Brandon()

602 posts

Brandon() banner
Brandon()

Brandon()

@brandonbango

PA Katılım Ağustos 2008
165 Takip Edilen123 Takipçiler
Sabitlenmiş Tweet
Brandon()
Brandon()@brandonbango·
If you're trying to learn something new or build a skill, it's important to manage expectations and realize it's a process and not an event. Set small, obtainable goals and work towards it every day. Ask yourself what you need to do to win the day and do it.
English
0
1
5
0
Brandon()
Brandon()@brandonbango·
OpenClaw Chain Vulnerabilities Expose 245,000 Public AI Agent Servers to Attack CVE-2026-44112 (CVSS 9.6 – Critical) CVE-2026-44115 (CVSS 8.8 – High) CVE-2026-44118 (CVSS 7.8 – High) CVE-2026-44113 (CVSS 7.7 – High)
Cyber Security News@The_Cyber_News

🚨 OpenClaw Chain Vulnerabilities Expose 245,000 Public AI Agent Servers to Attack Source: cybersecuritynews.com/openclaw-chain… A chain of four critical vulnerabilities discovered in OpenClaw, one of the fastest-growing open-source platforms for autonomous AI agents, has left an estimated 245,000 publicly accessible server instances exposed to remote exploitation, credential theft, and persistent backdoor installation. Shodan and ZoomEye scans as of May 2026 reveal approximately 65,000 and 180,000 publicly accessible OpenClaw instances, respectively, totaling roughly 245,000 exposed servers. What makes this chain especially dangerous is that the attacker weaponizes the AI agent’s own privileges. #cybersecuritynews

English
0
0
0
75
Brandon() retweetledi
The Hacker News
The Hacker News@TheHackersNews·
🚨 WARNING: The self-spreading “Mini Shai-Hulud” worm compromised npm & PyPI packages tied to TanStack, Mistral AI, Guardrails AI, OpenSearch & more. The attack used GitHub OIDC token hijacking and cache poisoning to spread credential-stealing malware across 42 TanStack packages and 84 versions. Check your dependencies immediately → thehackernews.com/2026/05/mini-s…
The Hacker News tweet media
English
29
211
612
93.4K
Brandon() retweetledi
Maciej Mensfeld
Maciej Mensfeld@maciejmensfeld·
We're dealing with a major malicious attack on @rubygems right now. Signups are paused for the time being. Hundreds of packages involved - mostly targeting us, but some carrying exploits. The team has been on this for hours. More details to follow once we're through it. #ruby
English
27
277
1.2K
185.6K
Brandon() retweetledi
Claude
Claude@claudeai·
Claude Security is now in public beta for Claude Enterprise customers. Claude scans your codebase for vulnerabilities, validates each finding to cut false positives, and suggests patches you can review and approve.
English
848
2K
21.5K
4.9M
Brandon()
Brandon()@brandonbango·
@basedgunnar @rockkdev I think it's a good idea to get into the habit of going directly to the app instead of clicking links in emails, even if they seem legit.
English
0
0
0
84
Gunnar
Gunnar@basedgunnar·
@brandonbango @rockkdev I got it and just immediately reset all my passwords and devices. Looked legit until it took me to download something.
English
1
0
1
104
Abdel
Abdel@rockkdev·
New Robinhood phishing chain that's kinda beautiful: 1. Attacker creates an RH account using the Gmail dot trick of your email (same inbox, different address) 2. Sets device name to HTML 3. RH's "unrecognized activity" email renders the device name unsanitized (html injection) The result is a real email from noreply@robinhood.com, DKIM pass, SPF pass, DMARC pass, with a phishing CTA Just because it's real, doesn't mean it's safe... $HOOD
Abdel tweet mediaAbdel tweet mediaAbdel tweet media
English
181
365
3.8K
3M
Brandon()
Brandon()@brandonbango·
I received this phishing email last night as well. On the surface it looks legit, and since it's from Robinhood and not a random email address, it did have me concerned for a minute. First thing I checked was the and addresses and I noticed my email address had a dot in it. Obviously I didn't create my RH account with the dot in my email. Next I logged into the app and there was no mentioned of the case # or an unrecognized device logged in. Just to be safe, I went to Devices and logged out all other devices. If you're concerned it's worth changing your password, make sure MFA and/or a passkey is setup on your account.
Abdel@rockkdev

New Robinhood phishing chain that's kinda beautiful: 1. Attacker creates an RH account using the Gmail dot trick of your email (same inbox, different address) 2. Sets device name to HTML 3. RH's "unrecognized activity" email renders the device name unsanitized (html injection) The result is a real email from noreply@robinhood.com, DKIM pass, SPF pass, DMARC pass, with a phishing CTA Just because it's real, doesn't mean it's safe... $HOOD

English
0
0
0
53
Brandon() retweetledi
Bitwarden
Bitwarden@Bitwarden·
Bitwarden identified and contained a malicious package briefly distributed through the npm delivery path for the Bitwarden CLI in connection with the broader Checkmarx supply chain incident. No user vault data or production systems were compromised or at-risk. Additional details and updates are available here: community.bitwarden.com/t/bitwarden-st…
English
62
667
3.6K
396.5K
Brandon()
Brandon()@brandonbango·
How A Roblox Cheat Download Triggered A $2 Million Hack At Vercel An employee at a small AI startup called Context AI was searching for and downloading "auto-farm" scripts and game exploit executors, the kind of tool that automates grinding inside Roblox. Hidden in one of those downloads was Lumma Stealer, one of the most widely distributed pieces of infostealer malware currently in circulation. The attacker used those credentials to breach Context AI, steal the OAuth tokens of its customers, and pivot into the Google Workspace of a Vercel employee who had signed up for Context AI's product and granted it "Allow All" permissions on their enterprise account. Wow - link to the full article below.
English
1
0
0
59
Peter Steinberger 🦞
Peter Steinberger 🦞@steipete·
Since this is blowing up on hacker news. Boris said that CLI usage is allowed. Thus we added support for it, only to find out that we are still blocked there. It is trival to work around with a few renames, but I don't wanna play that game. So it's in a weird limbo where cli use should work in theory but doesn’t in practice. x.com/bcherny/status…
Dan McAteer@daniel_mac8

Anthropic allows OpenClaw usage again. From @openclaw docs.

English
151
186
2.8K
641.4K
Dan McAteer
Dan McAteer@daniel_mac8·
Anthropic allows OpenClaw usage again. From @openclaw docs.
Dan McAteer tweet media
English
211
157
2K
1.3M
Brandon()
Brandon()@brandonbango·
@daniel_mac8 @openclaw Unfortunately I still couldn't get it to work properly with OpenClaw v2026.4.2 because it wasn't generating the auth-profiles.json file for it. I think it was a bug but not sure - I ended up upgrading to the newest version and switching to GPT-5.4.
English
0
0
0
724