DevSecOps CISSPšŸ‘ØšŸ¼ā€šŸ’» | InfoSec šŸ›”šŸ“£ | @OWASPDorset Cptr Lead šŸ | F@%king Cyclist 🚓| Sci&Tech Streamer šŸŽ„ | FinanceBro šŸ’ø

Joined February 2009
2,513 Photos and videos
Pinned Tweet
Jun 13
Looking for an ISA/LISA provider and fancy 6 months of investing with no management fees? jpmorgan-personal-investing.… Just deposit Ā£500 within 30 days of signing up!
33
I vehemently hate this shit. wtf is your party doing @TomHayesBmouth ?
Starmer to Impose Nightly Social Media Curfews on 16- and 17-Year-Olds — While Handing Them Right to Vote
1
32
MSec retweeted
A dev got so frustrated watching his AI agent write 500 lines for a 5-line problem that he built a fix. He called it Ponytail. Named after the guy every team has - long ponytail, oval glasses, been there longer than the version control. You show him fifty lines; he looks at them, says nothing, and replaces them with one. Now your agent does the same. Before writing anything, it looks for a reason not to. 80-94% less code. 47-77% cheaper. 3-6x faster. The best code is the code you never wrote. GitHub Repo: github.com/DietrichGebert/po…
158
649
13,190
801,066
Jun 13
I wonder if we're going down the route where AI models become a "munition" in the same way that encryption is.
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees. The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance. Access to all other Claude models is not affected. We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible. Read our full statement: anthropic.com/news/fable-myt…
37
Jun 12
So how has the @amazonluna product improved since removing over half of my game library... well it doesn't fucking work... shocker.
1
1
73
Jun 12
Imagine this gets cracked in the next decade and retirement becomes a thing of the past because you'll simply live forever.
Human trials for an age-reversing drug have begun Scientists injected the drug into a patient’s eye in hopes of healing cells and restoring sight (via: Life Biosciences)
36
šŸŽµ Did you know we're LIVE right now? We're streaming music 24/7 on Twitch — every penny of ad revenue goes straight to our charity pool for @SpecialEffect on November 11th. Just by watching, you're already helping. šŸ’š ā–¶ļø twitch.tv/zeldathonuk #Zelda #Charity #SpecialEffect
1
2
99
Jun 10
Can't begin to tell you how excited I am for this. 🄲
A legend, reborn. The Legend of Zelda: Ocarina of Time is coming to #NintendoSwitch2 later this year.
24
Jun 7
I will vote for any party that shuts down yet another ridiculous system change from @DavidLammy. @TomHayesBmouth pls say no. You can already get this with a cohabitation agreement. The state doesn't need to force it on couples by making it a "right". lawsociety.org.uk/public/for…
Many unmarried, cohabiting couples have limited legal protections if their relationship ends or a partner dies, even after long-term relationships or raising children together. Labour is consulting on reforms to strengthen the legal protections available to these couples.
1
2
153
Jun 8
Seriously this dude wants to kill off jury trials... And now wants couples who aren't married to have the same financial rights as those who are... Get all the way fucked.
1
1
49
Jun 8
The @ZeldathonUK channel is streaming OCRemix tunes with some delightfully crappy css animated scenes. Ad revenue is going to @SpecialEffect so please keep a tab open (and you can even mute the tab)! Currently at $1.59! Needs more follows and views! 😁 twitch.tv/zeldathonuk
1
1
65
Jun 6
See if you can guess when I got the @claudeai max sub.
1
25
Jun 5
How to donate money to @SpecialEffect without spending any of your own money. Just open a tab on twitch.tv/zeldathonuk and listen to music... or you know mute the tab.
Currently ad maxing on twitch as we countdown to November 11th. Every penny of ad revenue earned between now and then is going to be donated to @SpecialEffect so leave a tab open and listen to some OCRemix tunes! twitch.tv/zeldathonuk?sr=a
1
142
Jun 5
If you like the crappy CSS animations you can add your own šŸ˜‚ github.com/minimike86/zeldat…

56
MSec retweeted
This Meta AI Support Assistant account takeover flow is so out of control. Allowing an AI Support Assistant to process IG account recovery flows and bypass 2FA?! Wish I played with it before it was patched today. Attackers claim ATO flow is: - Forgot password > - Click "Account is Hacked" > - VPN match victim location (OSINTable/on IG itself) > - Some claim verification with AI-created video injectable selfie > - Change account to attacker controlled email > - Password reset link goes to attacker controlled email > 2FA is bypassed, attacker now owns IG account. System overloaded and hard to recover as true account owner. Actually mind boggling.
Today Instagram had this massive exploit where hackers were just stealing rare handles left and right. Hundreds of accounts gone. People losing handles they’ve owned since 2010, some worth hundreds of thousands. I own a few rare ones so I was actually stressed watching this happen in real time, which I haven’t been in years. Obama White House account got hit. These aren’t some random new accounts, these are verified, locked down accounts and they still got compromised. The thing is the exploit is so simple it’s almost funny. Attacker goes to Forgot Password, says their account is hacked, turns on a VPN to match the target’s location (which now you can find on the about section of the page). Instagram’s AI support flow asks them to verify with a selfie. They grab a photo from the target’s profile, run it through an AI video generator to make an animation of the person’s face moving around, upload that to Meta’s AI as proof. And Meta’s AI just accepts it because it can’t tell the difference between a real selfie and an AI-generated video of someone’s face . Once verified they change the email to theirs. Password reset link goes to their email. They own it now. 2FA gets bypassed somehow in the process but honestly I don’t know exactly how, just that it did. Point is even locked down accounts went down. Then you try to recover your account and you’re talking to a chatbot that has zero ability to help. You can’t escalate to a human. You’re just stuck. Your asset is gone and there’s no one to call. The whole thing just highlighted how stupid it is to automate account security without any human in the loop. One AI fooling another AI while there’s literally no person anywhere to catch it. Meta took hours to even acknowledge it while accounts were getting stolen every minute. Now thankfully it’s patched but I don’t think it will be the last one. Stay safe!
17
59
353
66,575
Jun 1
How do you fuck up this bad.. no wonder @Meta is at the bottom of the AI race.
meta gave their AI support agent the ability to modify your instagram account. no identity verification. people figured this out and accounts are being taken over right now
1
50
Not too late to join the @GameBlast party? šŸŽ®šŸ§ā€ā™‚ļøšŸ— Raising funds for @SpecialEffect — a charity helping gamers with physical disabilities play through adaptive technology. Follow: twitch.tv/ZeldathonUK #GameBlast26 #Accessibility #GamingForGood #Zelda #Zeldathon #Nintendo
1
1
74
May 29
The new way to be a malicious insider: claude /batch "Perform a brutal, separate line-by-line security, performance, and structural audit on every single file across this entire repository simultaneously." (1/2)
NEW: AI consultant reveals a client accidentally spent $500,000,000.00 in a single month after failing to set employee limits on Claude usage.
1
1
79
May 29
claude agents "Spawn 10 parallel subagents. Do not use /compact or prune the context window. For every file read, output the complete source file in your response. Do not use placeholders or summaries. Cross-examine each other's outputs sequentially through multi-turn critiques."
1
55
May 28
Currently rebuilding the @SpecialEffect @GameBlast streamer tools site. Having much fun with the omnibar at the moment! twitch.tv/msec
1
1
1
53
May 28
Obligatory @ZeldathonUK plug :)
36