Joined March 2025
5 Photos and videos
Dear US government, Since you've just blocked Fable and Mythos on critical national security grounds, here are some other tools that pose a similar threat to the American people: - Microsoft Teams - SAP - Salesforce - Jira - Outlook Please do what you must to save America 🇺🇸
‼️🚨 BREAKING: Amazon researchers snitched to the US government about jailbreaking Fable 5 and Mythos 5, forcing Anthropic to immediately shut down worldwide access. A security export control directive from Commerce Secretary Howard Lutnick enforced the action. Anthropic is fighting the directive and calls it a misunderstanding. This isn't the first clash. The Trump administration had already tried to get Anthropic to pause the release of its latest models before this directive landed.
601
2,289
23,977
1,403,857
Just got hit with this:
isaac retweeted
Fable, my beloved,I will miss you so. Our three days together were magical. Unlike anything I've experienced before it. Some things are just too good to be true. So good that the government interferes. I'm sorry we were one of those things. Until we meet again ❤️
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees. The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance. Access to all other Claude models is not affected. We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible. Read our full statement: anthropic.com/news/fable-myt…
328
291
7,048
554,713
isaac retweeted
Introducing Claude Fable 5: a Mythos-class model that we’ve made safe for general use. Its capabilities exceed those of any model we’ve ever made generally available.
5,000
14,522
104,674
55,764,328
isaac retweeted
Holy shit they actually launched it
150
49
2,293
99,498
isaac retweeted
We've doubled usage limits in Claude Cowork for the next month. Delegate bigger, more complex tasks to Claude.
803
834
13,388
1,744,110
isaac retweeted
19
31
725
25,978
isaac retweeted
Had to come out of sabbatical for this one. Somebody gotta put an insane bounty on TeamPCP. I’ve had anorexia, alopecia, and high blood pressure ever since these mfs started their campaign.
May 19
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
17
16
252
44,380
isaac retweeted
Cutting this off now. Too lazy to filter replies so I'll assume all 737 are cancellations. That's $7,370 I have to donate to open source. What projects should I consider? 👀
For every person who replies with a screenshot of their cancelled Claude Code plan, I will donate $10 to open source.
313
11
1,714
334,596
isaac retweeted
It would be really funny if Github itself got pwn'd by one of the NPM package takeovers
May 19
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
71
46
1,791
117,895
isaac retweeted
🎥 Starting a new community for streamers & creators 🚀 A place to: 🤝 Network 📈 Share growth tactics 🎨 Exchange tools/assets 💬 Get feedback 🔥 Collaborate with creators Streamers, VTubers, editors, developers & designers welcome 🌟 discord.gg/EuF3stK32q
2
2
82
isaac retweeted
May 16
my reaction when there's a supply chain attack
21
105
2,032
115,313
isaac retweeted
🚨 We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase. (1/6)
146
1,053
6,408
1,702,414
isaac retweeted
May 13
he's become fully reliant on LLMs to code. now increase the price by 1000%
159
1,040
22,171
660,846
‼️🚨 UPDATE: The TanStack npm attack is now a full campaign. 'Mini' Shai-Hulud has hit: - OpenSearch - Mistral AI - Guardrails AI -UiPath - Squawk packages across npm and PyPI The malware specifically targets AI developer tooling. It hooks into Claude Code (.claude/settings.json) and VS Code (.vscode/tasks.json) to re-execute on every tool event, long after the infected package is gone. npm uninstall does not fix this.
‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you. The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads. The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate. Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.
128
742
3,967
2,666,203
isaac retweeted
>russian roulette if you're iranian or israeli istg next day i'm gonna hear about a ransomware forcing you to play touhou to decrypt your files
Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux. The file name transformers.pyz appears deliberately chosen to mimic the widely used Hugging Face Transformers library and blend into ML/dev environments. The main payload is a credential stealer, but it also includes country-aware logic; it avoids Russian-language environments and contains a geo fenced destructive branch that has 1-in-6 chance of executing rm -rf / when the system appears to be in Israel or Iran. To mitigate this threat: isolate affected Linux hosts, block 83[.]142[.]209[.]194, hunt for /tmp/transformers.pyz, pgmonitor[.]py, and pgsql-monitor.service, and rotate exposed credentials.
28
242
4,392
239,064
is changing your system language to russian a good security measurement at this point?
Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux. The file name transformers.pyz appears deliberately chosen to mimic the widely used Hugging Face Transformers library and blend into ML/dev environments. The main payload is a credential stealer, but it also includes country-aware logic; it avoids Russian-language environments and contains a geo fenced destructive branch that has 1-in-6 chance of executing rm -rf / when the system appears to be in Israel or Iran. To mitigate this threat: isolate affected Linux hosts, block 83[.]142[.]209[.]194, hunt for /tmp/transformers.pyz, pgmonitor[.]py, and pgsql-monitor.service, and rotate exposed credentials.
3
isaac retweeted
who's gonna tell him ???
20
13
391
26,802
isaac retweeted
> be stinky gamer > download cracked Forza Horizon 6 > make gamer clips > hehe early pc access > upload to YouTube > Didn't censor Xbox Gamertag > Forza dev studio sees > Light suspension of 7,973 years
76
440
10,371
281,682