Mechanical Engineer, Information Security architect, CEO of @htmx_org & Sona OTP.
Gaining root access to ur heart since 1997🗝️🖤links.abu.guru not montreal :(Joined July 2022
‼️🚨 BREAKING: Another researcher skipped coordinated disclosure entirely and dropped a critical 1-click GitHub token theft in public because he doesn't want to deal with MSRC. In his own words: "I really don't want to deal with MSRC on VSCode bugs."
The bug: just clicking a link can hand an attacker a GitHub token that reads AND writes to all your repos, including private ones. It lives in github[.]dev, GitHub's browser-based VSCode editor, which passes the browser an OAuth token that isn't scoped to a single repo. That token can touch everything you can.
Researcher Ammar Askar found that VSCode's sandboxed "webviews" leak keyboard events to the main editor. A malicious repo opened via one link can simulate keystrokes, install a local extension that skips VSCode's publisher-trust check, and exfiltrate your token. He published a working proof-of-concept.
He says when he reports github[.]dev bugs, GitHub tells him they're out of scope and to go report to MSRC, and a prior VSCode bug he reported was silently fixed with no credit. One commenter summed up the mood: "MSRC has turned into Feedback Hub."
I'd just like to interject for a moment. What you're referring to as Linux utilities are in fact not Linux, nor even GNU. They're uutils, or as I've recently taken to calling it, not-GNU-but-GNU-compatible. These tools are not Linux command line utilities unto themselves, but rather a clean-room Rust reimplementation of the GNU coreutils, made useful only because the GNU Project defined what cat, cp, ls, and mv should do in the first place.
Many developers will run a modified version of these utilities on Windows every day without realizing it. Through a peculiar turn of events, the utilities you're shipping are often called "Linux," and many of your users are not aware that Linux is merely the kernel, the program that allocates the machine's resources, and has nothing to do with grep at all.
There really is a Linux, and it really is a kernel, but it is not what you've packaged here. What you've actually bundled is uutils/coreutils, uutils/findutils, and a separate grep implementation, compiled into a single multi-call binary. Crucially, these are not the GNU originals. GNU coreutils is licensed GPLv3, whereas uutils is permissively MIT-licensed and written in Rust, which is rather the entire reason Microsoft can ship it natively in the first place.
So calling these "Linux-like command line utilities" is wrong twice over. They are GNU-like utilities, reimplemented as uutils, running on Windows. Or, if you insist on precision: not-Linux, not-GNU, uutils-on-NT.
"You can run OpenClaw inside your company now." Annoucing our work with @Microsoft to bring OpenClaw to the Microsoft and Windows ecosystems. Claws now work securly in the enterprise.
If the Jack Quaid gelatinous cube contains gelatine he’s haram and I can’t play God of War Laufaye. Does anyone know if the Jack Quaid gelatinous cube is halal or haram?
"You can run OpenClaw inside your company now." Annoucing our work with @Microsoft to bring OpenClaw to the Microsoft and Windows ecosystems. Claws now work securly in the enterprise.
"see? you can just ssh from your phone into a remote vps using tailscale to code with claude opus 4.8. people don't need to walk around with a macbook pro slightly ajar to keep their agents running"
96K Followers 101K FollowingTHE HARROD REPORT: Comprehensive up-to-date news coverage, aggregated from sources all over the world by The https://t.co/BJQ2VKnVYP news network
721 Followers 492 Followingjust a german guy building stuff while travelling the world
👉 https://t.co/ddOYFIJqdX - color toolkit
👉 https://t.co/iEgSP30toz - banger hooks
217 Followers 2K FollowingI`ve never been in love... But I imagine its similar to the feeling you get when you see your waiter arriving with your food.
3K Followers 7K FollowingWe have been the leading community people who love and invest in blockchain.We focus on bringing the brightest minds together to build the future of technology.
2K Followers 1K Followingol blobby blobfish in his sea lab makin intergalactic peace happen. ride humans around to do stuff. has a time machine. steward of https://t.co/m61SuW9AGj
56 Followers 316 FollowingBuilding a Personal Learning Network (PLN) to help teachers navigate and slice through any EdTech Nonsense 🤯. I teach technology to K-8 students.
1K Followers 65 FollowingForward Deployed Red Team Engineer and CoT expert.
Has jailbroken all major LLMs, Claude Expert.
Willing to jailbreak any model upon request
20K Followers 18K FollowingFreeBSD advocate who is heavily into Ansible, BGP (AS20621), DevOps, Kubernetes, Proxmox, XCP-ng, Python, Rust & RISC-V and builds own decentralized solutions.
160 Followers 2K FollowingDear Teachers, if I sit next to my best friend, I`ll whisper to him. If you move me away, I`ll shout to him. It`s your choice.
13K Followers 24 FollowingBuilding a new class of safer, more capable AI systems we call Humanist Superintelligence: AI that is always aligned, controllable, and in service of humanity.
198K Followers 299 FollowingA little bit geek, wonk, and nerd. Repeat entrepreneur, recovering lawyer, and former ski instructor. Co-founder & CEO of Cloudflare (NYSE: NET).
203K Followers 8 FollowingWeb Design Museum exhibits thousands of screenshots and videos of websites, apps, software, and Flash games from the 1990s to the late 2000s.
23K Followers 3K FollowingI'm at @picopicocafe making fantasy consoles and trashgifs.
#pico8 #voxatron #picotron #tweetcart
🦣 mastodon: https://t.co/6p13q13PxM
13K Followers 10 FollowingWindrose is a survival adventure in the Age of Piracy. Available now!
Steam: https://t.co/w4gtZDoZ0g
EGS: https://t.co/Tb9u0LoiZR
65K Followers 5K FollowingWe defend and extend the digital rights of people and communities at risk 🌎 RightsCon: @rightscon Latin America: @accessnow_latam
22K Followers 276 FollowingI find and exploit 0day, develop OSes, hypervisors and emulators, design massively parallel data structures and code, and do precision machining! Optimization❤️
122K Followers 8K FollowingDepartment of Cyber WAR.
Member of the Counter Spider Collective.
Wielder of AI to defend in Cyber Space.
Ralph Vibe Specialist.
VibeOps Operator!
721 Followers 492 Followingjust a german guy building stuff while travelling the world
👉 https://t.co/ddOYFIJqdX - color toolkit
👉 https://t.co/iEgSP30toz - banger hooks
1.2M Followers 788 FollowingProfessor at NYU & Executive Chairman at AMI Labs.
Ex-Chief AI Scientist at Meta.
Researcher in AI, Machine Learning, Robotics, etc.
ACM Turing Award Laureate.
46K Followers 2K FollowingSoftware Engineer. Prev, Riot. TanStack, Next, React, C++ when I'm feeling nasty. Beer, whiskey, coffee snob. Book lover. Jr Developer for life.