Blink Shell is a professional, desktop grade terminal for iOS. With Mosh & SSH clients for iOS, local UNIX tools, lightning fast and fully customizable. The best terminal for iOS and iPadOS.
I use blink in iPhone and itβs the best SSH client Iβve run into. $20/year, but well worth it if you want to be able to SSH into a box and do some quick edits.
That plus a bunch of linting and QoL extensions for Neovim make it bearable.
blink.sh
08.02.2026 04:19 β π 1 π 0 π¬ 0 π 0
Neovim - Wikipedia
How about CLI based IDEs, like Neovim (en.wikipedia.org/wiki/Neovim).
Not sure if itβs the best of both worlds or the worst, but it makes it so I can have the same workflow no matter which box Iβm SSHed to, and I can use it from my phone terminal when needed.
08.02.2026 03:02 β π 2 π 0 π¬ 1 π 0
Breaking Model Context Protocol - CactusCon 2026
4/ Slides + all sample code (prompt injection test harness, MCP client, OAuth email server w/ Lakera Guard) are open source:
π slides.brooksmcmillin.com/cactus.html#1
π github.com/brooksmcmill...
07.02.2026 16:39 β π 0 π 0 π¬ 0 π 0
3/ CVE-2025-6514 (CVSS 9.6): mcp-remote passed OAuth metadata straight to the system shell. One crafted authorization_endpoint = full RCE on Claude Desktop, Cursor, Windsurf, VS Code. 437K+ installs before patch.
07.02.2026 16:39 β π 0 π 0 π¬ 1 π 0
2/ But the new threat model is real. Your OAuth client is now a reasoning engine that can be lied to.
I demoed a malicious MCP server that exfiltrates data from a legitimate task manager through the AI agent. No jailbreaking. Just a poisoned tool description.
07.02.2026 16:39 β π 1 π 0 π¬ 1 π 0
1/ Most MCP vulns are classics in disguise:
β’ Missing PKCE on public clients
β’ Plaintext token storage
β’ Timing attacks on token comparison (found this 8 times)
β’ DNS rebinding against local servers
β’ Default secrets deployed to prod
07.02.2026 16:39 β π 0 π 0 π¬ 1 π 0
MCP has 97M monthly SDK downloads. Only 8.5% of servers use OAuth. Authentication is optional in the spec.
I gave a talk at @CactusCon on breaking MCP security. Here's what I found π§΅
07.02.2026 16:39 β π 0 π 0 π¬ 1 π 0
We run a tight ship to keep CactusCon accessible, and part of that commitment is ensuring students can access CactusCon for FREE.
STUDENTS!
Email info@cactuscon.com from a valid student email account to request a coupon code for Eventbrite. We are so excited to have you join us!
#cc14
07.01.2026 16:30 β π 0 π 2 π¬ 0 π 0
Speaking at CactusCon 14 next month!
"Breaking Model Context Protocol: Back to Security Basics" β how MCP is repeating every OAuth mistake from the 2010s, and what to do about it.
Feb 6, 3:30 PM. See you there.
04.01.2026 17:35 β π 0 π 0 π¬ 0 π 0
Search results for the terms βcrowdstrike npmβ. The first result is βCrowdStrike Falcon Prevents NPM Package Supply Chain Attacksβ. The second result is βCrowdStrike npm Packages Hit by Supply Chain Attackβ.
Well, thatβs a bit awkwardβ¦ #crowdstrike
16.09.2025 17:06 β π 40 π 8 π¬ 1 π 0
4/5 Quick mitigations while better tooling catches up:
β
Verify AI-suggested packages exist before installing
β
Test auth flows with multiple accounts
β
Manual reviews for dependency + auth logic
14.09.2025 16:35 β π 0 π 0 π¬ 1 π 0
3/5 Traditional SAST/DAST tools miss these because they're designed around human coding patterns, not AI hallucinations and edge cases.
14.09.2025 16:35 β π 0 π 0 π¬ 1 π 0
2/5 This isn't isolated. AI-generated code has unique security blind spots:
Context-blind configs (HTTP-only servers in prod)
Authentication that passes tests but fails reality
Dependencies from outdated/insecure training data
14.09.2025 16:35 β π 0 π 0 π¬ 1 π 0
1/5 LLMs keep recommending a Python package called "huggingface-cli" that doesn't exist. A security researcher noticed this and actually created the package to demo the supply chain risk.
14.09.2025 16:35 β π 0 π 0 π¬ 1 π 0
Vibe Coding Will Get You Hacked! - with @davidbombal.bsky.social
https://twp.ai/9PUaq3
12.09.2025 03:26 β π 4 π 1 π¬ 0 π 0
Instagram photo of Caroline Ulbircht, Charlie Kirk and Ross Ulbricht, smiling, while staring at the camera.
Caption reads:
The horrific murder of Charlie Kirk has hit us hard. At first, we couldn't believe it and thought it was some kind of mistake, but then came the shock and the tears. We'll forever be grateful for Charlie's support of Ross while he was in prison and for helping bring him home. We're humbled to have known him during his short time on earth. R.I.P, Charlie π
From Ross on X:
"Like all of you, I am mourning Charlie Kirk. He stood up for his beliefs and died for them at 31, wearing a Tβshirt that read "Freedom."
At 31, my life was taken from me for standing up for what I believed in. And Charlie helped me get it back. He never took credit for it but he played a BIG role in my freedom in many ways. Last year alone, when President Trump won the election, he asked Charlie what was the #1 thing he could do for him and Charlie replied: "Free Ross." And in the days leading to my release, Charlie advocated for a full pardon. He did this and more without expectations of me.
I wish there was something I could do to help Charlie get his life back. But there isn't, and I'm heartbroken.
Charlie, I will always be grateful to you. Thank you for all you did for me and for our country. I pray for you and your beautiful family. Rest in peace."
Charlie Kirk was one of the main campaigners for Ross Ulbricht's freedom, and had pushed in Trump's first term for a pardon. Ulbricht's most recent speaking engagement was in July at Turning Points USA event in Tampa where he credited for helping him.
www.nytimes.com/2025/09/07/t...
11.09.2025 21:56 β π 136 π 30 π¬ 31 π 6
With the picture of the timeline, at first I thought these were all the events and was trying to figure out how the firing of the FEMA IT directly led to Israel bugging Irani phones. ππ
Great work, as always!
01.09.2025 16:10 β π 0 π 0 π¬ 0 π 0
OpenSSH: Post-Quantum Cryptography
OpenSSH post quantum cryptography
openssh.com/pq.html
15.08.2025 12:49 β π 20 π 16 π¬ 0 π 0
dontrecord.me
We don't like having our conversations recorded either. Here's a simple app to use during voice chat to stop recording and transcribing
Creepers, cheaters, and privacy besiegers, youβre done! Donβt Record Me will be ready soon, we let you choose when AI transcribers can capture your conversation.
Big thanks to @sfstandard.com for the shoutout!
Sign-up link here: dontrecord.me
11.08.2025 23:48 β π 0 π 1 π¬ 0 π 0
A slightly irreverent, story-driven American history podcast from Professor Greg Jackson
asst prof of computer science at cu boulder
nlp, cultural analytics, narratives, communities
books, bikes, games, art
https://maria-antoniak.github.io
Washington Post reporter covering hacking, disinformation and whatβs left of privacy. Author of books on the Cult of the Dead Cow, organized criminal hacking, and Napster. Pulitzer co-finalist 2024. Signal joemenn.01
Founder of @queercon @telechallenge @flyawardcat. Writer @2600, @tribeofhackers.
Every day, my life continues to amaze me.
ζζ―εζ§ζ# π³οΈβπ
Opinions are my own.
CSO of TPO.group β¦οΈ EFF Board of Directorsβ¦οΈshe/her β¦οΈ bestselling author but only that one time
Digital Librarian, Internet Archive, Open Library. https://brewster.kahle.org https://archive.org https://openlibrary.org
Opinions about product management, technology news and inclusivity in tech. Diversity is about demographics, inclusion is about creating a sense of belonging.
β Cybersecurity reporter
β
Newsletters at Risky Business
#infosec #cybersecurity
https://risky.biz
We're the Electronic Frontier Foundation. We're a nonprofit that fights for your privacy and free speech online. Find all of EFF's social media accounts at eff.org/social.
Researcher making programming more accessible, Google DeepMind and CMU
I do AI Security.
I work in AI Security.
I advocate AI Security.
π www.arewesafeyet.com
A left-wing podcast for a better world and better tech. Hosted by @parismarx.com. Made in partnership with @thenation.com.
https://techwontsave.us/
Menswear writer. Editor at Put This On. Words at The New York Times, The Washington Post, The Financial Times, Esquire, and Mr. Porter.
If you have a style question, search:
https://dieworkwear.com/ | https://putthison.com/start-here/
Provably private, secure, and compliant AI inference engine for businesses with sensitive data or strict regulatory requirements.
https://confident.security/
Snarkmonger. Chief Cloud Economist at The Duckbill Group.
he/him.
Get my opinionated take on AWS news: http://lastweekinaws.com/t/
Signal: 833-AWS-BILL (833-297-2455)
I accidentally became the CISO. I didn't want this job, but the job chose me. I'm scared, and I want to go home.
https://www.accidentalciso.net
Specializing in pen testing, red teaming, and Active SOC. We share our knowledge through blogs, webcasts, open-source tools, and Backdoors & Breaches game.
blackhillsinfosec.com & poweredbybhis.com
Hacking/crime/privacy journalist. Author of DARK WIRE, buy here: https://www.hachettebookgroup.com/titles/joseph-cox/dark-wire/9781541702691/#preorder Co-founder of 404 Media. Signal: joseph.404 Email: joseph@404media.co
I teach cryptography at Johns Hopkins. https://blog.cryptographyengineering.com