0xfran6(🍊,💊)

11.1K posts

0xfran6(🍊,💊) banner
0xfran6(🍊,💊)

0xfran6(🍊,💊)

@yeabor

IT Support Engineer and Crypto Enthusiast

Abuja Katılım Mart 2011
6.5K Takip Edilen1.1K Takipçiler
0xRiim
0xRiim@0xRiim·
-$133 in pnl + fees. trust me, my life on @tread_fi yesterday sucked, lol. ran 16 setups in the last 24 hours and only 2 actually completed. the rest either got stopped out or i couldn’t stomach the drawdown so i cancelled. pushing a few final setups today just to hit my target volume on @risextrade, then it’s goodbye to treadfi and back to my normal trade setups. imo, it’s not worth it.
0xRiim tweet media0xRiim tweet media
0xRiim@0xRiim

10x volume boost on @risextrade (3 days to go) today, i came across an article on how to use @tread_fi’s market maker bot to generate volume on Risex. before that, i had already spent most of the day experimenting with the bot myself. fun fact: it’s actually good and very convenient, but also pretty expensive, at least in my opinion. still, i’m making another deposit right now with the intention of burning through about 50% of it chasing volume. if things go well, i might even close the hunt in positive pnl. link to article if interested: x.com/og_branxi/stat… wish me luck, amigos.

English
6
0
25
1.7K
0xRiim
0xRiim@0xRiim·
10x volume boost on @risextrade (3 days to go) today, i came across an article on how to use @tread_fi’s market maker bot to generate volume on Risex. before that, i had already spent most of the day experimenting with the bot myself. fun fact: it’s actually good and very convenient, but also pretty expensive, at least in my opinion. still, i’m making another deposit right now with the intention of burning through about 50% of it chasing volume. if things go well, i might even close the hunt in positive pnl. link to article if interested: x.com/og_branxi/stat… wish me luck, amigos.
0xRiim tweet media
0xRiim@0xRiim

the subtle art of depositing on @risextrade gut feeling; good things are coming

English
6
1
29
3.2K
0xRiim
0xRiim@0xRiim·
the subtle art of depositing on @risextrade gut feeling; good things are coming
0xRiim tweet media
English
3
0
21
2.1K
Sam Altman
Sam Altman@sama·
we're starting rollout of GPT-5.5-Cyber, a frontier cybersecurity model, to critical cyber defenders in the next few days. we will work with the entire ecosystem and the government to figure out trusted access for cyber; we want to rapidly help secure companies/infrastructure.
English
1K
824
12.9K
1M
tether wallet
tether wallet@tetherwallet·
The tap is turned back on! 🚰⚡️ The @btc faucet is officially LIVE again. To claim your free Sats, reply to this tweet, making sure to tag @btc AND include your @tether.me username. We will instantly drop a piece of Bitcoin straight into your wallet! Follow @btc & @tetherwallet
English
3.2K
614
1.8K
91.9K
0xfran6(🍊,💊)
0xfran6(🍊,💊)@yeabor·
Worth noting that PIM needs Entra ID P2. It's not bundled with Business Premium or below, which feels like a strange omission for a feature this fundamental. Come on MS, you can do better 😀
Merill Fernando@merill

Entra Hardening Tip #6: Kill Standing Access 🔐 Admin accounts are the ultimate target. If these accounts stay active 24/7, you're leaving a door open for attackers to disable policies, create identities + credentials and hide in your tenant. To harden Microsoft Entra, you need Zero Standing Access. ⏰ Just-In-Time (JIT) Access Stop using permanent role assignments. Use Privileged Identity Management (PIM) so roles are only active when they are actually being used. This limits the time an attacker has to exploit a compromised account. 👥 The Second Admin Rule Don't let a single user activate a high-risk role alone. Require a second admin to approve the request. This forces an attacker to compromise two accounts to get anywhere. This "two-key" system breaks the attack chain and creates logs that are much easier to monitor. Checklist: ✅ Use PIM: Move your admins from "Permanent" to "Eligible." ✅ Log Justifications: Every activation needs a business reason. ✅ Enforce Approvals: Require a second admin for high privileged roles. ✅ Audit Often: Use Entra ID Governance to ensure access is still necessary. If they can't get the time or the second approval, they can't get to your data.

English
0
0
3
49
Andrew Warner
Andrew Warner@AndrewWarner·
Apps are cooked. Screenshot anything in the App Store → drop it into chat → swipe up for an instant @openclaw agent → delete app, save $29/year @shanemac showed me how to: Add OpenClaw or Hermes to chats. Have them build. Or just be assistants. Invite only. Comment "agent" if you want early access.
English
17
2
13
7.4K
Chief Outside Officer
Chief Outside Officer@TheOutsidePlug·
To save his daughter, he took an entire mysterious organization single-handedly 🔥🎬
English
54
68
432
3.2K
EZ
EZ@IAMERICAbooted·
IT Security: No shortage of ego, big shortage of skill :p
English
8
3
48
1.9K
0xfran6(🍊,💊)
0xfran6(🍊,💊)@yeabor·
@david_das_neves Amazing resource. Something I would like is to be able to filter pillars based on licensing requirements i.e Org has a Business Premium License, selecting this, I can view all the controls/pillars that allows me.
English
1
0
8
536
sǝʌǝN sɐp pᴉʌɐD
sǝʌǝN sɐp pᴉʌɐD@david_das_neves·
Zero Trust Explorer (by Merill Fernando): interactive map of M365/Azure security controls across identity, devices, apps, and data. Great way to see how Entra ID, Defender, Intune, and Purview fit together in real architectures. buff.ly/5cBFqy6 #ZeroTrust
sǝʌǝN sɐp pᴉʌɐD tweet media
English
2
28
193
14.4K
Azure Jay ☁️
Azure Jay ☁️@CloudTechJay·
@yeabor I had to put all the OU’s in the script. Groups are cloud based. Dynamic groups are set up so once the delta sync runs they get placed in the respective groups.
English
2
0
0
210
Azure Jay ☁️
Azure Jay ☁️@CloudTechJay·
Finished creating a PowerShell Script to scan for New Hire requests listed in our client’s Sharepoint, then triggers the next script to create the User in Active Directory On-Premise!
Azure Jay ☁️ tweet media
English
13
16
180
11.6K
Ghost St Badmus
Ghost St Badmus@commando_skiipz·
A very short story …
Ghost St Badmus tweet mediaGhost St Badmus tweet mediaGhost St Badmus tweet media
GIF
English
27
46
212
70.6K
EZ
EZ@IAMERICAbooted·
@yeabor they'll have no problem finding another job if that happens. Strategically, it's not a good move to fire them :) Shit happens. People's have been distilling Anthropics models for years.
English
1
0
1
85
EZ
EZ@IAMERICAbooted·
holy cow if true👀👀
Jeremy@Jeremybtc

Anthropic accidentally leaked their entire source code yesterday. What happened next is one of the most insane stories in tech history. > Anthropic pushed a software update for Claude Code at 4AM. > A debugging file was accidentally bundled inside it. > That file contained 512,000 lines of their proprietary source code. > A researcher named Chaofan Shou spotted it within minutes and posted the download link on X. > 21 million people have seen the thread. > The entire codebase was downloaded, copied and mirrored across GitHub before Anthropic's team had even woken up. > Anthropic pulled the package and started firing DMCA takedowns at every repo hosting it. > That's when a Korean developer named Sigrid Jin woke up at 4AM to his phone blowing up. > He is the most active Claude Code user in the world with the Wall Street Journal reporting he personally used 25 billion tokens last year. > His girlfriend was worried he'd get sued just for having the code on his machine. > So he did what any engineer would do. > He rewrote the entire thing in Python from scratch before sunrise. > Called it claw-code and Pushed it to GitHub. > A Python rewrite is a new creative work. DMCA can't touch it. > The repo hit 30,000 stars faster than any repository in GitHub history. > He wasn't satisfied. He started rewriting it again in Rust. > It now has 49,000 stars and 56,000 forks. > Someone mirrored the original to a decentralised platform with one message, "will never be taken down." > The code is now permanent. Anthropic cannot get it back. Anthropic built a system called Undercover Mode specifically to stop Claude from leaking internal secrets. Then they leaked their own source code themselves. You cannot make this up.

English
4
0
18
5.8K
EZ
EZ@IAMERICAbooted·
@yeabor I always recommend delegated permissions wherever possible. They are usually enough to enable the org. Permission drift usually happens because people hit hurdles in the dev process and think it's a permissions issue when it's not.
English
1
0
2
154
EZ
EZ@IAMERICAbooted·
New blog post preview: When you have given an Entra App Registration any of these application permissions (not delegated), you have given the application whats equivalent to a highly stealthy SharePoint Admin: Allsites.FullControl (SharePoint API) Allsites.Manage (SharePoint API) Allsites.readwrite (SharePoint API) Sites.fullcontrol.all (Graph) Sites.manage.all (Graph) Sites.readwrite.all (Graph) When you give an Entra App Registration the following application permissions (not delegated), you have given the people who have access to the client secret a higly stealthy privilege escalation to Global Admin: ApplicationRoleAssignment.readwrite.all Application.readwrite.OwneBy Application.readwrite.all When you give an Entra App Regiatration application permissions (not delegated) to the following permissions, if the client secret is compromised, you lose the integrity of every file in your organization allowing an attacker to stage persistance, privilege escalation, lateral movement, and organization wide data compromise: Files.readwrite.all More to come in an upcoming blog post.
English
6
15
115
9.5K