Artis3n's Avatar

Artis3n

@hackthedigital.cloud

Doing application security things. He/him

50
Followers
71
Following
5
Posts
15.05.2023
Joined
Posts Following

Latest posts by Artis3n @hackthedigital.cloud

Post image

This has everything: malleabile encryption, complex packets, memory safety, unsafe terminal UI, wontfix.

Incredible.

Plaintext exfiltration if you just click a link.

I canโ€™t be convinced gpg can be used safely.

27.12.2025 16:53 ๐Ÿ‘ 103 ๐Ÿ” 18 ๐Ÿ’ฌ 5 ๐Ÿ“Œ 4

I donโ€™t think anyone is prepared for what they just did w/ ICE.

This is not a simple budget increase. It is an explosion - making ICE bigger than the FBI, US Bureau of Prisons, DEA,& others combined.

It is setting up to make whatโ€™s happening now look like childโ€™s play. And people are disappearing.

03.07.2025 18:58 ๐Ÿ‘ 97268 ๐Ÿ” 37815 ๐Ÿ’ฌ 4432 ๐Ÿ“Œ 2658
Preview
TeleMessage suspends services after hackers claim breach The app was seemingly used by Mike Waltz in last week's cabinet meeting, according to a photograph published by Reuters.

NEW: TeleMessage, the Signal knockoff used by Mike Waltz and potentially other gov officials to archive group chats in plaintext, has suspended all services after it was hacked *at least twice.* @404media.co reported a hack last night; a different hacker also broke in and gave me evidence.

05.05.2025 19:05 ๐Ÿ‘ 2718 ๐Ÿ” 1032 ๐Ÿ’ฌ 52 ๐Ÿ“Œ 164

Hours ago, @politico.com revealed that DOGE is working with DHS on automating mass deportation efforts โ€” likely explaining why many US citizens, green card holders, and even a Canadian (in Canada) got threatening emails last night terminating โ€œyour paroleโ€ and telling them to leave the US in 7 days.

12.04.2025 02:53 ๐Ÿ‘ 8553 ๐Ÿ” 4753 ๐Ÿ’ฌ 291 ๐Ÿ“Œ 546
Vittoria Elliott Leah Feiger
Feb 7, 2025 2:47 PM
A US Treasury Threat Intelligence Analysis Designates DOGE Staff as โ€˜Insider Threatโ€™
An internal email reviewed by WIRED calls DOGE staff's access to federal payments systems โ€œthe single biggest insider threat risk the Bureau of the Fiscal Service has ever faced.โ€

Vittoria Elliott Leah Feiger Feb 7, 2025 2:47 PM A US Treasury Threat Intelligence Analysis Designates DOGE Staff as โ€˜Insider Threatโ€™ An internal email reviewed by WIRED calls DOGE staff's access to federal payments systems โ€œthe single biggest insider threat risk the Bureau of the Fiscal Service has ever faced.โ€

NEW: An internal email obtained by WIRED from a threat intelligence team monitoring US Treasury systems advised labeling DOGE operatives an "insider threat," adding that it recommended suspending their access "immediately."
|
www.wired.com/story/treasu...

07.02.2025 19:57 ๐Ÿ‘ 18173 ๐Ÿ” 6210 ๐Ÿ’ฌ 314 ๐Ÿ“Œ 392
Preview
The US Treasury Claimed DOGE Technologist Didnโ€™t Have โ€˜Write Accessโ€™ When He Actually Did Sources tell WIRED that the ability of DOGE's Marko Elez to alter code controlling trillions in federal spending was rescinded days after US Treasury and White House officials said it didn't exist.

DOGE operative Marko Elez got the ability to alter US Treasury payment system code on Feb 1, WIRED's sources say.

For days, Trump officials fed members of Congress and the press a different story.

Elez is out now for posts reading "I was racist before it was cool" and "normalize Indian hate."

07.02.2025 00:16 ๐Ÿ‘ 2958 ๐Ÿ” 1217 ๐Ÿ’ฌ 125 ๐Ÿ“Œ 91
Preview
A 25-Year-Old Is Writing Backdoors Into The Treasuryโ€™s $6 Trillion Payment System. What Could Possibly Go Wrong? Just months after we learned Chinese hackers had compromised US telecom systems through government-mandated backdoors, an inexperienced developer from Muskโ€™s DOGE unit is pushing untested codโ€ฆ

Okay, let's keep going. Got another one today looking at just how absolutely fucking crazy it is that an inexperienced Musk-lackey is apparently pushing untested live code to America's checkbook. Tried to contextualize all of it.

www.techdirt.com/2025/02/05/a...

05.02.2025 18:53 ๐Ÿ‘ 2029 ๐Ÿ” 844 ๐Ÿ’ฌ 90 ๐Ÿ“Œ 83
Preview
Elon Musk's Friends Have Infiltrated Another Government Agency Elon Muskโ€™s former employees are trying to use White House credentials to access General Services Administration tech, giving them the potential to remote into laptops, read emails, and more, sources ...

NEW: Elon Musk's friends have infiltrated the GSA and they're looking for ways to use White House credentials to access agency tech, potentially allowing them to remote into laptops, read emails, and more, sources say.

w/ @zoeschiffer.bsky.social

www.wired.com/story/elon-m...

31.01.2025 23:34 ๐Ÿ‘ 5383 ๐Ÿ” 3068 ๐Ÿ’ฌ 313 ๐Ÿ“Œ 495
Preview
Elonโ€™s Twitter Destruction Playbook Hits The US Government, And Itโ€™s Even More Dangerous Remember how Elon Musk destroyed Twitter by ripping apart its infrastructure without understanding it? Now imagine that same playbook applied to the federal government. Itโ€™s happening, and thโ€ฆ

โ€œLetโ€™s be crystal clear about whatโ€™s happening: A private citizen with zero Constitutional authority is effectively seizing control of critical government functions.โ€- @mmasnick.bsky.social

www.techdirt.com/2025/01/31/e...

01.02.2025 01:56 ๐Ÿ‘ 734 ๐Ÿ” 287 ๐Ÿ’ฌ 20 ๐Ÿ“Œ 12
Preview
Siri โ€œunintentionallyโ€ recorded private convos; Apple agrees to pay $95M Apple users may get $20 each for up to five Siri-enabled devices.

So it appears Apple has "agreed to pay $95 million to settle a lawsuit alleging that its voice assistant Siri routinely recorded private conversations that were then shared with third parties and used for targeted ads."

But it was "unintentional," so don't worry about it...

03.01.2025 05:32 ๐Ÿ‘ 183 ๐Ÿ” 37 ๐Ÿ’ฌ 12 ๐Ÿ“Œ 16

Mad Enough to Blog Itโ„ข๏ธ www.indignity.net/the-washingt...

10.12.2024 04:46 ๐Ÿ‘ 267 ๐Ÿ” 61 ๐Ÿ’ฌ 6 ๐Ÿ“Œ 8

I donโ€™t know why everyone puts up with turkey. We moved to making fried chicken for Thanksgiving a few years ago and have not looked back

28.11.2024 23:48 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Researchers link Polyfill supply chain attack to huge network of copycat gambling sites | TechCrunch A supply chain hack targeting 100,000 websites was launched to redirect internet users to a massive online gambling network.

NEW: The Polyfill supply chain attack was launched with the goal of redirecting users to thousands of fake Chinese gambling sites, according to security researchers.

FUNNULL, the company allegedly responsible, did not respond to multiple requests for comment.

techcrunch.com/2024/10/22/r...

22.10.2024 16:15 ๐Ÿ‘ 14 ๐Ÿ” 9 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Preview
Millions of Vehicles Could Be Hacked and Tracked Thanks to a Simple Website Bug Researchers found a flaw in a Kia web portal that let them track millions of cars, unlock doors, and start engines at willโ€”the latest in a plague of web bugs thatโ€™s affected a dozen carmakers.

When you build vehicles with remote functionality, you get security and privacy problems like this. For the love of God, please stop building cars with the ability to lock/unlock, stop/start the engine from an app or a website.
www.wired.com/story/kia-we...

26.09.2024 18:41 ๐Ÿ‘ 467 ๐Ÿ” 181 ๐Ÿ’ฌ 28 ๐Ÿ“Œ 17
Preview
Data center emissions likely 662% higher than big tech claims. Can it keep up the ruse? Emissions from in-house data centers of Google, Microsoft, Meta and Apple may be 7.62 times higher than official figures

Google and Microsoft recently admitted their emissions are soaring as they build out data centers to power the AI boom.

But analysis from The Guardian suggests the data center emissions of Google, Meta, Microsoft, and Apple are 662% higher than the companies are reporting.

16.09.2024 16:38 ๐Ÿ‘ 1353 ๐Ÿ” 739 ๐Ÿ’ฌ 29 ๐Ÿ“Œ 192

Wow, the Linux kernel man pages were someone's side project??

16.09.2024 18:13 ๐Ÿ‘ 47 ๐Ÿ” 15 ๐Ÿ’ฌ 4 ๐Ÿ“Œ 3
Post image

The Economist has published a deeply-researched story about car bloat -- and it's very, very damning.

"For every life that the heaviest 1% of SUVs and trucks save, there are more than a dozen lives lost in other vehicles."

Well worth your time: www.economist.com/interactive/...

01.09.2024 15:23 ๐Ÿ‘ 2571 ๐Ÿ” 1311 ๐Ÿ’ฌ 64 ๐Ÿ“Œ 136
Preview
SpaceX repeatedly polluted waters in Texas this year, regulators found SpaceX violated environmental regulations in releasing pollutants into or nearby bodies of water in Texas, a state environmental agency found.

SpaceX's water deluge system repeatedly violated the Clean Water Act, per TCEQ and the EPA. These violations could well scupper SpaceX's bid to massively expand rocket launches at the site.

Great reporting as usual from @lorak.bsky.social

www.cnbc.com/2024/08/12/s...

12.08.2024 19:08 ๐Ÿ‘ 571 ๐Ÿ” 204 ๐Ÿ’ฌ 26 ๐Ÿ“Œ 30

This account might get some views this week, I should probably look like I post (I don't)

06.08.2024 23:07 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
To me it seems not at all unlikely that a future Republican administration would instruct a future FTC to crack down on videos explaining how transgender youth can seek medical care. Sen. Ron Wyden (D-OR), one of the three Senators to vote against the bill, cited that risk as a reason for his position. KOSA could โ€œbe used as a tool for MAGA extremists to wage war on legal and essential information to teens,โ€ Wyden said.

Moreover, itโ€™s not even clear extremists would have to declare war to get platforms to do their bidding. Should KOSA become law, platformsโ€™ logical next step will be to actively suppress content that the law describes as harmful, for fear of being sued otherwise. This is not a theoretical possibility: fear of being accused of violating anti-terrorism laws has led Meta to suppress online speech in Arabic-speaking and Muslim communities, its Oversight Board found earlier this year.

To me it seems not at all unlikely that a future Republican administration would instruct a future FTC to crack down on videos explaining how transgender youth can seek medical care. Sen. Ron Wyden (D-OR), one of the three Senators to vote against the bill, cited that risk as a reason for his position. KOSA could โ€œbe used as a tool for MAGA extremists to wage war on legal and essential information to teens,โ€ Wyden said. Moreover, itโ€™s not even clear extremists would have to declare war to get platforms to do their bidding. Should KOSA become law, platformsโ€™ logical next step will be to actively suppress content that the law describes as harmful, for fear of being sued otherwise. This is not a theoretical possibility: fear of being accused of violating anti-terrorism laws has led Meta to suppress online speech in Arabic-speaking and Muslim communities, its Oversight Board found earlier this year.

KOSA passed the Senate today, which means we're a step closer to the government pressuring sites like this one to remove legal speech www.platformer.news/kosa-coppa-s...

30.07.2024 23:38 ๐Ÿ‘ 112 ๐Ÿ” 42 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Helping our customers through the CrowdStrike outage - The Official Microsoft Blog On July 18, CrowdStrike, an independent cybersecurity company, released a software update that began impacting IT systems globally. Although this was not a Microsoft incident, given it impacts our eco...

Microsoft now says the CrowdStrike crash hit 8.5 million Windows machines. blogs.microsoft.com/blog/2024/07...

I think that's the biggest disruption of computers ever. (Though maybe not the worst, given NotPetya and WannaCry did more lasting damage to hundreds of thousands of machines.)

20.07.2024 18:42 ๐Ÿ‘ 28 ๐Ÿ” 14 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 2
Preview
Vendors' response to my LLM-crasher bug report was dire Fixes have been made, it appears, but disclosure or discussion is invisible

It turns out reporting bugs and major issues with LLMs is just as frustrating if not more than reporting security bugs

Vendors go through stages of denial, push back, silent fixes, and hand-wringing statements about safety, but acceptance? Not quite

www.theregister.com/2024/07/10/v...

10.07.2024 18:16 ๐Ÿ‘ 25 ๐Ÿ” 7 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 1
Preview
Microsoft Chose Profit Over Security and Left U.S. Government Vulnerable to Russian Hack, Whistleblower Says Former employee says software giant dismissed his warnings about a critical flaw because it feared losing government business. Russian hackers later used the weakness to breach the National Nuclear Se...

Microsoft has long downplayed its role in the 2020 "SolarWinds" attack โ€” one of the largest cyberattacks in U.S. history โ€” but a new ProPublica investigation reveals that the tech giant ignored warnings that could have stemmed the damage... ๐Ÿงต
www.propublica.org/article/micr...

13.06.2024 10:52 ๐Ÿ‘ 303 ๐Ÿ” 134 ๐Ÿ’ฌ 7 ๐Ÿ“Œ 13

This will ultimately be fine for what I am doing because I am not defending a high-value target against a determined attacker, but...

I would not trust any insider protection I could build on GitHub honestly. I'd just assume anyone with Write has the keys to the castle.

That's worrying.

08.06.2024 11:55 ๐Ÿ‘ 7 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
To better understand the clash, The Times interviewed Ms. Baden, her mother and her husband, as well as other neighbors, and reviewed the texts that Ms. Baden and her husband sent to friends after the episodes. Justice Alito, who did not respond to questions for this article, has in recent weeks given his own explanation of what happened.

There are some differences: For instance, the justice told Fox News that his wife hoisted the flag in response to Ms. Badenโ€™s vulgar insult. A text message and the police call โ€” corroborated by Fairfax County authorities โ€” indicate, however, that the name-calling took place on Feb. 15, weeks after the inverted flag was taken down.

To better understand the clash, The Times interviewed Ms. Baden, her mother and her husband, as well as other neighbors, and reviewed the texts that Ms. Baden and her husband sent to friends after the episodes. Justice Alito, who did not respond to questions for this article, has in recent weeks given his own explanation of what happened. There are some differences: For instance, the justice told Fox News that his wife hoisted the flag in response to Ms. Badenโ€™s vulgar insult. A text message and the police call โ€” corroborated by Fairfax County authorities โ€” indicate, however, that the name-calling took place on Feb. 15, weeks after the inverted flag was taken down.

Alito lied about the reason the flag was up because he didnโ€™t know the couple had text messages establishing the date of when the incident took place. They were supporting the insurrection. www.nytimes.com/2024/05/28/u...

28.05.2024 23:44 ๐Ÿ‘ 2589 ๐Ÿ” 922 ๐Ÿ’ฌ 68 ๐Ÿ“Œ 111
Climate change is making turbulence worse, although deaths are still rare, experts say | CBC News Most people whoย have flown have likely felt their stomach drop when the "fasten seat belt" sign switches on during a bumpy flight, but turbulence can be severe and experts warn it'sย becoming more common.

Yes, turbulence on planes is getting worse and yes, climate change is a factor

"Our latest future projections indicate a doubling or tripling of severe turbulence in the jet streams in the coming decades, if the climate continues to change as we expect"

www.cbc.ca/news/world/t...

21.05.2024 17:17 ๐Ÿ‘ 451 ๐Ÿ” 159 ๐Ÿ’ฌ 16 ๐Ÿ“Œ 17
Preview
Toxic Gaslighting: How 3M Executives Convinced a Scientist the Forever Chemicals She Found in Human Blood Were Safe Decades ago, Kris Hansen showed 3M that its PFAS chemicals were in peopleโ€™s bodies. Her bosses halted her work. As the EPA now forces the removal of the chemicals from drinking water, she wrestles wit...

Toxic Gaslighting: How 3M Executives Convinced a Scientist the Forever Chemicals She Found in Human Blood Were Safe

www.propublica.org/article/3m-f...

20.05.2024 11:46 ๐Ÿ‘ 309 ๐Ÿ” 146 ๐Ÿ’ฌ 7 ๐Ÿ“Œ 38
Preview
Scarlett Johansson lawyers up over ChatGPT voice that โ€˜shocked and angeredโ€™ her | CNN Business Actress Scarlett Johansson said in a statement shared with CNN on Monday that she was โ€œshocked, angered and in disbeliefโ€ that OpenAI CEO Sam Altman would use a synthetic voice released with anย update...

OpenAI only paused its ScarJo-sounding ChatGPT voice after the actor hired lawyers to send letters to the company, she says in a new statement expressing shock, anger and disbelief www.cnn.com/2024/05/20/t...

20.05.2024 23:27 ๐Ÿ‘ 92 ๐Ÿ” 19 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 3
Preview
Police are not primarily crime fighters, according to the data A new report adds to a growing line of research showing that police departments donโ€™t solve serious or violent crimes with any regularity, and in fact, spend very little time on crime control, in contrast to popular narratives.

"A new report adds to a growing line of research showing that police departments donโ€™t solve serious or violent crimes with any regularity, and in fact, spend very little time on crime control, in contrast to popular narratives." www.reuters.com/legal/govern...

19.05.2024 01:17 ๐Ÿ‘ 956 ๐Ÿ” 427 ๐Ÿ’ฌ 17 ๐Ÿ“Œ 35