// tomhatzer - let's build together! 🚀

10.3K posts

// tomhatzer - let's build together! 🚀 banner
// tomhatzer - let's build together! 🚀

// tomhatzer - let's build together! 🚀

@phpastes

Let's bring your web projects to life 🚀 Founder @twopeaksdigital - Building https://t.co/PQjUnGh0jI

Bregenz / Lochau Katılım Şubat 2010
691 Takip Edilen543 Takipçiler
// tomhatzer - let's build together! 🚀
@ashleyhindle Me too, but really nothing worked, like i could se the cursor moving but nothing else did anything 😄 when clicking on an icon in the dock, the app showed like it was force closed even though its window was still shown 😂 funny lil thing
English
1
0
1
6
Ashley Hindle
Ashley Hindle@ashleyhindle·
@phpastes Oh that sucks! I've not restarted yet, I'd rather my laptop be half broken than have to restart 😂
English
1
0
1
18
Ashley Hindle
Ashley Hindle@ashleyhindle·
I _think_ this means I have unlimited RAM now?
Ashley Hindle tweet media
English
4
0
2
765
// tomhatzer - let's build together! 🚀 retweetledi
redpillbot
redpillbot@redpillb0t·
Remember just a couple years ago when using electricity and diesel caused climate change, now data centers use as much power as cities and its no problem
English
360
10.7K
44K
426.3K
Simon Bennett
Simon Bennett@MrSimonBennett·
Sample Products ordered PCB designs on the way too. Lets see if I can build a real product
English
3
0
6
720
Simon Vrachliotis
Simon Vrachliotis@simonswiss·
I tore my calf at basketball last night 😭 The CLASSIC "negative step" stop-start move that gets everyone to tear some lower leg stuff. Felt like I got kicked really hard in the back of the leg. In the second clip you can see me ask the guy I was defending if he kicked me 😂
English
5
0
3
2K
// tomhatzer - let's build together! 🚀 retweetledi
JustSteveKing
JustSteveKing@JustSteveKing·
Most PHP devs know PSR-4 and PSR-12. But there are other standards you’re probably ignoring that change how you write PHP entirely. PSR 7, 14, 15, 17, and 18 - they give you a complete model for HTTP-aware PHP that’s tied to no framework. Write to the interface, not the implementation. juststeveking.com/articles/the-p…
English
2
9
74
4.3K
// tomhatzer - let's build together! 🚀 retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
🚨 How the TanStack npm attack actually happened: 1. Attacker opened a normal-looking pull request (#7378) on the TanStack repo. 2. GitHub automatically ran CI tests on that PR. 3. Code inside the PR stole the workflow's GitHub Actions Cache write token during the test run. 4. The attacker used that token to plant poisoned files in the shared build cache. The PR could be closed afterwards. The poisoned cache stays. 5. The official release workflow later pulled from the cache, baked the malicious files into the build, and signed and published 84 malicious package versions to npm.
Adnan Khan@adnanthekhan

This attack leveraged GitHub Actions Cache Poisoning. Payload deployed here: github.com/TanStack/route… It looks like it detonated here: #step:26:2" target="_blank" rel="nofollow noopener">github.com/TanStack/route…

English
61
575
4.7K
801.9K
// tomhatzer - let's build together! 🚀 retweetledi
Socket
Socket@SocketSecurity·
🚨 UPDATE: Mini Shai-Hulud has crossed from @npmjs into @pypi and is still spreading. Newly confirmed compromised artifacts: @​opensearch-project/opensearch: 3.5.3, 3.6.2, 3.7.0, 3.8.0 (1.3M weekly downloads) mistralai: 2.4.6 on PyPI guardrails-ai: 0.10.1 on PyPI additional @​squawk/* packages on npm guardrails-ai 0.10.1 executes malicious code on import. On Linux, it downloads git-tanstack[.]com/transformers.​pyz, writes it to /tmp/transformers.​pyz, and runs it with python3 without integrity verification. The git-tanstack.​com domain displayed a message signed “With Love TeamPCP,” along with: “We've been online over 2 hours now stealing creds Regardless I just came to say hello :^)” The page also linked to a YouTube video and you can probably guess which one.
Socket tweet media
English
61
489
2.3K
952.5K
// tomhatzer - let's build together! 🚀 retweetledi
Aikido Security
Aikido Security@AikidoSecurity·
Update 5:05 PT: The attack has now expanded well beyond @TanStack and @Mistral. 373 malicious package-version entries across 169 npm package names, including @uipath, @squawk, @tallyui, @beproduct, and more. The malware propagates by stealing your CI credentials and using them to publish new compromised versions. Full IOCs, affected package list, and detection steps: aikido.dev/blog/mini-shai…
Aikido Security@AikidoSecurity

🚨 Update: @mistralai npm packages are now confirmed compromised as part of the ongoing Mini Shai Hulud attack. Affected versions: @mistralai/mistralai 2.2.2, 2.2.3, 2.2.4@mistralai/mistralai-azure 1.7.1, 1.7.2, 1.7.3@mistralai/mistralai-gcp 1.7.1, 1.7.2, 1.7.3If you use the Mistral SDK in any CI pipeline, treat your environment as compromised. Rotate npm tokens, GitHub PATs, and cloud credentials immediately.

English
76
492
2.6K
2.4M
// tomhatzer - let's build together! 🚀 retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you. The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads. The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate. Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.
International Cyber Digest tweet media
English
139
956
6.4K
1.4M
// tomhatzer - let's build together! 🚀 retweetledi
vx-underground
vx-underground@vxunderground·
Hahahahahaha VPNs are HURTING CHILDREN Hahahaha fucking stupid fucks
European Parliamentary Research Service@EP_EPRS

Virtual private networks #VPN are increasingly used to bypass online age verification. Protecting children online is a priority, with new rules being implemented requiring a minimum age for access to some services Read👉 link.europa.eu/FGfr6C #DSA @EP_Justice @FZarzalejos

English
158
2.5K
22.6K
520.4K
// tomhatzer - let's build together! 🚀 retweetledi
Mike Benz
Mike Benz@MikeBenzCyber·
Incredible. The public pressure on the EU over its Digital Censorship Act has led EU censors to move to closed-doors meetings and auto-delete messages in coordinating their censorship ops.
Mike Benz tweet media
James Holland@James7Holland

In Politico today: Senior 🇪🇺 official admits greater public scrutiny of DSA has lead to meetings becoming secret and his staff using Signal to communicate—thereby making it virtually impossible for voters/journalists to probe work of this EU department. Something to hide?

English
163
3.5K
9.5K
211K
// tomhatzer - let's build together! 🚀 retweetledi
Sukh Sroay
Sukh Sroay@sukh_saroy·
Plug a $30 USB stick into your laptop and you can listen to satellites, decode pager traffic, intercept walkie-talkies, and watch TV signals fall out of the air around you. Free. No license. No subscription. Just one tool nobody outside the radio underground talks about. It's called SigDigger. An open source digital signal analyzer that turns a cheap SDR dongle into a full radio intelligence rig. Here is what it can actually do. Point it at the sky and you can pull down NOAA weather satellite images as they pass overhead. Tune it to your local airport and you can decode aircraft transponders in real time. Sweep the FM band and you can demodulate analog voice the moment it hits the antenna. The interface looks like a Bloomberg Terminal for the airwaves. A live waterfall display showing every signal in your area. PSK, FSK, and ASK demodulation. Burst signal analysis for the weird short transmissions nobody can identify. Analog video decoding. Panoramic spectrum sweeping across entire frequency ranges. All running on a Linux or macOS laptop with zero specialized hardware. What used to require a $40,000 spectrum analyzer locked inside a defense lab now runs in your living room for the price of a USB stick. The author built the entire DSP backend from scratch instead of leaning on GNU Radio. He wrote his own core library called Suscan, his own signal processing library called Sigutils, and his own widget library called SuWidgets. Faster. Cleaner. Optimized for the exact tasks reverse engineers and amateur radio operators actually need. Plugin support is built in. AmateurDSN for deep space network monitoring. APTPlugin for weather satellites. AntSDRPlugin for the AntSDR hardware. ZeroMQPlugin for piping signal data into other tools. Everything snaps in with one command. The whole stack supports SoapySDR, which means almost every SDR device on the market works out of the box. RTL-SDR. HackRF. LimeSDR. Airspy. Plug it in and start digging. 1.5K stars. LGPL-3.0. 100% Opensource.
Sukh Sroay tweet media
English
26
280
1.7K
78.7K
// tomhatzer - let's build together! 🚀 retweetledi
Tom Dörr
Tom Dörr@tom_doerr·
Hardware-isolated VMs boot in under 300ms on Proxmox VE github.com/rcarmo/pve-mic…
Tom Dörr tweet media
English
3
42
311
20.2K
// tomhatzer - let's build together! 🚀 retweetledi
Chris Jones
Chris Jones@leeked·
Ever needed a second layer of multi-tenancy in your @filamentphp applications? → Regions → Departments → Service Area Add as many as you want with my new plugin! github.com/leek/filament-…
Chris Jones tweet media
English
0
8
42
3.5K
// tomhatzer - let's build together! 🚀 retweetledi
pHiycrtyl
pHiycrtyl@iycrtylph·
get this through your thick fucking heads: technology never shortens labor time on its own. no boss ever has said, "ah, now that these machines have production more efficient, i guess i can let my workers work less." only class struggle shortens labor time.
English
48
2.2K
18.6K
489.8K
// tomhatzer - let's build together! 🚀 retweetledi
Alex Ellis
Alex Ellis@alexellisuk·
Inspect and filter every HTTP request leaving your microVM. New post on @slicervm's proxy: secret injection without sentinels, OAuth that actually works, and stage-by-stage policy you can change mid-flight with code. slicervm.com/blog/programma…
English
3
9
112
14K
slinafirinne
slinafirinne@slinafirinne·
@evilsocket I signed up for the $200 codex plan as well and I'm gonna do a bake off this weekend & see how they perform.
English
1
0
2
66
Simone Margaritelli
Simone Margaritelli@evilsocket·
dude i'm fixing really stupid mistakes that opus 4.7 started making at max effort, with sonnet 4.5 ... wtaf is anthropic doing to this model
English
8
0
27
4.7K
// tomhatzer - let's build together! 🚀 retweetledi
Ashley Hindle
Ashley Hindle@ashleyhindle·
👋 Vask says howdy: Websockets, but better 🔥 • Powered by Cloudflare • No fanout tax: 1 broadcast to 500k = 1 message • Drop-in Pusher replacement First 20 peeps: code ASHLEY-ISNT-THAT-BAD = 50% off forever (only if you agree, Stripe checks) vask.dev
English
22
36
344
37.2K