
After nearly two weeks spent thoroughly assessing each and every submission, we're proud to present you with our four winners from Scroll's "Quill and Scribes" Competition 🥳 Congratulations to @mr_abims, @Envoy_1084, @0xAzan, and @TechieTeee. 🧵 👇
Abims
1.9K posts

@mr_abims
Explorer | Building on Bitcoin and EVM chains

After nearly two weeks spent thoroughly assessing each and every submission, we're proud to present you with our four winners from Scroll's "Quill and Scribes" Competition 🥳 Congratulations to @mr_abims, @Envoy_1084, @0xAzan, and @TechieTeee. 🧵 👇


We asked Claude to find a bug in Vim. It found an RCE. Just open a file, and you’re owned. We joked: fine, we’ll switch to Emacs. Then Claude found an RCE there too. Full story: blog.calif.io/p/mad-bugs-vim…


Prior to his death, Eric Dane sat for an interview with the understanding that it would only be shared with the world after he passed. In that conversation, he reflected on his battle with ALS, his struggles with addiction, and his marriage to Rebecca Gayheart: “I will never, by the time anybody sees this, have fallen in love with another woman as deeply as I fell in love with Rebecca.” Famous Last Words is now on Netflix.

World Labs has raised $1 billion in new funding. We are grateful and excited to partner with our investors, including AMD, Autodesk, Emerson Collective, Fidelity Management & Research Company, NVIDIA, and Sea, among others. worldlabs.ai/blog/funding-2…






i genuinely think everyone in this space should immediately switch to using Vim. DPRK started abusing VS Code hooks that run _automatically_ in the background when you open a folder. ZERO fucking user interaction required _after_ trusting the repo (the trusting part is important here). Yes, read it again. ZERO. INTERACTION. REQUIRED. so what happens is the following: they (in the usual case the Contagious Interview group, meaning some fake recruiting guy) share GitHub, Bitbucket, and GitLab repos containing a `.vscode/` subdirectory with malicious hooks. the one example I share here executes a fake font that's actually heavily-obfuscated JS and will absolutely rek you. all your fancy software that feels "convenient" makes tradeoffs. those tradeoffs are now being abused to silently rek your devices. use Vim. and use Qubes. Thx.




