Okay, enough screaming.
Professional mode.
*Ahem*
Code Lyoko is back.
Current news:
They are currently working on a new season.
Full crew is back. Thomas Romain and Tania Palumbo included.
Writing has begun.
It's gonna be a while but...
Here we are going far, folks!
Made a thing: https://t.co/I1PJI78hD7
Trained an ML model to classify news articles against the Mitre ATT&CK framework… could be useful for threat intel!
The earliest DOS source code was found on printer paper in Tim Paterson's garage so we've open sourced it on 86-DOS 1.00’s 45th anniversary! This is next-level software archaeology for study, preservation, and plain ol’ curiosity. Go dig in and learn how it was recovered! #DOS #RetroComputing
https://t.co/l0ZRMSC5LS
If you understand LLMs at even the most basic level, this should be obvious to you. LLMs are not possible as a path to consciousness and anyone telling you it is has a compound to finance.
“Expecting an algorithmic description to instantiate the quality it maps is like expecting the mathematical formula of gravity to physically exert weight.”
There is a project on GitHub called Axios.
Axios is extremely popular. It is used by millions upon millions of applications.
Axios is a programming library that helps your JavaScript code make HTTP/S requests (communicate with websites).
In simple terms, if you're a programmer doing something with JavaScript, and want to do stuff that communicates with a website in literally any capacity, people heavily recommend using Axios due to its simplicity. Using Axios you don't have to reinvent the wheel and do a bunch of work. All you need to do is import Axios into your code and you're off to the races.
Someone (currently unknown) compromised Axios (currently unknown how) to deliver malware to people. When someone updates or installs Axios, Axios itself contains malware.
What the malware does is (currently) unknown, but it is being reversed engineered by probably every malware analyst on the planet at this moment. In a few hours more details will emerge. Information is being exchanged in real time on social media and private communication platforms as I write this.
Due to the size and popularity of Axios, it is unknown how many are impacted, it could be millions, it could be thousands, or if we're lucky, only hundreds of people or organizations will be impacted.
If this is absolute worst case scenario, millions of organizations across the planet have been infected with malware which (currently) we do not understand. However, the likelihood of this is low. It appears Axios being compromised was detected quickly, potentially within minutes (or hours) of it being compromised to deliver malware. Additionally, the likelihood of every single Axios user updating Axios as soon as it was compromised to deliver malware is astronomically low. It is basically zero.
The impact from Axios being compromised is devastating, the fallout from this will be a massive headache. This is unironically a malware nuclear missile and will likely be studied in the future.
🚨 do you understand what Karpathy just said..
the guy who co-founded OpenAI.. led AI at Tesla.. one of the best engineers alive..
built an app with AI.. and said the code was the easy part..
the hard part was Stripe.. auth.. DNS.. databases.. deploying it.. connecting 15 different services that all have different dashboards and different docs and different billing pages..
AI can write your entire app in 20 minutes.. but it still can't click "confirm email" on Vercel..
so the thing that's "replacing developers" can't do the thing developers actually spend 80% of their time doing..
vibe coding didn't kill software engineering.. it just proved that coding was never the job.. the job was dealing with the mess around the code.. and that mess is still 100% human.
I am genuinely impressed by mainstream media outlets ability to find absolute nobodies in cybersecurity. It's remarkable. I am often left speechless.
There has been dozens occasions, especially as of recent, where some media outlet will be like, "Today as a special guest is world-renowned cybersecurity expert and ethical hacker Joe McCyberSecurity".
I'm like, who the fuck is Joe McCybersecurity? I've been doing cybersecurity and malware stuff for a long time and I've never once seen or heard of Joe McCybersecurity. If he is world-renowned, I would THINK I would have seen them or heard of them.
The camera then pans over to Joe McCybersecurity and it is the most generic cookie cutter white dude in a cheap suit and the tag below him will say something like, "Joe McCybersecurity, Ethical Hacker, CEO of Cybersecurity McJoe Industries"
I'm like, "Cybersecurity McJoe Industries? What the fuck is that?". I look it up and it's a generic WordPress website hosted on GoDaddy with an expired SSL cert.
Joe McCybersecurity then babbles incomprehensible nonsense for about 60 seconds until the TV host goes "woaw" and it cuts to a commercial.
Absolute cinema.