but the most skilled humans. anthropic.com/glasswing
English
1.9K
6.6K
43.2K
29.8M
๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž retweetledi
๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž retweetledi
Josh Kale
Josh Kale@JoshKaleยท
This is big... Anthropic just announced a model so powerful they won't release it to the public out of fear over the damage it will cause ๐Ÿ˜จ Claude Mythos Preview found thousands of zero-day exploits in every major operating system and web browser... The numbers are hard to believe: > $50 to find a 27-year-old bug in OpenBSD, one of the most security-hardened operating systems ever built > Under $1,000 to find AND build a fully working remote code execution exploit on FreeBSD that grants unauthenticated root access from anywhere on the internet > Under $2,000 to chain together multiple Linux kernel vulnerabilities into a complete privilege escalation exploit For context: these are the kinds of findings that previously required elite security researchers working for weeks. Anthropic engineers with no formal security training asked Mythos to find exploits overnight. They woke up to working code the next morning. The results were so impressive Anthropic assembled Apple, Google, Microsoft, Amazon, NVIDIA, and seven other organizations into Project Glasswing: A $100M defensive coalition. They're not releasing this model publicly. Instead, they're racing to patch the world's infrastructure before models like this proliferate.
Anthropic@AnthropicAI

Introducing Project Glasswing: an urgent initiative to help secure the worldโ€™s most critical software. Itโ€™s powered by our newest frontier model, Claude Mythos Preview, which can find software vulnerabilities better than all but the most skilled humans. anthropic.com/glasswing

English
693
2.4K
18K
3.9M
๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž retweetledi
memoryunlocked
memoryunlocked@corememunlockedยท
memoryunlocked tweet media
ZXX
34
75
1.2K
42.1K
๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž retweetledi
Storch_i
Storch_i@Storch_iยท
"Deutschland kauft jedes Jahr im Ausland fรผr 80.000.000.000 โ‚ฌ fossile Energie ein. Dieses Geld wird jedes Jahr verbrannt, in ร–l, Kohle & Gas. Wir stรคrken die Feinde der Demokratie mit unserem Geld, weil wir es nicht schaffen unabhรคngig von fossilen Energien zu werden." #Habeck
Deutsch
76
1.2K
4.5K
101.1K
๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž retweetledi
Tuki
Tuki@TukiFromKLยท
๐Ÿšจ Andrej Karpathy just explained the scariest thing happening in software right now.. someone poisoned a Python package that gets 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine.. SSH keys.. AWS credentials.. crypto wallets.. database passwords.. git credentials.. shell history.. SSL private keys.. everything.. and here's the part that should terrify every developer alive.. the attack was only discovered because the attacker wrote sloppy code.. the malware used so much RAM that it crashed someone's computer.. if the attacker had been better at coding.. nobody would have noticed for weeks.. one developer.. using Cursor with an MCP plugin.. had litellm pulled in as a dependency they didn't even know about.. their machine crashed.. and that crash saved thousands of companies from getting their entire infrastructure stolen.. Karpathy's take is the real wake up call.. every time you install any package you're trusting every single dependency in its tree.. and any one of them could be poisoned.. vibe coding saved us this time.. the attacker vibe coded the attack and it was too sloppy to work quietly.. next time they won't make that mistake.
Andrej Karpathy@karpathy

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

English
285
2.2K
13.9K
3.2M
๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž retweetledi
Donald Tusk
Donald Tusk@donaldtuskยท
The news that Orbรกnโ€™s people inform Moscow about EU Council meetings in every detail shouldnโ€™t come as a surprise to anyone. Weโ€™ve had our suspicions about that for a long time. Thatโ€™s one reason why I take the floor only when strictly necessary and say just as much as necessary.
English
2.2K
9.3K
43.6K
2M
๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž retweetledi
Leon Simons ๐ŸŒ
Leon Simons ๐ŸŒ@LeonSimons8ยท
Our solar panels were not blocked by any war today. 112 kWh and going.
Leon Simons ๐ŸŒ tweet media
English
89
250
3.3K
99.8K
๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž retweetledi
Arnold Schwarzenegger
Arnold Schwarzenegger@Schwarzeneggerยท
Chuck was an icon. I am grateful that I was able to work with him in multiple ways over the years, from promoting fitness to sharing the screen together. He was a badass, in real life and in Hollywood. His legend will be with us forever. My thoughts are with his family.
English
1.2K
15.4K
152.2K
1.8M
๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž retweetledi
๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž retweetledi
Storch_i
Storch_i@Storch_iยท
Robert #Habeck macht @Markus_Soeder ein Angebot in Sachen #Atomkraft: wenn er jemanden findet, der ein neues Atomkraftwerk ohne Subventionen baut, dann klopft er ihm auf die Schulter und gibt รถffentlich zu, dass er falsch lag.
Deutsch
208
1.1K
6K
203.2K
๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž retweetledi
Tom Dรถrr
Tom Dรถrr@tom_doerrยท
Strategy game with singleplayer campaigns and multiplayer mode github.com/widelands/wideโ€ฆ
Tom Dรถrr tweet media
English
11
148
2.1K
84.9K
๐€๐ง๐๐ซ๐ž๐š๐ฌ ๐–. ๐ƒ๐ข๐ญ๐ณ๐ž retweetledi
Stormslayer -HD Remasters/Gamedev
Stormslayer -HD Remasters/Gamedev@StormslayerDevยท
There's now a launcher where you can download your favorite delisted games from the internet archive! Easy to use with one click! Some of my favorites from here!
Stormslayer -HD Remasters/Gamedev tweet media
RohanKar@RohanKarMooN

Link -> github.com/Kilted-Kraken/โ€ฆ Want all of my repacks in one place without navigating to Internet Archive? Well my follower @ruester79 have created a custom launcher from where you can easily install and play my repacks!! I didn't had any involvement in creation of the software, but it's actually pretty decent and y'all can give it a try.

English
48
849
8.6K
616.4K