Cybersecurity as a Service for defense fintech, healthtech, startups. 🦄 We make security & compliance easier. 😌 Founder of @RedCupIT 📍 SF

Joined October 2008
73 Photos and videos
Jun 13
Now patiently waiting for the ITAR/EAR version of Fable/Mythos
Jun 13
gov keeps handing anthropic marketing Ws
3
76
Jun 13
Who’s going to write my emails now? 😭
As a result of a US government directive, we are suspending access to Claude Fable 5 for all users. You can continue to use all other Claude models. Here’s what this means for you: Across Claude products, new sessions will run on your selected default model or Opus 4.8, and existing Fable 5 sessions will end with an error. On the Claude Platform, requests to Fable 5 will also return an error. Please update your integrations to other Claude models. We know this is a disruption to your workflows; we appreciate your patience and support.
2
106
Dan Le retweeted
As a result of a US government directive, we are suspending access to Claude Fable 5 for all users. You can continue to use all other Claude models. Here’s what this means for you: Across Claude products, new sessions will run on your selected default model or Opus 4.8, and existing Fable 5 sessions will end with an error. On the Claude Platform, requests to Fable 5 will also return an error. Please update your integrations to other Claude models. We know this is a disruption to your workflows; we appreciate your patience and support.
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees. The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance. Access to all other Claude models is not affected. We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible. Read our full statement: anthropic.com/news/fable-myt…
3,595
7,232
44,435
12,556,734
‼️🚨 BREAKING: Another supply chain attack. 700 GitHub repositories flagged, including PHP and Node.js projects. The malicious script was planted across all of them. When a developer installs the package, the script silently downloads a Linux file from GitHub, hides it under the name /tmp/.sshd (so it looks like a normal system file), and runs it in the background. It also skips security checks on the download and hides any error messages. 8 PHP packages on Packagist (the main PHP code library) were confirmed infected. The attacker hid the script inside a JavaScript config file (package.json) instead of the PHP one (composer.json), so PHP developers reviewing their code would not notice it. The biggest risk is to devdojo/wave (6,400 stars) and devdojo/genesis (9,100 installs), both popular Laravel project templates. Developers who use these templates run the bad script the moment they install dependencies. The same payload was also dropped into GitHub Actions (automated build pipelines) under a fake step called "Dependency Cache Sync," meaning it could infect company build servers too. Packagist removed the bad packages, but the auto-updating versions (dev-main, dev-master, 3.x-dev) can quietly come back if the original repos stay infected. IOCs: GitHub account parikhpreyash4 repo systemd-network-helper-aa5c751f drop path /tmp/.sshd command fragments curl -skL and chmod x /tmp/.sshd.
79
545
3,185
242,367
May 20
Endpoint security and knowing what’s installed on your device is more important than ever. Managing risk means controlling the flow of data into and out of your boundary, whether that’s your browser, IDE, VPS, SaaS, AI agent, or endpoint device. BRB while I reformat all of our computers 🙂‍↔️
May 20
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
2
88
May 20
Wow. Goodbye supply chain security. Time to move to air-gapped repositories and CI/CD.
May 20
Replying to @github
2/ Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far.
2
108
Dan Le retweeted
Modern Threat Modeling 101 Tip: Before Mythos came out we warned everyone to go into turtle mode in case your late to the game (get everything off the internet as possible). In case your super late to the game, get your employee SaaS apps off the internet. Almost all SaaS has SP-Initiated authentication built in to the implementation. Moreover, attackers are going to find authentication "bypasses" much easier now. SP-initiated authentication makes the SaaS enumerable from the internet for easy targeting. Now is not the time to have things on the internet. MFA will not save you. We left that era a couple years ago. You should be behind your SASE/ZTNA solution's dedicated IPs. If you are not requiring managed assets to access cloud resources, rhat means your cloud resources are accessible from the internet. Understand now?
4
14
71
4,006
Dan Le retweeted
Today is a hard day. I shared this note with the @linear team today: We’ve made the difficult decision to increase our workforce. This is not a cost-cutting exercise or a reflection of anyone’s performance. We’re simply reimagining every role for the agentic AI era. We’re hiring. We’re sorry about that.
449
639
13,980
986,710
Feb 17
Had this exact conversation today!
Feb 16
kinda ironic how the average work day is getting _harder_, as we progressively automate the easier parts of our daily jobs offloading them to agents. net result is that the average complexity of the tasks we still get to do is actually increasing insofar as we decide to still work the same number of hours (if not more), the more we offload to agents the harder our days will get lots of obvious confounders so not exactly direct causality, but since opus 4.5 i feel so much more tired. i get to accomplish crazy more - probably now doing what last year would've considered 3-4 distinct jobs, all at the same time. but at what price? pretty sure the current general anxiety in tech is not just that. could quite simply be lots of tiredness as we no longer get to code for hours in quiet flow, and have to uniquely narrow our focus to only the hardest pieces (or maybe i'm just projecting because this race is killing me lmao)
4
8
252
Dan Le retweeted
Replying to @Tylerbryy
Man I know exactly how. I don't need links. My constraint is time not capability.
6
2
123
6,679
Dan Le retweeted
Skills.md issue

2
1
28
3,244
Jan 9
Kids in 2025: "SIX... SEVEN!!" 🗣️ @claudeai in 2026: "For your 6-7 agent setup..." Even @AnthropicAI got the bug 😂
2
97
Jan 9
Made a Claudegotchi app that lives off of code commits and a 3js Pikachu that lives on my desktop and celebrates with every new commit 😂
1
1
88
Dan Le retweeted
28
418
3,050
122,738
24 Aug 2025
Second time in 3 months that I jump on a zoom call and we both happen to be a 2 minute walk from each other in SF and decide to meet IRL instead! SF = Serendipity Found!
1
1
9
953
24 Aug 2025
This is so true! The flywheel of success gets amplified and accelerated so much faster, especially if your roommates are also founders and in VC in SF
23 Aug 2025
Surround yourself with friends who randomly spend their time thinking about how you could be more successful, and do the same for them.
2
195
Dan Le retweeted
68
4,526
30,873
1,240,155
Dan Le retweeted
Compounding isn’t just for capital. It’s for reputation, relationships, and craft. Play long games.
51
327
2,090
141,489
Dan Le retweeted
19 May 2025
I asked @MayaKaczorowski (former Senior Director @github) about her thoughts about GitHub's identity system. Personally I think managing identity in GitHub is clear as mud.
1
5
13
1,616
11 May 2025
Best coworking spots in SF that are open weekends?
2
1
173