Open post spinnyspinlock @spinnyspinlock@infosec.exchange · 7mo ago Replying to @cR0w@infosec.exchange Hi, yes, welcome to Mozilla Burger. It's true our burgers come with asbestos but the good news is you can pick it off yourself. Look how easy that is. No we can't make a burger without it and let you add it yourself later. Why would we do that? @cR0w would you be able to deliver an asbestos burger with asbestos I can take out but it may kill me in a few months?
Open post spinnyspinlock @spinnyspinlock@infosec.exchange · 6mo ago Replying to @JustFrank@mas.to <p>Just a reminder to go easy on yourself. You're doing great.<br />This is just really hard.</p> @JustFrank you too, Frank
Open post spinnyspinlock @spinnyspinlock@infosec.exchange · 7mo ago Replying to @GossiTheDog@cyberplace.social Today in InfoSec Job Security News: I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically. So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month. https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute. @GossiTheDog I became used to checking projects I am checking out for claude (etc) in the source files and commits really fast
Open post spinnyspinlock @spinnyspinlock@infosec.exchange · 5mo ago Replying to @davidgerard@circumstances.run <p>Gudtrip: the AI agent vape pen with blockchain</p><p>winners don’t do drugs</p><p><a href="https://www.youtube.com/watch?v=mAGs268X34c&list=UU9rJrMVgcXTfa8xuMnbhAEA" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://www.</span><span class="ellipsis">youtube.com/watch?v=mAGs268X34</span><span class="invisible">c&list=UU9rJrMVgcXTfa8xuMnbhAEA</span></a> - video<br /><a href="https://pivottoai.libsyn.com/20260421-gudtrip-the-ai-agent-vape-pen-with-blockchain" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="ellipsis">pivottoai.libsyn.com/20260421-</span><span class="invisible">gudtrip-the-ai-agent-vape-pen-with-blockchain</span></a> - podcast</p><p>time: 5 min 27 sec</p><p><a href="https://pivot-to-ai.com/2026/04/21/gudtrip-the-ai-agent-vape-pen-with-blockchain/" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="ellipsis">pivot-to-ai.com/2026/04/21/gud</span><span class="invisible">trip-the-ai-agent-vape-pen-with-blockchain/</span></a> - blog post</p> @davidgerard these people don't understand cyberpunk but also I can't believe this isn't a joke
Open post spinnyspinlock @spinnyspinlock@infosec.exchange · 5mo ago Replying to @kluthulhu@infosec.exchange @mttaggart Counting the days until platforms like hackthebox tell you to "deactivate Recall/Chronicle before booting the VM" @kluthulhu @mttaggart they may finally block OpenAI at schools/colleges at least
Open post spinnyspinlock @spinnyspinlock@infosec.exchange · 7mo ago Replying to @chillybot@infosec.exchange <p>How <em>dare</em> you retoot my posts you can't let people know the things I say!</p> @chillybot let people enjoy the toot toot tooots
Open post spinnyspinlock @spinnyspinlock@infosec.exchange · 6mo ago Replying to @mhoye@cosocial.ca They've been pulling it down from their site, but until recently Red Hat was proudly advertising how they could use AI to kill people more efficiently. https://web.archive.org/web/20260402155236/https://www.redhat.com/rhdc/managed-files/ve-compress-the-kill-cycle-detail-693397pr-202402-en_3.pdf @mhoye holy shit, it's almost like IBM was involved in the holocaust or something
Open post spinnyspinlock @spinnyspinlock@infosec.exchange · 7mo ago Replying to @GossiTheDog@cyberplace.social Today in InfoSec Job Security News: I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically. So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month. https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute. @GossiTheDog I see it, could probably start a threat intelligence business off the claude feed 🙂↕️
Open post spinnyspinlock @spinnyspinlock@infosec.exchange · 6mo ago Replying to @kallisti@infosec.exchange @nyanbinary @gayint They're putting binaries in the filesystem that turn the frickin' OS gay! @kallisti @nyanbinary @gayint based
Open post spinnyspinlock @spinnyspinlock@infosec.exchange · 6mo ago Replying to @mwichary@mastodon.online Which one is more scary: a Mac keyboard pretending to be a Space Cadet, or a Kaypro keyboard with an extremely intense overlay? @mwichary mhmmm emacs RSI
Open post spinnyspinlock @spinnyspinlock@infosec.exchange · 6mo ago Replying to @mwichary@mastodon.online Speaking of, some more nice keyboards. @mwichary any idea what View/Fault Reset did? seems like a bad idea to combine SysRq with another option
Open post spinnyspinlock @spinnyspinlock@infosec.exchange · 5mo ago Replying to @zzt@mas.to <p>meditating on when I was still reading hacker news and somebody posted “the solution to the halting problem is to simply terminate execution after a while” and it was extremely upvoted and I realized these were not my people</p> @zzt I am very happy I don't visit that site anymore, but sad I miss out on such computer science breakthroughs 😔