MA7C

482 posts

MA7C banner
MA7C

MA7C

@ma7c_de

CyberSec education is the most powerful weapon / SecOps & TI - @[email protected] // #ONE-CYBER-SECURITY

DE-BY-FUE Katılım Temmuz 2017
2.4K Takip Edilen175 Takipçiler
MA7C retweetledi
Pirat_Nation 🔴
Pirat_Nation 🔴@Pirat_Nation·
Google Chrome is quietly downloading a roughly 4 GB AI model to many users’ computers without clear upfront consent. The file, called weights.bin, is part of Google’s Gemini Nano on-device language model and lands in the browser’s user data folder under OptGuideOnDeviceModel. It powers built-in AI tools such as “Help me write,” smarter tab suggestions, on-device scam detection, and page summarization. The download triggers automatically for devices meeting minimum hardware requirements, and Chrome often replaces the files if deleted. While the model processes data locally, installation happens in the background with minimal notification. The scale is noteworthy. Hundreds of millions or billions of installations add up to thousands of tonnes of carbon emissions globally from data transfer, even though each is a one-time event. To prevent or remove it, go to chrome://flags, disable the entries for the optimization guide on-device model and Prompt API, restart the browser, and manually delete the folder.
Pirat_Nation 🔴 tweet mediaPirat_Nation 🔴 tweet media
English
529
4.8K
18.4K
9.1M
MA7C retweetledi
Ben Phillips
Ben Phillips@benphillips76·
Plans to invade Greenland have just been cancelled after this
English
778
5.3K
57.5K
3.2M
MA7C
MA7C@ma7c_de·
Great, I love the humor.
Peter Girnus 🦅@gothburz

I spent $1.4 million on Microsoft Copilot. $30 per seat per month. 4,000 employees. Why? 2 words. Digital transformation. This morning I opened Microsoft Teams. My top notification wasn't from my boss. It wasn't from my team. It wasn't a customer escalation. It wasn't my wife. It was Microsoft. Telling me to learn how to use the thing I already bought. It said ... "Elevate your expertise with new Copilot courses." I've had these licenses for 6 months. Apparently ... I should have waited. The courses are 47 minutes each. There are 9 of them. That's 7 hours of learning. Times 4,000 employees. 28,000 hours. To learn the tool ... that was supposed to save us 40,000 hours. We're already down 12,000 hours. And no one's opened it yet. Here's the math I don't put in the deck. 4,000 employees. Average salary ... $105,000. That's $50 an hour. Times 7 hours of training. Times 4,000 people. $1.4 million. In labor. Just to learn the tool. The training ... costs as much as the software. $2.8 million. Year 1. To save 12,000 hours. That's $233 ... per hour saved. The CFO will never see this slide. But I'll mandate the training. Completion rates will be tracked. Tracked means dashboarded. Dashboarded means presented. Presented means ... "adoption metrics are strong." The graph will go up ... and to the right. Strong adoption ... of the training ... for the tool no one uses. Microsoft will send another case study team. The case study will be called "Enterprise drives 98% Copilot Academy completion." The CEO will post it on LinkedIn. He still won't know what Copilot does. But he'll know we're ... "committed to continuous learning." Learning is a journey. The journey costs $1.4 million per year. Plus $1.4 million in training labor. To summarize emails ... we could read in 30 seconds. But here's the thing. I'll renew next year. Because canceling requires a business case. The business case requires ROI data. The ROI data comes from the dashboard. The dashboard shows 98% training completion. 98% is a success. Success means renewal. Renewal means ... I keep my job. My job is ... making decisions. I made a decision. The decision was $2.8 million. The decision cannot be wrong. Because wrong decisions ... don't get promoted. I got promoted. So the decision was right. This is called ... "strategic alignment." Next quarter ... we're adding Microsoft 365 Copilot Studio. It costs extra. It lets us build ... custom Copilots. Custom Copilots ... to automate the workflows ... no one has ... because everyone's still ... in training. Microsoft says it's ... "transformational." I believe them. I have to. I already signed the contract.

English
0
0
0
8
MA7C retweetledi
Peter Girnus 🦅
Peter Girnus 🦅@gothburz·
I am a Microsoft security architect. In 1994, researchers discovered RC4 was fundamentally broken. We made it the default cipher in Windows anyway. By 2000, every machine on Earth was running it. We called it "battle-tested." Technically true. It lost every battle. In 2013, more researchers confirmed it was still broken. We published a knowledge base article thanking them for their passion. In 2015, the entire industry formally deprecated it. We kept it enabled by default. Compatibility is more important than security. Security is just compatibility with not being hacked. Hospitals ran their patient records through it. Banks authenticated their transactions with it. Fortune 500 companies trusted their crown jewels to it. The Ascension breach happened. 5.6 million patient records. 140 hospitals offline. Ransomware walked through our cipher like it wasn't there. It basically wasn't. Senator Wyden called it "gross cybersecurity negligence." He demanded an FTC investigation. We released a statement thanking him for his continued partnership. After 26 years of careful consideration, we've made a decision. We're going to disable RC4 by default. In mid-2026. We're giving everyone 18 months notice. Because we believe in thoughtful transitions. We've been thoughtfully transitioning since the Clinton administration. Two Clintons could have run for president in the time we've been "evaluating options." Some things are just hard to kill off. Like a legacy cipher. Or institutional momentum. Or the phrase "we take security seriously." We do take it seriously. We just don't take it urgently. Urgency is for startups. We're a mature organization. We mature our vulnerabilities like fine wine. 26 years. That's not negligence. That's commitment.
Peter Girnus 🦅 tweet media
English
69
442
3.1K
172.6K
MA7C retweetledi
Deutsche Telekom CERT
Deutsche Telekom CERT@DTCERT·
🚨 Telekom Security detected a major #vishing campaign against multiple targets in #Germany, likely related to a ransomware group. We are still analyzing, but here is what we know so far 🧵1/x
Deutsche Telekom CERT tweet media
English
6
52
164
40.9K
MA7C retweetledi
el.cine
el.cine@EHuanglu·
wow.. this AI is scary GeoSpy AI now can find your exact location from even an indoor photo..
English
315
1.4K
10.6K
1.6M
MA7C
MA7C@ma7c_de·
@EHuanglu your [prompt text] seems to be wrong here.
English
1
0
8
394
el.cine
el.cine@EHuanglu·
Sora vs. Hunyuan: Animal movement Prompt: [Woman is walking and crying on a crowded street]
English
9
3
59
35.1K
el.cine
el.cine@EHuanglu·
OpenAI Sora was out of the game on day one. To be fair, I compared it with Hunyuan, which dropped 6 days ago, it's an open-source AI model and you can run it locally for free. TBH, if I were to compare it to Hailuo AI or Kling AI, Sora would look even worse. Let’s dive in:
English
214
384
3.5K
1.3M
MA7C retweetledi
MhicRoibin
MhicRoibin@MhicRoibin·
There is an arms race going on between loader developers and security vendors. I came across a particularly egregious example of this recently. I wish to share with you. 🧵
English
23
223
2.1K
355.9K
MA7C retweetledi
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
My friend Arnim created a Top 50 vendor list from @CISAgov’s KEV list with filter on CVE-202* 148 Microsoft 63 Apple 50 Google ** 25 Cisco** ** 21 Ivanti** 20 Apache 19 VMware 12 Oracle 12 Adobe 11 Samsung 11 Android ** 10 Fortinet** ** 10 Citrix** ** 9 Trend Micro** 9 D-Link 9 Atlassian 9 Arm 8 Zoho ** 8 SonicWall** 8 Qualcomm ** 7 Zyxel** 7 Zimbra 7 Roundcube 7 Linux 6 SolarWinds ** 6 Palo Alto Networks** ** 6 Juniper** ** 6 F5** ** 5 Sophos** 5 Mozilla 4 Veeam 4 SAP 4 QNAP 4 Progress 4 Mitel 4 IBM 4 DrayTek 4 Accellion 3 Veritas 3 SaltStack 3 Nagios 3 Fortra 2 Zabbix 2 WordPress ** 2 WatchGuard** 2 VMware Tanzu 2 Unraid 2 Tenda 2 ServiceNow 2 Red Hat
Florian Roth ⚡️@cyb3rops

I’d love to see @CISAgov publish a ‘Top 10 Vendors’ list for releasing products with serious, frequently exploited vulnerabilities (CVSS > 8.5). It’d be a data-driven ‘wall of shame’ based on their exploited vulnerability reports. If they won’t do it, I might. And if a vendor sues me, I’ll live-tweet the court proceedings with the stats in hand. 📊

English
18
98
336
63.2K
MA7C retweetledi
Lilith Wittmann
Lilith Wittmann@LilithWittmann·
Hallo @ArvatoFinance und @Experian, eure Credit Scoring API funktioniert nicht. Aber hab euren Algorithmus für euch gebackupt. Smart wie ihr für dieselbe Adresse einfach 15 Punkte addiert, wenn man 25 Jahre älter ist. Und die 11 Punkte mehr für Frauen sind natürlich auch schlau.
Lilith Wittmann tweet media
Deutsch
19
150
993
62.9K
Russell Kaplan
Russell Kaplan@russelljkaplan·
Trying to convince the United gate agent to let me reboot Windows in safe mode and delete “C-00000291*.sys”, to no avail
Russell Kaplan tweet media
English
473
3.9K
90.4K
5.5M
MA7C retweetledi
Satya Nadella
Satya Nadella@satyanadella·
Yesterday, CrowdStrike released an update that began impacting IT systems globally. We are aware of this issue and are working closely with CrowdStrike and across the industry to provide customers technical guidance and support to safely bring their systems back online.
English
2K
5.2K
51.5K
5.6M
MA7C retweetledi
Hillai Ben-Sasson
Hillai Ben-Sasson@hillai·
I hacked the @SAP AI platform by changing my UID to 1337. …Yeah, really. This led to admin permissions on several SAP systems, but also access to customers’ secrets and private AI files 👀 This is the story of #SAPwned 🧵⬇️
Hillai Ben-Sasson tweet media
English
25
329
1.7K
228.8K
MA7C
MA7C@ma7c_de·
@LilithWittmann @BMI_Bund Der Lagerbericht des BSI bezeichnet dich als "bereits schon einmal einschlägig auffällige Angreiferin" – das ist typisch deutsch. Spreche doch mal mit Claudia Plattner...
MA7C tweet media
Deutsch
7
4
58
37.5K
Lilith Wittmann
Lilith Wittmann@LilithWittmann·
Achtung @BMI_Bund, muss euch ein Geheimnis verraten: Ist nicht nur eine oder zwei oder zehn Webseiten mit der Sicherheitslücke, die den Redirect ermöglichen. Sondern sind mindestens alle, die das Produkt "ITEBO OpenR@thaus" benutzen.
Deutsch
6
6
159
9.3K
MA7C
MA7C@ma7c_de·
Am I the only one who has these problems?
MA7C tweet mediaMA7C tweet mediaMA7C tweet media
English
0
0
0
118