300 million Investment portfolio. How investing 100k per month with dedicated discipline can help you build your investment poortfolio in 100s of million.
With illustrative numbers.
https://t.co/kgMAv6oogq
๐จ Oracleโs 943-patch update includes critical WebLogic flaws that can let attackers take over servers
Source: https://t.co/O0BUGwJgF7
#cybersecuritynews#vulnerability
Good evening.
Today afternoon, someone hacked into my @gmail and took control of my @YouTube Channel and deleted my videos.
Weโre doing our best to secure it.
Admin.
Mandiant reports that their Agentic Vulnerability Discovery Harness rapidly analyzes code, finds vulnerabilities at scale, and blends AI with human expertise to accelerate detection and validation in proactive defense. https://t.co/FhfDgxi0n3
this is f**king dangerous
A guy built a system of 7 Claude agents on his MacBook.
No assistant. No sales team. No office.
Every day it scans Google Maps across 3 cities, finds small businesses with no website or one from 2014, builds a landing page mockup, renders a 10-second video of it, and sends a personalized cold message โ before he wakes up.
47 clients a month. $400 each.
$18,800/month. $480 in API costs.
Traditional web agencies run 8-person teams for the same order flow.
He runs it alone from a MacBook and an iPhone.
When a positive reply comes in while he's in a taxi, his Mobile agent books the Zoom call. He taps "approve" and joins 10 minutes later.
The only time the system wakes him is when a deal breaks $3,000 or the reply rate drops below 12%.
Everything else runs without him.
Here's the complete playbook for building such $10K/month passive income machine with AI โ
If I were running a small brand today, I'd care less about making one impressive AI ad.
I'd want one workflow that can turn a product into an entire library of usable content.
Seedance 2.5 is already available on CapCut, and Seedance 2.5 1080p is now live.
Here's how I'd build it.
#CapCutPC #AIVideoEditor
Sandra Joyce's @jumpforjoyce team at @Google Threat Intelligence Group spent the last year making disruption look controlled, legal, and boringly effective.
A national security presidential memorandum signed Wednesday authorizes vetted private US companies to run cyber surveillance and cyber effects operations against foreign criminal organizations: breaking in quietly and breaking things, in the memo's own definitions, under federal direction, with a bond of at least $1 million posted against noncompliance and every operation approved in writing by co-directors at DOJ and DHS.
But the interesting question is this: why did Washington suddenly believe this could work?
Joyce proved disruption works while staying scrupulously inside the legal line. IPIDEA in January. GRIDTIDE in February. Measurable degradation across hundreds of threat groups, zero unauthorized access, and a bright line she kept repeating: "this is not hacking back."
Joyceโs work accomplished two things at once: It produced results no sanctions package has ever produced. And it made private-sector operations look like something a government could supervise instead of something it should fear.
Be precise about what happened, though, because this memo is uncharted waters, and licenses a lane Google deliberately refused to enter. The memo authorizes something companies could not do before as published federal policy: they may now operate on systems it does not own: covert access to collect intelligence, then operations to manipulate, disrupt, deny, degrade, or destroy those systems if DOJ and DHS approve the work in writing, and at the pace of written interagency approval.
Which is my first worry. The permissionless lane, where GTIG shut down attacker cloud projects, domains, and API access on its own systems, and used court orders when the infrastructure sat elsewhere, is the one that produced the results.
The second worry is older. The program assumes a target is criminal rather than state-run unless clear intelligence says otherwise, and in the Russian ecosystem that distinction is one phone call. Attribution is the load-bearing wall. Almost right is the expensive kind.
Joyce said disruption has to become the status quo in our industry. As of Wednesday it's federal policy with an escrow account. The marque question is settled. Whether the oversight holds is not. Tell me where you land.
โ The memorandum: https://t.co/sysPc6dTuU
โ โDisrupting threat actors must become the status quo in our industry.โ What will actually degrade an adversary?
https://t.co/KPnC85rJN6
Treasury Bond Auction analysis. Navigating Easing Interest rates amidst the New upcoming September Bonds.
10 Year Bond coming in at 8.5% Premium. 3 Year Bond coming in at 7% Premium. Lessons and plans ahead. Plus a Message to BoU https://t.co/TmEGrdyvuA
๐จ BLACKROCK IS QUIETLY TURNING STREET LIGHTS INTO SURVEILLANCE CAMERAS
While everyone was focused on tearing down Flock cameras, a much bigger player was already rolling out the replacement.
Axon, one of the hottest companies in the surveillance market, is now partnering to turn regular street lights into smart cameras.
No new poles needed.
They just convert the lights you already drive under every day into:
โข License plate readers
โข Live streaming cameras
โข AI that recognizes vehicle make, model, color, damage, bumper stickers, and more
Counties are canceling Flock contracts and spending tens of millions on Axon systems instead.
Hereโs the part most people donโt know:
About 25% of Axon is owned by BlackRock, Vanguard, and State Street. The same firms that have openly talked about โforcing behaviors.โ
Axonโs CEO has said their goal is to build a society where crime โjust doesnโt make sense anymoreโ through constant monitoring.
He also made $164 million in a single year.
While people were busy removing Flock cameras, this more advanced, harder-to-detect system was already being installed in plain sight.
Street lights โ cameras.
BlackRock ownership.
AI vehicle tracking.
Stealth rollout.
Is this just โpublic safetyโโฆ or the next phase of the surveillance grid?
Rwanda, what an experience.
It was an honour to deliver a keynote at the All-Africa Leadership Summit in Kigali and connect with some brilliant business minds.
A gathering filled with bold ideas, meaningful conversations and people actively building across the continent.
The future is in Africa.
Africa is not next.
Africa is NOW!
VT
JPMorgan CEO Jamie Dimon on the day he was fired from Citigroup after 15 years: "my boss called me in and said we want you to resign - to which I said, OK. I went home. the youngest one said, Dad, do we have to sleep on the streets?"
this is him explaining how he rebuilt a bank from a $511 million loss into the largest in America, what he does every Sunday with the problems he is avoiding, and what he told the man who fired him a year later
"it was my net worth, not my self-worth"
"I called him a year later. I told him I didn't think he did the right thing for Citigroup. then I told him the mistakes I made. he acknowledged my mistakes"
"if you split a taxi receipt, that's stealing. if I caught you doing that, I'd fire you"
"would you have your child work for that person? half the time we promote people, we would not let our kid work for them"
bookmark & watch the full conversation โ
B2B sales is being rewired. As agentic AI takes on more execution, the role of sellers becomes more strategic.
The biggest opportunity is redesigning commercial workflows so sellers can focus on creating value for customers. https://t.co/wqbiI6eEyD
The next competitive advantage in cybersecurity won't come from buying more tools. It'll come from building teams that know how to use them.
See what the latest research reveals in the Wired Together Report: โคต๏ธ
https://t.co/nKalsdbtWV
When #phishing campaigns are backed by resilient infrastructure, detection becomes significantly harder.
#GitBait combined trusted infrastructure with institution-specific phishing portals to sustain a long-running campaign against Mexico's #financialsector.
๐ง๐ผ๐ฝ ๐ฑ ๐ฃ๐น๐ฎ๐ฐ๐ฒ๐ ๐๐ฒ๐๐ฒ๐น๐ผ๐ฝ๐ฒ๐ฟ๐ ๐๐ฐ๐ฐ๐ถ๐ฑ๐ฒ๐ป๐๐ฎ๐น๐น๐ ๐๐ฒ๐ฎ๐ธ ๐๐ฃ๐ ๐๐ฒ๐๐
API keys are meant to authenticate applications not to be publicly accessible. Yet exposed API keys remain one of the most common security issues, often leading to unauthorized access, unexpected cloud costs, data exposure, or even full account compromise.
Here are five places where API keys are commonly leaked: