Reposted by becojoRachel Tobac @racheltobac.bsky.social · 30/07/2026The new “⚠️Seems like AI slop” button on LinkedIn is sending me into orbit lmao 1419735
Reposted by becojoWilliam Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 07/07/2026You shouldn’t trust Trusted Publishing blog.yossarian.net/2026/07/07/You-s… #python #security #oss 01510
Reposted by becojoSeth Larson @sethmlarson.dev · 10/06/2026Every code generation LLM model available will at some point suggest insecure code as a part of “code completion”. Should this behavior be considered a vulnerability? #security #opensource #programming sethmlarson.dev/are-insecure...sethmlarson.devAre insecure code completions a vulnerability?Three months ago I saw that PyCharm shipped with a “Full Line Completion” plugin that “uses a local deep learning model to suggest entire lines of code”. These suggestions manifest as whole-line su... 53610
Reposted by becojoKen Klippenstein @kenklippenstein.bsky.social · 28/05/2026If you're worried about AI data centers, Congress is taking notice — not by passing any laws, but by spying on critics through its new intelligence bureau: www.kenklippenstein.com/p/exclusive-...kenklippenstein.comExclusive: New Intel Bureau Eyes AI Data Center CriticsCongress has its own CIA and it’s sounding the alarm about anti-AI grievances 8324117
Reposted by becojoJanne M. Korhonen @jmkorhonen.fi · 26/05/2026I well recall the online debates where the majority of debaters opined that zero traffic deaths is an utopian goal and would require methods that would kill Helsinki, if not bring about totalitarian communism 222075528
Reposted by becojoBrian Merchant @bcmerchant.bsky.social · 11/05/2026What so many have experienced personally has been confirmed by a new study: AI has been a disaster for working artists.bloodinthemachine.comThe AI-inflected crisis artists are facing, in 4 chartsAn alarming new study reveals the dire impact AI is having on artists' livelihoods. It does offer some hope, too. 211150487
Reposted by becojoFilippo Valsorda @filippo.abyssdomain.expert · 28/04/2026… are fucking kidding me. A github.com cross-account RCE due to the most pedestrian of injection attacks along the obvious exposed surface… and they actually have a globally shared “git” UNIX user!! This is not what taking the role of supply chain stewards seriously looks like.wiz.ioGitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz BlogA CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution. Read the threat brief and find vulnerable GHES instances from Wiz. 735099
Reposted by becojoSocket @socket.dev · 23/04/2026🚨 Bitwarden CLI 2026.4.0 was compromised as part of the ongoing Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline. We’ll continue updating our coverage as more details are confirmed. socket.dev/blog/bitward...socket.devBitwarden CLI Compromised in Ongoing Checkmarx Supply Chain ...Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline. 43417
Reposted by becojoMatt Brown @mattbrown.bsky.social · 11/04/2026Okay CTA. This is a good sign. 90243034519
becojo @becojo.com · 29/03/2026TIL the Raspberry Pi firmware supports the storage of ECDSA private keys which allows the user-space to sign data. I ported rpifwcrypto in Go to add the ability to sign ES256 JWT tokens and export public keys as JWKS or PEM to authenticate with external services. github.com/ezoidc/go-rp...github.comGitHub - ezoidc/go-rpi-crypto: Pure Go library and CLI to access the Raspberry Pi's firmware cryptographic functionsPure Go library and CLI to access the Raspberry Pi's firmware cryptographic functions - ezoidc/go-rpi-crypto 010
becojo @becojo.com · 26/03/2026turn it off here github.com/settings/cop...github.blogUpdates to GitHub Copilot interaction data usage policyFrom April 24 onward, interaction data from Copilot Free, Pro, and Pro+ users will be used to train and improve our AI models unless they opt out. 010
Reposted by becojoJoseph Cox @josephcox.bsky.social · 03/03/2026New from 404 Media: CBP tapped into the online advertising ecosystem to track peoples' movements, according to an internal DHS document. Shows for the first time DHS tracked phones via process for putting ads in ordinary apps—video games, fitness apps, many more www.404media.co/cbp-tapped-i...404media.coCBP Tapped Into the Online Advertising Ecosystem To Track Peoples’ MovementsAn internal DHS document obtained by 404 Media shows for the first time CBP used location data sourced from the online advertising industry to track phone locations. ICE has bought access to similar t... 281170722
Reposted by becojoZack Whittaker @zackwhittaker.com · 10/02/2026Even the internet's favorite dog account calls out Ring video cameras what they are: Mass surveillance. 18731
Reposted by becojoKevin Beaumont @doublepulsar.com · 09/12/2025Notepad++ have published an update to fix the software being hijacked by threat actors remotely: notepad-plus-plus.org/news/v889-re... This was being abused by threat actors in China, a blog from mine from a week ago: doublepulsar.com/small-number...notepad-plus-plus.orgNotepad++ v8.8.9 release: Vulnerability-fix | Notepad++ 510032
Reposted by becojoantirez @antirez.bsky.social · 11/01/2026New blog post: Don't fall into the anti-AI hype. antirez.com/news/158 2027260
Reposted by becojoJoseph Cox @josephcox.bsky.social · 07/01/2026New: DHS is lying to you. At least four videos show what really happened when ICE shot a woman in Minneapolis. Shots clearly fired while vehicle already turning away from the officer. But DHS lied. Trump lied. Noem lied. Even judges have catalogued DHS' serial lying www.404media.co/dhs-is-lying...404media.coDHS Is Lying To You About ICE Shooting a WomanAt least four videos show what really happened when ICE shot a woman in Minneapolis on Wednesday. DHS has established itself as an agency that cannot be trusted to live in or present reality. 211440561
Reposted by becojoMerriam-Webster @merriam-webster.com · 15/12/2025bit.ly/453uzfxbit.ly2025 Word of the Year: SlopPlus 'gerrymander', 'touch grass', 'performative', and other words that defined the year 251451250
Reposted by becojo404 Media @404media.co · 18/11/2025After 404 Media's months-long reporting and pressure from lawmakers, the data broker owned by the U.S.’s major airlines will now shut down a program in which it sold access to hundreds of millions of flight records to the government and let agencies track peoples’ movements without a warrant.404media.coAirlines Will Shut Down Program That Sold Your Flights Records to GovernmentThe move comes after intense pressure from lawmakers and 404 Media’s months-long reporting about the airline industry's data selling practices. 91186447
Reposted by becojoNicolas Grégoire @agarri.fr · 16/11/2025Argument injection (and RCE) in three distinct AI agents blog.trailofbits.com/2025/10/22/p...blog.trailofbits.comPrompt injection to RCE in AI agentsWe bypassed human approval protections for system command execution in AI agents, achieving RCE in three agent platforms. 085
becojo @becojo.com · 12/11/2025"an agent is simply an LLM call in a loop" sure and a web server is just accept(2) in a loop 020
Reposted by becojoWhitney Merrill @wbm312.bsky.social · 22/06/2025Identifying birds using the Merlin Bird ID is real life Pokémon. 4516
Reposted by becojorkletr @merkletr.ee · 18/05/2025My writeup for @northsec.io CTF 2025's "Containers" reverse track: merkletr.ee/ctf/2025/nse...merkletr.eeNorthSec 2025: Containers 012
Reposted by becojoZack Whittaker @zackwhittaker.com · 30/04/2025If there's one thing I've learned about covering cybersecurity over the past decade or so, is that the cybersecurity community (the fixers and breakers) and the cybersecurity industry (profits above all else) are two very, very different things. 721054
Reposted by becojoMontréHack @montrehack.bsky.social · 10/03/2025👋 Hello Bsky! MontréHack is a bilingual, monthly cybersecurity workshop in Montreal where challenge designers present their CTF challenges and participants solve them. 022
Reposted by becojoÉmilio Gonzalez @res260.xyz · 31/01/2025Fellow cybersecurity folks: Make sure to follow @northsec.bsky.social if you came to bluesky from Twitter! Great conference in Montreal and probably the biggest on-site CTF in the world. 035
Reposted by becojoZack Whittaker @zackwhittaker.com · 27/12/2024New, w/ @lorenzofb.bsky.social: Data-loss prevention startup Cyberhaven was hacked to publish a malicious update to its Chrome extension, affecting potentially thousands of users. A security researcher says other big Chrome extensions were hacked in the same campaign. techcrunch.com/2024/12/27/c...techcrunch.comCyberhaven says it was hacked to publish a malicious update to its Chrome extension | TechCrunchThe data-loss startup says it was targeted as part of a "wider campaign to target Chrome extension developers." 0105
becojo @becojo.com · 26/12/2024Design Space for Code Search Query ast-grep.github.io/blog/code-se...ast-grep.github.ioDesign Space for Code Search QueryA review of the design space for code search tools. 020
Reposted by becojoRicochet Media @ricochetmedia.bsky.social · 17/12/2024Dying to win: Canadian provinces are expanding legal gambling despite ‘one death every nine days.’ Michener-funded investigation into gambling-related suicide data shows tracking of deaths lags, while governments ignore risks to chase industry profits. ricochet.media/justice/dyin... #cdnpoliricochet.mediaDying to win: Canadian provinces are expanding legal gambling despite one death every nine daysInvestigation into gambling-related suicide data shows tracking of deaths lags while governments ignore risks to chase industry profits 26641
Reposted by becojoLouis Dion-Marcil @ldionmarcil.bsky.social · 06/12/2024I wrote a thing with my colleague Ilyass El Hadi (0xc0ffee_) & Charles Prevost, about how we've been leveraging offensive webapp testing during Red Teams. 4 use cases of external breaches using webapps inside, enjoy! #appsec cloud.google.com/blog/topics/...cloud.google.comBridging the Gap: Elevating Red Team Assessments with Application Security Testing | Google Cloud BlogRed team and targeted external assessments should incorporate application security expertise to better simulate modern adversaries. 0187
Reposted by becojoUncle Joe @sydseter.com · 01/12/2024Please vote for better 2FA support on bsky! github.com/bluesky-soci...github.com2-Factor Authentication Support · Issue #1071 · bluesky-social/social-appIs your feature request related to a problem? Please describe. 2Factor authentication is generally a very handy feature for security purposes as passwords and logins sometimes fail. 2Factor Authent... 68734
Reposted by becojoLouis Dion-Marcil @ldionmarcil.bsky.social · 21/11/2024Been having a ton of fun solving these, only 2/3 done and i'm quite humbled so far challenge-xss.quiz.flatt.trainingchallenge-xss.quiz.flatt.trainingFlatt Security XSS ChallengeExecute alert(origin) on each challenge origins. 062
becojo @becojo.com · 21/11/2024add that to the reasons to stop using bash in production pipelines yossarian.net/til/post/som... #security #cicd #appsecyossarian.netTIL: Some surprising code execution sources in bash 051
Reposted by becojoCatalin Cimpanu @campuscodi.risky.biz · 14/11/2024PyPI replaces PGP signatures with digital attestation system blog.pypi.org/posts/2024-1...blog.pypi.orgPyPI now supports digital attestations - The Python Package Index BlogAnnouncing support for PEP 740 on the Python Package Index 042