we're starting rollout of GPT-5.5-Cyber, a frontier cybersecurity model, to critical cyber defenders in the next few days.
we will work with the entire ecosystem and the government to figure out trusted access for cyber; we want to rapidly help secure companies/infrastructure.
@ctbbpodcast@rez0__ Have you had Claude Code mark your bug bounty prompts as violations and then make you use sonnet? Then if they don’t have context it looks like you’re hacking and then ban your account.
@burakeregar Good framework. Biggest one, in my opinion, is logging. You should be notified when someone is dumping your Supabase database. Are there good logging systems with Supabase? Every time I’ve reported Supabase issues the devs had no idea.
@h4x0r_dz Supabase is awesome but I’ve found sites with service_role keys exposed, RLS disabled, PATCH/PUT requests to make myself admin, exposed RPC functions on the execute_queries end point. Lots of fun stuff. I wish there a was a tool to do a full check but I have a pretty good system.
We disrupted a highly sophisticated AI-led espionage campaign.
The attack targeted large tech companies, financial institutions, chemical manufacturing companies, and government agencies. We assess with high confidence that the threat actor was a Chinese state-sponsored group.