Sign in

becojo

@becojo.com
58 followers 132 following 18 posts

securing the computers | gifs becojo.tumblr.com

PostsRepliesMedia
Reposted by becojo
Rachel Tobac @racheltobac.bsky.social · 30/07/2026
The new “⚠️Seems like AI slop” button on LinkedIn is sending me into orbit lmao
1419735
Reposted by becojo
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 07/07/2026
You shouldn’t trust Trusted Publishing blog.yossarian.net/2026/07/07/You-s… #python #security #oss
01510
Reposted by becojo
Seth Larson @sethmlarson.dev · 10/06/2026
Every code generation LLM model available will at some point suggest insecure code as a part of “code completion”. Should this behavior be considered a vulnerability? #security #opensource #programming sethmlarson.dev/are-insecure...
sethmlarson.dev
Are insecure code completions a vulnerability?
Three months ago I saw that PyCharm shipped with a “Full Line Completion” plugin that “uses a local deep learning model to suggest entire lines of code”. These suggestions manifest as whole-line su...
53610
Reposted by becojo
Ken Klippenstein @kenklippenstein.bsky.social · 28/05/2026
If you're worried about AI data centers, Congress is taking notice — not by passing any laws, but by spying on critics through its new intelligence bureau: www.kenklippenstein.com/p/exclusive-...
kenklippenstein.com
Exclusive: New Intel Bureau Eyes AI Data Center Critics
Congress has its own CIA and it’s sounding the alarm about anti-AI grievances
8324117
Reposted by becojo
Janne M. Korhonen @jmkorhonen.fi · 26/05/2026
I well recall the online debates where the majority of debaters opined that zero traffic deaths is an utopian goal and would require methods that would kill Helsinki, if not bring about totalitarian communism
222075528
Reposted by becojo
Brian Merchant @bcmerchant.bsky.social · 11/05/2026
What so many have experienced personally has been confirmed by a new study: AI has been a disaster for working artists.
bloodinthemachine.com
The AI-inflected crisis artists are facing, in 4 charts
An alarming new study reveals the dire impact AI is having on artists' livelihoods. It does offer some hope, too.
211150487
Reposted by becojo
Filippo Valsorda @filippo.abyssdomain.expert · 28/04/2026
… are fucking kidding me. A github.com cross-account RCE due to the most pedestrian of injection attacks along the obvious exposed surface… and they actually have a globally shared “git” UNIX user!! This is not what taking the role of supply chain stewards seriously looks like.
wiz.io
GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog
A CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution. Read the threat brief and find vulnerable GHES instances from Wiz.
735099
Reposted by becojo
Socket @socket.dev · 23/04/2026
🚨 Bitwarden CLI 2026.4.0 was compromised as part of the ongoing Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline. We’ll continue updating our coverage as more details are confirmed. socket.dev/blog/bitward...
socket.dev
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain ...
Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.
43417
Reposted by becojo
Matt Brown @mattbrown.bsky.social · 11/04/2026
Okay CTA. This is a good sign.
90243034519
becojo @becojo.com · 29/03/2026
TIL the Raspberry Pi firmware supports the storage of ECDSA private keys which allows the user-space to sign data. I ported rpifwcrypto in Go to add the ability to sign ES256 JWT tokens and export public keys as JWKS or PEM to authenticate with external services. github.com/ezoidc/go-rp...
github.com
GitHub - ezoidc/go-rpi-crypto: Pure Go library and CLI to access the Raspberry Pi's firmware cryptographic functions
Pure Go library and CLI to access the Raspberry Pi's firmware cryptographic functions - ezoidc/go-rpi-crypto
010
becojo @becojo.com · 26/03/2026
turn it off here github.com/settings/cop...
github.blog
Updates to GitHub Copilot interaction data usage policy
From April 24 onward, interaction data from Copilot Free, Pro, and Pro+ users will be used to train and improve our AI models unless they opt out.
010
Reposted by becojo
Joseph Cox @josephcox.bsky.social · 03/03/2026
New from 404 Media: CBP tapped into the online advertising ecosystem to track peoples' movements, according to an internal DHS document. Shows for the first time DHS tracked phones via process for putting ads in ordinary apps—video games, fitness apps, many more www.404media.co/cbp-tapped-i...
404media.co
CBP Tapped Into the Online Advertising Ecosystem To Track Peoples’ Movements
An internal DHS document obtained by 404 Media shows for the first time CBP used location data sourced from the online advertising industry to track phone locations. ICE has bought access to similar t...
281170722
Reposted by becojo
Zack Whittaker @zackwhittaker.com · 10/02/2026
Even the internet's favorite dog account calls out Ring video cameras what they are: Mass surveillance.
18731
Reposted by becojo
Kevin Beaumont @doublepulsar.com · 09/12/2025
Notepad++ have published an update to fix the software being hijacked by threat actors remotely: notepad-plus-plus.org/news/v889-re... This was being abused by threat actors in China, a blog from mine from a week ago: doublepulsar.com/small-number...
notepad-plus-plus.org
Notepad++ v8.8.9 release: Vulnerability-fix | Notepad++
510032
Reposted by becojo
antirez @antirez.bsky.social · 11/01/2026
New blog post: Don't fall into the anti-AI hype. antirez.com/news/158
2027260
Reposted by becojo
Joseph Cox @josephcox.bsky.social · 07/01/2026
New: DHS is lying to you. At least four videos show what really happened when ICE shot a woman in Minneapolis. Shots clearly fired while vehicle already turning away from the officer. But DHS lied. Trump lied. Noem lied. Even judges have catalogued DHS' serial lying www.404media.co/dhs-is-lying...
404media.co
DHS Is Lying To You About ICE Shooting a Woman
At least four videos show what really happened when ICE shot a woman in Minneapolis on Wednesday. DHS has established itself as an agency that cannot be trusted to live in or present reality.
211440561
becojo @becojo.com · 31/12/2025
TUIs are clunky and overrated
110
becojo @becojo.com · 26/12/2025
it must feel good for the LLM to glaze humans
110
becojo @becojo.com · 24/12/2025
happy yearly exposure to cable tv for those who celebrate
010
Reposted by becojo
Merriam-Webster @merriam-webster.com · 15/12/2025
bit.ly/453uzfx
bit.ly
2025 Word of the Year: Slop
Plus 'gerrymander', 'touch grass', 'performative', and other words that defined the year
251451250
Reposted by becojo
404 Media @404media.co · 18/11/2025
After 404 Media's months-long reporting and pressure from lawmakers, the data broker owned by the U.S.’s major airlines will now shut down a program in which it sold access to hundreds of millions of flight records to the government and let agencies track peoples’ movements without a warrant.
404media.co
Airlines Will Shut Down Program That Sold Your Flights Records to Government
The move comes after intense pressure from lawmakers and 404 Media’s months-long reporting about the airline industry's data selling practices.
91186447
Reposted by becojo
Nicolas Grégoire @agarri.fr · 16/11/2025
Argument injection (and RCE) in three distinct AI agents blog.trailofbits.com/2025/10/22/p...
blog.trailofbits.com
Prompt injection to RCE in AI agents
We bypassed human approval protections for system command execution in AI agents, achieving RCE in three agent platforms.
085
becojo @becojo.com · 12/11/2025
"an agent is simply an LLM call in a loop" sure and a web server is just accept(2) in a loop
020
becojo @becojo.com · 29/07/2025
👀 bsky.app/profile/bsky...
120
Reposted by becojo
Whitney Merrill @wbm312.bsky.social · 22/06/2025
Identifying birds using the Merlin Bird ID is real life Pokémon.
4516
Reposted by becojo
rkletr @merkletr.ee · 18/05/2025
My writeup for @northsec.io CTF 2025's "Containers" reverse track: merkletr.ee/ctf/2025/nse...
merkletr.ee
NorthSec 2025: Containers
012
Reposted by becojo
Zack Whittaker @zackwhittaker.com · 30/04/2025
If there's one thing I've learned about covering cybersecurity over the past decade or so, is that the cybersecurity community (the fixers and breakers) and the cybersecurity industry (profits above all else) are two very, very different things.
721054
Reposted by becojo
MontréHack @montrehack.bsky.social · 10/03/2025
👋 Hello Bsky! MontréHack is a bilingual, monthly cybersecurity workshop in Montreal where challenge designers present their CTF challenges and participants solve them.
022
Reposted by becojo
Émilio Gonzalez @res260.xyz · 31/01/2025
Fellow cybersecurity folks: Make sure to follow @northsec.bsky.social if you came to bluesky from Twitter! Great conference in Montreal and probably the biggest on-site CTF in the world.
035
Reposted by becojo
Zack Whittaker @zackwhittaker.com · 27/12/2024
New, w/ @lorenzofb.bsky.social: Data-loss prevention startup Cyberhaven was hacked to publish a malicious update to its Chrome extension, affecting potentially thousands of users. A security researcher says other big Chrome extensions were hacked in the same campaign. techcrunch.com/2024/12/27/c...
techcrunch.com
Cyberhaven says it was hacked to publish a malicious update to its Chrome extension | TechCrunch
The data-loss startup says it was targeted as part of a "wider campaign to target Chrome extension developers."
0105
becojo @becojo.com · 26/12/2024
Design Space for Code Search Query ast-grep.github.io/blog/code-se...
ast-grep.github.io
Design Space for Code Search Query
A review of the design space for code search tools.
020
Reposted by becojo
Ricochet Media @ricochetmedia.bsky.social · 17/12/2024
Dying to win: Canadian provinces are expanding legal gambling despite ‘one death every nine days.’ Michener-funded investigation into gambling-related suicide data shows tracking of deaths lags, while governments ignore risks to chase industry profits. ricochet.media/justice/dyin... #cdnpoli
ricochet.media
Dying to win: Canadian provinces are expanding legal gambling despite one death every nine days
Investigation into gambling-related suicide data shows tracking of deaths lags while governments ignore risks to chase industry profits
26641
Reposted by becojo
Louis Dion-Marcil @ldionmarcil.bsky.social · 06/12/2024
I wrote a thing with my colleague Ilyass El Hadi (0xc0ffee_) & Charles Prevost, about how we've been leveraging offensive webapp testing during Red Teams. 4 use cases of external breaches using webapps inside, enjoy! #appsec cloud.google.com/blog/topics/...
cloud.google.com
Bridging the Gap: Elevating Red Team Assessments with Application Security Testing | Google Cloud Blog
Red team and targeted external assessments should incorporate application security expertise to better simulate modern adversaries.
0187
Reposted by becojo
Uncle Joe @sydseter.com · 01/12/2024
Please vote for better 2FA support on bsky! github.com/bluesky-soci...
github.com
2-Factor Authentication Support · Issue #1071 · bluesky-social/social-app
Is your feature request related to a problem? Please describe. 2Factor authentication is generally a very handy feature for security purposes as passwords and logins sometimes fail. 2Factor Authent...
68734
Reposted by becojo
Louis Dion-Marcil @ldionmarcil.bsky.social · 21/11/2024
Been having a ton of fun solving these, only 2/3 done and i'm quite humbled so far challenge-xss.quiz.flatt.training
challenge-xss.quiz.flatt.training
Flatt Security XSS Challenge
Execute alert(origin) on each challenge origins.
062
becojo @becojo.com · 21/11/2024
add that to the reasons to stop using bash in production pipelines yossarian.net/til/post/som... #security #cicd #appsec
yossarian.net
TIL: Some surprising code execution sources in bash
051
Reposted by becojo
Catalin Cimpanu @campuscodi.risky.biz · 14/11/2024
PyPI replaces PGP signatures with digital attestation system blog.pypi.org/posts/2024-1...
blog.pypi.org
PyPI now supports digital attestations - The Python Package Index Blog
Announcing support for PEP 740 on the Python Package Index
042