🚨 Anthropic just showed a 27-minute workshop on how to actually do prompts for Claude.
Taught by the people who built it.
Free. No registration. No paywall.
I've seen $300 courses that don't cover what they teach in the first 8 minutes.
Watch the session
Google has lost the browser war and nobody told them yet.
An ex-Google engineer open-sourced a privacy-first browser with a native AI agent, MCP server, scheduled tasks, and 40+ app integrations.
Free, private, and it can run entirely on local models.
What's inside:
→ 53+ browser automation tools you control with natural language
→ Built-in MCP server, drive the browser from Claude Code or Gemini CLI
→ Cowork mode: agents that read the web AND write to your local files in the same task
→ Scheduled tasks that run agents on autopilot, hourly or daily
→ BYO Claude/GPT/Gemini keys, or run Ollama locally
→ 40+ app integrations: Gmail, Slack, Notion, Linear, Figma, Salesforce
→ 10x more ad blocking than Chrome
Ask it to book flights, fill forms, research anything, it does it live in your browser.
It's a real Chromium fork with the agent loop baked into the browser process itself. Chrome literally can't ship this without competing against its own ad business.
Imports every Chrome bookmark, password, and extension in one click.
100% open source. runs 100% locally.
🎭 Faker – Generate Realistic Fake Data (such as names, addresses, and phone numbers.) for Development & Testing
Faker is one of the most widely used open-source Ruby libraries for generating realistic fake data. It helps developers populate databases, create test fixtures, and build demos using fake names, addresses, emails, phone numbers, financial data, and much more.
✨ Key Features:
• 👤 Generate fake names, profiles, bios, and job titles
• 📧 Create realistic email addresses, domains, and passwords
• 🏠 Generate addresses, cities, countries, ZIP codes, and phone numbers
• 💳 Produce finance, banking, cryptocurrency, and transaction data
• 🌍 Supports 40+ locales for localized data generation
• 🎲 Deterministic random generation using configurable seeds
• 🔒 Unique value generation to avoid duplicate test data
• ⚡ Ideal for Rails applications, API testing, database seeding, and automated tests
🔗 https://t.co/b8HiklbE3k
#Ruby #RubyOnRails #Faker #Testing #DatabaseSeeding #OpenSource #SoftwareDevelopment #DeveloperTools
This is the most comprehensive OSINT repo I've ever found on GitHub.
Someone published an open source encyclopedia with 1100+ tools, websites, and bots across 50+ categories. Every entry ships with install commands or direct links.
Here's what's actually inside:
→ Username search across 3000+ sites with Sherlock, Maigret, Blackbird
→ Email breach hunting with h8mail, Holehe, Have I Been Pwned, DeHashed
→ Phone OSINT with PhoneInfoga, Truecaller, GetContact
→ Reverse image and face search with Yandex, PimEyes, https://t.co/acWYoENQDh, GeoSpy
→ Domain and IP recon using Shodan, Censys, Amass, Subfinder, https://t.co/NgMcMTpAY5
→ Dark web search engines including Ahmia, Torch, Haystak
→ Crypto investigation tools for tracing Bitcoin and Ethereum addresses
→ A Google dorking bible covering exposed credentials, .env files, and SQL dumps
→ Full Termux and Kali setup guides so everything runs on Android or Linux
→ OSINT focused operating systems, browser extensions, and Telegram bots
This is the kind of resource investigators and security researchers spend years compiling.
MIT License. 100% Opensource.
10 TOOLS ON GITHUB THAT FEEL ILLEGAL TO BE FREE
Bookmark every single one. Each one does something that looks like it should cost money, require a login, or get someone sued. All free.
1. https://t.co/PKb3pEQw5n
Download video or audio from YouTube and 1,800+ other sites straight to your drive, full quality, with subtitles and metadata. 171K stars and a new release every two weeks because YouTube keeps trying to break it and it keeps winning. The Unlicense, which means it's freer than free.
2. https://t.co/j7Qed5Kzq2
Every Adobe Acrobat feature, merge, split, sign, OCR, compress, redact, convert, running on your own machine so no file ever uploads anywhere. A UK dev built it in a day because he refused to pay Adobe just to sign a PDF. 78K stars, 25 million downloads. MIT.
3. https://t.co/RE1H55WHIF
A gorgeous dashboard that pulls live status from every service and app you run into one screen, the kind of control panel companies pay for. Free, self-hosted, and it makes your setup look like a NASA console. The thing that ties your whole stack together.
4. https://t.co/8gWTZZIXyM
AirDrop for every device. Send files between Windows, Mac, Linux, Android, and iOS over your own network with no account, no cloud, no size limit. Apple locked their best version inside their ecosystem. This one works on everything and costs nothing.
5. https://t.co/1RBMSQu38m
The entire Notion, rebuilt open-source and offline-first, so your notes, docs, and databases live on your machine instead of a company's server. Notion is valued at $10 billion. This does the core of it for free and never sells your data. 60K+ stars.
6. https://t.co/Qm55OR5YI1
Google Photos on hardware you own. Phone auto-backup, face recognition, AI search, shared albums, all of it, while Google stops mining your family photos to train its models. The single most satisfying thing to self-host, and people who try it never go back.
7. https://t.co/B57eBygDK6
Build unlimited professional resumes, host them, track them, all free and private, while every resume site online charges you the moment you hit download. 30K+ stars. The paywall that wastes job seekers' money, deleted.
8. https://t.co/zajmBsDn9M
OpenAI's own speech-to-text model, free to run, transcribing 99 languages at the accuracy that Otter, Rev, and Descript literally charge per minute for. The exact engine inside the paid apps, sitting on your laptop for $0. MIT.
9. https://t.co/13hzF0PW7N
Connect any app to any other app and automate entire workflows, the thing Zapier charges by the task for. Hundreds of integrations, self-hosted, running on your own server with no per-action fee. The automation tax, gone. 100K+ stars.
10. https://t.co/TyOTBGduto
Turn any website into clean, structured data an AI can read, in one call. The kind of scraping infrastructure companies sell for hundreds a month, open-sourced. Point it at a site, get back exactly what you need. The frontier devs are already building on it.
Free was always the default. Someone just had to build it.
Someone open-sourced a tool that takes any username or email and finds every account linked to it across 600+ social networks in seconds.
Just one command and it scans every platform, runs free AI profiling to build a full behavioral profile of the target, and exports the whole thing as a clean PDF report.
→ 600+ sites scanned
→ free AI profiling included
→ username OR email lookup
→ low false positive rate
→ PDF + CSV exports
→ runs from one CLI
100% Open Source.
Burp Suite Professional costs 475 dollars a year per seat.
A senior software engineer in Amsterdam built the open source replacement as a side project. He put it on GitHub for free. It has 10,569 stars.
His name is David Stotijn. The software is Hetty.
Here is what Hetty is.
An HTTP toolkit for security research. A machine-in-the-middle proxy that sits between your browser and the target. Every request and every response flows through Hetty. You can read them, search them, intercept them, edit them, replay them, and send them again.
This is the core loop of every web application security test ever performed. Burp Suite charges 475 dollars a year for it. Hetty does the same job for zero.
Here is the feature set.
A machine-in-the-middle HTTP proxy with full logs and advanced search. An HTTP client for manually creating and editing requests, and replaying any request you already proxied. Request and response interception for manual review, with full edit, send, receive, and cancel control. Scope support to keep your work organized to a single target. A web-based admin interface that runs in your browser. Project-based database storage so multiple engagements stay separate. A GraphQL service for programmatic access.
The installer is a single Go binary. Works on macOS, Linux, and Windows. No Java runtime, no enterprise license server, no machine fingerprinting, no telemetry.
Here is the price ladder.
Burp Suite Professional: 475 dollars a year per seat.
Burp Suite Enterprise: thousands per year, contact sales for a quote.
Burp Suite Community Edition: free, but throttled, no scanner, no project save, no intruder rate.
OWASP ZAP: free and open source, now owned by Checkmarx after a 2024 acquisition.
Hetty: zero. Forever. One binary. No account.
A pentester working full time pays Burp 475 dollars a year. A team of 10 pentesters pays 4,750 dollars a year. A bug bounty hunter who finds one vulnerability has already paid for Burp twice over.
Or they download a 30 MB Go binary written by a freelancer in Amsterdam and keep every dollar they earn.
David has not pushed a new commit in 16 months. The last commit was January 13, 2025. That is normal for a tool that is feature-complete. HTTP has not changed. The proxy still proxies. The intercept still intercepts. MIT licensed code does not expire when the maintainer takes a break.
Buy a domain. Find a bug. Cash a bounty.
PortSwigger took a free industry tool and put it behind a 475 dollar paywall. A freelancer in Amsterdam gave it back. On every platform. For zero dollars.
Your proxy. Your binary. Your bounties.
(Link in the comments)
The Book of Secret Knowledge: A Curated Goldmine for Cybersecurity, DevOps & Linux Professionals
🔥 One of the best free knowledge repositories for tech professionals.
Packed with tools, cheat sheets, blogs, tutorials, one-liners, security resources, and learning materials for Linux, networking, DevOps, and cybersecurity.
🔗 https://t.co/S1fjZzUqaB
#CyberSecurity #Linux #DevOps #Pentest #Networking #OpenSource
One of the largest free cybersecurity knowledge repositories on GitHub 💀🔥
The Art of Hacking (h4cker)
26K+ stars and thousands of curated resources covering:
• Ethical Hacking
• OSINT
• DFIR
• AI Security
• Cloud Security
• Exploit Development
• Reverse Engineering
• Certifications
• Home Labs & Cyber Ranges
Organized into domains, certifications, labs, and AI-focused learning paths.
🔗 https://t.co/Ir57bRkHC8
If you're building a cybersecurity roadmap, this repo can save hundreds of hours of searching.
#CyberSecurity #OSINT #DFIR #Pentesting #ThreatIntel #AIsecurity #Infosec