In this writeup! , I shared how I was able to ex filtrate data from airgaped computer which does not have internet , bluetooth , Wifi etc via camera status light and screenbrightness variation
https://t.co/KRmQJel8u6
Excited to share my first arXiv paper:
CosmicFish-HRM: Adaptive Reasoning via Hierarchical Recurrent Mechanisms in Compact Language Models (arXiv:2605.28919)
The work explores adaptive reasoning depth in compact language models through a Hierarchical Reasoning Module (HRM) that dynamically allocates compute during inference.
Paper: https://t.co/VPK6UDdYpO
likes and Retweets are greatly appreciated!
I had hacked CBSE's OSM (On-Screen Marking Portal) in February and had reported the vulnerabilities to CERT-In, but they were unable to patch most of them.
I've written a detailed blog post about it here: https://t.co/qyT23GkTEJ
you SHOULD NOT drop out to start a company.
i get this question every day where some random student who has never built shit in his life asks if he should drop his classes and chase the sf dream.
this might sound counterintuitive coming from me, but there is a simple reason why you can or can’t.
you need to have a clear reason why and what you are going to do in the next 3 to 6 months. for me, it was getting into the best program in europe (as i thought at the time) called ef and raising $1m from arguably the best eu fund plus a couple other angels.
i didn’t drop out because i wanted to start a company. i did it because i literally had to, to continue further. otherwise i would have just stayed in my AP classes, which i would have failed anyway.
do not be blinded by some twitter chuds telling you to drop out on day one.
just build shit and do it if it becomes inevitable.
Here's how to triage:
1. Go to https://t.co/bfAEiJ6emr
2. Security → Access and data control → API controls → App access control → Manage Third-Party App Access
3. Search for client ID:
110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj
if found → revoke / block
we hired a 20-year-old engineer with no experience. it sounds insane. but it was one of the best decisions we made.
we get inbound from staff engineers at uber. principal scientists from meta. ten, twenty years of experience.
then this kid dm'd me on twitter. said he loved wispr flow and wanted to work with us.
it was 10am on a saturday. i was in the office. i replied: "come by in two hours."
he showed up. we talked for 45 minutes. smart kid, no fancy resume. i told him about a project that would normally take a day and a half. asked if he wanted to start monday.
he said "i'll start now."
by sunday morning he texted me: "tanay, i just pulled an all-nighter. it's done."
thousands of lines of code. fully functioning feature.
now he's one of our highest-performing engineers. the whole team respects him.
a lot of founders optimize for credentials. where someone went to school, where they worked before. it's an easy filter.
but the best hires aren't the ones with the perfect resume. they're the ones who do more than what's asked.
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
��� Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.