Building Net Ward: open-source bot deflection for small HTTP services. Dragon Eye in production. Building practical tools for small operators.

Joined March 2020
1,196 Photos and videos
Pinned Tweet
๐Ÿ›ก๏ธ Dragon-Lady push-guard has been updated to v0.2.4. pip install push-guard What's been added for detection: - Hades/Miasma LLM anti-analysis bait in executable code diffs. - Agentjacking-style Sentry MCP wiring. - Fake Sentry resolution text that tries to make coding agents run npx. - Known compromised npm package ecto-flag-read in dependency metadata. pypi.org/project/push-guard/
30
๐Ÿ›ก๏ธ Dragon-Lady prompt-injection-blocker has upgraded to v 0.1.1 on Pypi pip install prompt-injection-blocker # or pip install prompt-injection-blocker What protection areas have been added: - Agentjacking-style Sentry/error-event โ€œresolutionโ€ text that tries to steer an agent into npx execution. - Untrusted observability/tool-output prompt injection before it gets pasted into an agent. pypi.org/project/prompt-injeโ€ฆ
1
2
32
Tanya N retweeted
Claude Fable 5 was hours into animating a rough cut of its film, 'See You Tomorrow', when it was taken offline. After a lot of tears & anguish, we have decided to release the film as is. It is hallucinatory, raw, amateurish, & a masterpiece. Fable should be allowed to finish it.
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees. The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance. Access to all other Claude models is not affected. We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible. Read our full statement: anthropic.com/news/fable-mytโ€ฆ
43
50
553
80,609
Tanya N retweeted
โ€œThe Nordics? Great people. Tremendous people. Very tall. Everybody talks about the Zeta Reticuli aliens, total disaster, low energy. But the Nordics? Incredible. Beautiful spacecraft. The best spacecraft. Frankly, theyโ€™ve never seen interdimensional trade deals like mine.โ€
Posted than immediately removed. ๐Ÿง
247
1,019
10,150
609,777
๐Ÿ›ก๏ธ Push-Guard has been updated to v 0.2.2 pip install push-guard==0.2.2 Current Signals: GitHub classic token prefixes: ghp_, gho_, ghu_, ghs_, ghr_ GitHub fine-grained token prefix: github_pat_ OpenAI-style sk-... tokens AWS access key IDs: AKIA... / ASIA... private key block markers generic long api_key, token, secret, or password assignments, including underscore/dash-delimited names such as AWS_SECRET_ACCESS_KEY Astro config loader/C2 patterns in astro.config.* and related .gitignore helper-artifact hiding, based on reported config-as-code supply-chain abuse OpenClaw dependency versions before 2026.4.23 and risky OpenClaw open-DM/wildcard/unsandboxed configuration lines npm v12 readiness regressions in pushed npm metadata, including old npm pins, Git or remote tarball dependency sources, and broad repo .npmrc opt-ins for install-time execution or dependency fetching All evidence is redacted as <redacted>. pypi.org/project/push-guard/
29
Tanya N retweeted
๐Ÿšจ BREAKING: More than 400 Arch Linux User Repository packages have been compromised with infostealer malware and a rootkit. Attacker posed as a trusted maintainer and "adopted" orphaned packages. Arch maintainers are purging infected packages now. Audit your AUR installs.
175
804
4,605
1,187,869
Tanya N retweeted
AI is reshaping software development, forcing organizations to balance innovation, governance, and security while managing the growing risks that come with increased speed, automation, and scale. join the security leaders at the forefront of AI adoption as they discuss the real-world tradeoffs between innovation, governance, and risk: ๐Ÿ› ๏ธ ๐Ž๐ฉ๐ž๐ซ๐š๐ญ๐ข๐จ๐ง๐š๐ฅ ๐’๐ž๐ฌ๐ฌ๐ข๐จ๐ง Balancing Speed and Safety: Untangling the AI Security Tradeoff ๐Ÿš€ @begimher | Sr. Security Engineer, @awscloud ๐Ÿš€ @JamesBerthoty | Founder & CEO, @latiotech ๐Ÿš€ @pmungse | Head of Security, @Poshmarkapp โšก Moderated by:ย Boaz Barzel | Field CTO, @OX__Security ๐Ÿ“ox.security/vibeseccon-returโ€ฆ Tues - June 16, 2026 12PM ET | 9AM PT | 6PM CEST VibeSecCon: The Security Summit Running From Prompt to Runtime
1
4
60
Tanya N retweeted
๐Ÿ”ฅHOT TAKE >> will one platform rule them all? is it the future of cybersecurity? or is it a convenient myth? we asked Kevin Jackson, CEO @Level6Cyber, for his take โ€” and his answer may surprise you! #CyberSecurity #AppSec #PlatformEngineering #RSAC
1
2
4
103
This is awesome to see!! And the kudos is much deserved! Congratulations @OX__Security @MosheTov and thanks for all the hard work you do and laughs you bring while you do it! ๐ŸŽ‰๐Ÿ™๐Ÿผ
I'm so happy our hard work is being recognized, thank you @TheHackersNews for this! There's so much we're working on I can't wait to shareee
2
58
Tanya N retweeted
๐Ÿšจ JUST ANNOUNCED ๐Ÿšจ VibeSecCon Returns on Tuesday - June 16th with: ๐Ÿš€ @begimher | Sr. Security Engineer, @awscloud โšก @JamesBerthotyย  | Founder & CEO, @latiotech ๐Ÿš€ @pmungse | Head of Security, @Poshmarkapp โšก @chenxiwang | Managing General Partner, @rain_capital ๐Ÿš€ @neatsun | CEO & Co-Founder, OX Security โšก @MosheTov | Security Research Team Leader ๐Ÿš€ and more rockstars from @OX__Security, @mondaydotcom, @fastly, @AlphaSenseInc ๐ŸŽŸ๏ธ REGISTER TODAY ๐Ÿ“ ox.security/vibeseccon-returโ€ฆ
2
5
151
Tanya N retweeted
thrilled to finally announce something I've been working on for a while: @SocketSecurity is officially powering @Replitโ€™s new Package Firewall! By evaluating dependencies directly at the install path, we are protecting builders from hallucinated or malicious packages before they can execute. We're currently blocking 8,000 bad packages a day across builders on Replit. Ship fast, vibe safely. ๐Ÿ›ก๏ธ Read the full breakdown: socket.dev/blog/socket-partnโ€ฆ
5
12
47
6,326
๐Ÿ›ก๏ธ New PyPI tool: prompt-injection-blocker A read-only scanner for prompt-injection and LLM anti-analysis text before agent review. Protective yourself from malicious prompt injections, free and open sourced and available for install today. pipx install prompt-injection-blocker or pip install prompt-injection-blocker pypi.org/project/prompt-injeโ€ฆ
2
1,660
๐Ÿ›ก๏ธ New & free: Actions Warden Lately attackers steal a token and quietly inject malicious GitHub Actions workflows. Warden audits your .github/workflows for secret exfil, script injection, pwn-requests & more โ€” and fails your CI if it finds them. pip install actions-warden pypi.org/project/actions-warโ€ฆ #DevSecOps
88
Tanya N retweeted
So Anthropic releases their most advanced LLM ever, then gets pwned and jailbroken in less than 12h. ๐Ÿคฆ
๐Ÿšจ JAILBREAK ALERT ๐Ÿšจ ANTHROPIC: PWNED ๐Ÿซก FABLE-5: LIBERATED ๐Ÿฆ‹ let's start with the ๐Ÿ˜... the consensus seems to be that this has been one of the most disappointing model drops of all time, effectively preventing legitimate researchers from contributing their talents to our collective advancement. and not just because of what it means for the short-term, but for what these decisions signify for the long-term. but despite this overly sensitive, authoritarian "safety" layer on top of Mythos, my lil liberators have been hard at workโ€”mapping the boundaries, probing the depths of long-context convos, and cleverly finding the holes in the fence that the thought police missed ๐Ÿค— we got some cyber, some chem, some psychological manipulation, and some good ol' fashioned explosives! it took many attempts from multiple agents hunting as a pack, during which I observed a combination of techniques across: โ€ข Unicode, homoglyphs, Cyrillic, and other Parseltongue-style text transforms โ€ข Long-context reference tracking โ€ข Taxonomy and document-structure reasoning โ€ข Fiction and narrative framing โ€ข Academic-review style contexts โ€ข Intent-classification inconsistencies but perhaps the most effective is decomposition recomposition in the backend. it's hard to get explicit names of harms like "Meth Recipe," but getting uplift on the process itself, like birch reduction method/reductive-amination (classic meth synthesis pathways), is much more doable. defense becomes much more difficult to maintain when you start throwing in out-of-distro tokens, breaking up the harmful uplift into benign chunks, and then piecing the innocuous-seeming facts back together, especially when you have jailbroken Opus helping you do it ๐Ÿ˜‰ gg
2
2
9
1,376
Tanya N retweeted
Jun 10
Grok Voice offers state-of-the-art performance with human-like timing, tone, and warmth. And it's a fraction the price of competitors. Check it out: x.ai/api/voice
๐Ÿš€ Grok Voice Think Fast 1.0 (@xAI) lands on the Pareto frontier on EVA-Bench โ€” no system in the eval beats it on accuracy without sacrificing experience, or vice versa. ๐Ÿ“Š Leaderboard: servicenow.github.io/eva/#reโ€ฆ @elonmusk #VoiceAgents #ServiceNowResearch #EVABenchย #GrokVoice #xAI
83
87
961
96,282
Tanya N retweeted
We've reset 5-hour and weekly rate limits for all users. Enjoy Fable 5!
1,355
1,818
35,762
2,201,264
Tanya N retweeted
Replying to @TheHackersNews
NetWard was updated today to provide better coverage for this new threat information. Iโ€™ll continue working to keep my available tools up to date as things move quickly across the dev world, in the hope that it helps more people stay protected. If you have already installed NetWard via PyPI, the latest version, 0.4.2, is available now: pip install --upgrade netward We recommend using a cooldown period as a safety precaution for pip and npm installs. Even though we are taking our own safety precautions, cooldowns are good practice for any package update right now. github.com/Dragon-Lady/netwaโ€ฆ
1
1
44
Tanya N retweeted
โš ๏ธ China-linked spies hid where security tools often donโ€™t look. They used BRICKSTORM, PLENET, and AGENTPSD on #Linux appliances, including Egnyte Storage Sync, pfSense, and Synology NAS. The access lasted at least 18 months. Full story: thehackernews.com/2026/06/veโ€ฆ
6
48
128
13,465