Jo Haugum
13 posts


@USOCC @FTC @NYDFS @federalreserve Please note Chase has removed 180000 points from a consumer account while providing no proof of transmission no trace ID no reconciliation case and no return of points despite partner denial of receipt. 7 day tx policy = practically useless
English

@ChaseSupport @USOCC @FTC @NYDFS @federalreserve URGENT regulatory escalation. Chase removed 180000 UR points for an Aeroplan tx 4 days ago. Aeroplan confirms it received NOTHING. Chase rep lied about points being sent, on a recorded call.

English

@ChaseSupport transferred 180k UR points 3 days ago, still O points in aeroplan. $800/yr for chase sapphire reserve, but good luck booking flights with several day transfer delays! cs rep lied on phone and said it was sent, Aeroplan confirms they don't see ANYTHING from chase.

English

@ChaseSupport transferred 180k UR points 2 days ago, still 0 points in aeroplan. $800/yr for chase sapphire reserve, but good luck booking flights with several day transfer delays! cs rep lied on phone and said it was sent, Aeroplan confirms they don’t see ANYTHING from chase.
English

@ChaseSupport $800/yr for chase sapphire reserve but points transfers lag for days. 7 business days for aeroplan transfer? total joke. 3 seats left on the flight I want to book. about to waste 180k points on your old technology. 10 year customer, closing my account today.
English

@doodlestein @LLMJunky it’s clever, but easily beaten by intercepting network calls to github for the token, and forcing 200 responses (or if it’s explicitly checking for 40X, simply disconnect and revoke from another machine?)
English

@LLMJunky Kind of ingenious. How did no one think of doing that before? Also the whole “delete everything if the git api key is revoked” is cruel but effective psychological warfare.
English

This is crazy. The shai hulud exploit is embedding itself in Claude and VSCode to re-execute itself, even after the original packages have been uninstalled.
I'm never installing anything ever again.
International Cyber Digest@IntCyberDigest
‼️🚨 UPDATE: The TanStack npm attack is now a full campaign. 'Mini' Shai-Hulud has hit: - OpenSearch - Mistral AI - Guardrails AI -UiPath - Squawk packages across npm and PyPI The malware specifically targets AI developer tooling. It hooks into Claude Code (.claude/settings.json) and VS Code (.vscode/tasks.json) to re-execute on every tool event, long after the infected package is gone. npm uninstall does not fix this.
English

@paulg “information collected in this form is required and gathered in accordance with the implementation of Law No. 1.362 of August 3, 2009, as amended, as well as the applicable sovereign ordinances relating to the fight against money laundering, terrorist financing, …”
English
Jo Haugum retweetledi


@sama @yacineMTB use 5.5 if you like being flagged for high risk cyber activity (logging into airline website and looking for flights)

English

@aidan_mclau i can imagine! how do you secure it? i’m gradually expanding my codex and openclaw use into more personal use cases, but i’m still running separate non-admin macos user with no personal data or services logged in, openclaw in docker etc.
English





