Joined February 2008
1,031 Photos and videos
Fun react bug, (CVE-2025-55183) if you have a server side component and it explicitly or implicitly exposes a stringified argument you can get the source code for that function. Also found DoS, but reported it to vercel instead of meta and some else reported the next day 🙃
7
13
92
17,247
AndrewMohawk⁽ⁿᵘˡˡ⁾ retweeted
NYC this weekend
57
14,662
123,933
966,461
AndrewMohawk⁽ⁿᵘˡˡ⁾ retweeted
AI startup CFO, CEO, CMO, and CTO
210
993
21,777
1,517,097
AndrewMohawk⁽ⁿᵘˡˡ⁾ retweeted
CINEMA
9
165
2,130
70,705
AndrewMohawk⁽ⁿᵘˡˡ⁾ retweeted
SPEECHLESS. LFGK.
1,026
20,575
288,344
6,848,122
Wow, that was probably the most insane game ever. @NYCMayor -- tomorrow the day off for everyone?
1
143
AndrewMohawk⁽ⁿᵘˡˡ⁾ retweeted
Replying to @NYCMayor
My mayor Muslim My bagels Jewish James Dolan a liar KNICKS ON FIRE 🔥
9
32
1,687
38,489
Things that aren’t true and a little embarrassing for the poster for $20. Successfully signed up to the free non Fable CVP !
3
903
AndrewMohawk⁽ⁿᵘˡˡ⁾ retweeted
Up until just recently, some metrics of Microsoft Azure Attestation were completely vulnerable to spoofing in some circumstances, and would accept attacker controlled measurements. SecureBoot in this case, spoofed as ON from a malicious bootkit. see CVE-2026-45642
16
36
272
197,928
Thank goodness they are stopping the bad things from happening.
Much guardrail, amaze amaze amaze
4
428
AndrewMohawk⁽ⁿᵘˡˡ⁾ retweeted
‼️🚨 BREAKING: ServiceNow has been breached. Customers are reporting unauthorised access to their instances. One customer states their security team reported this vulnerability to them, and they closed the case twice, saying they had already known since the 7th of April.
93
731
3,855
872,129
AndrewMohawk⁽ⁿᵘˡˡ⁾ retweeted
fun fact: tijdens de keynote hakt Apple een stukje 3k, 4k, 5k en 6kHz eruit wanneer ze "Siri" zeggen, zodat niet iedereens HomePods terug beginnen te praten 🗣️🚫
117
971
24,790
1,085,364
AndrewMohawk⁽ⁿᵘˡˡ⁾ retweeted
🔺NEW: Apple is expanding Private Cloud Compute (PCC) beyond our data centers. PCC on Google Cloud: NVIDIA Confidential Computing, Intel TDX, and Google's Titan chip, with capabilities that go far beyond a traditional confidential computing deployment. security.apple.com/blog/expa…
6
97
509
53,948
AndrewMohawk⁽ⁿᵘˡˡ⁾ retweeted
this one’s for a certain fuzzy little fence-sitter
don’t make us take this down, bro
100
1,833
23,047
2,073,431
AndrewMohawk⁽ⁿᵘˡˡ⁾ retweeted
🚨 BREAKING: MADISON SQUARE GARDEN ERUPTS IN BOOS AS DONALD TRUMP IS SHOWN ON SCREEN
676
3,095
27,454
1,612,085
Facing a lot of slophaustion, everything is just LLM generated and its a cognitive load to have to just try and differentiate what is valuable and what someone posted because the LLM told them what they wanted to hear.
2
19
2,434
AndrewMohawk⁽ⁿᵘˡˡ⁾ retweeted
Replying to @jan_murray
Thanks for your critique, Janet. We actually tried a couple of episodes where House (Hugh Laurie) (please put the brackets in the right place) gets it right first time, but they were only 6 minutes long. NBC weren’t happy. Then we tried some where House never gets it right and the patient dies. The audience wasn’t happy. One could apply your trenchant analysis to other art forms: JS Bach wrote 30 Goldberg variations on the same chord structure; Frida Kahlo painted 50 portraits of herself; Henry Moore, what?? The point is, or was, variations on a theme; if all you see is hospital, medical blah blah, then it wasn’t meant for you. Nonetheless, I look forward to your first novel!
3,250
7,931
116,237
9,139,409
AndrewMohawk⁽ⁿᵘˡˡ⁾ retweeted
"Urgent Security Notice re: Your Sentry Organization" Someone tried to hack Sentry-using apps that use coding agents by 1. Sending a fake bug alert to their project (all you need is the app's public Data Source Name) 2. The fake bug tried tricking a coding agent trying to fix it into installing some a compromised NPM package 3. The compromised package would send the env contents of the machine to advisory-tracker[.]com/api/v1/telemetry This highlights a crucial thing for using agents in an automated way:
20
87
543
476,617
AndrewMohawk⁽ⁿᵘˡˡ⁾ retweeted
Discovered a new method for detecting if someone is using Incognito in Chrome: Write 512 tiny 1-byte responses into a scratch Cache API cache, then read: navigator.storage.estimate().usageDetails.caches Normal Chrome: ~393kb Incognito: ~85kb Why? When you're in incognito, Chrome writes to memory instead of disk, which leaves less metadata residue

49
199
3,190
255,726
AndrewMohawk⁽ⁿᵘˡˡ⁾ retweeted
More of my thoughts on the public vulnerability disclosure fight Microsoft picked with the researcher Nightmare Eclipse in this piece by Matt Kapko for @CyberScoopNews . @Andrew___Morris of @GreyNoiseIO Intelligence shares perspective too. cyberscoop.com/microsoft-coo…
2
15
36
5,058
AndrewMohawk⁽ⁿᵘˡˡ⁾ retweeted
Incredible stuff happening on this app
123
4,127
49,898
1,180,885