Lost my phone at the office and spent 30 minutes turning the place over. Find My was disabled by MDM.
Out of ideas, I asked Claude how I could find it. It suggested tracking the Bluetooth signal strength, then wrote me a meter in about a minute.
I walked around watching the number climb. Found it.
Apparently you can just make the tool you need now.
Code: https://t.co/fmnISzHfZ2
Things are getting weird (or interesting?) in the vulnerability research space. I published some of my personal thoughts on what we're seeing and what our broad strategy is here:
https://t.co/C229t5ryeK
Ainda bem que eu não vi esse jogo do gremio. Melhores momentos teve bola na trave a 5m do gol, tesourada do marlon por nada e cartao vermelho. E o tecnico falando q na vida tem momentos tristes. Em fim. O grêmio avacalha o torcedor #gremio
Análise preliminar das implicações do corte de preços no Luna e Terra (baseado no DeepSWE):
- Sol medium não serve mais pra nada. Luna Max é melhor e 3x mais barato. O mesmo vale para Terra xhigh.
- Terra max passa a fazer sentido. Sol xhigh > Terra max > Sol high tanto no score quanto no preço, e a progressão é quase linear entre eles.
Ou seja: Luna Max pode ser um bom daily driver e escalar os problemas mais difíceis para o Terra max ou Sol high/xhigh, a depender do seu plano e quanto de limite resta.
Ads's hackbot gives every agent an assess-confidence tool, and the model on the other end of it remembers every false XSS the earlier agents already chased on that same program. When an agent thinks it has a gadget, a lead or a bug, it calls the tool instead of writing a report. A stronger reflection model grades the finding against roughly the CIA triad and answers if this is a gadget/lead, or a waste of time.
Each program carries its own big JSON of past tool calls, so the reflector reasons with the memory: X agents already thought they popped XSS here and none of it held up, go somewhere else. You end up with an assistant per program that the hacking agent checks with before it commits, and the same dead ends stop repeating across runs.
Having no 5 hour window on codex has been such a lifer @thsottiaux@jxnlco. i can actually "check out" from work because i know ill max it by end of week but when there are 5 hour windows, i am constantly mix-maxxing it and it adversely affects my life.
proposal for google, anthropic, and openai, build a crowdsourced bug-hunting platform where trusted researchers get frontier model access and subsidized tokens for security research.
i don’t know whether threat actors are sleeping, silently pwning everything, or whether trusted cyber access programs are actually working. but ask any offensive security researcher who has used gpt-5.6 sol and mythos. they’ll tell you the capability gap between these models and older ones is terrifying.
we are popping major companies out of thin air almost every day
just because finding bugs got easier doesn't mean there will be fewer bugs. If anything, we're going to see a lot more compromises, not fewer.
and it's naive to assume that because openai and anthropic have the budget to just run loops at scale, their systems will be secure. a research team with taste, one that knows where to look, will always find something devastating.