VBAnimal
@VBAnimal
Followers
477
Following
183
Media
63
Statuses
2K
Dev... this account may thus behave strangely for testing ! #Python #PHP #JS #HTML #VBA
TheMoon
Joined October 2015
Fara-7B is our first agentic small language model for computer use. This experimental model includes robust safety measures to aid responsible deployment. Despite its size, Fara-7B holds its own against larger, more resource-intensive agentic systems: https://t.co/lT9m0uH4gQ
58
293
2K
I made a human-readable CSV lookup file that maps coordinates to their country code. This one has an accuracy of 30km
95
251
6K
The *full* Python Documentary will be released this Thursday (Aug 28) at 10am PDT / 19:00 CET. More at https://t.co/ifkBoVOkxX Don't miss the online release party / chat! @TECHDOCU
discuss.python.org
Folks have been able to see sections of this at (since?) EuroPython, and snippets have been posted by cult.repo on YouTube, but this time it’s the full reel! Here’s the official trailer: https://ww...
17
197
936
A new attack on Linux is challenging everything we thought we knew. We found malware hidden not in the content, but in the filename itself. Read the full analysis. https://t.co/rBNo97GRSM
20
187
1K
Finally, with @hw16, we managed to bypass the @Cloudflare mTLS protection after around 5 days of work. I'd like to share a few golden tips for bug bounty hunters who might face something similar in the future. But first, here's a quick summary: The target was a banking app with
Did @Cloudflare just defeat @Burp_Suite and @CaidoIO? Cloudflare protection is becoming very common. This is the third app I’ve seen using it. Changing the user agent doesn’t help, and Burp TLS-fingerprint bypass plugin didn’t work. The app blocks any request when it detects
33
157
791
Good read : Exploring Javascript events & Bypassing WAFs via character normalization
0x999.net
This blog post explores advanced techniques for bypassing WAFs by leveraging quirks in JavaScript event handling, alternative encodings, and character normalization. It demonstrates how discrepancies...
0
0
0
Today, we're announcing our first hosted infrastructure product: pyx, a Python-native package registry. We think of pyx as an optimized backend for uv: it’s a package registry, but it also solves problems that go beyond the scope of a traditional "package registry".
80
288
3K
Still my favorite set of redirects. So many "hackers" probe these basic wordpress routes. Always nice to give them a pleasant distraction 😄
138
303
7K
You didn’t click, but your password challenge is leaked. I’m excited to share my latest research: CVE-2025-50154, a high severity NTLM hash disclosure vulnerability in the explorer.exe process, exploitable without any user interaction. https://t.co/ssA9YdBE6J
cymulate.com
Learn about CVE-2025-50154 and its risk of NTLM attacks and RCE even after Microsoft’s fix for CVE-2025-24054.
0
35
81
we got a persistent 0click on ChatGPT by sharing a doc that allowed us to exfiltrate sensitive data and creds from your connectors (google drive, sharepoint, ..) + chat history + future conversations it gets worse. we deploy a memory implant #DEFCON #BHUSA @tamirishaysh
21
196
823
We (+@ronenshh) hacked NVIDIA's Triton AI server by abusing a single error message🚨 The result is unauthenticated RCE allowing attackers to compromise the server and steal proprietary AI models🤯 For more details & mitigations check out our blog @wiz_io
https://t.co/v5kpI1eedL
5
60
230
hashcat v7.0.0 released! After nearly 3 years of development and over 900,000 lines of code changed, this is easily the largest release we have ever had. Detailed writeup is available here: https://t.co/fxAIXNXsEr
22
375
1K
Je sais que la procédure civile, c'est pas sexy, ça n'intéresse personne hormis les professionnels et la presse spécialisée. Sachez juste que le gouvernement va permettre, dans tous les litiges civils à partir du 1er septembre, …
82
1K
2K
We found a new container escape affecting all container runtimes using @NVIDIA GPUs. The crazy part? The exploit is just three lines long 🤯 This is the story of #NVIDIAScape 🧵👇
10
134
643
Nuxt 4.0 is here at last … and it's all about DX ✨ 🗂️ app/ directory for better organisation 🔄 smarter data fetching ⚡️ a faster CLI with socket communication 🔧 improved TypeScript integration ... and a smooth upgrade experience. 💚 https://t.co/Jvf5DOGzE9
nuxt.com
Nuxt 4.0 is here! A thoughtful evolution focused on developer experience, with better project organization, smarter data fetching, and improved type safety.
48
315
1K
Google has just used AI and threat intel to foil a zeroday before it could launch. Working from artifacts gathered by GTIG, Big Sleep was used to identify a vuln before actors could ramp up exploitation. It doesn’t get much better than this in intel.
blog.google
Here’s what we’re announcing at cybersecurity conferences like Black Hat USA and DEF CON 33.
4
71
215
Turns out you can just hack any train in the USA and take control over the brakes. This is CVE-2025-1727 and it took me 12 years to get this published. This vulnerability is still not patched. Here's the story:
Perhaps one of the most badass CVE's I've ever seen from @midwestneil 💪😤 https://t.co/HpWUpTIeAC
46
555
3K
some guy at Mastercard prompt injected a job posting and just days later it tricked somebody’s ai 😂
93
1K
18K
How Anthropic built its multi-agents system. Interesting read.
anthropic.com
On the the engineering challenges and lessons learned from building Claude's Research system
0
0
0
>changes their EULA to allow spyware >makes their best game free on steam >people realize its spyware and review bomb it Masterful gambit Mr. Gearbox and Take Two
947
9K
146K