Info-Sec/Security, Cycling, and monitoring the situation

Joined October 2020
300 Photos and videos
Aaronstotle retweeted
Novo Nordisk has been compromised. Novo Nordisk has confirmed the compromise. Novo Nordisk is the company that became famous after producing weight loss drugs like Ozempic and Wegovy The Threat Actor(s) responsible for the attack has been playfully extorting Novo Nordisk (they're not being playful) and have unveiled some details regarding what was stolen. Interestingly, it appears Novo Nordisk has it's own internal AI thing because some of the data stolen was stuff from their internal AI agents. Data stolen (according to the Threat Actor): - Trained model checkpoint (16GB) - Proprietary training dataset (407MB) - Full source code (modeling_novopert.py, training pipeline) - 113 training runs with complete logs - Internal infrastructure maps (HPC, Slurm, SSH) - Container images (53GB ) - Developer identities and internal hostnames - Private GitHub repository URL
34
178
1,507
107,961
Aaronstotle retweeted
Arch Linux is still having supply-chain attacks and other misc. security issues. This is devastating to the over 25 people who use Arch as a daily driver.
184
259
4,253
120,855
Aaronstotle retweeted
This is the only angle that does that miracle justice.

251
5,263
79,190
2,337,492
Aaronstotle retweeted
OG Anunoby leaving Toronto and thriving in America like every homegrown Waterloo software engineer
65
515
9,343
327,405
Aaronstotle retweeted
the most sinister, hopeless backroom in mahattan
105
1,388
17,140
889,401
Aaronstotle retweeted
Hidden gem!!!
I have officially decided that this area in nyc is the best
84
175
12,642
846,647
Aaronstotle retweeted
Jun 10
Another iOS app accidentally shipped a CLAUDE.md file: Netflix
131
334
7,354
955,900
Aaronstotle retweeted
I just open sourced my "Is this slop?" simple test
115
1,044
19,176
454,898
Aaronstotle retweeted
One of my personal favorite features announced at WWDC will I suspect be a sleeper hit: container machines, allowing your Mac to run a lightweight, persistent Linux environment with your home directory and repos automatically mounted: github.com/apple/container/b…
228
815
9,698
732,690
Aaronstotle retweeted
I don’t know how this referee is making it out of New York tonight
243
1,394
23,482
530,587
Aaronstotle retweeted
Before AI, I’d spend a weekend building 1 useless app. Now I can build 67 useless apps over a weekend, each with a logo, a fancy webpage, and 0 user.
426
554
8,267
266,785
Aaronstotle retweeted
As someone who: > Hacked basically every component of openclaw's ecosystem (harness, skills ecosystem etc) > Helped lead security, trust & threat modelling > Found 15 CVE's in the software Absolutely do not run OpenClaw on your enterprise device.
30
93
616
42,079
Aaronstotle retweeted
Someone hid a self-replicating worm inside 37 npm packages. Written in Rust. Hidden behind an eBPF kernel rootkit. Talking to its operator over Tor. It steals 86 environment variables. AWS keys. GCP keys. Vault secrets. Kubernetes tokens. Your Anthropic API key. Your OpenAI key. Your Exodus wallet seed phrase. Then it uses your own npm credentials to republish itself into your packages. So your code infects the next developer. Who infects the next one. The commits were backdated up to 13 years. The commit author name was “claude.” The malware named itself after the AI to hide in plain sight. The attacker also left their own wallet recovery phrase in the debug data. Nobody is having a good day. Check your preinstall hooks.
⚠️ New "IronWorm" supply-chain attack: 30 npm packages from @ asteroiddao shipped a malicious Rust binary firing on preinstall. It sweeps 86 env vars 20 credential files (AWS, GCP, Vault, npm, plus AI keys like Anthropic & OpenAI), hits Exodus wallets, hides behind an eBPF rootkit, and beacons over Tor. Self-propagates via npm Trusted Publishing OIDC, with backdated commits faked as claude/dependabot/renovate.
91
538
3,286
503,974
Aaronstotle retweeted
Can we PLEASE for the love of all that his holy STOP NORMALIZING THIS INSTALL METHOD
399
282
6,956
586,739
Aaronstotle retweeted
did you know that in most white collar jobs you can just go for a 15-20 minutes walk multiple times a day and they just like don't care
173
269
16,880
874,726
Aaronstotle retweeted
the four horsemen of the apocalypse
308
1,303
21,444
2,962,210
Aaronstotle retweeted
another week at the prompt factory.
23
193
2,556
70,899
RT @wongmjane: Even my Instagram account got hacked The password got changed without my knowledge and I was getting different password res…
108
Aaronstotle retweeted
Me celebrating my 10% YTD return after missing out on generational wealth in semis and memory:
48
159
6,489
369,601
Aaronstotle retweeted
Opus 4.8 is insane guys. It one shotted my session usage limit.
420
969
25,615
1,246,417