Manaf

21 posts

Manaf

Manaf

@manaaaaaaaf

Lausanne, Switzerland Katılım Eylül 2024
176 Takip Edilen167 Takipçiler
Manaf retweetledi
Lovable
Lovable@Lovable·
Introducing the world’s first penetration testing for vibe coding to Lovable. You can now prove the security of your Lovable-built apps through a swarm of AI agents that run comprehensive tests, checking for OWASP Top 10 vulnerabilities, privilege escalation, and data exposure, powered by @AikidoSecurity. This used to take weeks, require dedicated security teams, and cost $5k-$50k. All findings are validated to eliminate false positives and sync back into Lovable as actionable issues. This generates a formal pentest report for SOC 2, ISO 27001, client security questionnaires, or even investor due diligence.
English
145
147
1.7K
334.3K
Manaf retweetledi
pilvar (Philippe Dourassov)
pilvar (Philippe Dourassov)@pilvar222·
Few months ago, @manaaaaaaaf and I decided to join @AikidoSecurity because there is no better place to build AI Pentest. A platform to cover all security aspects is the only way to achieve unhackability. Aikido is now a 🦄
pilvar (Philippe Dourassov) tweet mediapilvar (Philippe Dourassov) tweet media
English
1
2
36
2.6K
Manaf retweetledi
pilvar (Philippe Dourassov)
pilvar (Philippe Dourassov)@pilvar222·
For my French-speaking friends: You can find the replay of the stream my co-founder @manaaaaaaaf and I were invited to, in which we talk AI stuff and present @haicker_app in action! 🔥 Thank you @TheLaluka for the invitation! ❤️
Laluka@OffenSkill@TheLaluka

Last replay : documenté, chapitré, sourcé ! 💣🧠🔫 On y aborde la recherche de failles par agents IA via l'entreprise & produit @haicker_app (hors sponso), en compagnie des créateurs @pilvar222 @manaaaaaaaf et du fidèle compagnon @KharaTheOne pour la partie Techno Watch ! 💌 youtube.com/live/fa8KV76h9…

English
1
3
11
2K
Manaf retweetledi
pilvar (Philippe Dourassov)
pilvar (Philippe Dourassov)@pilvar222·
It's finally out! :D @manaaaaaaaf and I have been building @haicker_app for the last 6 months, putting all our knowledge and skills into it. We're releasing it to the market. Any organization can now secure their application using @haicker_app ! Very excited for what's next!
Haicker@haicker_app

Introducing Haicker: your AI penetration tester Continuous, automated vulnerability scanning for your web codebases. Cheaper, faster, and more efficient than traditional pentesters. Book a demo now, link in the comments.

English
1
5
27
3.8K
Manaf
Manaf@manaaaaaaaf·
Hey ! This is a combination of both SAST and DAST. The agent will have both the code and an isolated instance of the website. It will be able to identify the vulnerabilities better than traditional SAST thanks to increased context comprehension while maintaining a 0% false positive rate by testing its exploit on the instance
English
0
0
1
233
Manaf retweetledi
pilvar (Philippe Dourassov)
pilvar (Philippe Dourassov)@pilvar222·
My friend @manaaaaaaaf and I have created an AI hacker! 👨‍💻 It can find 0-days in web applications with 0% false positives, and it also works on CTF challenges! What you see ⬇️ is @haicker_app solving a web challenge from UMassCTF 2025 (only 45/557 teams were able to solve it!)
English
13
41
373
36K
Manaf retweetledi
Haicker
Haicker@haicker_app·
Waitlist is open, sign up for early access 👀 👉haicker.app
English
1
1
5
1.6K
Manaf
Manaf@manaaaaaaaf·
@lovable We're building a tool to fix this ! haicker.app We're fixing vibe coding mistakes, you can now have your own AI hacker that finds the vulnerabilities before the code gets shipped in prod
English
0
1
3
416
Lovable
Lovable@Lovable·
Thread on vibe coding security and how we’re planning on making Lovable the safest place to build with AI. //1
English
58
40
825
165.2K
Manaf retweetledi
@goth
@goth@goth600·
“So is it over or, are we back? It can’t be both. You have to call it.“
@goth tweet media
English
42
490
7.9K
284.5K
Manaf
Manaf@manaaaaaaaf·
@kuba_developer @peer_rich unfortunately, you can’t use components which start with a lowercase letter, because jsx will automatically assume this is an html tag even if you have a defined variable Example: <a/> will transpile to jsx("a", {}) instead of jsx(a, {}) just use LinkIcon lol
English
0
0
0
59
Peer Richelsen
Peer Richelsen@peer_rich·
if you know you know
Peer Richelsen tweet media
English
61
23
698
73.3K
Manaf retweetledi
Ilya Sutskever
Ilya Sutskever@ilyasut·
it may be that today's large neural networks are slightly conscious
English
452
612
3.9K
0
Manaf
Manaf@manaaaaaaaf·
@MarkusEicher70 @czue @Hetzner_Online Performances are also very unpredictable. During December, one of my vps was taking 30 seconds for an ssh login. I asked them about it and they said they were aware but did not do anything.
English
0
0
0
428
Manaf
Manaf@manaaaaaaaf·
@MarkusEicher70 @czue @Hetzner_Online okay, random comment but contabo locked me out of my main vps for 2 days this weekend, and their support were silent, you should definitely change ASAP, they're very unhelpful I'm now moving everything to Hetzner, their dedicated (AX41-NVMe) are so affordable for what you get
English
3
0
2
676
Cory Zue
Cory Zue@czue·
The Hetzner box that I run multiple production apps (including place card me) on is so cheap they just decided not to bill me this month. 🤯
Cory Zue tweet media
English
89
102
4.2K
319.5K
Manaf
Manaf@manaaaaaaaf·
@BatkuEst @nyaathea @dx9er I went to a talk in September, they managed to bruteforce 2FA on an app in less than 24 hours, because it's not hard to do that many requests without rate limits.
Manaf tweet media
English
0
0
7
234
Manaf
Manaf@manaaaaaaaf·
@BatkuEst @nyaathea @dx9er The probability is 1 - (1 - 1/10^6)^tries. 500k tries and you have 39.34% chance of recovering If they do > 693,146 random tries, they have a 50% chance of getting their account back. Here, it really depends on the Discord rate limit and IP bans, to get it "under 20 years"
English
2
1
15
1K
Manaf retweetledi
daniel
daniel@hackermondev·
Research into a unique 0-click deanonymization exploit targeting Signal, Discord and hundreds of platform 🧵
daniel tweet mediadaniel tweet media
English
102
482
4.4K
420K
Manaf
Manaf@manaaaaaaaf·
@nathan___gage @idolmomentum you can store values before Unix epoch using signed ints (e.g. -2208988800 for 1st jan 1900). They are probably just using a signed int64 for timestamp
English
0
0
0
58