Nicolò Fornari's Avatar

Nicolò Fornari

@rationalpsyche.bsky.social

Penetration Tester. Art passionate. Friends call me "grandpa".

22 Followers  |  58 Following  |  43 Posts  |  Joined: 10.11.2024  |  1.7706

Latest posts by rationalpsyche.bsky.social on Bluesky

Preview
How My Reporting on the Columbia Protests Led to My Deportation As an Australian who wrote about the demonstrations while on campus, I gave my phone a superficial clean before flying to the U.S. I underestimated what I was up against.

It's important for Europeans, and others from visa-waiver countries, to understand they don't have freedom of speech rights when visiting the United States.

The Trump regime is still deporting visitors for critical comments made online, because they can.

05.11.2025 08:05 — 👍 45    🔁 20    💬 1    📌 0
Update to our Terms and data use | LinkedIn Help Update to our Terms and data use

Starting Monday LinkedIn will begin using data from your profiles/posts to train AI. If you live in EU/EEA/Switzerland/Canada/Hong Kong your data is subject to being used this way, but you can opt out. Go to Settings/Privacy/Data for Generative AI Improvement and toggle the switch to off

30.10.2025 16:13 — 👍 23    🔁 24    💬 1    📌 1

Day to day: the user experience of getting a direct answer for simple things compared to scrolling a bloated blog post, with ads and cookie banners. It would be better to solve the state of the web but hey, it's a workaround.

30.10.2025 22:41 — 👍 0    🔁 0    💬 0    📌 0
Preview
Xavier Mertens 🇧🇪 (@xme@infosec.exchange) Attached: 1 image When you leave a coffee machine unprotected at a hacker conference… #hacklu2025

If you know who did this, or if you know how to set it back, the hotel kindly asks you to do so, respecting the fun achievement unlocked :)
https://infosec.exchange/@xme/115422139879568495

23.10.2025 07:27 — 👍 3    🔁 2    💬 0    📌 0

Great work guys!!

22.10.2025 18:55 — 👍 1    🔁 0    💬 0    📌 0
Post image

#Pentest of gRPC-Web apps is tricky due to the binary format. We are releasing bRPC-Web, a @portswigger.net @burpsuite.bsky.social extension developed by our @muukong.bsky.social that helps manipulate #gRPC-Web traffic, even in absence of #protobuf schemas. blog.compass-security.com/2025/10/brpc...

21.10.2025 11:38 — 👍 7    🔁 3    💬 0    📌 0

pagedout.institute ← we've just released Paged Out! zine Issue #7
pagedout.institute/download/Pag... ← direct link
lulu.com/search?page=... ← prints for zine collectors
pagedout.institute/download/Pag... ← issue wallpaper
Enjoy!

Please please please share to spread the news - thank you!

04.10.2025 10:40 — 👍 17    🔁 16    💬 1    📌 3
Study of the European Commission: Survey on the Governance and Sustainability of Critical Open Source Software

The @EUCommission would like to hear your views on the governance and sustainability of critical open source software. The survey closes October 5th.

https://ec.europa.eu/eusurvey/runner/FOSSEPS_Governance_and_Sustainability_Survey

#OpenSource #Governance #Sustainability

30.09.2025 14:23 — 👍 1    🔁 25    💬 0    📌 0

"Employees are using AI tools to create low-effort, passable looking work that ends up creating more work for their coworkers.[...] it shifts the burden of the work downstream, requiring the receiver to interpret, correct, or redo the work. In other words, it transfers the effort
1/2

23.09.2025 11:10 — 👍 3    🔁 1    💬 1    📌 0
White House press conference with Trump, RFK Jr, Marty Makary, and Dr. Oz, for fuck's sake

White House press conference with Trump, RFK Jr, Marty Makary, and Dr. Oz, for fuck's sake

It is representative of a *profound* failure of a country that this group of people are up there talking about medicine and science at all

22.09.2025 21:13 — 👍 481    🔁 116    💬 13    📌 14

Beyond the message of the talk, the insights on the parliamentary monitoring system are super interesting!

22.09.2025 17:22 — 👍 0    🔁 1    💬 0    📌 0

Europe stands with Estonia in the face of Russia’s latest violation of our airspace.

We will respond to every provocation with determination while investing in a stronger Eastern flank.

19.09.2025 15:19 — 👍 1000    🔁 239    💬 81    📌 24
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-gl...

17.09.2025 13:20 — 👍 87    🔁 38    💬 9    📌 5
Preview
Defeating Nondeterminism in LLM Inference Reproducibility is a bedrock of scientific progress. However, it’s remarkably difficult to get reproducible results out of large language models. For example, you might observe that asking ChatGPT the...

Deterministic LLMs are possible.
thinkingmachines.ai/blog/defeati...

15.09.2025 15:51 — 👍 0    🔁 0    💬 0    📌 0
Post image

We use @jameskettle.com Burp extension Collaborator Everywhere daily. Now our upgrades are in v2: customizable payloads, storage, visibility. Perfect for OOB bugs like SSRF.

Find out more here: blog.compass-security.com/2025/09/coll...

#AppSec #BurpSuite #Pentesting

09.09.2025 11:54 — 👍 8    🔁 6    💬 0    📌 0
Preview
Exclusive: ASML becomes Mistral AI’s top shareholder after leading latest funding round, sources say The round will make Mistral the most valuable AI company in Europe with a 10-billion-euro pre-money valuation in its latest Series C funding round, sources said.

This is a fascinating move

www.reuters.com/world/europe...

07.09.2025 19:41 — 👍 61    🔁 26    💬 4    📌 3
Preview
How a Top Secret SEAL Team 6 Mission Into North Korea Fell Apart

Wow

"Flashlights from the bow swept over the water. Fearing that they had been spotted, the SEALs opened fire. Within seconds, everyone on the North Korean boat was dead."

05.09.2025 10:57 — 👍 103    🔁 52    💬 9    📌 6
Post image

EPFL, ETH Zurich, and CSCS released Apertus, Switzerland's first large-scale, multilingual language model (LLM). As a fully open LLM, it serves as a building block for developers and organizations to create their own applications: www.cscs.ch/science/comp... @ethz.ch #AI #Apertus #AIforGood

02.09.2025 08:14 — 👍 5    🔁 2    💬 0    📌 1
ChatGPT release notes: Project-only memory The feature I've most wanted from ChatGPT's memory feature (the newer version of memory that automatically includes relevant details from summarized prior conversations) just landed: With project-only...

ChatGPT just shipped the exact memory feature I've always wanted - automatic memory that's scoped to a specific project simonwillison.net/2025/Aug/22/...

22.08.2025 22:44 — 👍 130    🔁 11    💬 8    📌 1

In a somewhat better world this ChatGPT suicide case should at minimum trigger resignations from OpenAI top brass. This won't happen of course, showing what kind of people we are dealing with there.

And yes, this case is different from finding similar information via search
1/2

27.08.2025 10:04 — 👍 0    🔁 1    💬 1    📌 0

Still more evidence that the US under Trump is an enemy of Europe.

27.08.2025 08:51 — 👍 8    🔁 5    💬 0    📌 0

This is a magnificent read.

"Every warning about AGI danger is also a pitch deck for more funding"

"The future is already here. You just have to stop looking for it in the wrong place."

12.08.2025 18:03 — 👍 1    🔁 0    💬 0    📌 0

I never managed to do any meaningful work on the train, I need a comfortable setup for it. With chatpgt I can (let it) work on small side projects I never allocated time for.

09.08.2025 07:33 — 👍 0    🔁 0    💬 0    📌 0

FYI I recommend this series of blog posts on EU dependence on US clouds

bsky.app/profile/bert...

05.08.2025 06:05 — 👍 6    🔁 3    💬 0    📌 0

UK is beta testing all the shittiest ideas, first brexit and now this. At least other countries will see the consequences before wanting to follow.

31.07.2025 15:25 — 👍 0    🔁 0    💬 0    📌 0
AppSec Ezine

AppSec Ezine - 597th edition #AppSec #Security

pathonproject.com/zb/?0f5e45f0...

25.07.2025 14:10 — 👍 2    🔁 2    💬 0    📌 0
Preview
AINews | AINews Weekday recaps of top News for AI Engineers

To keep up to date on AI topics without being on twitter I recommend
news.smol.ai
(Newsletter & RSS feed)

25.07.2025 05:39 — 👍 0    🔁 0    💬 0    📌 0
Original post on fosstodon.org

One of my coworkers refers to Open Source as “the most incredible thing humanity has ever accomplished.” When he says that, he’s not making a socioeconomic or political statement, nor is he ignoring technical shortcomings. Rather, he is making an observation about how millions of people have […]

10.07.2025 23:58 — 👍 8    🔁 101    💬 7    📌 0
Post image

We've just released a massive update to Collaborator Everywhere! This is a complete rewrite by @compass-security.com which adds loads of features including in-tool payload customization. Massive thanks to Compass for this epic project takeover. Check out the new features:

14.07.2025 14:51 — 👍 19    🔁 7    💬 1    📌 1

Many static site generator templates don't include meta tags for #RSS / #Atom feeds, but the data is generated by default. It's worth to check:

/index.xml
/feed.xml

#syndication


Original->

14.07.2025 07:57 — 👍 1    🔁 1    💬 0    📌 0

@rationalpsyche is following 20 prominent accounts