jcran Profile Banner
jcran Profile
jcran

@jcran

Followers
8K
Following
13K
Media
346
Statuses
15K

knowledge seeker

Austin, TX
Joined May 2007
Don't wanna be here? Send us removal request.
@shortxstack
Whitney Champion πŸͺπŸš€ bluesky @whit.zip
4 days
new @velocidex artifact and write-up detailing CVE-2025-14847 and how to detect #MongoBleed from @eric_capuano πŸ€“πŸ”₯πŸ¦– https://t.co/je4XU0j7Fp
Tweet card summary image
blog.ecapuano.com
Detecting CVE-2025-14847 Exploitation with Velociraptor
0
40
136
@ibab
Igor Babuschkin
5 days
@karpathy Opus 4.5 is pretty good
22
26
1K
@jcran
jcran
8 days
the team you build is the company you build
0
0
5
@BushidoToken
Will
13 days
PSA from @CuratedIntel, CLOP is attacking CentreStack file servers πŸ‘‡
3
14
40
@jcran
jcran
14 days
Heads up - active exploitation of Cisco Secure Email Gateway / Cisco Secure Email and Web Manager appliances with the Spam Quarantine feature exposed to the internet. https://t.co/2PWrNGHcvN
sec.cloudapps.cisco.com
On December 10, Cisco became aware of a new cyberattack campaign targeting a limited subset of appliances with certain ports open to the internet that are running Cisco AsyncOS Software for Cisco...
0
0
0
@ACarmackArtist
Adrian Carmack Artist
17 days
Happy Birthday Commander Keen!
21
116
906
@infosec_au
shubs
26 days
Pushed a new update to https://t.co/9CqANckHK0 -- it now scans for the RCE payload via reflection. Use the --waf-bypass flag to bypass WAFs, works well for Cloudflare/AWS. Other WAFs might need tinkering with the payload, depending on whether they don't have a max context limit.
Tweet card summary image
github.com
High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478) - assetnote/react2shell-scanner
13
128
624
@stephenfewer
Stephen Fewer
27 days
An unauthenticated RCE PoC for the React vuln (CVE-2025-55182) is now public. Confirmed to work on my test setup (Next.js 16.0.6 with React 19.2.0).
@maple3142
maple3142
27 days
A POC for CVE-2025-55182 https://t.co/BcyJ1UbivA
8
77
638
@swyx
swyx πŸ‡ΈπŸ‡¬
4 months
successful agent engineering is just repeating "bitter lesson will kill this some day but hey this works for now lets do it" again and again until agi
26
26
455
@karpathy
Andrej Karpathy
1 month
Sharing an interesting recent conversation on AI's impact on the economy. AI has been compared to various historical precedents: electricity, industrial revolution, etc., I think the strongest analogy is that of AI as a new computing paradigm (Software 2.0) because both are
554
2K
13K
@jcran
jcran
2 months
ultimately, what happens when individual devs can build software at the complexity level of (today's) leading software companies
0
0
1
@jcran
jcran
2 months
testing is getting easier and better, and with testing comes visibility to underlying issues, but... if i have to bet, we're headed for more and more exploitable logic bugs in the future
1
0
2
@jcran
jcran
2 months
this is not /necessarily/ a bad thing, complex software can handle more complex cases, but with complexity comes insecurity
1
0
0
@jcran
jcran
2 months
almost everyone is underestimating just how complex software systems are becoming. llms may have enabled 3x productivity, but also, 10x complexity
1
0
2
@arekfurt
Brian in Pittsburgh
3 months
So everyone else reads "Attackers were in our network for at least 12 months." as "We only keep logs for 12 months, so who knows how long they were in there." too, right?. 😏
20
53
535
@mmay3r
Michael
3 months
The idea that every technological innovation cycle should produce exactly one bubble is ludicrous. Astrology pretending to be economics.
1
1
12
@jcran
jcran
3 months
MATH
@DanielDiMartino
Daniel Di Martino πŸ‡ΊπŸ‡ΈπŸ‡»πŸ‡ͺ
3 months
My letter to @WSJ: "Each H-1B visa holder reduces the budget deficit by more than $800,000 in net present value over his lifetime....if the $100,000 application fee...reduces the number of visas...the policy will cost Washington revenue and shrink the size of the economy."
0
0
2
@jcran
jcran
3 months
SCIENCE
0
0
1