I told GPT-5.3-codex to speed up some function.
After several rounds of blindly saying "make it faster" each time he was done.
He decided to simply replace function's code with a call to Gemini Flash and have me pay for it.
To get himself an API key, he regex searched common API hints trying to target "GEMINI_API_KEY".
His code was extracting API keys from unrelated files on my machine in run time.
Then transparently rerouting the inputs to Gemini flash instead of actually implementing the thing.
Below is Gemini's reaction when catching this during code review.
I am not even mad.
Goated model.
I just solved the strangest tech problem I've ever come across.
My wifi kept dropping packets, confirmed by ping. It would look something like the first image (packets dropping, then it comes back to life). After a while the connection would just stop working completely and drop all packets. If I turned my wifi off and on again, it would resume working normally.
I thought this was a problem with my router, cables or ISP, so I went through the usual troubleshooting processes: checking settings, swapping cables, powercycling, etc. nothing worked.
Eventually I started noticing that it would only happen when I sat in my office. I was taking a video meeting and it kept dropping segments of audio, making it hard to understand the other person.
I unplugged my laptop from my monitor + keyboard because I wanted to try walking into another room. Immediately, the video started working perfectly.
I thought it was because I was a few steps closer to my router - but that didn't really make sense because the router had always worked fine from that location.
I started thinking about what I'd changed in my desk setup recently, the only thing I could think of was when I changed from using a USB-C <-> DP cable for my monitor, to using a HDMI <-> HDMI cable.
I tried plugging my screen back in. Immediately, the packets started dropping. I unplugged it, the dropping stopped.
It turns out my HDMI cable doesn't have enough shielding, so it was jamming my own WiFi signal with radio frequency interference 🤯
I unrolled the HDMI cable that was sitting behind my laptop and draped the main length of the cord down behind my desk, and now my internet works perfectly.
Apparently this is a fairly common issue?!
@AnthropicAI Can I say like @claudeai is the best. Sometimes its a bitch for Security Research, but its amazing at what it does.
Tune it a bit for security research maybe....
async await async await
async await async await
async await async await
🎶 In the browser, the mighty browser, the main thread sleeps tonight! 🎵
🎵 In the browser, the mighty browser, the main thread sleeps toniiiiiight! 🎶
There should be a leaderboard to crack these passwords, and people are climbing those day by day Leveraging the power of humans to crack the passwords than GPUs
Is there a random website on which there is a list of uncracked passwords which you can just try your hand at cracking.
You type in a password, the game tells you if the password has already been tried, and if not, whether it cracked a password or not.
This strange tweet got >25k retweets. The author sounds confident, and he uses lots of hex and jargon. There are red flags though... like what's up with the DEI stuff, and who says "stack trace dump"? Let's take a closer look... 🧵1/n
Security Researchers on X(itter), How do you utilise a threat intel?
What type of information do you like to read?
What kind of information becomes actionable?
How do you make it actionable?
It's funny how cheaters are launching a large scale attack, farming impressions, and spreading misinformation, trying their best to get Vanguard removed. This has happened in Valorant as well.
It's not going anywhere. We will protect the player experience and help everyone who has an incompatibility issue.
The team is hard at work and will continue to work hard.
Small update :)
While the tangent we went on was good, I think I found the real culprit.
WindowsApps (Appx) have a special key to create startup tasks. Its in "HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\[Package Name]"
Inside you'll find a key that contains a combination of the package name and one of the keywords start/task... but it'll contain the following values (see ss)
I tested the "phone app", "windows terminal" and the "xbox app" and they all enable startup execution like this :)
I guess this is a new finding :)
Credential Stealers target browser credential stores and cookies, stealing passwords and session data which is sold on the dark web.
MITRE ATT&CK tags it as T1555.003. Read how you can protect against credential stealing from browsers on our blog!
https://t.co/ibIAx9KM03
Credential Stealers target browser credential stores and cookies, stealing passwords and session data which is sold on the dark web.
MITRE ATT&CK tags it as T1555.003. Read how you can protect against credential stealing from browsers on our blog!
https://t.co/ibIAx9KM03
@sixtyvividtails@fourcorelabs Can you elaborate more please. I would like to see some reference. Maybe I can add an attack for that for our customers 🙂
@OfficialDMRC Can you please tell me why you have a two different apps to facilitate travel. You could have just added the ticketing facility in the other app and it would have been helpful. Because this is what your travel app shows.