1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
Have been using Opus 4.7 since launch and I can say for sure I prefer 4.6. 4.7 just feel dump. I need to do more followups and it assumes things waaaaay often, wrongly..
Multiple customers asked for this already and I'm so happy to launch it!
+ full redesign of the phone app to make it even simpler and easier.
https://t.co/aW2fD6Zzjx
Team & business features just dropped on Zenophone! Create a team, invite members, share one balance. Admins get full call analytics. Conference calling? Yep.
Same super cheap rates to 180+ countries โ now for your whole team. https://t.co/CVWVFyudMH
This week I had to block a @getzenophone user because he abused the system to make calls using IRSF.
Whatโs IRSF? Itโs International Revenue Sharing Fraud, a well-known fraud in telecom where someone exploits a phone app to call international premium numbers and share revenue with a carrier.
They managed to get around $20 from zenophone.
On https://t.co/T5yibCrjFT, thereโs a Caller ID feature that lets you show your own number when making a call. To activate it, the app calls your number and you enter a code.
The issue: the app could call any number for that verification step.
The fraudster leverage this feature to make outbound calls to these premium rate numbers for free.
Fortunately I had a top-up limit with my telco provider, which triggered a notification. Otherwise this couldโve cost much more.
The fix was simple:
- Caller ID now costs 1$: cheap for regular users, but expensive enough to discourage abuse
- Blocking high-risk / premium numbers
- More aggressive rate limits
I knew about IRSF when building @getzenophone but missed this specific abuse vector. Glad the impact stayed small.
Iโll try to share more learnings building zenophone.
Anthropic should pause all features dev at this point and focus on reliability for the next 2 week, similar to what Cursor did end of last year. I donโt care about a review feature if the core product had been so bad this week.
The importance of reaching out to every customer.
A customer replied to my check-in email about @getzenophone. They shared a bug in the auto-topup feature that charged them twice. They also said the email didn't work๐คฆโโ๏ธ So double failure from my part! I've apologized ofc, reimbursed them and fixed the bug.
Ghostty 1.3 is now out! Scrollback search, native scrollbars, click-to-move cursor, rich clipboard copy, AppleScript, split drag/drop, Unicode 17 and international text improvements, massive performance improvements, and hundreds more changes. https://t.co/IMk3i6528t
We're seeing a spike in calls to Middle East countries due to the current sitation.
If you're trying to reach family or your loved ones, Zenophone makes it affordable and easy.
Call now from anywhere https://t.co/9mb20G9UaM