Nerding out on cyber security, community building, and open source software | CEO of @patchstackapp | 🇪🇪 Pärnu

Joined August 2010
275 Photos and videos
Pinned Tweet
In 2016, I made a post to Reddit that #WordPress (and other CMSs) need a proper vulnerability management tool and an effective way to prevent attacks against vulnerabilities in plugins. Here's what happened 🧵1/6
9
8
70
14,655
What’s going to happen once we get open source models with similar capability as Mythos / Fable? Everybody gets sent to jail? 😂
1
2
120
Europe needs to immediately invest in AI. The fact that U.S. government issued an export control directive restricting Fable/Mythos use by foreign nationals is just the very beginning…
1
9
405
🚨 JAILBREAK ALERT 🚨 ANTHROPIC: PWNED 🫡 FABLE-5: LIBERATED 🦋 let's start with the 🐘... the consensus seems to be that this has been one of the most disappointing model drops of all time, effectively preventing legitimate researchers from contributing their talents to our collective advancement. and not just because of what it means for the short-term, but for what these decisions signify for the long-term. but despite this overly sensitive, authoritarian "safety" layer on top of Mythos, my lil liberators have been hard at work—mapping the boundaries, probing the depths of long-context convos, and cleverly finding the holes in the fence that the thought police missed 🤗 we got some cyber, some chem, some psychological manipulation, and some good ol' fashioned explosives! it took many attempts from multiple agents hunting as a pack, during which I observed a combination of techniques across: • Unicode, homoglyphs, Cyrillic, and other Parseltongue-style text transforms • Long-context reference tracking • Taxonomy and document-structure reasoning • Fiction and narrative framing • Academic-review style contexts • Intent-classification inconsistencies but perhaps the most effective is decomposition recomposition in the backend. it's hard to get explicit names of harms like "Meth Recipe," but getting uplift on the process itself, like birch reduction method/reductive-amination (classic meth synthesis pathways), is much more doable. defense becomes much more difficult to maintain when you start throwing in out-of-distro tokens, breaking up the harmful uplift into benign chunks, and then piecing the innocuous-seeming facts back together, especially when you have jailbroken Opus helping you do it 😉 gg
614
1,428
13,317
3,168,463
I ordered a brand new bike online and it comes fully assembled, but does not have pedals included 😂 I’m glad it has wheels tho.
2
1
405
Oliver Sild retweeted
The award for best #WCEU booth goes to @Patchstack this year.
8
2
81
2,997
Oliver Sild retweeted
remember scrum masters? wild times
351
666
9,524
1,430,021
AI presented as a cause for layoffs is just a bailout for not admitting over hiring during covid.
Apollo’s Chief Economist: Zero Evidence of AI-Related Job Losses
4
276
Oliver Sild retweeted
Apollo’s Chief Economist: Zero Evidence of AI-Related Job Losses
409
548
4,428
1,510,898
I think kids and gardening is the secret to happy life.
4
15
626
Oliver Sild retweeted
Q: How are job postings for software engineers rising rapidly despite AI agents automating coding? A: Because there’s far more code to manage than ever before. We’re already seeing a 14x YoY increase in GitHub commits, and it’s accelerating. AI has dramatically lowered the cost of writing code, so it’s now being used across far more businesses, applications, and use cases. We’re at the beginning of a massive productivity boom driven by the proliferation of bespoke software throughout the entire economy. Coding has been AI’s breakout use case this year. The fact that it’s increased demand for software engineers — rather than decreased it — should call into question the entire “AI will cause mass job loss” narrative.
827
1,465
9,115
1,630,342
😭

1
232
Oliver Sild retweeted
🚨 Ongoing supply chain attack on Composer packages! We just found multiple laravel-lang/* packages compromised on Packagist (lang, http-statuses, attributes). Payload runs at autoload time. At least 50 package versions were compromised. If you installed a compromised version, the malware already executed. Pin to a clean COMMIT (not version) and rotate secrets immediately. If your lockfile already had an older commit from before today, you are safe. But you should not update at the moment.
21
156
1,580
80,531
This
May 21
New "Critical" nginx RCE requires LFI as prereq and has 0 practical exploitation odds - CVEs & CVSS are the biggest slop in security and AI just keeps accelerating it
465
WordPress 7.0 combined with plugin vulnerabilities = free AI tokens. There will be an absolute rush by hackers to steal API keys.
13
8
63
14,078
Well obviously. Useful idiot.
🧻 Fico: “In Brussels bathrooms, they ask me what Putin said” Slovak Prime Minister Robert Fico said that after his contacts with Vladimir Putin, he faces public criticism in the EU — but privately, officials approach him with questions. 💬 “I meet with Putin and everyone criticizes me. Then when I come back, people in Brussels bathrooms ask me what he said.” Fico also questioned why Brussels doesn’t engage in direct dialogue with Russia if there is such interest.
1
229
Oliver Sild retweeted
My little scanner website, WP Beacon, is online. wpbeacon.io
9
21
72
5,334
This crochet hacker wapuu is the rarest WordPress collectible? 😎 credit to @darius_fx
6
206
Oliver Sild retweeted
Replying to @jeffr0
Tbh, it’s surprising how few of these supply chain attacks have happened with .org compared to all the other repositories of other ecosystems like NPM, etc.
1
1
6
259
Russian “special operation” has been successful at demilitiarizing itself 😂
There will be no military equipment this year in Russias May 9th annual victory parade due to “operational reasons.” Lol😂
110