Qwen 3.8 27B Q4 is now running on an RTX 4060 with just 8GB VRAM and a 64,000 token context window using Unsloth's new IQ4_XS quant at 14.6GB on disk.
→ Prefill at 150 tokens per second, decode at 5 tokens per second via native MTP
→ Only 25 GPU layers offloaded to stay within 8GB VRAM without spillover
→ Quantized KV cache crushes the memory footprint
→ A model that beats Claude Opus 4.6 on several benchmarks running on a $300 GPU
The employee changed his Microsoft 365 password twice.
The attacker still logged back in.
That was the moment we knew we were not dealing with a normal stolen-password incident.
The first alert came from an impossible-travel sign-in. The employee had authenticated from Maryland, then the same account appeared from another country less than an hour later.
We reset the password.
Twenty minutes later, another suspicious session appeared.
So we reset it again and forced MFA re-registration.
The attacker came back.
At that point, I stopped looking at the account and started looking at the employee’s laptop.
Inside the Downloads folder was a file called:
Invoice_Viewer.exe
The employee remembered downloading it from a website that claimed he needed a special viewer to open an invoice.
Windows logs showed the file running at 9:14 AM.
Seconds later, it launched PowerShell in the background.
Then we found something else.
A scheduled task called MicrosoftEdgeUpdateCheck had been created on the machine.
The name looked legitimate enough to ignore if you were moving quickly, but it was not one of Microsoft Edge’s normal update tasks.
We also found an outbound HTTPS connection from the compromised host to an external IP address.
The file hash was submitted for malware analysis.
It came back as an information stealer.
That explained why changing the password had not solved the problem.
The malware had stolen browser data, including authentication cookies and active session information.
The attacker was not repeatedly discovering the employee’s new password.
They were reusing a session that had already been authenticated.
We revoked every active Microsoft 365 session, isolated the laptop from the network, removed the persistence, reset the credentials again, and rebuilt the endpoint.
The suspicious logins finally stopped.
A compromised account does not always mean the attacker still knows your password.
Sometimes you already changed the password.
The attacker is still inside because they stole the session.
this video for how to set it up fully uncensored Ai models running for local machine.
David Ondrej showcases SuperGemma 26B, a fully uncensored fine-tune of Google's Gemma model with 26 billion parameters, running locally on consumer hardware with zero guardrails.
We’ve updated our joint Cybersecurity Advisory on Medusa ransomware with @FBICyberDiv & @HHSgov to share new details on Medusa’s ransomware-as-a-service operations + detection & incident response guidance to protect your org from extortion. Learn more 👉 https://t.co/nynK9wDkWP
this is f***king crazy
GLM 5.3 API keys are officially live but can still use it for FREEEEEEEE
Zai just shipped GLM-5.3 for coding agents and 50% improvement over their previous one.
it's the same model behind zai's coding plan, available as a subscription for agent tools.
what it does:
- production-grade code generation
- long-horizon tasks, full-context reasoning
- works with Cline, Kilo Code, Claude Code, OpenClaw, and 20+ other agent tools
- open source SOTA on coding benchmarks
how to use it:
step 1: go to https://t.co/1wNslZFCai
> download the desktop app
step 2: create an account
> sign up with email
step 3. Go to manage model > choose plan (use $0.00 plan for 5M GLM token everyday)
> then use https://t.co/lNtrMszlSm
additionally, configure it in your agent tool (Cline, Kilo Code, Claude Code, etc.), set the model provider to zai paste your API key from the dashboard
important: you get 5M GLM token everyday so use it wisely
Simulates attacks on LLMs, AI agents, and RAG pipelines to uncover vulnerabilities like jailbreaks, prompt injections, and PII leakage.
https://t.co/hZRjOLxyOq
Cyber Threat Intelligence & OSINT Analysis Toolkit
Transform Claude into a trained intelligence analyst 74+ commands, 49 techniques, zero API keys required for core functionality.
Resource: https://t.co/4UagFQ4GwK
100+ World Intelligence MCP Servers
Financial Markets
Economic
Conflict & Security
Military & Defense
Maritime
Geospatial Datasets
Intelligence Analysis
Aviation
Social & Sanctions
Country Intelligence
Traffic
https://t.co/SYcJX6k3d1
#geoint
You can now run Qwen3.8 model in your phones just 1GB.
- 262k context with Real reasoning.
the full reasoning curriculum from Qwen’s 2.4T flagship
- distilled Qwen3.8 2.4 Trillion model into 2B and it actually worked
- Full-parameter SFT.
Same curriculum as the 9B and 4B.
- Not LoRA, Real traces from the teacher.
- then Suddenly it scores 28.3 to 54.8 MMLU CoT
- & GSM8K: 33 to 64
Native 262k context & function calling.
Q4_K_M is only 1.3 GB.
Best current local Qwen3.8-27B uncensored for cybersecurity research (code review, vuln analysis, agentic DFIR) run locally 12GB
this is the version you actually want.
- Weight-level refusal removal.
- No fine-tune. No LoRA, multimodal capabilities.
- Same strong reasoning Just without the safety theater.
- Full K-quant ladder, vision projectors.
- Dual-use? Yes.
- No more constant refusals when you’re analyzing real exploits, mal/ware, or attack chains.
For local cybersecurity AI, this is a clear upgrade over the stock model.
@OpenAI just launched a new feature last night called Computer History. For DFIR analysts, this is a new artifact class worth knowing about. I turned it on on my MacBook, parsed the artifacts, and it produced about 3,616 timeline events from ~2 hours of normal work.
While Computer History is on, it logs input, app focus, and what was on screen, then stores it on the Mac. It keeps a timed record of what you clicked, typed, and opened, including chats in Slack, WhatsApp, Telegram, and other apps. That record stays on the Mac.
IRFlow-Timeline 1.0.10 now parses those Computer History artifacts and builds a timeline of the activity, so you can walk the investigation instead of grepping raw cache files. On a compromised Mac, this shows what was typed, clicked, and read. Not just that the app was installed.
#dfir #incidentresponse #openai #computerhistory
Connects enterprise knowledge across your organization to build AI agents, RAG applications, and search on a single governed context layer.
https://t.co/52vTggk0qs