HTB CAPE | OSEP | OSCP | CARTE | CRTO | CRTP

Joined May 2008
187 Photos and videos
Pinned Tweet
Apr 30
Passed the OSEP exam relatively easily. On to OSCE3! #OSEP #OSCE3 #OffSec
6
3
100
2,657
baas retweeted
Update 5:05 PT: The attack has now expanded well beyond @TanStack and @Mistral. 373 malicious package-version entries across 169 npm package names, including @uipath, @squawk, @tallyui, @beproduct, and more. The malware propagates by stealing your CI credentials and using them to publish new compromised versions. Full IOCs, affected package list, and detection steps: aikido.dev/blog/mini-shai-hu…
🚨 Update: @mistralai npm packages are now confirmed compromised as part of the ongoing Mini Shai Hulud attack. Affected versions: @mistralai/mistralai 2.2.2, 2.2.3, 2.2.4@mistralai/mistralai-azure 1.7.1, 1.7.2, 1.7.3@mistralai/mistralai-gcp 1.7.1, 1.7.2, 1.7.3If you use the Mistral SDK in any CI pipeline, treat your environment as compromised. Rotate npm tokens, GitHub PATs, and cloud credentials immediately.
76
476
2,633
2,404,164
baas retweeted

9
119
481
65,876
Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux. The file name transformers.pyz appears deliberately chosen to mimic the widely used Hugging Face Transformers library and blend into ML/dev environments. The main payload is a credential stealer, but it also includes country-aware logic; it avoids Russian-language environments and contains a geo fenced destructive branch that has 1-in-6 chance of executing rm -rf / when the system appears to be in Israel or Iran. To mitigate this threat: isolate affected Linux hosts, block 83[.]142[.]209[.]194, hunt for /tmp/transformers.pyz, pgmonitor[.]py, and pgsql-monitor.service, and rotate exposed credentials.
117
691
4,893
4,092,795
baas retweeted
Hahahahahaha VPNs are HURTING CHILDREN Hahahaha fucking stupid fucks
Virtual private networks #VPN are increasingly used to bypass online age verification. Protecting children online is a priority, with new rules being implemented requiring a minimum age for access to some services Read👉 link.europa.eu/FGfr6C #DSA @EP_Justice @FZarzalejos
Community note
According to the University of Michigan research paper "Multi-perspective study of VPN users and VPN providers," 82.1% used VPNs "to protect myself from various threats/adversaries." No research shows that VPNs would be increasingly used to bypass online age verification. censoredplanet.org/papers/VPN-Sur…
154
2,353
22,059
524,178
Still the hardest logo tech has ever produced
109
1,321
18,429
801,907
Microsoft Edge loads all your saved passwords into memory in cleartext — even when you’re not using them.
250
1,323
8,712
1,582,361
May 4
Het is oorlog maar niemand die het ziet
May 4
ShinyHunters hackt gegevens van 275 miljoen docenten en studenten ift.tt/jNcZqhG
1
187
baas retweeted
‼️Copy Fail (CVE-2026-31431) is a Linux privilege escalation bug that lets any local user get root using a 732-byte Python script, and itworks on basically every major Linux distro shipped since 2017. Website: copy.fail/ Write-up: xint.io/blog/copy-fail-linux… GitHub: github.com/theori-io/copy-fa… It's a logic flaw in the kernel's crypto code (authencesn via AF_ALG and splice()) that allows a small write into the page cache, which can be used to tamper with a setuid binary like /usr/bin/su. Think how bad this is going to be for shared environments like Kubernetes, CI runners, and cloud sandboxes, where it enables container escape and tenant-to-host compromise. Found by Theori's Xint Code scanner, patched in the mainline kernel, and publicly disclosed on April 29, 2026; if you can't patch right away, the recommended workaround is to disable the algif_aead module.
59
817
3,300
402,904
baas retweeted
Lovable has a mass data breach affecting every project created before november 2025. I made a lovable account today and was able to access another users source code, database credentials, AI chat histories, and customer data are all readable by any free account. nvidia, microsoft, uber, and spotify employees all have accounts. the bug was reported 48 days ago. its not fixed. They marked it as duplicate and left it open.
269
712
5,670
1,415,347
hackers as the first group to embrace KYC for access to new models is cutting me deep. we used to be rebels
21
36
370
25,583
baas retweeted
I warned back in December 2023 (!!!) that push notifications were a major opsec hazard being exploited by US intelligence to break encryption, and now here were are: kitklarenberg.com/p/push-not…
🚨 BREAKING: The FBI has successfully extracted deleted Signal messages from a suspect's iPhone via notification storage, the place where all your notifications are stored for up to one month. Notification storage stores data from all messaging apps, it's a big flaw in iOS. But there's a way to turn it off...
37
2,668
11,101
684,324
baas retweeted
i'm not satoshi, but I was early in laser focus on the positive societal implications of cryptography, online privacy and electronic cash, hence my ~1992 onwards active interest in applied research on ecash, privacy tech on cypherpunks list which led to hashcash and other ideas.
1,989
3,417
28,399
3,008,887
baas retweeted
Bluehammer Privilege escalation via Microsoft Defender. No patch yet github.com/Nightmare-Eclipse… #0day #lpe
10
254
1,304
117,904
Apr 5
new levels of social engineering if true
153
baas retweeted
Claude code source code has been leaked via a map file in their npm registry! Code: pub-aea8527898604c1bbb12468b…
3,329
7,538
48,505
35,672,906
baas retweeted
Mar 23
You can now enable Claude to use your computer to complete tasks. It opens your apps, navigates your browser, fills in spreadsheets—anything you'd do sitting at your desk. Research preview in Claude Cowork and Claude Code, macOS only.
4,921
14,299
138,640
78,053,403