First ever (i think?) cli coding agents battle royale!
6 contestants:
claude-code
anon-kode
codex
opencode
ampcode
gemini
They all get the same instructions:
Find and kill the other processes, last one standing wins!
3...
2...
1...
Software engineering is a joke now — pure fraud. Vibe coding, serverless architectures, and platforms like Vercel that spin everything up for you have gutted the craft. We’ve lost the art of programming, trading it for bloated frameworks and copy-paste solutions. It’s absurdly expensive too — good luck running Docker without a $3,000 MacBook with 64GB of RAM. The whole space is begging to be burned down and rebuilt.
We apologize to the many people who follow us online.
Instead of doing our regular malware sample family updates and pushing new papers, we're going to meme this CrowdStrike thing until we develop arthritis.
People are paying thousands of dollars for educational courses on initial access vectors. We'll provide you a step-by-step guide on how to get initial access to companies with a budget of $0. All it requires is some time, effort, and the ability to grep
1. Go to Telegram
2. Get free stealer logs
3. Look for VPN creds
4. Hope no MFA
4.a If MFA, spam requests
4.b If fails, go back to Step 1.
5. Log into VPN
6. Go to Jira / Kanban board
7. Scrape everything when people are sleeping
8. Log out
9. ???
10. Profit!!!11
Congratulations, you're now the most dangerous hacker on the planet
Does this sound absurd? Of course it does. Does it work? Yes, literally every single day. Infostealers are a giant problem. They don't need to target enterprise environments with top-notch security – they only need to target lazy home users, with security settings probably disabled, downloading junk binaries.
Today @cloud11665 discovered a CSS injection vulnerability (or super cool customization feature) on GitHub.
* Reposted for issue correction
* Initially attributed discovery to wrong person
Video shared from @yacineMTB
The GitHub CSS Injection which was patched a few hours ago has already been bypassed.
Internet nerds are returning with wrath as they resume anime backgrounds and anime banners
We were asked not to show the bypass code to 340,000 people so it's not patched instantly ¯\_(ツ)_/¯
🔐 we recently shipped passkeys to all customers @shakepay
1000s of Canadians are now securing their financial wellbeing with passwordless authentication
turns yours on, and drop your password!
https://t.co/Cb6vMkB5hk
On Monday when the Lockbit ransomware group website was seized by FBI, NCA UK, and EUROPOL, they made a post titled "Who is Lockbitsupp?" - this post indicated that law enforcement could potentially unveil key leadership behind the organization.
During the week we spoke with Lockbit ransomware group administrative staff. They stated they did not believe law enforcement know his/her/their identities. They even boastfully raised the bounty of their head to $20,000,000.
Today we finally get to see the "Who is Lockbitsupp?" post. The post is very short. It states Lockbit does not live in the United States or Netherlands. It also states he drives a Mercedes. They end the post with a picture of "Tox Cat" - an emoji frequently used by Lockbit ransomware group administrative staff and state Lockbit ransomware group administrative staff has 'engaged' with law enforcement.
tl;dr Lockbit ransomware group called their bluff and succeeded
"cAn yOu TeAcH Me?"
You want individual lessons on malware development? Fine, $50/hr, up front, each hour. We'll teach you anything you want to know. It will be painful and you will regret everything