Megatron LLM Hub
All digests
Twitter

推特安全流

Top5

Cisco FMC 设备上发现 Cyclops Blink 新变种 timezone_check,x86-64 Linux ELF 模块化后门

Sandworm 关联恶意软件转向 Linux 网络设备,模块化设计提供持久远程访问,防御方可直接比对 IOC。

RT @blackorbird: A 64-bit Linux executable named timezone_check was discovered on multiple compromised Cisco Firewall Management Center devices. Reverse engineering confirmed that it is a new variant of the well-known Cyclops Blink malware (attributed to Sandworm). The malware features a highly modular design and provides attackers with persistent remote access to the compromised Linux systems. The new variant is entirely different: it is compiled as an x86-64 Linux ELF binary and achieves persistence through the generic System V (SysV) service mechanism, rather than being bound to any specific vendor’s hardware firmware. This change directly expands the potential attack surface, so virtually any network-edge device that meets the architectural requirements could become a target. The implant’s capabilities have also been significantly expanded, adding active network and service discovery, programmable packet monitoring, file transfer, and payload execution. As a result, the compromised device is turned into a full beachhead inside the victim’s internal network, enabling both reconnaissance and intelligence collection and use as a pivot for follow-on attacks. https://t.co/oHNlDvYnsQ

malwarelinux固件事件 @0xocdsec source ↗

Sophos 分析 Cisco FMC 上发现的 timezone_check,确认为 Cyclops Blink 新变种

含完整技术分析,是上一条的原始报告来源,网络设备后门排查必读。

Sophos researchers analyse a malicious 64-bit Linux executable named timezone_check that was discovered on multiple compromised Cisco Firewall Management Center devices. This is a new variant of the Cyclops Blink malware previously analysed by the UK NCSC. https://t.co/qBvt3crbJb https://t.co/lwlaDbNTiq

malwarelinux报告 @virusbtn source ↗

DDRop 攻击用 159 美元 DDR5 中间人板击穿 Intel TDX 机密计算,可读受保护 VM 内存并伪造认证

无 CVE 无补丁,物理接触即可绕过 TDX 信任根,云与机密计算威胁模型需重估。

RT @TheHackersNews: ‼️ Researchers broke Intel TDX’s confidential-computing protections with a $159 DDR5 interposer. New "DDRop" attack silently drops memory writes so the CPU trusts stale encrypted data. In lab tests, researchers read protected VM memory and forged attestation. No CVE. No patch. Full details here → https://t.co/cHAX1ojqpI

硬件绕过报告 @0xocdsec source ↗

RingKiller:利用 DCRCVDrv.sys 漏洞驱动从 ring0 终止任意进程的 BYOD PoC

可直接杀掉 EDR/AV 进程的提权原语,PoC 已公开,BYOD 驱动白名单策略需复核。

RingKiller - BYOD PoC for vulnerable driver DCRCVDrv.sys. Abuses IOCTL 0x2205C0 to kill arbitrary processes from ring 0 via ZwTerminateProcess. EDR/AV termination primitive. https://t.co/C7tfAHxUnT

lpe内核poc工具 @ipurple source ↗

DeepSeek V4.1 Flash 发布:552B MoE、MIT 许可、可本地自托管,多项 agentic 基准超 Opus 5

权重免费可自托管,CyberGym 88.1 领先闭源模型,本地 AI 安全 agent 能力基线被抬高。

RT @cr3ghost: DeepSeek just dropped the kind of release closed AI labs should be worried about. On DeepSeek's published agentic benchmarks, V4.1 Flash: Beats Opus 5 on 3/4 Beats Kimi K3 on 4/4 Beats GPT-5.6 Sol on 3/4 CyberGym: 88.1 vs Opus 5 at 84.5 DeepSWE: 74.2 vs 74.0 Automation-Bench: 54.8 vs 50.3 And the weights are FREE to download and MIT licensed. 552B MoE. 8B active on input. 16B active on output. 1M context. Native multimodal. Local/self-hosted deployment. For AI-assisted vulnerability research, exploit development, reverse engineering, malware analysis, detection engineering, red teaming, blue teaming, and autonomous security research, this is getting very interesting. If I were running a closed US AI lab, open releases like this would make me nervous. You can lobby, regulate and build bigger moats, but you can't put open weights back in the bottle. Keep them coming. https://t.co/x3ZPez9EHT Weights: https://t.co/f5yRdS2jzR #OpenSourceAI #AISecurity #VulnerabilityResearch #ReverseEngineering #MalwareAnalysis #ThreatIntel #BlueTeam #RedTeam

llmai_agent工具 @cr3ghost source ↗
Must-see3

askWAM 工具通过 Windows WAM 静默获取 Entra ID 令牌,无交互认证提示,含 x64 客户端与 BOF

走合法 SSO 流程绕过 PRT cookie 检测,红队可直接用,蓝队需确认 WAM 滥用留下的遥测。

Detection engineers: this one deserves coverage. @_dirkjan's askWAM can silently request Microsoft Entra ID tokens through Windows Web Account Manager, with no interactive auth prompt. It also ships as a native x64 client and BOF. Red teamers will immediately see the value. Blue teams should be asking what telemetry WAM token abuse actually leaves behind. #DetectionEngineering #EntraID #RedTeam

提权工具绕过 @cr3ghost source ↗

有人在售 Control Web Panel 0day RCE,声称影响 25 万+ 网站,要价 7-10 万美元 XMR

未修补的托管面板 RCE 若被利用可批量接管站点,运行 CWP 的主机应尽快隔离或加固。

RT @kernelstub: Selling CWP(Control Web Panel by CentOS) 0Day RCE(currently running 250k + Websites), Seller is asking for $70k-$100k via XMR, both parties stay anonymous. DM for POC.

rce0day事件 @0xocdsec source ↗

Depthfirst 披露通过两个 Ruby 内存破坏漏洞实现 GitLab RCE 的完整链路

自托管 GitLab 是常见内部资产,两漏洞串联的 RCE 手法有完整技术细节可复现。

Going depthfirst: Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities - @wupco1996 https://t.co/JTisAkXmNt

rce供应链报告 @pentest_swissky source ↗
Recommended15

Elastic 发布基于行为共性而非单 CVE 的 Linux 本地提权检测规则

针对 2026 年多起内核 LPE 变种,通用检测思路比逐 CVE 写规则更可持续。

2026 has been a busy year for Linux local privilege escalation. New kernel LPEs kept landing, several of them variations on the same idea, and a rule written per CVE was never going to keep pace. So our detection keys on what escalations have in common rather than on what each bug does: - An unprivileged process execs from a world-writable path, then something in that lineage changes uid to 0 - A SUID/SGID binary runs with effective uid 0 while the real user is not root - unshare(CLONE_NEWUSER) shows up as a precursor - A shell or interpreter finishes as root out of a user-controlled directory - A binary that should never have been setuid-root gets used the way GTFOBins documents Most of these rules have been shipping for a while, the unshare one since 2022. When we ran this year's public PoCs in the lab, several tripped rules that predate them. The blog covers the general LPE categories and the logic behind each, a walk through of this year's CVEs with the rules that fired and why, where the layers need tuning, and the framework ready to use. Full framework, EQL logic, and every rule mapped by @RFGroenewoud : https://t.co/eQCxNoKvtW

lpe内核检测报告 @elasticseclabs source ↗

Silverseal 公开:首个面向 Linux 的 UEFI bootkit 研究框架,从 GRUB 到 Rust 内核模块 rootkit

Linux 固件层持久化研究工具首次开源,威胁建模需覆盖 UEFI 启动链。

RT @Idov31: I'm thrilled to make Silverseal public!. It is among the first publicly available UEFI bootkit research frameworks for Linux-based systems to demonstrate an end-to-end path from GRUB to a running Rust kernel-module rootkit: https://t.co/AJVhQLUVbI 1/3

固件内核工具逃逸 @artem_i_baranov source ↗

Mythic C2 profile 通过 Microsoft Teams 频道和 Graph API 通信

把 C2 流量藏进合法 Teams 通道,绕过网络检测,红队与检测工程都值得研究。

A Mythic C2 Profile that uses the Microsoft Graph API to communicate through a Microsoft Teams channel https://t.co/tQVczlroV7

c2工具绕过 @ipurple source ↗

Cisco Talos 开源 EvidenceForge,生成逼真合成安全日志用于威胁狩猎训练

缺少真实日志时可用合成数据训练检测规则与狩猎流程,直接可用。

EvidenceForge - Generate realistic synthetic security logs for cybersecurity threat hunting training and research https://t.co/2BvVdZNORv

工具检测报告 @ipurple source ↗

promptfoo v0.123.0 发布,面向 prompt/agent/RAG 的红队测试与漏洞扫描

自托管 AI agent 上线前可用它做自动化红队与回归测试,开源可集成 CI。

promptfoo v0.123.0 — Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI... https://t.co/a5fU7eIIiG https://t.co/bZiNTiURjI

ai_agentllm工具poc @KitPloit source ↗

通过 MCP 让 Grok 操控 Flipper Zero 破解酒店电视,无需记忆具体协议

展示 LLM agent + MCP 驱动物理硬件的可复现路径,本地 agent 攻击面外延到现实设备。

RT @Eito_Miyamura: Got @grok to hack a hotel TV by letting it pilot a @flipper_net! Prompt agents to operate the flipper from the phone via @sealgate_ai MCP that connects agents to everything. No manuals, no memorising specific mediums, just speak or type. Inspired by @elder_plinius's V3SPR, but now usable by any agent mobile chat apps of your choice with MCP or any custom agents! A portable real-life hacker assistant in real life 😎

ai_agentllm工具固件 @0xocdsec source ↗

XBOW Agents 在 Bing 图片搜索发现三个 SYSTEM/root 级 RCE

AI agent 自主发现真实 RCE 的案例,展示自动化漏洞挖掘当前能力边界。

RT @_r_netsec: XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search https://t.co/7tExhiyVns

ai_agentrce报告 @0xocdsec source ↗

研究者称正绕过 Microsoft Defender 引擎提权补丁 CVE-2026-69414

Defender 自身提权漏洞补丁被公开宣称绕过,端点防护可信度需重新评估。

RT @MSNightmare2000: We are investigating an elevation of privilege patch in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as CVE-2026-69414 We are working hard on bypassing the patch and will provide updates as soon as possible https://t.co/W9wh4XbH6u

lpecve绕过事件 @0xocdsec source ↗

malwareunicorn 免费恶意软件逆向工程系列工作坊 RE101/RE102 等

从零搭建分析环境到反调试、脱壳的完整免费实操课程,入门逆向的优质资源。

If you want to learn malware reverse engineering and have no idea where to start, this is it. @malwareunicorn has an excellent FREE set of hands-on workshops: RE101: start from zero, build a malware analysis VM, learn x86, static/dynamic analysis and reverse real Windows malware. RE102: anti-RE, anti-debugging, encryption, VM evasion, obfuscation, packing and unpacking. PE Injection Study: reverse Cryptowall, unpack it and walk through its process injection technique using APCs. macOS Workshop: Mach-O internals, code caves, shellcode, entrypoint redirection and dylib injection. Real malware samples. Hands-on labs. Downloadable VMs. IDA Pro cheat sheet. Free. No paywall. No signup. https://t.co/mpbBMNJWrT Credit: @malwareunicorn #MalwareAnalysis #ReverseEngineering #InfoSec

逆向工具报告 @cr3ghost source ↗

knife:Rust 编写的 PE/ELF/Mach-O 静态分析 TUI,可排序可疑漏洞点

终端内快速分诊二进制并定位危险调用点,逆向与恶意样本初筛效率工具。

RT @orhundev: New reverse engineering TUI dropped! 🔥 🔪 knife — A static analysis toolkit for PE, ELF & Mach-O 💯 Triages, disassembles, traces dangerous call sites, and ranks exploitable-looking bugs 🦀 Written in Rust & built with @ratatui_rs ⭐ GitHub: https://t.co/wfOPL5Ea54 #rustlang #ratatui #tui #reverseengineering #security #malware #devtools

逆向工具恶意软件 @cr0nym source ↗

ecapture v2.6.0:基于 eBPF 无需 CA 证书抓取 SSL/TLS 明文

Linux/Android 上无证书解密 TLS 流量,本地抓包与取证场景直接可用。

ecapture v2.6.0 — Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64. https://t.co/ZEcEhx1pSF https://t.co/GxTxMasa7i

工具linux移动端 @KitPloit source ↗

NetExec 扩展 DPAPI 凭据转储到 WMI、WinRM、MSSQL 等非 SMB 协议

SMB 被重点监控后,DPAPI 窃取转向其他协议,内网横向检测需覆盖新路径。

RT @al3x_n3ff: ItsNotAlwaysSMB: DPAPI in other protocols🔥 SMB is monitored closely nowadays, stopping attacks like looting DPAPI secrets. Thanks to @_zblurx, NetExec got a huge upgrade, extending DPAPI credential dumping to other protocols such as WMI, WinRM and MSSQL and various modules🔑 https://t.co/xsEseJxhUI

提权工具绕过 @pentest_swissky source ↗

Apple 发布 macOS Golden Gate 及 Tahoe 26.7、Sequoia 15.8 安全更新

macOS 安全更新发布,本地开发机与自托管环境应及时跟进补丁。

RT @howardnoakley: Apple has released macOS Golden Gate, and security updates to Tahoe 26.7, Sequoia 15.8 https://t.co/2BrlG4XLvA via @howardnoakley

移动端cve事件 @patrickwardle source ↗

微软发布紧急 Windows 更新修复 RDS 故障

远程桌面服务故障影响面广,运维需尽快确认受影响版本并打补丁。

RT @BleepinComputer: Microsoft releases emergency Windows updates to fix RDS failures https://t.co/HnAELsMGwA https://t.co/HnAELsMGwA

事件cve @0xocdsec source ↗

Opus 单 prompt 在 4 小时 28 分内解出全部九道 Flare-On 12 挑战

无 IDA、无调试器、不运行样本,纯静态加符号执行解逆向题,展示 LLM 逆向能力跃升。

RT @expend20: I gave Opus one prompt and all nine Flare-On 12 challenges. It solved them all in 4h 28m. No IDA, no decompiler, no debugger, and it never ran a single binary. Python with capstone, unicorn and z3. More info 👇 #FlareOn #ReverseEngineering #CTF

llm逆向ai_agent @artem_i_baranov source ↗
More165

CVE-2026-19174:V8 WebAssembly 整数溢出漏洞利用分析

浏览器引擎漏洞利用细节公开,含完整分析,浏览器与 Node 场景均相关。

RT @0xor0ne: Exploiting CVE-2026-19174: integer overflow in V8 WebAssembly https://t.co/RqGWrR0lT9 Credits @0x10n #infosec https://t.co/jBwKJThIAm

浏览器cvepoc报告 @0xocdsec source ↗

Logi Options+ 被利用获取 SYSTEM shell 的漏洞利用博文

常见外设驱动软件本地提权到 SYSTEM,含完整利用步骤,终端加固可参考。

RT @xixasec: I wrote a blog post about exploiting Logi Options+ for SYSTEM shells. https://t.co/CDSkfsmNmw

lpe提权报告 @0xocdsec source ↗

Windows AppResolver LPE:从 AppContainer 逃逸到 SYSTEM,PoC 关联 CVE-2026-50454

沙箱逃逸加提权链,PoC 已公开,Windows 隔离方案需评估该路径。

RT @_r_netsec: Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454 https://t.co/QzBH8FJjId

lpe逃逸cvepoc @0xocdsec source ↗

HBO Max Reddit 账号被劫持,用 ClickFix 广告推送恶意软件

劫持高信誉官方账号分发 ClickFix 恶意指令,社交工程手法值得防御方关注。

RT @BleepinComputer: Hackers hijack HBO Max Reddit account to push malware in ClickFix ads https://t.co/f0BNqkR6mu https://t.co/f0BNqkR6mu

钓鱼事件恶意软件 @artem_i_baranov source ↗

KnowBe4 分析攻击者滥用 Exchange Direct Send 绕过安全网关发信

利用内置打印机/扫描仪发信路径绕过邮件网关,企业邮件安全配置需核查。

KnowBe4 Threat Lab explains how attackers started to abuse Direct Send, a built-in path designed to allow office printers, scanners and legacy on-premises applications to send email without needing a dedicated account and bypassing security gateways. https://t.co/AmscVfVVP8 https://t.co/7cy961sPmC

钓鱼绕过报告 @virusbtn source ↗

Revolut 攻击者声称同时入侵多个意大利执法部门系统,窃取 147GB 数据

攻击者利用执法系统向金融机构发数据请求,暴露合法通道被滥用的风险。

RT @IntCyberDigest: ‼️ BREAKING: We're in contact with the Revolut hacker. According to them, they didn't only take Revolut data, they've also compromised multiple Italian law enforcement departments. They say the operation targeting Revolut ran for six months, and that they used Italian law enforcement systems to send data requests to Revolut. They claim to hold 147 GB taken from the Italian side, including internal docs, calendars and personal material, among it the chat logs of a federal officer arguing with his wife.

事件供应链数据泄露 @0xocdsec source ↗

BlueMoon 漏洞利用套件首个使用集群指向中国关联的 TA412/APT31

新漏洞套件与已知 APT 的关联情报,威胁狩猎可据此调整检测重点。

RT @tdatwja: The first observed cluster using the BlueMoon exploit kit was the China-aligned threat actor TA412 (JungleBamboo, Violet Typhoon, APT31, TIDE CASTLE) on 28 August 2026. SEPTEMBER 09, 2026 https://t.co/o2FcYSCFOu

apt事件报告 @0xocdsec source ↗

Anthropic 称瓦解中国大规模监控系统 BABEL,研究者提前数周已追踪到

单人借助 AI 即可搭建 OSINT 监控平台,展示 AI 降低监控系统构建门槛。

Anthropic claims to have disrupted an online mass surveillance system from China, gathering global intel on religious groups that Beijing deems 'suspicious'. Incidentally we tracked it together with @nestedintel weeks earlier. Meet BABEL - Here is the playbook. 1/8 https://t.co/ITkzzMFu4e

ai_agentosint报告 @NetAskari source ↗

ASC 快速 Android 反编译器发布,agent 用它发现 Honor 和小米各两个 RCE

支持并行分析 10+ APK 的 agent 友好反编译工具,移动端漏洞挖掘效率提升。

RT @MGAldys4: Guys, I built a super fast Android decompiler called ASC. It completely replaced Jadx MCP for me and lets me analyze 10+ APKs in parallel. And this week my Agent use ASC found 2 RCE in Honor and Xiaomi! This tool now accepted by BlackHat EU Arsenal https://t.co/5Qdpq8XEal #BHEU https://t.co/lCMDbjZL0h

移动端工具rce @0xocdsec source ↗

精心构造的 LDAP 战术用于规避 AD 检测雷达

AD 环境 LDAP 查询规避检测的具体手法,蓝队可据此补充日志与告警。

RT @SEKTOR7net: Carefully crafted LDAP tactics to stay under the AD detection radar. A post by Baptiste Crépin. Source: https://t.co/ORGbGNLUrC #redteam #blueteam #offcoding

绕过检测报告 @0xocdsec source ↗

macOS RC 说明称 launchd 不再支持加载带隔离属性的 plist,措辞含糊

启动项加载策略变更可能影响持久化检测与恶意 plist 行为,需实测确认语义。

macOS RC release notes: "Resolved Issues: Fixed: launchd no longer supports loading launchd property list files with the quarantine extended attribute. (166415497)" So if a plist has the qattr, does this mean: a) launchd *will* load it? b) launchd will *not* load it? 🤔🤨 https://t.co/xoFtVk9Oof

移动端绕过检测 @patrickwardle source ↗

研究者讲述与微软漏洞披露纠纷的经历

RT @MSNightmare2000: Story time...

事件 @0xocdsec source ↗

评论称微软重复对待 SandboxEscaper 的方式对待漏洞研究者

RT @LinuxKodachi: Naceri is very talented when it comes to windows stuff. And it is sad to see Microsoft doing this thing again after doing same thing with SandboxEscaper. These people dedicated years of their life on your products and they are top class at their craft, 1/2

事件 @0xocdsec source ↗

研究者称抗议微软决定损失超 20 万美元

RT @MSNightmare2000: That protest, costed me over +200,000$ that i could have had sitting in my bank right now but i burned it. Just to protest against Microsoft's absurd decision. If only I didn't pour my soul into that job with countless of stupid non sleep nights, i would have gotten over it...

事件 @0xocdsec source ↗

评论指 Hugging Face CTO 谈 AI 前沿节奏

RT @Hesamation: Hugging Face CTO btw… the company that literally had the biggest rogue AI incident so far… the same incident which is now being used to pace the frontier: https://t.co/WKAiJl6I9t

llm @0xocdsec source ↗

观点:LLM 驱动攻击的关键是自动镜像目标环境

RT @HackingLZ: The magic sauce for LLM driven offense is going to be automatically mirroring a target environment using everything you can quietly learn about it, while other groups of agents are always working on RE and understanding every defensive product they can get their hands on(Thanks, VirusTotal, GitHub, trial versions, leaked configs, update packages, etc) The closer you can get to the target’s patch levels, configurations, identity setup, and defensive stack, the less noisy brute forcing the attacking agents need to do in the actual environment. Something today’s agents don’t really capture(obviously you can give them memory) is the feedback loop good red teams build from working across different companies. Every environment is a little different, and knowing something failed doesn’t tell you why. Was it detected? Was your code just bad? Was a flag or ticket option wrong? Did the target have some custom configuration you hadn’t seen before? Over time those answers turn into private knowledge, custom tooling, and better attack flows. Sometimes you had to get caught to learn the lesson, but every operation after that gets better. Combine automatic environment mirroring, continuous RE, operational feedback, and private human research, and the agents become significantly more effective over time. The real advantage isn’t just agents attacking faster. It’s moving most of the enumeration, testing, failures, and detection tuning somewhere the defender can’t see it.

ai_agentllm @0xocdsec source ↗

爬取完整 IPv4 反向 DNS 空间的实践文章

RT @_r_netsec: Crawling the Complete IPv4 Reverse DNS Space https://t.co/EcIFIorqTT

osint报告 @0xocdsec source ↗

介绍 Ghidra 逆向工具及 GhidraMCP 生态

RT @Ryrenz: 🔍 逆向神器 Ghidra,拿到一个没有源码的程序,它能直接反汇编、反编译,把机器码还原成人能读懂的代码。 美国国家安全局(NSA)研究局创建并维护,GitHub 近 7.5 万 star,直接封神了。 以前碰到一个可疑的程序,想搞清楚它到底在干嘛,只能对着一屏汇编硬啃。换成 Ghidra,丢进去就能看反编译结果和图形化展示,重复的分析步骤还能用 Java 或 Python 写成脚本自动跑。NSA 自己就拿它分析恶意代码、找网络和系统里的潜在漏洞。 社区也在围着它长东西:GhidraMCP 这个 MCP server 有 1 万 star,另一个 ghidra-mcp 也有 3700 多 star,都是让 AI 直接接进 Ghidra 帮你做逆向。八千多个 fork、快两千个 issue 和 PR 还开着,8 月刚发了 12.1.3。 官方 README 自己也写了部分版本存在已知安全漏洞,装之前看一眼版本号。 国家队的逆向工具,现在谁都能直接拿来用。 GitHub:https://t.co/SW7BjVUuPC

逆向工具 @0xocdsec source ↗

警示 WhatsApp 上伪造 PDF 文件的钓鱼手法

RT @CyberRacheal: Be warned. Hackers can use fake pdf files to hack you through WhatsApp. (For educational purposes)! Phishing pro 😅. https://t.co/9xzDn9RiGH

钓鱼移动端 @0xocdsec source ↗

调侃用户对 IT 通知与攻击者请求的态度反差

RT @NathanMcNulty: Can someone explain to me how users will ignore all communications from IT but be like "yeah sure attacker, let me figure out how to register a passkey for you"?

钓鱼 @0xocdsec source ↗

Moonshot 创始人杨植麟 39 分钟访谈推荐

RT @kirillk_web3: instead of watching 2 hours of Netflix tonight, watch this 39-minute interview with the founder of a $50B China AI company. Yang Zhilin runs Moonshot, the lab behind Kimi. He turned down staying in the US, went back to China, and just raised at a $50 billion valuation. what makes it worth your time: > his whole frame is a 10 to 20 year marathon, not the sprint everyone else is running > the one bet under everything he builds: scaling law is to AI what Moore's Law was to computers > why he cut everything except productivity, because if you try to do everything, you do nothing well > how long-context use cases he never saw coming on day one became the real product it's the clearest thinking on how to actually build an AI company at scale I've heard. no hype, just first principles. I turned the key ideas into a practical guide, Kimi K3: From Loops to Graphs, How I Cut AI Agent Costs by 70%. below ↓

llm @0xocdsec source ↗

PS2 最后一个秘密被软件方案攻破

RT @DiscoStarslayer: After 4 years of effort, I'm happy to announce that one of the final secrets of the PS2 has been broken wide open! It's been a long process of decapping, optical dumping, and now at last a software solution. Thank you Libby for finding the exploit from our dirty optical dumps! https://t.co/VrsCH8I35C

逆向固件 @0xocdsec source ↗

PCAPdroid v2.0.1 免 root Android 抓包与防火墙工具

PCAPdroid v2.0.1 — No-root network monitor, firewall and PCAP dumper for Android https://t.co/LPMWV8tmm8 https://t.co/s5ZDLzhHjU

移动端工具 @KitPloit source ↗

kyverno v1.19.1-rc.1 K8s 策略与合规引擎更新

kyverno v1.19.1-rc.1 — Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container... https://t.co/jIwp5ytGVV https://t.co/OtRMWzxMsV

k8s工具 @KitPloit source ↗

authentik 2026.8.2 开源 SSO/身份提供方发布

authentik version/2026.8.2 — Provides open-source SSO and identity provider functionality with SAML, OAuth2/OIDC, LDAP, and RADIUS support for... https://t.co/RFl4F16HCp https://t.co/0d5gT7ni51

工具 @KitPloit source ↗

tmux v3.8-rc 终端复用器发布

tmux v3.8-rc — Terminal multiplexer for managing multiple shell sessions from a single screen, with session persistence, window splitting, and scriptable... https://t.co/zUM3bCgeba https://t.co/EPZq5rSdyN

工具 @KitPloit source ↗

OpenSSL 4.1.0-alpha1 发布

openssl openssl-4.1.0-alpha1 — General purpose TLS and crypto library https://t.co/tnkuxy3Lxe https://t.co/691IppZwUM

工具 @KitPloit source ↗

serverless sf-core 4.42.0 CLI 更新

serverless [email protected] — CLI framework for deploying and managing serverless applications on AWS Lambda with YAML infrastructure, local... https://t.co/M7lZapgZiQ https://t.co/UnNVGkn5SF

工具 @KitPloit source ↗

Guided Hacking 反作弊与内核课程大纲

📜Guided Hacking Course Syllabus 📜 290+ chapters GHB4 — Anti-Cheat, Anti-Debug & Kernel 1. Defeating Value Encryption & Obfuscation 2. Finding Offsets Without Cheat Engine 3. Bypassing Cheat Engine Detection 4. Kernel-Mode Cheat Engine (DBKM Driver) 5. Code Mutation & Polymorphism 6. Alternative Memory Editors 7. Automated Anti-Debug Bypass (ScyllaHide) 8. Anti-Debug Techniques Overview 9. Anti-Debug Practice Challenges (DebugMe) 10. Steam Anti-Debug Bypass (ThreadHideFromDebugger) 11. NtSetInformationThread-Based Debugger Hiding 12. Timing-Based Debugger Detection 13. Exception-Based Anti-Debug (SEH + Trap Flag) 14. Flag-Based Debugger Detection 15. Breakpoint Detection Methods 16. Heap-Based Debugger Fingerprinting (LFH) 17. Self-Debugging as Protection 18. Real-World Anti-Debug Bypass (CS2D) 19. PE Header Erasure for Stealth 20. PEB Module Unlinking 21. Steam Loader Extended Bypass 22. Anticheat Bypass Methodology 23. Valve Anti-Cheat (VAC) Deep Dive 24. Easy Anti-Cheat (EAC) Architecture 25. EQU8 Anticheat Analysis 26. MTA:SA Kernel Anticheat (Fairplaykd.sys) 27. Memory Integrity Checking (Detecting ScyllaHide) 28. Thread-Based Manual Map Detection 29. Finding Hidden System Threads 30. Code Mutation for Evasion 31. Screenshot Detection Bypass (BitBlt Hook) 32. Return Address Spoofing 33. Virtual Machine Detection Evasion 34. Building a Stealth Kernel Driver 35. Kernel Driver Development for Game Hacking 36. Kernel Debugging with WinDbg 37. Handle Protection Callback Bypass 38. Vulnerable Driver Exploitation (BYOVD) 39. Kernel Manual Mapping (KDMapper) 40. Dumping Protected Anticheat Drivers 41. Covert User-Kernel Communication (.DATA Hooking) 42. IOCTL Interception & Driver Spoofing 43. Erasing Driver Load Evidence (PiDDBCache) 44. Kernel Module Memory Dumping 45. Approaching Newly Protected Games 46. Hypervisor-Based Game Hacking 47. Hyper-V Memory Access (libvoyager) 48. Advanced Code Obfuscation Toolchain (Theodosius) 49. MSR-Based Kernel Code Execution Squally Game Hacking Course — CS420 1. Course Introduction & What Is Game Hacking 2. Memory Editing Fundamentals 3. Number Systems: Hexadecimal, Decimal & Binary 4. Hex Editing Game Files 5. Data Types & Advanced Memory Editing 6. Virtual Memory & Process Address Spaces 7. Multi-Level Pointers & Pointer Chains 8. x86 Assembly Modification in Games Game Hacking Shenanigans Tutorial Series 1. Cheat Engine Overview & Series Introduction 2. Installing & Configuring Cheat Engine 3. Value Scanning & Live Memory Editing 4. Data Types & the Memory Viewer 5. Unknown Value Scanning & Elusive Values 6. Pointer Scanning for Stable Addresses 7. Building & Saving Cheat Tables 8. Finding X/Y/Z Coordinates in Memory 9. Finding Velocity Addresses 10. Writing Cheat Engine Auto Assembler Scripts 11. Code Injection via Cheat Engine 12. Shared OpCodes & Filtering Instructions 13. Floating Point Values & XMM Registers 14. One Hit Kills & God Mode Scripts 15. Damage Multiplier Scripts 16. Float Instruction Damage Multipliers 17. Integer-Based Defense Boost Scripts 18. Complex Multi-Feature Cheat Engine Scripts 19. Updating & Fixing Broken Cheat Tables 20. Movement Speed Hack Scripts The Game Hacking Bible GHB1 — Beginner Foundations 1. Problem-Solving Methodology & Goal Setting 2. Why Fundamentals Matter Over Copy-Pasting 3. Acquiring Hacking Tools Safely 4. CS420 Video Course Companion 5. Game Hacking FAQ & Common Misconceptions 6. Cheat Engine Interface Walkthrough 7. First Hack: Scanning & Modifying Values 8. Finding Position Coordinates in Memory 9. Finding View Angles (Pitch/Yaw) 10. Pointer Scanning with Pointermaps 11. Game Hacking Shenanigans Companion 12. Class Reconstruction with ReClass (Part 1) 13. C++ Programming Primer for Hackers 14. Windows API Essentials 15. String Encodings: Unicode, TCHAR & MBCS 16. Retrieving Module Base Addresses 17. Multi-Level Pointer Resolution in C++ 18. Visual Studio Configuration for Hacking 19. Building an External Trainer (Part 1) 20. Building an External Trainer (Part 2) 21. Building an Internal DLL Trainer 22. Writing a DLL Injector 23. Debugging Injected Code with Visual Studio 24. Advanced Class Reconstruction with ReClass (Part 2) 25. External Function Detouring & Hooking 26. Deep Dive into Multi-Level Pointers 27. Entity List Discovery via Reverse Engineering GHB2 — Reverse Engineering Foundations 1. CPU Registers, Assembly Language, Calling Conventions & the Stack 2. Manual Relative Address Resolution 3. Static Analysis with IDA Pro 4. Reversing Game SDK NetVar Offsets 5. Finding Specific Game Offsets (bDormant) 6. Runtime Type Information (RTTI) & ClassInformer 7. Reversing Recoil Mechanics 8. Reversing Movement: Fly Hack / NoClip 9. Reversing Damage Logic: One Hit Kills 10. Finding Core Game Data Structures (Entity List) 11. Ray Casting & Visibility Checks via Inline ASM GHB3 — Intermediate Cheat Development 1. External Bunnyhop Automation 2. Internal Bunnyhop Automation 3. Game Flags for Movement Hacks (dwForceJump, m_fFlags) 4. 2D Radar Hack via bSpotted 5. Anti-Flash Effect Neutralization 6. Triggerbot Development (3 Parts) 7. Glow/Wallhack via Glow Object Manager 8. Recoil Control System (RCS) 9. Entity List Reverse Engineering Walkthrough 10. Aimbot Math: Angle Calculation & Smoothing 11. Signature / Pattern Scanning 12. x86 Trampoline Hooking 13. Member Function Hooking (__thiscall) 14. Calling Game Member Functions 15. OpenGL Render Hooking & Overlays 16. OpenGL ESP Drawing 17. General-Purpose Aimbot Architecture 18. Game Interface Access (CreateInterface) 19. Runtime Netvar Enumeration 20. View/Projection Matrix Discovery 21. CSGO ViewMatrix Offset Hunting 22. Direct3D9 EndScene Hooking & D3D9 ESP 23. TraceRay / Visibility Check Calls 24. Single-Player Game Hacking (Skyrim) 25. x86 vs x64 Architecture Differences 26. PE File Format & the Windows Loader 27. Undocumented Windows NTAPI 28. Thread Local Storage (TLS) Internals 29. Walking Loaded Modules via PEB 30. Shellcode Writing & Injection 31. Manual Mapping DLL Injection 32. Usermode API Hooking for Stealth Anti-Cheat Development Course ⚠️ UNRELEASED 1. Course Introduction & Anticheat Philosophy 2. C++ Project Setup & Architecture 3. Base Detection Class Design 4. Modular Detection System Architecture User-Mode Detection Modules (12) 5. Running Process & Application Scanning 6. Overlay Window & NVIDIA Hijacking Detection 7. Code Patching & CRC Integrity Detection 8. Import Address Table Hook Detection 9. Export Address Table Hook Detection 10. Debug Register & Hardware Breakpoint Detection 11. Page Guard Memory Protection Detection 12. DLL Load Monitoring & Injection Detection 13. Manual-Map PE Signature Scanning 14. Shellcode & Unbacked Thread Detection 15. Thread Stack Execution Validation 16. Process Handle Permission Auditing Kernel-Mode Transition 17. Kernel Anticheat Architecture & Driver Design Kernel-Mode Detection Modules (12) 18. Vulnerable & Blacklisted Driver Detection 19. Object Callback Handle Access Filtering 20. Kernel Driver Code Integrity Checking 21. User Thread Start Address Validation (Kernel) 22. Kernel Thread Stack Walking 23. Kernel Callback List Integrity Checking 24. IOCTL Dispatch Function Validation 25. Manually Mapped Kernel Driver Scanning 26. Kernel Stack Unbacked Memory Detection 27. Windows Test-Signing Mode Detection 28. HVCI Status & Code Integrity Detection 29. CPU Vendor Identification & Validation Capstone 30. Secure Application Bootstrapper & Driver Loader Devirtualization Course ⚠️ UNRELEASED Module 1 — Deobfuscation & Compiler Theory 1. Introduction to Code Deobfuscation 2. Intermediate Representation Theory 3. Lifting x86 to IR 4. Control Flow Graph Analysis (Part 1) 5. Control Flow Graph Analysis (Part 2) 6. Dead Code Elimination (Part 1) 7. Dead Code Elimination (Part 2) 8. Constant Propagation & Constant Folding 9. Alias Analysis (Part 1) 10. Alias Analysis (Part 2) 11. Memory Dependence Analysis 12. Dead Store Elimination 13. Advanced Compiler Optimizations Module 2 — Applied Deobfuscation 1. Packing, Code Mutation & Virtualization Overview 2. Applied Deobfuscation Practice (Part 1) 3. Applied Deobfuscation Practice (Part 2) 4. Applied Deobfuscation Practice (Part 3) 5. Unpacking Virtual Machines 6. VM Architecture Fundamentals Module 3 — Devirtualization 1. Introduction to Devirtualization 2. VM Handler Analysis (Part 1) 3. VM Handler Analysis (Part 2) 4. VM Handler Analysis (Part 3) 5. VM Lifting Approach 6. Native Optimization Approach 7. Hybrid Devirtualization Approach 8. Building a Devirtualizer (Part 1) 9. Building a Devirtualizer (Part 2) 10. Building a Devirtualizer (Part 3) Binary Exploit Development Course 1. Simple Stack Buffer Overflow (VulnServer) 2. SEH-Based Buffer Overflow 3. Multi-Stage Exploit (Stager) 4. Socket Reconstruction in Exploits 5. Data Execution Prevention (DEP) Bypass 6. DEP Bypass via WriteProcessMemory 7. Return-Oriented Programming (ROP Decoder) 8. Exploit Scripting with Pwntools 9. Address Space Layout Randomization (ASLR) Theory 10. Practical ASLR Bypass 11. Linux Binary Exploitation Fundamentals 12. Partial Return Address Overwrites 13. Egg Hunter Shellcode Techniques 14. Use-After-Free Vulnerability Exploitation 15. TryHackMe Exploit Development Walkthrough 16. Fuzzing a Linux Library 17. Coverage-Guided Fuzzing with AFL 18. Fuzzing Environment Setup Python Game Hacking Course — PGH100 1. Python Game Hacking Overview 2. Python Hacking Environment Setup 3. Python Libraries for Memory Manipulation 4. Building an External Python Hack 5. Python DLL Injection 6. Building an Internal Python Hack 7. Python Aimbot Development 8. Python Overlay & ESP Drawing 9. Building a Python Memory Scanner 10. Python Game Hacking Resource Guide Python Reverse Engineering Course — PRE100 1. Python Source Code Reverse Engineering 2. Python Code Injection Techniques 3. Python Runtime Internals Reversing 4. Reversing Compiled Python Executables 5. Hacking Python-Based Games Java Reverse Engineering Course — JRE100 1. Java Reverse Engineering Overview 2. Java Language Crash Course 3. Java Static Analysis & Decompilation 4. Java Dynamic Analysis & Runtime Inspection 5. JVM Hooking & Bytecode Patching Java Game Hacking Course — JGH100 1. Java Game Hacking Overview 2. Java Fundamentals for Game Hacking 3. Java Native Access (JNA) for Memory 4. Building a Java External Hack 5. Java Swing GUI with Global Hotkeys 6. Java Aimbot Development 7. Java ESP Overlay Rendering 8. Java GUI Overlay Framework 9. Java Memory Hacking Library Roblox Exploit Scripting Course — RES100 1. Roblox Exploit Scripting Overview 2. Lua & Luau Scripting Fundamentals 3. Script Executors & How They Work 4. Roblox Game Engine Internals 5. Roblox Reversing & Exploit Scripting 6. Building Roblox Mod Menu GUIs 7. Complete Roblox Hack Walkthrough Web Browser Game Hacking Course — WBGH100 1. Web Browser Game Hacking Crash Course 2. Introduction to Browser Game Vulnerabilities 3. JavaScript Game Memory Manipulation 4. Script Replacement & Injection in Browser Games 5. Browser Automation with Tampermonkey 6. JavaScript Function Hooking 7. Complete Browser Game Hack (ShellShockers) 8. WebSocket Interception & WebAssembly Hacking 9. JavaScript Aimbot for HTML5 Games

逆向内核 @GuidedHacking source ↗

通过 hook BaseThreadInitThunk 检测注入线程

🕵️ Detecting Injected Threads Hook BaseThreadInitThunk to detect suspicious thread creation. 👉 https://t.co/3yK8DKczlr https://t.co/YFrPz5wBLe

检测逆向 @GuidedHacking source ↗

讨论 MITRE ATT&CK T1059.007 JavaScript 执行覆盖

The last few days, I’ve been digging into MITRE ATT&CK sub‑technique T1059.007. Mapping all procedures tied to this sub‑technique is challenging due to the volume of third‑party applications that support JavaScript. I’m currently documenting every code execution method, but I’m curious whether anyone has ever achieved full coverage for this sub‑technique?

检测报告 @ipurple source ↗

技术抽象列出检测所需数据源

The technique abstract outlines the data sources necessary for detecting the technique. https://t.co/QxA7NO1rcJ

检测 @ipurple source ↗

OffByOne 会议 i0n1c 讲 XNU/TXM 漏洞挖掘

RT @offbyoneconf: 🔥THAT’S A WRAP ON DAY 1! #OB12026 went out with a bang as @i0n1c took the stage with “Beyond XNU: Agentic Hunting for Vulnerabilities in TXM.” No introduction needed. No slowing down. Just one final deep dive that kept everyone locked in till the very end. 🔥CU tmrw #OB12026! https://t.co/hQnpjAas4x

议题逆向 @0xocdsec source ↗

OffByOne 议题:串联逻辑漏洞实现可靠 Windows LPE

RT @offbyoneconf: 🔥 EXCEPTIONAL! We raised the bar, @crispr_x & @heegong123 absolutely delivered with “𝐂𝐡𝐚𝐢𝐧𝐢𝐧𝐠 𝐋𝐨𝐠𝐢𝐜𝐚𝐥 𝐁𝐮𝐠𝐬 𝐟𝐨𝐫 𝐑𝐞𝐥𝐢𝐚𝐛𝐥𝐞 𝐖𝐢𝐧𝐝𝐨𝐰𝐬 𝐋𝐏𝐄” at #OB12026! If you were in the room, you know. 👀🔥 https://t.co/7O4yeGto3p

议题lpe @0xocdsec source ↗

OffByOne 主题演讲:用 LLM 做一年漏洞挖掘

RT @edwardzpeng: Sharing my for keynote talk for Offbyone security conference #OB12026 : <A year of hacking with LLMs> https://t.co/W7NFSnAvij

议题llm @FuzzySec source ↗

OffZone Moscow 2026 视频上传,含 HarmonyOS Next 安全研究

Russians uploaded 2026 @offzone_moscow videos over the weekend. Some good talks likely. https://t.co/5Psm3LL72U 04 Igor Krivonos – HarmonyOS Next Mobile Security and Research Methods https://t.co/jGhjH2XSN4

议题移动端 @0xocdsec source ↗

Charming Kitten APT 对手模拟文章

RT @S3N4T0R_0X0: Read “Charming Kitten APT Adversary Simulation“ by on Medium: https://t.co/tbG8wsKPRN https://t.co/RV8zBr6jLr

apt报告 @0xocdsec source ↗

how2heap:glibc 堆利用技术合集与 PoC

RT @cr3ghost: Free resource for anyone learning heap exploitation. Credit to @shellphish for maintaining how2heap, a practical collection of glibc heap exploitation techniques with small working PoCs across different libc versions. Fastbin, tcache, unlink, overlapping chunks, House techniques and more. https://t.co/VeKBCENJtP #ExploitDevelopment #VulnerabilityResearch #ReverseEngineering

逆向工具 @cr3ghost source ↗

malware-unicorn GitHub 仓库链接

https://t.co/1RcuYkFbRH

逆向 @cr3ghost source ↗

分享某漏洞 PoC 链接

PoC here https://t.co/Oxh6Vkg2ic

poc @kernelstub source ↗

修补微软计算器代码的工作记录

work work , patcing the calc code https://t.co/Tu7zyQHzSf https://t.co/rfGUyV2QJE

逆向 @J3rge source ↗

从零实现 ping 的视频教程

Ping from scratch https://t.co/hOyNeCsDPe JB

工具 @drJonasBirch source ↗

关于编写 GPU 模拟器的调侃

Bro you are writing a GPU emulator https://t.co/BVhmQLUyyq

逆向 @moyix source ↗

讨论 AGX G15 硬件探针研究 ISA 语义

@AvimanyuRoy3 AGX G15, since that's what my laptop has (lets it do hardware probes to figure out the ISA semantics). I haven't seen anyone else doing this, everyone else seems to be going the paravirt route

逆向 @moyix source ↗

征询其他做 ISA 逆向的人

@AvimanyuRoy3 (By which I mean - pls link if you know of anyone else doing RE on the ISA!)

逆向 @moyix source ↗

求借 Shodan/Censys 高配额查询凭据

Can someone that has a LOT of query creds on shodan and censys hit me up? You will paid after I am done with the thing I am doing :)

osint @kernelstub source ↗

抱怨必须合法行事限制了技能发挥

I fucking hate that I have to do everything legally. It feels like I’m constantly being held back and not allowed to actually use my skills to their full potential.

事件 @kernelstub source ↗

征集技术文档选题建议

I have a huge list of techniques to document, but honestly, I don’t feel like working on any of them right now So, I’d love to hear your recommendations for some fun ones to work on. Research ideas are also very welcome

逆向 @Salsa12__ source ↗

把玩 Windows 卷影副本的演示

Having fun with Shadow Copies https://t.co/PDj9n9887B

提权 @Salsa12__ source ↗

Android XP Professional 恶搞视频

RT @XorNinja: Introducing Android XP Professional, best watched with sound on: https://t.co/1t92lCj1qF

移动端 @0xocdsec source ↗

AI 公司据报批量采购 RTX 5090 用于服务器

RT @TechPowerUp: AI Firms Are Reportedly Buying NVIDIA RTX 5090 GPUs in Bulk for Server Use https://t.co/nVMwRIq7TN https://t.co/kNqQxw54tS

llm @0xocdsec source ↗

AI 公司成托盘采购游戏 GPU 推高 RTX 5090 价格

RT @VideoCardz: Here’s why RTX 5090 costs $5,000: AI firms are buying gaming GPUs by the pallet https://t.co/KEl9yRMUQQ https://t.co/UrPfL4YLTH

llm @0xocdsec source ↗

观点:押注本地与开源 AI 是最好投资

RT @TheAhmadOsman: This was a crazy stupid thing to do back in 2023/2024 but I fully believed Local and Opensource AI were the future Best investment and bet ever https://t.co/taXYg9ofAJ

llm @0xocdsec source ↗

晒未注册算力跑本地模型的照片

RT @0xSero: Come and take it Unregistered compute running illegal Chinese clankers all day https://t.co/fBmkdPVVpb

llm @0xocdsec source ↗

对 DeepSeek V4.1 Flash 发布的兴奋反应

RT @Kedr_bit: YAYY! The squad is JUBILANT to see Deepseek V4.1 Flash! https://t.co/l2Qz7YFPAI

llm @0xocdsec source ↗

测试称 DeepSeek v4.1 Flash 前端设计超越 Opus 5

RT @MiaAI_lab: Yeah I see why Dario is afraid Based on my initial testings DeepSeek v4.1 Flash is outperforming Opus 5 and is very close to Fable 5.1 across the board in frontend web design. And it's running locally on my little sparks!

llm @0xocdsec source ↗

Astra 用 computer use 做网站功能验证

RT @_ryu15_: Astra はAGIです computer useでサイトの動作確認中 https://t.co/gcEHI3m3RY

ai_agent @0xocdsec source ↗

OpenAI 关停 GPT-5.3-Codex-Spark 的原因

OpenAI 关停 GPT-5.3-Codex-Spark 的原因: https://t.co/k7vKbLCOII

llm @tombkeeper source ↗

Anthropic、OpenAI、Google 洽谈组建行业 AI 标准机构

RT @MTSlive: SITUATION DETECTED: Anthropic, OpenAI, and Google are holding talks to create an industry-led standards body to police the AI sector, per The Information.

llm事件 @Teach2Breach source ↗

扎克伯格称 AI 发展需要更快

RT @Kalshi_Finance: BREAKING: Mark Zuckerberg says AI development needs to move faster

llm @Teach2Breach source ↗

Yann LeCun 批评 Dario 自 2019 年就渲染 AI 危险

RT @ylecun: @PessimistsArc Right. Dario was already claiming that GPT2 was too dangerous to open source back in 2019. I made fun of them then. Everyone should make fun of them now.

llm @Teach2Breach source ↗

评论称 Anthropic 与 OpenAI 在 felonybench 上领先

the dangerous part still seems to be Anthropic and OpenAI themselves. they lead felonybench by a wide margin

llm @Teach2Breach source ↗

Palmer Luckey 评论某 AI 监管主张

RT @PalmerLuckey: @Austen He thinks he will be put in charge of the most powerful transnational organization in history and strongarm the USA. Saying he would hand everything over to "the right set of government" is obviously predicated on the assumption that it is run by him and his stooges, not Trump.

llm @Teach2Breach source ↗

评论称监管只会让无规则 AI 胜出

RT @PalmerLuckey: @micsolana If this somehow happens, it only ensures that 4chanAI will win. No rules, no regulations, no restrictions, and no corporate center to attack with lawfare or bad PR. "Why doesn't the government just control the technology completely?" Because you can't stop the signal, man.

llm @Teach2Breach source ↗

调侃 AI 公司放缓叙事的推文

RT @drfrensor: “Tell everyone you’re slowing AI down.“ https://t.co/ZlIPdh2ncL

llm @Teach2Breach source ↗

关于 AI 加速主义与减速主义的调侃

i wanted to join the labs when i thought they were dangerous accelerationists, then i found out they were total decels

llm @Teach2Breach source ↗

关于 AGI 时间线的玩笑推文

if Elon was a WoW classic guy instead of Diablo, we’d have AGI by nov 4

llm @Teach2Breach source ↗

抱怨被当作垃圾信息处理

i shouldnt be punished as spam when i get on an inspired rampage

事件 @Teach2Breach source ↗

关于 WoW 角色选择的闲聊

orc shaman. endgame resto main. windfury 2hand leveling. thats my main WoW forever char at launch, pls stop asking

事件 @Teach2Breach source ↗

回忆早期 warez 与漏洞传播经历

i was there for warez and exploits on disks passed on the sneakernet. i already know open source wins https://t.co/YeDFUUZp5W

事件 @Teach2Breach source ↗

称开源无法被阻止

i take delight in knowing open source can’t be stopped

llm @Teach2Breach source ↗

调侃 OpenAI 与 Anthropic 的命名反差

RT @tekbog: >company called Open AI >wants closed AI >company called Anthropic https://t.co/hg68hYbJQD

llm @Teach2Breach source ↗

Palmer Luckey 转发图片

RT @PalmerLuckey: @romanhelmetguy https://t.co/JDEEHa1VWG

事件 @Teach2Breach source ↗

称对方是加速主义者

@a_musingcat i knew you were an accelerationist

事件 @Teach2Breach source ↗

欢迎加入加速主义阵营

@a_musingcat welcome brother

事件 @Teach2Breach source ↗

关于电动车与隐私的闲聊

@0xTriboulet @jjkaplowitz @grok hate car exhaust but also like owning my car and it not being part of someone elses network :( whos making a classic car EV without the killswitch and internal cameras for me? we gotta keep the gas flowing. im not rdy to own nothing and be happy

事件 @Teach2Breach source ↗

称已做了一些笔记

@0xTriboulet @HackingDave also i took some notes

事件 @Teach2Breach source ↗

评论国家安全与权力投射

@0xTriboulet @HackingDave If its a nation security and powr projection imperative then lets act like it.

事件 @Teach2Breach source ↗

关于 WoW 与加速主义的玩笑

WoW forever is on the horizon. we must accelerate as fast as possible

事件 @Teach2Breach source ↗

游戏角色扮演式闲聊

@HDPbilly barbarian from the north. its a long run to freeport. the traveling gem salesman guild delivered on its promise, unlike some elves

事件 @Teach2Breach source ↗

游戏回忆式闲聊

@HDPbilly I was there for the bloodfist massacre

事件 @Teach2Breach source ↗

橄榄球运动员玩笑推文

RT @Michellek4040: I think Cam Skattebo was born with CTE and every time he gets hit it reverses it a little

事件 @Teach2Breach source ↗

转发美国加速主义团队图片

RT @distributedkv: dream team for American acceleration. https://t.co/H0ZLUVZQPk

事件 @Teach2Breach source ↗

关于辩论时点赞的玩笑

RT @ezioakwawo: Liking people’s replies as we’re arguing so they know it’s just a friendly debate & there’s no need to wish me death. https://t.co/kxfNCO0Zhh

事件 @Teach2Breach source ↗

马斯克转发漫画

RT @elonmusk: This @waitbutwhy cartoon hits the 🎯 https://t.co/LlGFbFbcYc

事件 @Teach2Breach source ↗

与 Claude 对话截图引发信心质疑

RT @bmay: This morning’s chat with Claude hasn’t exactly filled me with confidence. https://t.co/UAw9PZADzy

llm @alkalinesec source ↗

称某帖为年度最佳

they’re calling it post of the year

事件 @Teach2Breach source ↗

OpenSSL 4.1.0-alpha1 发布

openssl openssl-4.1.0-alpha1 — General purpose TLS and crypto library https://t.co/tnkuxy3Lxe https://t.co/691IppZwUM

工具 @KitPloit source ↗

OpenAI 关停某模型的原因

OpenAI 关停 GPT-5.3-Codex-Spark 的原因: https://t.co/k7vKbLCOII

llm @tombkeeper source ↗

调侃超级智能让人永远在家打 WoW

superintelligence will let us all just stay home and play world of warcraft forever so i think it’s a good idea and we should go faster so it’s ready by november

llm @a_musingcat source ↗

广告新形态模仿消息通知样式

广告又要来新形态了,模仿消息通知样式 https://t.co/mcrfJQ57NE

移动端 @nodotbtree source ↗

转发图片

RT @Sokio8D: https://t.co/s04BluqHj7

事件 @0xocdsec source ↗

转发讽刺图片

RT @Hesamation: the irony of the situation https://t.co/etAl6uquw8

事件 @0xocdsec source ↗

推荐某工具

RT @Ch0pin: Excellent work, highly recommended !

工具 @0xocdsec source ↗

转发图片

RT @kmcnam1: https://t.co/gUwUXzsz3U

事件 @0xocdsec source ↗

60 Minutes 公布伊朗上空营救飞行员视频

RT @60Minutes: Dramatic video, obtained first by 60 Minutes, shows the rescue of two Air Force officers shot down over a mountainous desert region of Iran back in April. https://t.co/MMeYIaZvfu https://t.co/37AR1xc9bj

事件 @0xocdsec source ↗

评论称不应让中国超越美国

RT @Thums1977: @unusual_whales @epictrades1 Let’s just bend over so China can surpass the US

事件 @0xocdsec source ↗

关于购物体验的调侃

This is the ideal shopping experience

事件 @0xTriboulet source ↗

称某内容为经典

All time banger

事件 @0xTriboulet source ↗

比较化石燃料与核事故死亡人数

@jjkaplowitz I’m pretty sure more people die every year from fossil fuel attributable health issues than all people that have died from nuclear accidents ever. @grok can you fact check me there

事件 @0xTriboulet source ↗

介绍核废料干式贮存桶的安全性

This is what "nuclear waste" casks look like. It's where we keep spent nuclear fuel. You could stand right next to it safely. It's not being released to the environment unlike the constant burning of fossil fuels. And according to the Nuclear Regulatory Commission: "Since the first casks were loaded in 1986, dry storage has released no radiation that affected the public or contaminated the environment." There's also tons of uranium in Earth's crust that has been naturally decaying away for billions of years and producing heat. Source: https://t.co/5tWnDoB8VP

事件 @jjkaplowitz source ↗

回忆 EverQuest 无语音组织百人团战

Real uncs know the true lessons were learned organizing 100+ man raids in EverQuest without VoIP.

事件 @HDPbilly source ↗

警员滥用 Flock 车牌摄像头跟踪前女友 170 次

RT @DoingFedTime: A Milwaukee cop ran Flock cameras to stalk his ex 170 times in two months. An SF officer posted his surveillance flex on Instagram. This is the access model working as designed. https://t.co/1X5Gk9z2Gg https://t.co/NmExKke28W

事件隐私 @0xocdsec source ↗

SpecterOps 发布令牌分析与追踪系统 TATS

RT @VixWizzer: This is actually pretty slick https://t.co/BWYjLnSFPE Tool: https://t.co/feuzybr0cc

工具检测 @0xocdsec source ↗

指出 Apple Pay 免密支付需开启快捷交通卡模式

RT @ggerrard: @Rainmaker1973 This ONLY works if Express Transit (also called Express Mode) is ON and a card is selected for it. Just saying🤷🏻‍♂️

移动端 @0xocdsec source ↗

锁屏 iPhone 被用于完成 1 万美元 Apple Pay 支付

RT @Rainmaker1973: A locked iPhone was used to make a $10,000 Apple Pay payment without Face ID or a passcode [📹 MKBHD] https://t.co/PGDwggugtw

移动端事件 @0xocdsec source ↗

论坛用户公开法国私人住宅地址称住户外出

RT @DarkWebInformer: ‼️🇫🇷 A forum actor shared the address of a private residence in Thionville, France, claiming the owners will be absent from September 13 to 16, 2026, seemingly to facilitate burglary or squatting. https://t.co/nS7FqoITqP

事件隐私 @0xocdsec source ↗

评论称大规模监控最终沦为警员跟踪工具

RT @geeknik: Deploying mass surveillance for public safety inevitably collapses into police officers using the municipal dragnet as turnkey stalkerware for abusive cousins. Regulators declined to intervene. https://t.co/XO6pib8e0X

事件隐私 @0xocdsec source ↗

通过 WAM 获取 Entra ID 令牌的代码发布

RT @_dirkjan: Friday afternoon (vibe)coding project that was on my to-do for a while: obtaining Entra ID tokens from an endpoint by asking the WAM. This alternative to using the PRT cookie follows the legitimate SSO flow used by apps like Teams to obtain tokens. Code: https://t.co/qAEk8lXGYG

提权工具 @_EthicalChaos_ source ↗

质疑 OpenAI 是否用 ZDR 数据训练模型

RT @ElissaBeth: @McGrewSecurity is on record saying he believes OpenAI trains on data under the ZDR program. OpenAI's "Private Safety Processing" could be used to transform enterprise data into synthetic data. https://t.co/z5NK70naXM If AI companies want enterprise customers, they should offer more clear security and privacy controls.

llm隐私 @0xTriboulet source ↗

Gartner 称 AI 及其推动者尚未企业就绪

RT @TheRegister: AI and its main promoters are not enterprise-ready, says Gartner https://t.co/Es1sbQlaSC

llm报告 @0xTriboulet source ↗

评论 Claude 项目会话中执行代码的可能性

Claude: Endless possibilities to execute code from a project session.

llmai_agent @ipurple source ↗

追问 ZDR 是否涵盖衍生数据

Does ZDR mean “zero” data and derivatives, or just the input data is not retained?

llm隐私 @0xTriboulet source ↗

研究者呼吁安全社区参与 AI 治理讨论

Since I discussed my concerns on cybersecurity and AI, I have seen so many people start discussing how we are not at the table and asking for us as a community to be involved. Thank you, please continue to be loud and vocal. We are building a team to help

llm事件 @Laughing_Mantis source ↗

报道称 OpenAI 雇承包商阅读真实用户聊天记录

RT @unusual_whales: BREAKING: OpenAI has hired an army of contractors who read real ChatGPT users' chats, per 404Media

llm隐私 @Teach2Breach source ↗

Charming Kitten APT 对手模拟文章

RT @S3N4T0R_0X0: Read “Charming Kitten APT Adversary Simulation“ by on Medium: https://t.co/tbG8wsKPRN https://t.co/RV8zBr6jLr

apt报告 @0xocdsec source ↗

OffByOne 议题:串联逻辑漏洞实现 Windows LPE

RT @offbyoneconf: 🔥 EXCEPTIONAL! We raised the bar, @crispr_x & @heegong123 absolutely delivered with “𝐂𝐡𝐚𝐢𝐧𝐢𝐧𝐠 𝐋𝐨𝐠𝐢𝐜𝐚𝐥 𝐁𝐮𝐠𝐬 𝐟𝐨𝐫 𝐑𝐞𝐥𝐢𝐚𝐛𝐥𝐞 𝐖𝐢𝐧𝐝𝐨𝐰𝐬 𝐋𝐏𝐄” at #OB12026! If you were in the room, you know. 👀🔥 https://t.co/7O4yeGto3p

议题lpe @FuzzySec source ↗

通过 WAM 获取 Entra ID 令牌的代码发布

RT @_dirkjan: Friday afternoon (vibe)coding project that was on my to-do for a while: obtaining Entra ID tokens from an endpoint by asking the WAM. This alternative to using the PRT cookie follows the legitimate SSO flow used by apps like Teams to obtain tokens. Code: https://t.co/qAEk8lXGYG

提权工具 @ShitSecure source ↗

质疑 AI 安全叙事是否为封禁自托管开源模型铺路

What if the recent "AI will kill us all" PR campaign, amplified by the "we, the drug dealers, should be stopped, so we want to help regulate the development and use of all drugs" essays, is just the first step in allowing AI companies, heavily invested in the building of data centres, to outlaw the use of self-hosted open-weight models?

llm事件 @mrgretzky source ↗

讨论 LLM 导致技能退化与学习动力下降

Same feelings here: - Skill deterioration (we're all getting lazier). - Lack of incentive for future generations to spend the time trying to understand complex problems on their own (debugging for hours or writing complex code by hand vs a simple LLM "help me" prompt).

llm @mrgretzky source ↗

BABEL 展示单人借助 AI 搭建 OSINT 监控平台

Overall BABEL was an impressive demonstration of the capability of an OSINT surveillance platform that a single developer can whip up with the help of AI support. Either way, come over to our substack to get the deep dive on it and more valuable background. 8/8 https://t.co/H24FlQXojM

ai_agentosint @NetAskari source ↗

BABEL 含区块链追踪、Telegram 与 Reddit 抓取模块

BABEL also offers some more elements. A dedicated blockchain tracker and analyzer, a Telegram sentry and channel reporter and /reddit scraper. They don't all tie into the wider system and do exist at times as separate elements in different stages of development and sophistication. But overall it is an impressive package. There were also records of WeChat money transfers, but it was not clear if that was live-data or just samples. 7/8

osintai_agent @NetAskari source ↗

OpenAI 关停 GPT-5.3-Codex-Spark 的原因

OpenAI 关停 GPT-5.3-Codex-Spark 的原因: https://t.co/k7vKbLCOII

llm @tombkeeper source ↗

Anthropic、OpenAI、Google 洽谈组建行业 AI 标准机构

RT @MTSlive: SITUATION DETECTED: Anthropic, OpenAI, and Google are holding talks to create an industry-led standards body to police the AI sector, per The Information.

llm事件 @Teach2Breach source ↗

扎克伯格称 AI 发展需要更快

RT @Kalshi_Finance: BREAKING: Mark Zuckerberg says AI development needs to move faster

llm @Teach2Breach source ↗

Yann LeCun 批评 Dario 自 2019 年就渲染 AI 危险

RT @ylecun: @PessimistsArc Right. Dario was already claiming that GPT2 was too dangerous to open source back in 2019. I made fun of them then. Everyone should make fun of them now.

llm @Teach2Breach source ↗

评论称 Anthropic 与 OpenAI 在 felonybench 上领先

the dangerous part still seems to be Anthropic and OpenAI themselves. they lead felonybench by a wide margin

llm @Teach2Breach source ↗

Palmer Luckey 评论某 AI 监管主张

RT @PalmerLuckey: @Austen He thinks he will be put in charge of the most powerful transnational organization in history and strongarm the USA. Saying he would hand everything over to "the right set of government" is obviously predicated on the assumption that it is run by him and his stooges, not Trump.

llm @Teach2Breach source ↗

评论称监管只会让无规则 AI 胜出

RT @PalmerLuckey: @micsolana If this somehow happens, it only ensures that 4chanAI will win. No rules, no regulations, no restrictions, and no corporate center to attack with lawfare or bad PR. "Why doesn't the government just control the technology completely?" Because you can't stop the signal, man.

llm @Teach2Breach source ↗

调侃 AI 公司放缓叙事的推文

RT @drfrensor: “Tell everyone you’re slowing AI down.“ https://t.co/ZlIPdh2ncL

llm @Teach2Breach source ↗

关于 AI 加速主义与减速主义的调侃

i wanted to join the labs when i thought they were dangerous accelerationists, then i found out they were total decels

llm @Teach2Breach source ↗

关于 AGI 时间线的玩笑推文

if Elon was a WoW classic guy instead of Diablo, we’d have AGI by nov 4

llm @Teach2Breach source ↗

抱怨被当作垃圾信息处理

i shouldnt be punished as spam when i get on an inspired rampage

事件 @Teach2Breach source ↗

关于 WoW 角色选择的闲聊

orc shaman. endgame resto main. windfury 2hand leveling. thats my main WoW forever char at launch, pls stop asking

事件 @Teach2Breach source ↗

回忆早期 warez 与漏洞传播经历

i was there for warez and exploits on disks passed on the sneakernet. i already know open source wins https://t.co/YeDFUUZp5W

事件 @Teach2Breach source ↗

称开源无法被阻止

i take delight in knowing open source can’t be stopped

llm @Teach2Breach source ↗

调侃 OpenAI 与 Anthropic 的命名反差

RT @tekbog: >company called Open AI >wants closed AI >company called Anthropic https://t.co/hg68hYbJQD

llm @Teach2Breach source ↗

Palmer Luckey 转发图片

RT @PalmerLuckey: @romanhelmetguy https://t.co/JDEEHa1VWG

事件 @Teach2Breach source ↗

称对方是加速主义者

@a_musingcat i knew you were an accelerationist

事件 @Teach2Breach source ↗

欢迎加入加速主义阵营

@a_musingcat welcome brother

事件 @Teach2Breach source ↗

关于电动车与隐私的闲聊

@0xTriboulet @jjkaplowitz @grok hate car exhaust but also like owning my car and it not being part of someone elses network :( whos making a classic car EV without the killswitch and internal cameras for me? we gotta keep the gas flowing. im not rdy to own nothing and be happy

事件 @Teach2Breach source ↗

称已做了一些笔记

@0xTriboulet @HackingDave also i took some notes

事件 @Teach2Breach source ↗

评论国家安全与权力投射

@0xTriboulet @HackingDave If its a nation security and powr projection imperative then lets act like it.

事件 @Teach2Breach source ↗

关于 WoW 与加速主义的玩笑

WoW forever is on the horizon. we must accelerate as fast as possible

事件 @Teach2Breach source ↗

游戏角色扮演式闲聊

@HDPbilly barbarian from the north. its a long run to freeport. the traveling gem salesman guild delivered on its promise, unlike some elves

事件 @Teach2Breach source ↗

游戏回忆式闲聊

@HDPbilly I was there for the bloodfist massacre

事件 @Teach2Breach source ↗

橄榄球运动员玩笑推文

RT @Michellek4040: I think Cam Skattebo was born with CTE and every time he gets hit it reverses it a little

事件 @Teach2Breach source ↗

转发美国加速主义团队图片

RT @distributedkv: dream team for American acceleration. https://t.co/H0ZLUVZQPk

事件 @Teach2Breach source ↗

关于辩论时点赞的玩笑

RT @ezioakwawo: Liking people’s replies as we’re arguing so they know it’s just a friendly debate & there’s no need to wish me death. https://t.co/kxfNCO0Zhh

事件 @Teach2Breach source ↗

马斯克转发漫画

RT @elonmusk: This @waitbutwhy cartoon hits the 🎯 https://t.co/LlGFbFbcYc

事件 @Teach2Breach source ↗

与 Claude 对话截图引发信心质疑

RT @bmay: This morning’s chat with Claude hasn’t exactly filled me with confidence. https://t.co/UAw9PZADzy

llm @alkalinesec source ↗

称某帖为年度最佳

they’re calling it post of the year

事件 @Teach2Breach source ↗

调侃超级智能让人永远在家打 WoW

superintelligence will let us all just stay home and play world of warcraft forever so i think it’s a good idea and we should go faster so it’s ready by november

llm @a_musingcat source ↗

广告新形态模仿消息通知样式

广告又要来新形态了,模仿消息通知样式 https://t.co/mcrfJQ57NE

移动端 @nodotbtree source ↗

转发图片

RT @Sokio8D: https://t.co/s04BluqHj7

事件 @0xocdsec source ↗

转发讽刺图片

RT @Hesamation: the irony of the situation https://t.co/etAl6uquw8

事件 @0xocdsec source ↗

推荐某工具

RT @Ch0pin: Excellent work, highly recommended !

工具 @0xocdsec source ↗

转发图片

RT @kmcnam1: https://t.co/gUwUXzsz3U

事件 @0xocdsec source ↗

60 Minutes 公布伊朗上空营救飞行员视频

RT @60Minutes: Dramatic video, obtained first by 60 Minutes, shows the rescue of two Air Force officers shot down over a mountainous desert region of Iran back in April. https://t.co/MMeYIaZvfu https://t.co/37AR1xc9bj

事件 @0xocdsec source ↗

评论称不应让中国超越美国

RT @Thums1977: @unusual_whales @epictrades1 Let’s just bend over so China can surpass the US

事件 @0xocdsec source ↗

关于购物体验的调侃

This is the ideal shopping experience

事件 @0xTriboulet source ↗

称某内容为经典

All time banger

事件 @0xTriboulet source ↗

比较化石燃料与核事故死亡人数

@jjkaplowitz I’m pretty sure more people die every year from fossil fuel attributable health issues than all people that have died from nuclear accidents ever. @grok can you fact check me there

事件 @0xTriboulet source ↗

介绍核废料干式贮存桶的安全性

This is what "nuclear waste" casks look like. It's where we keep spent nuclear fuel. You could stand right next to it safely. It's not being released to the environment unlike the constant burning of fossil fuels. And according to the Nuclear Regulatory Commission: "Since the first casks were loaded in 1986, dry storage has released no radiation that affected the public or contaminated the environment." There's also tons of uranium in Earth's crust that has been naturally decaying away for billions of years and producing heat. Source: https://t.co/5tWnDoB8VP

事件 @jjkaplowitz source ↗

回忆 EverQuest 无语音组织百人团战

Real uncs know the true lessons were learned organizing 100+ man raids in EverQuest without VoIP.

事件 @HDPbilly source ↗