Looking for a video on a specific hacking technique/tool? Check out https://t.co/yqxaZuwoyu - Searches over 100 hours of my videos to find you the exact spot in the video you are looking for.
@lawndoc@apiratemoo It is a 10.0 CVE on software that does not have any real risks associated with patching and doesn't require a reboot. If an organization is thinking about priority in this case, I would hate to run an audit on their environment... Especially after the recent flood of CVEs
@UK_Daniel_Card@AICyberHome I think it is rare for the TA to turn around and sell the breach advertised as the company breach. They likely sell it as a "combined list" with the victims name removed. Which in terms of PR is an infinitely better outcome for the victim than a public dump/outage/etc.
I've only read between the lines, but I think the crux of the issue is the reduction in pay is due to changing departments because the role no longer exists. I don't think FMLA really provides any protection in that case as it is not retaliatory, it's likely just an unfortunate coincidence.
Why do I think that? Because the person in question was visible under a title that is not "Penetration Testing". When you have your picture on a public website for your company, I think it is expected that position have a large salary tied to it.
I imagine that position got removed, they moved to a penetration tester (doing the right thing to not fire them). During some audit, they realize they didn't adjust the pay during the move and when correcting it something happened which caused this all to blow out of proportion.
Talking about it over social media made it worse. It's reasonable to be let go at that point. Is it retaliatory? Idk. Given the context of the original messages, I'd say it is but not illegal.
I'm really grasping at straws for the next part but I'm guessing to try and plug the PR Disaster. The original employment contract/agreements were brought up and one of the parties thought that included a non-compete. I only say that because the founder says they removed it, never enforced it, and there is plenty of other people leaving the company and working for (or becoming) competitors.
There has been a lot of talk about BHIS and our maternity and employment policies.
Please check out the following site for more details.
https://t.co/guIv8SkZV5
Thanks!
@MJHallenbeck Metasploit does support python/go/etc already -- The value of Metasploit isn't really the core, it is the community that keeps exploits up to date (and does Q/A). Just forking it to python wouldn't magically bring the community over to the python edition
@0xTib3rius Haha I just don’t think I’m sane enough to have that type of opinion. Tenure is no longer rewarded. I’ve had friends in similar positions and my comment to them was always lay low, do the bare minimum while you job hunt as it takes time to fire for laziness.
The HackTheBox Sorcery Video is up! An extremely long video, but for good reason, there were a lot of tough parts of this box. My favorite part was near the beginning, when we had an XSS Bug and had to use CSRF to MITM PassKey Enrollment https://t.co/Qpc6HBgnCB
I can't seem to find any examples on your timeline atleast within the last week. Again I don't doubt it, but I'm pretty tired of just seeing negative takes on things that have reasonable explanations.
I just empathize a lot with the employee's trying to manage and correct things when there is an overflow of random crap that gets started by a couple of YT/Twitch people that ought to know better but fell victim to the instant gratification hate/clickbait can bring.
Then when they do finally find/fix the problem and try to be transparent just get more crap flung at them. All that does is discourage them from being open in the future.
@MJHallenbeck@HackingDave Have anthropic employee's gaslit people? Or is that just the algorithm amplifying hate? I could be wrong, but I don't think I ever saw someone like Boris say there isn't a problem. Just try to debug via X which is a noble but impossible effort, so they direct people to /feedback
Yeah, but "exact public build" could mean a lot of things. Modification could be as simple as pointing to nightly models or something. Which is backed up by the following paragraph of them targeting specific models.
I'm not saying there wasn't an issue, definitely was. I just hate all the quick negative takes when people are trying to do good.
I think that could be a gross oversimplification. It is equally as likely they weren't impacted as much because they "use it properly", which partially masked the problem. I'd imagine their pre/post hooks among many other things look vastly different than the normal person, which could mask the problem slightly.
@MJHallenbeck@HackingDave Easy to point fingers but I’m not sure Claude being vibe coded is a bad thing. Vibe coding does seem like a major goal of theirs, so eating their own dog food does help them in the long run.
I’m pretty sure “department being disconnected” can be said about any large company.