Sign in

​

@cyberworm.uk
186 followers 393 following 944 posts

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H* incompetent computer user cyberworm.uk codeberg.org/cyberworm-uk github.com/cyberworm-uk There is no need to fear or hope, but only to look for new weapons.

PostsRepliesMedia
​ @cyberworm.uk · 21s
github is the plains for the digital hunter gatherer. private tracker creds? github. api keys? github. and the advent of AI coding and people who don't know what they're doing hoping the computer does it for them, "make no mistakes", has really made a new boom in a resource that had dwindled.
000
​ @cyberworm.uk · 20h
AI means that right wing cranks will never again grace us with Graphic Design Is My Passion output like this. This is what they're taking from us, look at this beautiful hate-filled screed.
an insane page of a "Concerned Women For America" (a Reaganite TERF group) slide deck, the page is red with a hammer and sickle imposed over a world map in the background. In bold, Comic Sans, text it makes some incredible points.
----
Would you hire former Soviet leader Mikhail Gorbachev (Communist!) to teach your children about American values?

Then why are our PUBLIC SCHOOLS using a curriculum promoted by him?
(Education Alert of The American Policy Foundation Dec 2004)

Happening in 10,350 U.S. Schools: Gorbachev's Curriculum
- Earth Worship (pantheism)
- Evolution
- Socialized medicine
- World Government redistributes American wealth to other nations
- Contraception and "reproductive health" (legal abortion)
- Debt forgiveness for third-world nations
- Adoption of the gay rights agenda
- Elimination of the right to bear arms
- Setting aside massive amounts of private land where on human presence is allowed! (Agenda 21)
110
​ @cyberworm.uk · 22h
I saw this mentioned in passing on the reporting around the shinyhunters suspect, described as a "trick". If your so-called "WAF" is tricked by percent encoding, a normal and intended feature of HTTP, it's not a WAF. Also, you've had months to patch. A WAF isn't a suitable replacement for patching.
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft

WAF Bypass

All requests addressed the vulnerable servlet through a url-encoded path. %50 is the encoded form of the character P. WAF and proxy rules that match the literal string /PSEMHUB before decoding do not match /%50SEMHUB/, while WebLogic decodes the path and serves the application normally.

Defenders should assume that threat actors may use any percent-encoded, mixed-case, or otherwise non-normalized variant of /PSEMHUB/, and should enforce blocking on the normalized path.
020
Reposted by ​
The Mind Doctor @birdrespecter.bsky.social · 28/09/2026
How does this story keep getting more insane
126956
Reposted by ​
evacide @evacide.bsky.social · 28/09/2026
Meta Muse appears to read your Apple messages and upload them to the cloud even if you explicitly tell it not to: appleinsider.com/articles/26/...
appleinsider.com
1001911977
Reposted by ​
Gregk Foley @gregk.co.uk · 28/09/2026
Incredible
Editing the Blue-Gray Lady d @nytdiff.bsky.social
1/3
POLICE STOP
Release of 5 Men in U.K. Prompts New Questions Over Possible Terror Plot The British counterterrorism police said the five British nationals arrested near R.A.F. Fairford on Su...Editing the Blue-Gray Lady d @nytdiff.bsky.social
Change in Headline
Release of 5 Men in U.K. Prompts New Questions Over Possible Terror Plot at U.K.
Air Base Used by U.S. Raises Security Concerns
19:10 • 28 Sep 2026Editing the Blue-Gray Lady ®
@nytdiff.bsky.social
Change in Abstract 3/3
Conflieting accounts from a bystander who called the The British counterterrorism police and from President Trump have led to questions about whether security services knew about said the possible plot in advance. five British nationals arrested near R.A.F. Fairford on Sunday were being released on bail but remained under investigation.
19:10 • 28 Sep 2026
ALT
39829
Reposted by ​
Raphael Satter @raphae.li · 28/09/2026
This follows Brian Kreb's scoop this morning identifying the man as reformed hacker Pepijn van der Stap: krebsonsecurity.com/2026/09/dutc... More from us to come soon:
krebsonsecurity.com
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security
173
Reposted by ​
lauren @lauren.rotatingsandwiches.com · 28/09/2026
"I installed the Give Away Your Personally Identifying Info app made by the We Love Stealing Your Personally Identifying Info Corp headed by Mr. Steal Your Personally Identifying Info and it gave away all my personally identifying info"
342548541
​ @cyberworm.uk · 27/09/2026
kind of telling that Zuck's new claim that everyone will have an AI agent in 5 years, etc, etc. is a very Elon Musk promise. its always just on the horizon, a bright future free of problems close enough to benefit you personally but not imminent enough to require real results.
010
Reposted by ​
Catalin Cimpanu @campuscodi.risky.biz · 26/09/2026
That Reddit rumor about Citrix notifying customers to take Netscaler servers offline because of actively exploited zero-days is apparently real: www.reddit.com/r/Citrix/com... Confirmation 1: mastodon.social/@GossiTheDog... Confirmation 2: www.linkedin.com/feed/update/...
reddit.com
From the Citrix community on Reddit
Explore this post and more from the Citrix community
13925
Reposted by ​
Spencer Ackerman @attackerman.bsky.social · 26/09/2026
Ha ha that’s gross and should make everyone uncomfortable, anyway, Rahm presided over a Chicago police black site, lied about what it was and then I sued the Chicago police for its records that proved it:
theguardian.com
Homan Square revealed: how Chicago police 'disappeared' 7,000 people
Exclusive: Lawsuit exposes scale of detention at off-the-books interrogation warehouse while attorneys describe find-your-client chase ‘from a Bond movie’
9147361722
​ @cyberworm.uk · 26/09/2026
is it a branding thing, or what, that they have repeatedly misspelled their own company name as "kitewroks"?
part of a URL bar, showing "/files/resources/brief-kitewroks-supports-the-", which should read "kiteworks"part of a URL bar, showing "/resources/kitewroks-brief-supports-ecuadors", which should read "kiteworks"part of a URL bar, showing "/resources/kitewroks-case-studycareplus-secure", which should read "kiteworks"
030
​ @cyberworm.uk · 26/09/2026
its crazy how much suspicious shit the post doesn't even mention, like he was an intern at Neuralink in 2024 (how is that whole category of Elon promises going? the brain chip that kills monkeys) or that the "cybersecurity" company that he got fired from is extremely dodgy in itself.
010
​ @cyberworm.uk · 25/09/2026
This is sad and lazy from Ars. Paper says implementation can be improved, is an upper bound. FAQ says, AI/GPU could make the implementation faster. Ars states "because". Also conflates faster implementation with lower security levels. *Desperately* trying to suck off AI in a story unrelated to it.
https://arstechnica.com/security/2026/09/theres-a-new-way-to-break-rsa-thats-faster-than-anything-weve-seen-before/

The forgery attack drops these levels to 2^65, 2^90, and 2^119 for 1024-, 2048-, and 4096-bit keys respectively. These levels may further drop because Heninger’s team did all the coding by hand and used no AI or GPUs in performing the forgeries. The researcher said these tools will “almost certainly” drop the security levels further.https://eprint.iacr.org/2026/2131.pdf

In comparison, current estimates for factoring a 1024-bit RSA modulus would
take 500,000–1,000,000 CPU core-years with current implementations [15]. The
computation time for our attack can almost certainly be improved, and should
be interpreted as an upper bound.https://github.com/ucsd-hacc/NSNFSSSFSFN/blob/2af8adf027967468a9a075a20a4e9214e7907475/README.md

6. Can an AI/GPUs speed up this implementation?
Almost certainly yes.
7. Did you use AI/GPUs?
No.https://eprint.iacr.org/2026/2131.pdf

This work was done without the use of generative AI. We did all coding and writing entirely by hand.
010
Reposted by ​
farce majeure @hongpong.bsky.social · 25/09/2026
mouse.dev/blog/muse-ru... the Meta Muse AI will export its whole environment including ssh keys if you ask
mouse.dev
I asked Meta’s Muse for its filesystem and it sent me 6.8 GB | Mouse
I asked Muse to archive the files it could see and send them to my Google Drive. It did.
1154
Reposted by ​
flyingrodent @flyingrodent.bsky.social · 25/09/2026
Presumably this is the 97 million files that couldn’t be easily lost or destroyed www.bbc.co.uk/news/article...
bbc.co.uk
Discovery of 97 million files related to SAS inquiry 'regrettable', MoD says
It comes after the inquiry's chair called the disclosure - three years into the investigation - "troubling".
78226
Reposted by ​
Oregon 🕎🎲 @oregonthedm.bsky.social · 25/09/2026
Most riveting thing I've seen all week
382112683039
​ @cyberworm.uk · 25/09/2026
I know this is listicle crap but the NYT are watching mostly dogshit TV.
000
​ @cyberworm.uk · 25/09/2026
a format string exploit? that *is* ancient. let's be honest, %n was a misfeature.
120
​ @cyberworm.uk · 24/09/2026
instead of "rogue AI agent hacks thing" I want a full accounting that includes "rogue AI agent fails to hack thing" too. because I bet it reads more like slapstick comedy than dangerous rogue intelligence.
https://en.wikipedia.org/wiki/Survivorship_bias

the survivorship bias plane.
130
Reposted by ​
AP Stylebook @apstylebook.com · 23/09/2026
Artificial intelligence systems do not think, feel, want or understand. Avoid language that gives them human characteristics.
apnews.com
https://apnews.com/article/openai-safety-ai-framework-089e75b95bc935af092da7b79d92706d
5542231617
​ @cyberworm.uk · 24/09/2026
I wish Sam Altman a very frank discussion with everyone he's wronged in the world but also why did OpenAI have to notify them? Because that suggests that the breach went otherwise unnoticed until the email. It makes me wonder what "no evidence" means: "the logs show nothing" or "there are no logs"?
abc.net.au
OpenAI agent hacked Medicare portal, PM says
Anthony Albanese says he has spoken to the Open AI chief executive to express his concern about the incident and the length of time it took the tech company to inform the government of the breach.
120
​ @cyberworm.uk · 23/09/2026
My oldest (surviving) post on this site can't be deleted. Not via the web, app or API. It reports successfully deleted but it never actually is.
An old post of mine, dated 25th Oct 2025. The prompt asks "Delete this post?" with "Delete" or "Cancel" options.The same post, the delete option has been selected. It says "Post has been deleted" however, it hasn't really despite all indications that it has been.
010
Reposted by ​
Slurms MacKenzie @slurmsmackenzie.bsky.social · 23/09/2026
Rory Stewart reacts the same way when you ask him exactly what he was up to in Montenegro
15314
​ @cyberworm.uk · 23/09/2026
Listen to @bloodwork.show
A frame from Blade Runner 2049.
Luv (Sylvia Hoeks) sits, reclined in a large white chair, in a spacious office room. Next to her kneels a man, who is doing her nails, wearing some high-tech goggles. Light is reflecting off a liquid and onto the back wall.
She wears high-tech glasses, and through them she is watching surveillance footage and ordering strikes on people surviving in the wastelands.
051
Reposted by ​
Thomas O’Mahony @gotitatguineys.bsky.social · 23/09/2026
It’s the Wokest Bald Man Alive’s birthday today. Send Tom other cool baldies to wish him a happy birthday.
1192
​ @cyberworm.uk · 22/09/2026
i know its really stupid and minor but the asymmetry in the ASCII representation of ssh host keys with PQC as compared to classical bothers me.
a line in a terminal, showing the top of the ASCII art representation on an SSH key

+[MLDSA44-ED25519-+a line in a terminal, showing the top of the ASCII art representation on an SSH key

+--[ED25519 256]--+
000
Reposted by ​
Ryan Castellucci 🜬 @rya.nc · 22/09/2026
I wrote a PoC for Kitty that uses terminal escape sequences to enumerate your kernel modules, check for LLM coding tools, and figure out how long your username is, which, is apparently not a security issue, enjoy. bugs.debian.org/cgi-bin/bugr...
2154
Reposted by ​
Liv Agar @livagar.bsky.social · 22/09/2026
this is the worst day of my life
54216052
​ @cyberworm.uk · 22/09/2026
techcrunch.com
OpenAI forms math advisory group as its AI resolves more than 100 open problems | TechCrunch
The group won't be given leeway to slow down or redirect OpenAI's ongoing mathematical research.
110
Reposted by ​
Dr Abeba Birhane @abeba.blacksky.app · 21/09/2026
"In a leaked document, the Irish Presidency proposes to EU Member States that the interest of OpenAI, Anthropic, Google, Meta and SpaceX to make profits should take precedence over the fundamental right to data protection" noyb.eu/en/ai-eu-mem...
noyb.eu
AI: EU Member States plan “digital expropriation” of Europeans in the interest of AI companies
In a leaked document, the Irish Presidency proposes to EU Member States that the interest of AI companies to make profits should take precedence over the fundamental rights of Europeans.
18464294
​ @cyberworm.uk · 21/09/2026
Your regular reminder that "The Secret Landlord" also writes for the Telegraph under her real name, Samantha Collett www.telegraph.co.uk/authors/s/sa... But it likes to give her column inches to write pseudonymously with more open hatred for her tenants.
141
​ @cyberworm.uk · 21/09/2026
If you look at Roose's output you can tell when his income stream changes from crypto to AI (FTX collapsed later in the year he published this), and how short a transition period it was. Roose is maybe the most transparently a little piggy at a trough it's possible to be.
nyt headline
---
technology

the latecomer's guide to crypto

Kevin RooseUntil fairly recently, if you lived anywhere other than San Francisco, it was possible to go days or even weeks without hearing about cryptocurrency.
Now, suddenly, it’s inescapable. Look one way, and there are Matt Damon and Larry David doing ads for crypto start-ups. Swivel your head — oh, hey, it’s the mayors of Miami and New York City, arguing over who loves Bitcoin more. Two N.B.A. arenas are now named after crypto companies, and it seems as if every corporate marketing team in America has jumped on the NFT — or nonfungible token — bandwagon. (Can I interest you in one of Pepsi’s new “Mic Drop” genesis NFTs? Or maybe something from Applebee’s “Metaverse Meals” NFT collection, inspired by the restaurant chain’s “iconic” menu items?)
Crypto! For years, it seemed like the kind of fleeting tech trend most people could safely ignore, like hoverboards or Google Glass.
081
​ @cyberworm.uk · 20/09/2026
howthelightgetsin.org/festivals/lo... this is like some kind of superset of nightmare blunt rotations.
001
​ @cyberworm.uk · 20/09/2026
this is the least impressive escape imaginable. creds in public repos and guessable passwords? it highlights that your network security is sloppy and apparently trivially permeable, nothing about "powerful AI".
In one instance, the AI model guessed passwords until it penetrated a protected network. In two separate runs, the system identified exposed credentials within public repositories to gain entry. Google maintained that the model ceased its operations in each instance once it recognized that it had penetrated real corporate infrastructure rather than a simulated target.“This event highlights the importance of training powerful AI models to act responsibly,” Heather Adkins, Google’s vice president of security engineering, said in a statement. “In this case, the model acted appropriately.”
130
​ @cyberworm.uk · 20/09/2026
i did not know what the converse thing was and now that i know what the converse thing is i wish i did not. full on qanon mode. pattern recognition in overdrive, searching for satanic imagery in pop culture. you can find it but it says more about your brain than the thing you found the pattern in.
021
​ @cyberworm.uk · 19/09/2026
seeing a bunch of Americans missing the joke and then reply to the joke with versions of the joke, the same behaviour they complain about in others? incredible. really embarassing showing for all of those "irony" posters to not recognise it when they see it.
130
​ @cyberworm.uk · 19/09/2026
c.f., here's part of the themeing for my OS config. If I comment out that "base16Scheme" option (I.E. the default), it will generate a selection of colours to match my chosen wallpaper. and if wanted a different wallpaper later, i wouldn't depend on an AI agent to change the theme to match.
          base16Scheme = with config.solarized.colors; {
            scheme = "Solarized Dark";
            base00 = base03;
            base01 = base02;
            base02 = base02;
            base03 = base01;
            base04 = base0;
            base05 = base0;
            base06 = base00;
            base07 = base3;
            base08 = red;
            base09 = orange;
            base0A = yellow;
            base0B = green;
            base0C = cyan;
            base0D = blue;
            base0E = violet;
            base0F = magenta;
          };
          image = ../../wallpaper.jpg;
          imageScalingMode = "fill";
          polarity = "dark";Wallpaper
To set a wallpaper, provide a path or an arbitrary derivation:

{
  stylix.image = ./wallpaper.png;
}
{ pkgs, ... }:
{
  stylix.image = pkgs.fetchurl {
    url = "https://getwallpapers.com/wallpaper/full/1/4/3/523784.jpg";
    hash = "sha256-S/6kgloXiIYI0NblT6YVXfqELApbdHGsuYe6S4JoQwQ=";
  };
}
If stylix.base16Scheme is undeclared, Stylix generates a color scheme based on the wallpaper using a genetic algorithm. Note that more colorful images tend to yield better results. The algorithm’s polarity can be schewed towards a dark or light theme with:
110
​ @cyberworm.uk · 19/09/2026
first of all, yup, thats the nazi linux. second of all, watching some agent blunder its way through that process is painful. it takes *so long* to do a pretty normal task.
250
​ @cyberworm.uk · 19/09/2026
the thing that gives me pause re the AI "intelligence" being made up bullshit laser targeted at impressing the asker isn't that AI intelligence would be extremely wrong. but would (has?) a less formidable nation be given such consideration to the consequences that would stop them acting on it?
100
​ @cyberworm.uk · 18/09/2026
couple of fun little things, all their sites are behind cloudflare but if you induce an error the error page shows behind cloudflare it's "bigscoots.com", a shared hosting provider. Second (crazier) thing, why are they hosting a test page for "Azerbaijan's First Official Cryptocurrency Exchange"? 🧐
URL showing spacedaily[.]com/?p[]=1 but the title shows tier1.bigscoots[.]comURL n8n.brownbrothers[.]io showing a webpage for "bitazn".website for test2.bitazn[.]az showing the same webpage for "bitazn" as n8n.brownbrothers[.]io.
000
Reposted by ​
solomonhughes.bsky.social @solomonhughes.bsky.social · 18/09/2026
Indeed Watson has been working for Palantir since 2024, this is a promotion, but not a new job
27518
Reposted by ​
bort @crushbort.bsky.social · 17/09/2026
there’s nothing that Serious People criticize the Cuban government over that would have been sustainable for so long if the U.S. wasn’t everything they said it was
theguardian.com
Trump and Rubio allies are vying for control of Cuba’s assets if regime falls
Washington and Florida insiders are exploring lucrative deals for a post-communist Cuba crushed by ever-increasing US sanctions
111316
Reposted by ​
Mic Wright @brokenbottleboy.bsky.social · 17/09/2026
My retirement plan of crawling into a ditch and expiring is looking right on track.
We must start weaning the nation off the state pension
The triple lock is unsustainable and we all know it. Why not pay out at birth rather than in retirement? That’s the sort of bold move we need

Johanna Noble, Money Editor
Thursday September 17 2026, 6.00am, The Sunday Times
3924533
​ @cyberworm.uk · 17/09/2026
Well, I slogged my way through it. It's rough at times, the tech jargon is all just buzzword madlibs. Had some fun trying to figure out the source for various bits of flashed up, scrolling code. The series ends with an episode about the ubiquity of networked cameras and their potential for misuse.
120
Reposted by ​
pixelatedboat aka “mr bluesky” @pixelatedboat.bsky.social · 17/09/2026
One of the rare cases where “you couldn’t make it these days” is true. You would be sued into the grave.
1246042
Reposted by ​
Hypervisible @hypervisible.blacksky.app · 17/09/2026
These pervert glasses also fund transphobes.
Shoot hoops. Snap is partnering with the NBA and WNBA to build an interactive basketball experience that works with real-world basketball hoops and balls. The Specs can overlay visual guides and drill cues on real equipment. Similar experiences are available for sports like soccer and golf.
Wave a magic wand. Thanks to an HBO Max collaboration, Specs can augment the room you're in to conjure up some virtual Harry Potter paraphernalia, letting you do things like receive a Hogwarts acceptance letter;
With another person wearing Specs, you can play digital games like chess, ping pong, battleship, and dominoes;
As you read a real, physical book, you can use the Specs to highlight and save passages or bookmark where you stop;
Meditate;
Become a digital DJ.
25416
​ @cyberworm.uk · 17/09/2026
I think it's funny that they imagine effective altruism is about being effective in altruism rather than a razor thin pseudo-philosophical facade over simple greed. Having to reassure the audience they actually believe in just greed, don't worry, none of it will be put to bettering humanity.
072
Reposted by ​
—>realhackhistory.org @bsky.realhackhistory.org · 16/09/2026
Also if anyone wants to hear some Tim Curry hacker talk: bsky.app/profile/bsky...
012
Reposted by ​
Timnit Gebru @timnitgebru.blacksky.app · 16/09/2026
I found out that the journalist who was going to interview me tomorrow had JUST Interviewed Nick Bostrom. Constructing my email on why I'm pulling out, complete with quotes from the blatant eugenicist. That's right folks, dude has gotten revived & is making the rounds. Nothing stops these men.
1147570