Joined September 2012
668 Photos and videos
Pinned Tweet
2 Mar 2021
static in a cube 🤔
3
19
#000000 retweeted
Jun 2
PSA: @TencentGlobal is aggressively scraping the Internet to build yet another AI slop chatbot, DDoSing many websites in the process. We've found that, as of last week, their scraping bots can now solve Cloudflare challenges and behave like real users while ignoring robots.txt. In the last 24 hours alone, our website received more than 3 million successful requests from Tencent bot IP addresses, plus another 1 million that were blocked by Cloudflare challenges. These recurring DDoS attacks from Tencent have been going on for over a year, and we have been constantly adjusting our firewall rules to filter them while trying not to impact Tencent's real users. Because that is no longer possible, we're now fully blocking Tencent IP addresses, starting with ASN 132203. We recommend other sysadmins do the same. Other ASNs displaying similar abusive behaviour will also be fully blocked from our services. We'd also like to thank @Cloudflare for sponsoring us with Project Alexandria as of 2025, giving our sysadmin the tools to keep RPCS3's online services running without service disruptions.
107
1,355
11,759
587,028
#000000 retweeted
Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux. The file name transformers.pyz appears deliberately chosen to mimic the widely used Hugging Face Transformers library and blend into ML/dev environments. The main payload is a credential stealer, but it also includes country-aware logic; it avoids Russian-language environments and contains a geo fenced destructive branch that has 1-in-6 chance of executing rm -rf / when the system appears to be in Israel or Iran. To mitigate this threat: isolate affected Linux hosts, block 83[.]142[.]209[.]194, hunt for /tmp/transformers.pyz, pgmonitor[.]py, and pgsql-monitor.service, and rotate exposed credentials.
117
691
4,893
4,092,927
#000000 retweeted
May 9
What would you name this cat?
1,677
791
13,372
450,417
“Non-technical teams are now shipping production code”
This is an email I sent earlier today to all employees at Coinbase: Team, Today I’ve made the difficult decision to reduce the size of Coinbase by ~14%. I want to walk you through why we're doing this now, what it means for those affected, and how this positions us for the future. Why now Two forces are converging at the same time. We need to be front footed to respond to both. First, the market. Coinbase is well-capitalized, has diversified revenue streams, and is well-positioned to weather any storm. Crypto is also on the verge of the next wave of adoption, with stablecoins, prediction markets, tokenization, and more taking off. However, our business is still volatile from quarter to quarter. While we've managed through that cyclicality many times before and come out stronger on the other side, we’re currently in a down market and need to adjust our cost structure now so that we emerge from this period leaner, faster, and more efficient for our next phase of growth. Second, AI is changing how we work. Over the past year, I’ve watched engineers use AI to ship in days what used to take a team weeks. Non-technical teams are now shipping production code and many of our workflows are being automated. The pace of what's possible with a small, focused team has changed dramatically, and it's accelerating every day. All of this has led us to an inflection point, not just for Coinbase, but for every company. The biggest risk now is not taking action. We are adjusting early and deliberately to rebuild Coinbase to be lean, fast, and AI-native. We need to return to the speed and focus of our startup founding, with AI at our core. What this means To get there, we are not just reducing headcount and cutting costs, we’re fundamentally changing how we operate: rebuilding Coinbase as an intelligence, with humans around the edge aligning it. What does this mean in practice? - Fewer layers, faster decisions: We are flattening our org structure to 5 layers max below CEO/COO. Layers slow things down and create coordination tax. The future is small, high context teams that can move quickly. Leaders will own much more, with as many as 15 direct reports. Fewer layers also means a leaner cost structure that is built to perform through all market cycles. - No pure managers: Every leader at Coinbase must also be a strong and active individual contributor. Managers should be like player-coaches, getting their hands dirty alongside their teams. - AI-native pods: We’ll be concentrating around AI-native talent who can manage fleets of agents to drive outsized impact. We’ll also be experimenting with reduced pod sizes, including “one person teams” with engineers, designers, and product managers all in one role. In short: AI is bringing a profound shift in how companies operate, and we’re reshaping Coinbase to lead in this new era. This is a new way of working, and we need to leverage AI across every facet of our jobs. To those who are affected I know there are real people behind these decisions — talented colleagues who have poured themselves into this company and our mission. To those of you who will be leaving: thank you. You’ve helped build Coinbase into what it is today, and I am sincerely grateful for everything you've done. All impacted team members will receive an email to their personal account in the next hour with more information, and an invitation to meet with an HRBP and a senior leader in your organization. Coinbase system access has been removed today. I know this feels sudden and harsh, but it is the only responsible choice given our duty to protect customer information. To those affected, we will be providing a comprehensive package to support you through this transition. US employees will receive a minimum of 16 weeks base pay (plus 2 weeks per year worked), their next equity vest, and 6 months of COBRA. Employees on a work visa will get extra transition support. Those outside of the US will receive similar support, based on local factors and subject to any consultation requirements. Coinbase prides itself on talent density. Our employees are among the most talented people in the world, and I have no doubt that your skills and experience will be highly sought after as you pursue your next chapters. How we move forward To the team that is staying, I know this is a difficult day. We’re saying goodbye to colleagues and friends you've been in the trenches with. But here’s what I want you to know as we move forward together: Over the past 13 years, we have weathered four crypto winters, gone public, and built the most trusted platform in our industry. We’ve made it this far by making hard decisions and by always staying focused on our mission. This time will be no different – nothing has changed about the long term outlook of our company or industry. And most importantly, our mission has never been more important for the world. Increasing economic freedom requires a new financial system, and we’re building it. The Coinbase that emerges from this will be more capable than ever to achieve our mission. Brian
64
408
6,618
238,270
#000000 retweeted
22 Jul 2025
221
19,636
95,235
9,660,446
#000000 retweeted
About the #Signal outage: In information security we look at three principles: secrecy, integrity, and availability. Signal’s outage affected only one of them: availability. The relay servers were down, so messages couldn’t move. But nobody could read them. Signal is open source and its end-to-end encryption has been reviewed by independent experts for years. The messages could sit on AWS, Google Drive, or even Reddit - still unreadable to anyone except sender and receiver Other messengers claim end-to-end encryption, but they’re closed source. You can’t verify what happens before encryption - you just have to trust them. With Signal, you don’t have to trust. You can verify. It’s still the best option from my pov.
69
147
1,346
121,564
#000000 retweeted
Now Playing UwU Underground Wanna Buy My Zero Days? 3:03 ------------|------ 4:26 ↻ ◁ || ▷ ↺ @opzero_en @SonicWall @MSFTResearch SLSH Track Progress: ▓░░░░░░░░░ 10%
28
50
185
38,485
#000000 retweeted
OUR LATEST ALBUM APT TALES VOL 3 "GHOSTS IN THE WALLS" IS OFFICIALLY OUT NOW! uwuunderground.bandcamp.com/…

16
27
75
22,702
#000000 retweeted
Hey guise I’m a Threat Actor about to do illegal shit, can anyone recommend a good DLP and maybe remote device management tools to install on my machine? Does Palantir have an agent I could install?
21
7
197
11,237
#000000 retweeted
In April this year, @grafana had a security incident due to an insecure GitHub Action. The attackers even tried covering their tracks. How were they discovered? Canarytokens.. Check out their (super transparent) post¹ on how they use our tokens at scale.. __ ¹ link follows
6
44
212
21,803
#000000 retweeted
Thai Buddhist monk: I .....will.....keep..... praying....
223
4,756
45,743
896,398
#000000 retweeted
It's the whole Internet
13
131
1,494
93,898
#000000 retweeted
12 Apr 2024
Name a more iconic duo... I'll wait
5
57
561
30,914
Can a DHCP administrator become a domain administrator? Well, as it turns out, sometimes it sure can. 🥴 In our latest blog post, see how Akamai researchers discovered a new PrivEsc technique affecting Active Directory. Full write-up: akamai.com/blog/security-res…
7
146
390
48,894
#000000 retweeted
17 Mar 2024
HUGE UPDATE TO THE CAT STREAM @uwukko and @schlizzawg have spent the last month cooking an entire overhaul of the meow.camera site. You can now watch the Hello Street Cat streams on just about any device! (even firefox) meow.camera/viewer/
5
140
655
29,745
#000000 retweeted
Today 70,000,000 records from an unspecified division of AT&T were leaked onto Breached. No information is available to indicate whether it is a 3rd party compromise, or which 'division' this data is from. Regardless, upon review we can confirm the stolen data is legitimate.
21
128
815
101,084
#000000 retweeted
So GPS jamming requires line of sight between the jammer and the target. Accounting for mountains, that is almost a perfect shape around Kaliningrad (Max of 270 ish miles for an at altitude plane, 220 ish for decent like over Sweden). Russia isn't even trying to hide it.
16 Mar 2024
Last 46 hours Baltic Jammer has been running in south Baltics. At least 873 unique aircrafts has had their navigation equipment jammed. Each one a passenger jet filled with civilians. E.g. Ryanairs SP-RKS has been without GPS for at least 2 hours going in and out of Vilnius.
9
60
175
28,179