Everyone losing their minds over the Visual Studio Code payload hitting GitHub. The research was published on @MDSecLabs site in 2023! Red Teams have used this on assessments for ages!! Microsoft knows all of this and didn't bother to fix it!!! IT'S BEEN IN INITIAL-ACCESS FRAMEWORKS FOR YEARS!!!! https://t.co/ifTXR9N7Ur
Marathon’s game director @Ziegler_Dev reflects on the journey so far and the weird and wild path ahead. Here’s the gist of it:
🔹With the first season of Marathon we’ve created a strong core community.
🔹We're embarking on a multi-season journey built around growing from the seed of this strong community.
🔹We’re looking to solve some pain points for players:
* Making the game less grindy, more rewarding
* Making improvements to things like the UI/UX, matchmaking, end game meta, playing as solos/duos, etc.
* Smoothing out onboarding
🔹We’re also going to build out more of the core game:
* Adding new fun and mind-bending content: new and updated zones, Runner shells, new combatants, weapons, loot, and more
* Building systems to make progressing more interesting
🔹We want to build more survival experiences for different moods, like if you want to full sweat or lean back and chill.
* Exploring more pure PVP, PVE, and PVP-lite experiences
* Continue experimenting with experimental queues to learn more around these experiences
Other highlights:
🔹We're bringing back Duos for Season 2 with a rotating Duos queue.
🔹We're testing some experiments in Season 2 around PVE and PVP-Lite modes.
🔹We’re expanding the max size of your Vault and increasing faction progression rates in Season 2.
🔹We’ll talk more about Season 2 content like Night Marsh, the new Cradle progression system, and the Runner shell Sentinel, the week of May 25.
If this summary has your interest piqued, read the full article here: https://t.co/P1RjJt1v4c
Microsoft: PowerShell is simple and easy to use.
Actual PowerShell command: Remove-MgIdentityAuthenticationEventFlowAsOnGraphAPretributeCollectionExternalUserSelfServiceSignUpAttributeIdentityUserFlowAttributeByRef
No, this isn't a joke. This was noted by @NathanMcNulty
AdminSDHolder in 45 minutes?
@JimSycurity distills a 159-page deep dive into the Windows access control model, SDProp, and the AD mechanics that keep breaking forests. #SOCON2026
We’re expanding Trusted Access for Cyber with additional tiers for authenticated cybersecurity defenders.
Customers in the highest tiers can request access to GPT-5.4-Cyber, a version of GPT-5.4 fine-tuned for cybersecurity use cases, enabling more advanced defensive workflows.
https://t.co/RMMXQklFar
Anthropic accidentally leaked their entire source code yesterday. What happened next is one of the most insane stories in tech history.
> Anthropic pushed a software update for Claude Code at 4AM.
> A debugging file was accidentally bundled inside it.
> That file contained 512,000 lines of their proprietary source code.
> A researcher named Chaofan Shou spotted it within minutes and posted the download link on X.
> 21 million people have seen the thread.
> The entire codebase was downloaded, copied and mirrored across GitHub before Anthropic's team had even woken up.
> Anthropic pulled the package and started firing DMCA takedowns at every repo hosting it.
> That's when a Korean developer named Sigrid Jin woke up at 4AM to his phone blowing up.
> He is the most active Claude Code user in the world with the Wall Street Journal reporting he personally used 25 billion tokens last year.
> His girlfriend was worried he'd get sued just for having the code on his machine.
> So he did what any engineer would do.
> He rewrote the entire thing in Python from scratch before sunrise.
> Called it claw-code and Pushed it to GitHub.
> A Python rewrite is a new creative work. DMCA can't touch it.
> The repo hit 30,000 stars faster than any repository in GitHub history.
> He wasn't satisfied. He started rewriting it again in Rust.
> It now has 49,000 stars and 56,000 forks.
> Someone mirrored the original to a decentralised platform with one message, "will never be taken down."
> The code is now permanent. Anthropic cannot get it back.
Anthropic built a system called Undercover Mode specifically to stop Claude from leaking internal secrets. Then they leaked their own source code themselves. You cannot make this up.
What if the attack paths you’re missing are outside your core identity stack? 🤔
Join @JustinKohler10 & @jaredcatkinson March 31 to see how BloodHound Enterprise now maps risk across Okta, GitHub, and Mac environments.
Save your spot! https://t.co/tSq17Re9ua
YES! Someone reverse-engineered Apple's Neural Engine and trained a neural network on it.
Apple never allowed this. ANE is inference-only. No public API, no docs.
They cracked it open anyway.
Why it matters:
• M4 ANE = 6.6 TFLOPS/W vs 0.08 for an A100 (80× more efficient)
• "38 TOPS" is a lie - real throughput is 19 TFLOPS FP16
• Your Mac mini has this chip sitting mostly idle
Translation: local AI inference that's faster AND uses almost no power.
Still early research but the door is now open.
→ https://t.co/qPwddSyV3f
#AI #MachineLearning #AppleSilicon #LocalAI #OpenSource #ANE #CoreML #AppleSilicon #NPU #KCORES
Remember the team at SpecterOps open-sourced their PowerShell training, which remains a hugely relevant concept, and APTs are still actively using it.
#redteam
https://t.co/vRrlfh9mha
Since I was bored in a plane I decided to revisit some of the Windows Hello tradecraft and finally implemented browser based FIDO2 auth using WHFB keys in roadtx. Thanks @fabian_bader and @NathanMcNulty for the inspiration!
Feeling nostalgic?
Enjoy Nintendo Entertainment System – Nintendo Classics titles, like Super Mario Bros. 3, and more with your #NintendoSwitchOnline membership.