zikasak

2.8K posts

zikasak

zikasak

@zikasak

Israel Katılım Aralık 2009
130 Takip Edilen26 Takipçiler
zikasak
zikasak@zikasak·
@h4x0r_dz Are we reading the same lovable response? They clearly said that the documentation provided to HackerOne was incorrect.
English
0
0
4
333
H4x0r.DZ 🇰🇵
H4x0r.DZ 🇰🇵@h4x0r_dz·
To be secure in 2026 you have to shut down your bug bounty program on HackerOne. Lovable got hacked because HackerOne's incompetent triage team closed multiple valid vulnerability reports starting February 22, 2026 as "intended behavior." Poorly trained monkeys. Zero escalation to Lovable's security team. AI bots auto-closing critical findings. The result? Public project chat history and source code were exposed for MONTHS until a researcher was forced to go public. Two companies. Same platform. Same failure. Same lies. ClickUp. Lovable. Both breached because HackerOne buried critical reports while collecting your bounty fees. HackerOne is NOT a security partner. They are a liability. They close real vulnerabilities. They protect their own metrics over your data. They let researchers get attacked while they stay silent. Stop paying HackerOne to get hacked. lovable.dev/blog/our-respo…
H4x0r.DZ 🇰🇵 tweet media
English
51
97
880
89.8K
zikasak
zikasak@zikasak·
@lhtness66060 @GergelyOrosz Read the message carefully... They are working on test coverage for merge queue operations. Reads like there were no tests
English
1
0
2
31
lhtness
lhtness@lhtness66060·
@GergelyOrosz Wait, github somehow failed to correctly implement "git merge origin/main", despite it previously being correctly implemented for a very long time? And tests did it catch it?
English
2
0
4
1.6K
Dito
Dito@morpig·
@rauchg still dont understand how "login with google" can gain access to vercel's internal stuffs. need clarity on this
English
5
1
25
7K
Guillermo Rauch
Guillermo Rauch@rauchg·
I want to keep everyone updated on the details of the security investigation. The team performed an in-depth analysis to search for root causes and to better understand the behavior of the threat actor. We cast a very wide net, pulling and processing nearly a petabyte of logs of the entire Vercel Network and API, extending well beyond the initial Context[.]ai compromise. We now understand that the threat actor has been active beyond that startup's compromise. Threat intel points to the distribution of malware to computers in search of valuable tokens like keys to Vercel accounts and other providers. Once the attacker gets ahold of those keys, our logs show a repeated pattern: rapid and comprehensive API usage, with a focus on enumeration of non-sensitive environment variables. As a result: ◾We've deepened and widened our collaboration with partners across the industry, like Microsoft, AWS and Wiz, to further protect the broader internet. ◾ We've notified other suspected victims of this threat actor, independent of this event, encouraging them to rotate credentials and adopt best practices. We've also shipped a bunch more product enhancements. I'm extremely thankful to our team and industry partners for working around the clock. For more details on the ongoing investigation, refer to our security bulletin: vercel.com/kb/bulletin/ve…
English
85
151
1.3K
210.1K
Artem Zakharchenko
Artem Zakharchenko@kettanaito·
@madebyhex There are several *standard* APIs in Safari that straight out don't work. Having spent half a year on a webview-based refactor, I know that architecture is a waste of time for some apps, if not all.
English
1
0
0
370
zikasak
zikasak@zikasak·
@brave An extension which precents pwa from poisoning brave history
English
0
0
0
4
Brave
Brave@brave·
What extensions would you most want to use in Brave for Android? 📱 (Bonus points if you have suggestions other than ad blockers and VPNs. We're looking for your picks across all categories!)
English
664
53
1.4K
136.2K
zikasak
zikasak@zikasak·
I wonder if #Apple eventually would fix ChatGPT integration in screenshots. Often it just loses the question and context ending with “What would you like to know?”
English
0
0
0
16
zikasak
zikasak@zikasak·
@Not_Prasar And even more: they have an instruction to do nothing
English
1
0
67
799
Pracar
Pracar@Not_Prasar·
That’s also why Apple employees on right video walk like nothing is happening. They don’t have to do anything, the guy already fucked up badly
English
2
6
770
11.6K
Private Talky
Private Talky@privatetalky·
What do you think the upcoming rumored OLED touchscreen MacBook Pro will be called? 👀
Private Talky tweet media
English
44
19
431
27.8K
zikasak
zikasak@zikasak·
@SebAaltonen There are 0 phones with a18 pro and 12 gb tam
English
0
0
14
291
zikasak
zikasak@zikasak·
@nsg650 And even more: macos does the same thing!
English
1
0
0
322
Vasiliy Zukanov
Vasiliy Zukanov@VasiliyZukanov·
PSA: gpt-5.2-high is much, MUCH better than gpt-5.3-codex, albeit slower. Codex models don't handle complex tasks well, only relatively straightforward instructions, while gpt-5.2-high is Opus 4.5 level of intelligence (close to Opus 4.6).
English
3
0
4
1.4K
Precious Vincent
Precious Vincent@vincent_presh·
@SebAaltonen Brother, people still pay for the tokens via API or subscriptions, its not free
English
9
0
0
664
Precious Vincent
Precious Vincent@vincent_presh·
Lmaooo what makes you think people will download open source models and use it themselves 🤣🤣, AI is not just the models, its the harness and the integrations that have to be built separately as well
Sebastian Aaltonen@SebAaltonen

Tiny (4GB) open source LLM models already match GPT 4.0. You can download one and run it for free on your entry-level GPU (runs on iGPU too). If these small open source models are good enough for most consumers, they will never become paying customers. That's a big risk.

English
2
0
2
9.2K
zikasak
zikasak@zikasak·
@SebAaltonen @CryptoCyberia And even apple didn't block third party OS on desktops/laptops. There is even a special mode for loading. But no documentation. Developers must do reverse engineering.
English
0
0
2
402
Sebastian Aaltonen
Sebastian Aaltonen@SebAaltonen·
@CryptoCyberia First of all, the image is 100% BS. Makes zero sense. Second, the ARM instruction set isn't locked down. It's entirely up to the CPU manufacturer to make these decisions. Of course Apple is locked down, but that's just a single ARM CPU manufacturer.
English
4
2
273
7.4K
Lain on the Blockchain
Lain on the Blockchain@CryptoCyberia·
I feel like privacy advocates don't talk about how shitty and locked down ARM chips are. While x86 allows for installing whatever operation system you want, ARM chips lack this flexibility so that OEMs can continue to force you to buy a new device every 5 years.
Lain on the Blockchain tweet media
English
101
28
591
66.5K
zikasak
zikasak@zikasak·
@JohnDekkaTech @thdxr Some time in the future people will learn that llms don't have self awareness
English
2
0
1
138
dax
dax@thdxr·
GLM5 is free in opencode for this week
English
141
110
2.9K
361.2K
SmokeyStack
SmokeyStack@SmokeyStack_·
😭There are people in the official MC Discord conspiring that Mojang is switching to Vulkan to kill off Minecraft on laptops and force players to use NVIDIA cloud gaming services.
English
96
185
6.8K
174.4K