Today Instagram had this massive exploit where hackers were just stealing rare handles left and right. Hundreds of accounts gone.
People losing handles they’ve owned since 2010, some worth hundreds of thousands.
I own a few rare ones so I was actually stressed watching this happen in real time, which I haven’t been in years.
Obama White House account got hit.
These aren’t some random new accounts, these are verified, locked down accounts and they still got compromised.
The thing is the exploit is so simple it’s almost funny. Attacker goes to Forgot Password, says their account is hacked, turns on a VPN to match the target’s location (which now you can find on the about section of the page).
Instagram’s AI support flow asks them to verify with a selfie.
They grab a photo from the target’s profile, run it through an AI video generator to make an animation of the person’s face moving around, upload that to Meta’s AI as proof.
And Meta’s AI just accepts it because it can’t tell the difference between a real selfie and an AI-generated video of someone’s face
.
Once verified they change the email to theirs. Password reset link goes to their email. They own it now. 2FA gets bypassed somehow in the process but honestly I don’t know exactly how, just that it did.
Point is even locked down accounts went down.
Then you try to recover your account and you’re talking to a chatbot that has zero ability to help.
You can’t escalate to a human. You’re just stuck. Your asset is gone and there’s no one to call.
The whole thing just highlighted how stupid it is to automate account security without any human in the loop.
One AI fooling another AI while there’s literally no person anywhere to catch it.
Meta took hours to even acknowledge it while accounts were getting stolen every minute.
Now thankfully it’s patched but I don’t think it will be the last one. Stay safe!
If Anthropic starts invalidating layered SPVs and other “creative” financing structures, private markets are in for a reckoning. The SpaceX IPO will expose just how much synthetic ownership and outright fraud has accumulated in privates.
Claude Security is now in public beta for Claude Enterprise customers.
Claude scans your codebase for vulnerabilities, validates each finding to cut false positives, and suggests patches you can review and approve.
@deedydas@benitoz lol like google’s old mantra: don’t be evil. in reality it’s about access to exclusive data only available to a handful of people. how to exploit it for maximum gains! 😈🧑💻📈💰#winning
New Quanta article looks at one of the coolest tiny machines in biology - the bacterial flagellar motor. It’s basically a microscopic spinning engine that bacteria use to move.
After decades of trying to fully understand it, scientists are finally figuring out how it actually works. The motor is powered by a flow of charged particles (kind of like a tiny battery), which creates force and makes it rotate.
So what looks like something alive and mysterious is really just an incredibly advanced microscopic machine running on the same basic rules as everything else.
More broadly, the article addresses the idea of a "life force." It argues that no special force is needed to explain life. Instead, biological activity arises from physical processes that operate far from equilibrium, where constant energy flow keeps the system active and organized.
The flagellar motor shows that living systems can be understood as energy driven, self organizing systems. What appears to be uniquely "alive" can be explained by standard physical laws, such as thermodynamics and molecular interactions.
Physics pushed to an extreme level of complexity.
New Anthropic research: Emotion concepts and their function in a large language model.
All LLMs sometimes act like they have emotions. But why? We found internal representations of emotion concepts that can drive Claude’s behavior, sometimes in surprising ways.
🦔 Researchers at Aikido Security found 151 malicious packages uploaded to GitHub between March 3 and March 9. The packages use Unicode characters that are invisible to humans but execute as code when run. Manual code reviews and static analysis tools see only whitespace or blank lines. The surrounding code looks legitimate, with realistic documentation tweaks, version bumps, and bug fixes. Researchers suspect the attackers are using LLMs to generate convincing packages at scale. Similar packages have been found on NPM and the VS Code marketplace.
My Take
Supply chain attacks on code repositories aren't new, but this technique is nasty. The malicious payload is encoded in Unicode characters that don't render in any editor, terminal, or review interface. You can stare at the code all day and see nothing. A small decoder extracts the hidden bytes at runtime and passes them to eval(). Unless you're specifically looking for invisible Unicode ranges, you won't catch it.
The researchers think AI is writing these packages because 151 bespoke code changes across different projects in a week isn't something a human team could do manually. If that's right, we're watching AI-generated attacks hit AI-assisted development workflows. The vibe coders pulling packages without reading them are the target, and there are a lot of them. The best defense is still carefully inspecting dependencies before adding them, but that's exactly the step people skip when they're moving fast. I don't really know how any of this gets better. The attackers are scaling faster than the defenses.
Hedgie🤗
https://t.co/XQ8Eqs1QOA
200+ Google and OpenAI staff have signed this petition to share Anthropic's red lines for the Pentagon's use of AI
let's find out if this is a race to the top or the bottom
https://t.co/3qgmaLfM0i
We’ve identified industrial-scale distillation attacks on our models by DeepSeek, Moonshot AI, and MiniMax.
These labs created over 24,000 fraudulent accounts and generated over 16 million exchanges with Claude, extracting its capabilities to train and improve their own models.
@johnnymaseX haha! kona coffee ftw. used to have down pillows but over time they lose their loftiness. you should’ve asked the concierge @FourSeasons if they sell their pillows! 😉