ojas
633 posts

ojas
@bionic_BUG
i crave knowledge and cats and borgirs || techbro, gamer, jack of not all trades || designing systems and ai agents



🚨 We’ve confirmed the intercom-client@7.0.4 was compromised in the ongoing Mini Shai-Hulud worm attack. The npm package includes a malicious preinstall hook that downloads and executes an unverified Bun binary, then runs an 11.7 MB obfuscated payload designed to steal Kubernetes, Vault, cloud, GitHub, and CI/CD secrets. The attack closely overlaps with the SAP CAP, Cloud MTA, and lightning@2.6.2 compromises.

Remember the security firm that Ubuntu hired to audit the (ill-advised, highly buggy) Rust-rewrites of all of the GNU Coreutils? Turns out that security firm is run by @gf_256, who: - Appears to be a man who thinks he's a woman ("trans"). - Uses an anime cartoon of a girl as his avatar. - Appears to have an OnlyFans page. I repeat: Ubuntu hired a "Trans" man, with an anime girl avatar and an OnlyFans page... to audit Rust code. It's hard to get more on-the-nose than that.




Mandatory human-in-the-loop is a cybersecurity cop-out. People are giving agents more and more autonomy. We need solutions that accept that world because there is no stopping it. It's like telling people in the 90s to not use the internet to avoid getting hacked. Good luck.

i converted my /pet of codex to a goblin just ask codex to install $.hatch-pet then describe how your pet looks like Now i have got a hard groove partner sitting on my screen vibing with me (sound up to vibe along)


DeepSeek releases DeepSeek-V4. 🐋 - DeepSeek-V4-Pro: 1.6T params - DeepSeek-V4-Flash: 284B params DeepSeek-V4-Pro rivals Claude-Opus-4.6-Max, GPT-5.4-xHigh and Gemini-3.1-Pro-High. They support 1M context length, thinking and set new records for Codeforces.

just checked github trending, the #1 repo this week is a CLAUDE.md file. 44,465 new stars this week. a skill distilling Andrej Karpathy's LLM coding pitfalls into 4 principles: → think before coding: ask when unsure, don't silently pick one interpretation and run with it → simplicity first: minimum code, any overengineering shows at a glance → surgical edits: only touch what's required, don't fix up neighboring code on the way by → goal-driven: translate fuzzy instructions into verifiable targets before starting swapped it into my claude.md, a few tasks in it feels tighter. repo below 👇


1/ today we're releasing muse spark, the first model from MSL. nine months ago we rebuilt our ai stack from scratch. new infrastructure, new architecture, new data pipelines. muse spark is the result of that work, and now it powers meta ai. 🧵






