Wijdan

692 posts

Wijdan banner
Wijdan

Wijdan

@wijdanri

Learning every day 👨‍💻

Katılım Ocak 2015
332 Takip Edilen133 Takipçiler
Sabitlenmiş Tweet
Wijdan
Wijdan@wijdanri·
Just a little concept experiment, having some fun with aesthetic layouts in Gemini Canvas.
Wijdan tweet media
English
1
0
1
502
Watcher.Guru
Watcher.Guru@WatcherGuru·
JUST IN: Google $GOOGL in talks with Elon Musk's SpaceX to launch data centers in space.
Watcher.Guru tweet mediaWatcher.Guru tweet media
English
90
39
310
10.3K
Wijdan
Wijdan@wijdanri·
@thsottiaux The ultimate super duper app: type one lazy prompt and it pays its own subscription, then builds its own empire while you do absolutely nothing. AI hustles, you relax forever. We’re not just building a coding tool anymore, we’re building our replacement. 😉
English
0
0
0
1.2K
Wijdan
Wijdan@wijdanri·
@Hesamation How we can shipping more fast, just delete all of the unit tests and use cheap AI model to test the code directly 😉
English
1
2
35
3.9K
Wijdan
Wijdan@wijdanri·
Bro just came to say hello :^)
Wijdan tweet media
English
0
0
0
33
Wijdan
Wijdan@wijdanri·
Black Tuesday for npm just hit different 😭 Mini Shai-Hulud woke up, stole CI creds, and started dropping malicious packages like it’s on a mission. Now it’s even on PyPI. Happy worm day everyone. Rotate your tokens or join the sandworm. 🪱🏜️
Socket@SocketSecurity

🚨 UPDATE: Mini Shai-Hulud has crossed from @npmjs into @pypi and is still spreading. Newly confirmed compromised artifacts: @​opensearch-project/opensearch: 3.5.3, 3.6.2, 3.7.0, 3.8.0 (1.3M weekly downloads) mistralai: 2.4.6 on PyPI guardrails-ai: 0.10.1 on PyPI additional @​squawk/* packages on npm guardrails-ai 0.10.1 executes malicious code on import. On Linux, it downloads git-tanstack[.]com/transformers.​pyz, writes it to /tmp/transformers.​pyz, and runs it with python3 without integrity verification. The git-tanstack.​com domain displayed a message signed “With Love TeamPCP,” along with: “We've been online over 2 hours now stealing creds Regardless I just came to say hello :^)” The page also linked to a YouTube video and you can probably guess which one.

English
0
0
1
383
Tibo
Tibo@thsottiaux·
Now that the Codex app is close to being the super app. What should the super duper app do?
English
1.2K
40
2.4K
157.7K
Wijdan
Wijdan@wijdanri·
@AishwaryaDevv Me explaining to the hospital why I need a third kidney: “Bro it’s for the Max tier, I need unlimited context or my startup dies.”
English
0
0
0
110
Aish
Aish@AishwaryaDevv·
Anthropic has changed the new Claude Code Plan.
Aish tweet media
English
70
51
1.3K
180.4K
by
by@beyoumf·
name one thing more valuable than money.
English
1.6K
118
1.5K
172.5K
vas
vas@vasuman·
Incredible
vas tweet media
English
97
972
53.6K
1.6M
Wijdan
Wijdan@wijdanri·
Company: $600 on Anthropic? Genius. Keep scaling those tokens. Same company: $23 Uber Eats? You’re $3 over budget, champ. 2026 priorities in one slide: AI gets the unlimited card, humans get the value menu.
vas@vasuman

Incredible

English
0
0
3
3.8K
Wijdan retweetledi
Tanner Linsley
Tanner Linsley@tannerlinsley·
Many recent TanStack Router versions from earlier today were compromised via a Mini Shai-Hulud Supply-Chain Attack. We've already unpublished affected versions and are still taking every action possible to secure our publishing pipelines. Luckily there's a lot of maintainers and talented people working on the issue. Follow the @Tan_Stack account or the tweet below for ongoing updates.
TANSTACK@tan_stack

SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.

English
26
44
659
68.1K
Wijdan
Wijdan@wijdanri·
Before Monday 💀
English
0
0
0
52
Vinay Juneja
Vinay Juneja@vinayjunejaa·
Hey everyone 💙 let's try to be more raw
Vinay Juneja tweet media
English
19
1
90
6.4K
Wijdan
Wijdan@wijdanri·
I'm not robot moment
International Cyber Digest@IntCyberDigest

‼️🚨 ALARMING: Google now treats privacy as suspicious behavior by default. Users of GrapheneOS, CalyxOS, /e/OS, and other deGoogled Android phones are being locked out of millions of websites unless they install the exact Google Play Services software they deliberately removed. GrapheneOS is recommended by the EFF and used by journalists, lawyers, and activists in high-risk environments. The audience most likely to read Google's data practices and refuse its terms is now flagged as fraudulent for that exact decision. What happened?: ▪️ Google announced "Cloud Fraud Defense" at Cloud Next on April 22-23, 2026, branding it "the next evolution of reCAPTCHA." Existing reCAPTCHA customers were auto-migrated. ▪️ When the system flags traffic as suspicious, the old click-the-bus puzzle is gone. Users get a QR code instead. ▪️ Scanning the QR code requires Google Play Services running on the device. Internet Archive snapshots show this requirement has been live since at least October 2025, silently rolled out for 7 months before anyone noticed. ▪️ No Play Services = no QR scan = locked out. The bigger picture: ▪️ Google already tried this in 2023. It was called Web Environment Integrity (WEI), and it would have let Google decide which devices were "real enough" to access the web. Standards bodies and the public pushed back hard, and Google killed it. Three years later, the same idea is back, just hidden behind a QR code instead of a browser feature. ▪️ reCAPTCHA runs on millions of websites. Every developer who keeps using it is now, by default, telling deGoogled Android users they're not welcome...

English
0
0
0
79
Wijdan
Wijdan@wijdanri·
@ohheyitstmas Hi I’m hooman 100% 🥹 and if yo talk to me you don’t need token and never will reach token limit 😉
English
0
0
0
16
TMAS
TMAS@ohheyitstmas·
Any real humans left on this app?
English
120
1
141
3.5K