VulnLLM-R-7B the first specialized reasoning model built only for vulnerability detection run locally on
4-GB RAM
A 7B model just outperformed much larger systems at finding real software vulnerabilities.
Instead of pattern matching, it analyzes data flow, control flow, and security context step-by-step just like an experienced security researcher.
It has already shown strong results against tools like CodeQL and even some commercial models, while staying small and efficient enough to run practically.
Early results look solid, and the team even built an agent around it that found zero-days.
🛑 One visit to a malicious webpage could have been enough to expose your #WhatsApp Web chats.
CVE-2026-48294 in Adobe Acrobat’s Chrome extension could read messages, contact names, chat previews, and profile data without malware, stolen credentials, or session cookies.
The extension has over 314 million users.
See how HermeticReader worked: https://t.co/iNIDeTr0mo
The Hacker Recipes is the AD attack bible that OSCP prep guides forget to mention.
Kerberos delegation abuses.
NTLM relay chains.
DCSync paths.
Constrained vs unconstrained delegation.
https://t.co/sOQy6OwG7S
HER İNTERNET KULLANICISININ BU HAFTA SONU KONTROL ETMESİ GEREKEN 10 WEB SİTESİ.
Bu listeyi kaydedin. Çoğu insan bunu asla görmeyecek.
1. https://t.co/vjB7rb3uXd
E-postanızın sızdırıldığı her veri ihlalini gösterir.
2. https://t.co/wjrpzXSkfS
Herhangi bir e-posta adresine bağlı her sosyal profil ve oturum açma bilgisini ortaya çıkarır.
3. https://t.co/mEPzGHKbyW
Tarayıcı parmak izinizin ne kadar izlenebilir olduğunu gösterir.
4. https://t.co/pUajEUXMyp
VPN'inizin gerçekten çalışıp çalışmadığını veya gerçek IP adresinizi sessizce ifşa edip etmediğini kontrol eder.
5. https://t.co/oDJxMa9X7l
Hesabınızı herhangi bir büyük hizmetten silmek için doğrudan bağlantılar.
6. https://t.co/YooqV5aJWe
Herhangi bir dosyayı veya bağlantıyı saniyeler içinde 70'ten fazla antivirüs motoruna karşı tarar.
7. https://t.co/wOW6ZAiGSD
Yüzünüzün izniniz olmadan yapay zeka modellerini eğitmek için kullanılıp kullanılmadığını gösterir.
8. https://t.co/8z5EqZ2VRl
Tarayıcınızın web sitelerine sızdırdığı her veri parçasını ortaya çıkarır.
9. https://t.co/ZuCgAZMoNg
Bilgisayarınızdaki hangi uygulamaların gereksiz yazılım veya casus yazılım olduğunu söyler.
10. https://t.co/qeJlNCT6yW
Haber sitelerindeki ödeme duvarlarını kaldırarak okumayı ücretsiz hale getirir.
Sonra bana teşekkür edersiniz.
Goodbye Claude Code subscription fees.
Someone just built a proxy that runs Claude Code completely free... and it's wild.
You literally plug in a free NVIDIA API key and point Claude Code at localhost.
That's it.
It handles everything:
- Converts Anthropic API calls to NVIDIA NIM format
- Unlocks 40 requests/min for free
- Supports Kimi K2, GLM 4.7, MiniMax M2, Devstral and more
- Streams thinking tokens and tool calls live
- Even includes a Telegram bot so you can run Claude Code from your phone
No API bill. No rate limit panic. No vendor lock-in.
Honestly, this goes beyond router tools like OpenRouter.
It doesn't just swap the model... it turns Claude Code into a free agent you can control remotely.
The project is open-source on GitHub.
It's called free-claude-code.
L’équipe d’Anthropic vient de montrer comment utiliser correctement Claude Code.
30 minutes. gratuit. présenté par la personne qui a créé Claude Code.
Regarde le workshop. Ajoute en signet 🔖
Ça vaut plus que tous les cours à 500$ que t’as failli acheter.
🧰🕵️OSINT Tool Explorer l'annuaire que tu cherchais
Le monde de l’OSINT est immense… et souvent bordélique
Des centaines d’outils, des bookmarks partout, et la moitié qu’on oublie
C’est pour ça que j’adore OSINT Tool Explorer : un vrai navigateur interactif ultra-clair de tout l’écosystème OSINT
Catalogue complet, catégories nettes, filtres gratuit/payant/freemium et une interface propre.
Zéro compte, zéro installation.
Excellent pour découvrir, redécouvrir ou retrouver des outils 🔥
Tout est organisé au même endroit, et c’est mis à jour régulièrement.
🚨 BREAKING: Someone just dropped the most advanced Steganography Platform EVER!! 😱🥚
https://t.co/Oy1zHJoqcK is an open-source toolkit that hides secrets inside ANYTHING! images, audio, text, PDFs, network packets, ZIP archives, and even emojis 😘️︎︎️️️️︎︎︎️︎︎️️︎︎︎️︎︎️️️️︎️︎️︎️️︎︎️︎︎︎️︎️︎︎️︎︎︎︎︎︎️︎️︎︎︎︎︎️︎︎️️︎︎︎️︎︎️︎︎️︎️︎︎️️️︎︎️︎️️︎︎️︎︎️️️️️︎
AND it has an AI agent built in 👀
🔍 REVEAL: drop any file and the AI agent tests every known decoding method automatically. 120 LSB combinations, DCT, PVD, chroma, palette, PNG chunks, trailing data, metadata, Unicode, and more. 50 tools running in parallel.
auto-extracts hidden payloads as downloadable artifacts. no config needed.
🔮 CONCEAL: type your secret, pick a method (or let the AI choose), upload a carrier image OR generate one with AI.
one click ��� encoded steg file. the agent recommends the optimal method based on your use case.
the methods:
⊰ LSB — 15 channel presets × 8 bit depths = 120 combinations. steghide has 1. st3gg has 120.
⊰ F5 — operates on JPEG DCT coefficients. SURVIVES social media compression. regular LSB is destroyed by ANY JPEG compression, even quality 99%.
⊰ PVD — encodes in pixel pair differences. statistically harder to detect than LSB.
⊰ CHROMA — hides data in color channels (Cb/Cr). human eyes are less sensitive to color than brightness.
⊰ SPECTER (unique) — data hops between RGB channels in a pattern that IS the key. like frequency hopping in radio.
⊰ MATRYOSHKA (unique) — images inside images inside images. 11 layers deep. each layer is a valid image.
⊰ GHOST MODE (unique) — AES-256-GCM (600k PBKDF2 iterations) + bit scrambling + 50% noise decoys.
13 text steganography methods (no other tool has any):
▸ ZERO-WIDTH — invisible characters between visible letters
▸ INVISIBLE INK — Unicode Tag Characters (U+E0000). renders invisible everywhere
▸ HOMOGLYPHS — 'a' → 'а' (Cyrillic). visually identical. different bytes
▸ VARIATION SELECTORS — invisible modifiers after characters
▸ COMBINING MARKS — invisible joiners after letters
▸ CONFUSABLE WHITESPACE — en-space = 01, em-space = 10, thin-space = 11. 2 bits per space. text looks normal. the spaces are "wrong"
▸ DIRECTIONAL OVERRIDES — invisible RLO/LRO bidi characters
▸ HANGUL FILLER — Korean invisible character replaces spaces
▸ MATH BOLD — 'a' becomes '𝐚'. looks like bold text. each bold letter = 1 bit
▸ BRAILLE — each byte maps to a Braille pattern character
▸ EMOJI SUBSTITUTION — 🔵 = 0, 🔴 = 1
▸ EMOJI SKIN TONE — 👍🏻👍🏼👍🏾👍🏿 four skin tone modifiers = 2 bits each. a row of thumbs-up with different skin tones looks like a diversity post. it's binary data. four emoji = one byte.
detection:
50 tools including RS Analysis (academic gold standard), Sample Pairs, chi-square, bit-plane entropy, PCAP protocol analysis, and the AI agent orchestrates all of them automatically.
for AI agents:
from steg_core import encode, decode
from analysis_tools import detect_unicode_steg, TOOL_REGISTRY
50 tools as importable functions. test prompt injection via images. detect covert agent channels. watermark outputs.
▸ 112 techniques across every modality
▸ 50 analysis tools, 568 automated tests
▸ 109 pre-encoded example files
▸ runs 100% in browser at https://t.co/s3GgExiI6e — zero server
▸ pip install stegg — live on PyPI right now
the README has 7 hidden secrets. the banner has 3 layers. the website has multiple easter eggs.
good luck!
⊰•-•✧•-•-⦑ ⦒-•-•✧•-•⊱
🔗 https://t.co/tr4nyru6UD
📦 pip install stegg
🐙 https://t.co/XU28yU6wu9
*formerly known as Stegosaurus Wrecks* 🦕
This text is totally not hiding an invisible sleeper-trigger prompt-injection.
🚨BREAKING: You can now run Claude Code for FREE.
No API costs. No rate limits. 100% local on your machine.
Here's how to run Claude Code locally (100% free & fully private):
🛡️🌐 KYCNOT .ME
Avant, tu perdais des heures à chercher des alternatives fiables aux plateformes qui exigent KYC passeport, selfie et justificatifs de revenus. Voici un outil qui fait gagner du temps !...
🛠️ @kycnot c'est un annuaire ultra-complet, open-source et 100% communautaire. Plus de 280 services privacy-first (dont ~80 approuvés & vérifiés en ce moment) pour échanger, acheter, payer, héberger, VPN, e-SIM, cartes cadeaux, outils IA… sans KYC
L’interface est ultra-puissante et intuitive :
👁️ Niveau KYC clair :
- Niveau 0 Garantie sans KYC (masque Guy Fawkes)
- Jusqu’au niveau 4 KYC obligatoire (empreinte digitale !)
👁️ Scores de confidentialité + confiance (0-10)
👁️ Filtres monstrueux : Réseaux (Clearnet, Onion, I2P), devises (Monero, Bitcoin, Lightning, espèces…)
- Catégories (Échanges 148, Agrégateurs 51, Hébergement 43, VPN 26, Shopping, e-SIM, etc.)
- Tri par score élevé a faible, et attributs détaillés (inscription sans identité, non-conservation des données, marché P2P, remboursements anonymes…)
👁️ Vérification communautaire : Vérifié, Approuvé, Communauté, ou Arnaque
Tout est open-source (repo sur Codeberg : pluja/kycnotme), mis à jour en live, avec une version .onion pour Tor, zéro tracking, zéro pub intrusive !
Tu peux contribuer toi-même en ajoutant ou en vérifiant des services.
👉 Avantages :
- Gratuit & sans inscription
- Filtres ultra-précis et notes détaillées
- Focus réel sur la privacy (exemples phares : Bisq, RoboSats, Mullvad VPN, CypherGoat, XmrBazaar, SporeStack…)
- Résistant à la censure et à la surveillance
- Communauté active qui vérifie régulièrement (mises à jour constantes en 2026)
👉 Inconvénients :
- Certains listings restent jeunes ou en vérification communautaire
⚠️ Comme toujours : fais ton propre DYOR et vérifie les conditions actuelles du service avant d’utiliser
Le projet est vivant, maintenu activement et grandit rapidement
Pour tous ceux qui en ont marre du KYC obligatoire !
#NoKYC #OpenSource