Nicolò Fornari
@rationalpsyche.bsky.social
📤 20
📥 56
📝 41
Penetration Tester. Art passionate. Friends call me "grandpa".
reposted by
Nicolò Fornari
Dave Levitan
about 15 hours ago
It is representative of a *profound* failure of a country that this group of people are up there talking about medicine and science at all
14
481
133
Beyond the message of the talk, the insights on the parliamentary monitoring system are super interesting!
add a skeleton here at some point
about 19 hours ago
0
0
1
reposted by
Nicolò Fornari
Ursula von der Leyen
4 days ago
Europe stands with Estonia in the face of Russia’s latest violation of our airspace. We will respond to every provocation with determination while investing in a stronger Eastern flank.
83
1004
263
reposted by
Nicolò Fornari
Dirk-jan
6 days ago
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog:
dirkjanm.io/obtaining-gl...
loading . . .
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...
https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/
9
85
43
Deterministic LLMs are possible.
thinkingmachines.ai/blog/defeati...
loading . . .
Defeating Nondeterminism in LLM Inference
Reproducibility is a bedrock of scientific progress. However, it’s remarkably difficult to get reproducible results out of large language models. For example, you might observe that asking ChatGPT the...
https://thinkingmachines.ai/blog/defeating-nondeterminism-in-llm-inference/
8 days ago
0
0
0
reposted by
Nicolò Fornari
Compass Security
14 days ago
We use
@jameskettle.com
Burp extension Collaborator Everywhere daily. Now our upgrades are in v2: customizable payloads, storage, visibility. Perfect for OOB bugs like SSRF. Find out more here:
blog.compass-security.com/2025/09/coll...
#AppSec
#BurpSuite
#Pentesting
0
7
6
reposted by
Nicolò Fornari
Sander Tordoir
16 days ago
This is a fascinating move
www.reuters.com/world/europe...
loading . . .
Exclusive: ASML becomes Mistral AI’s top shareholder after leading latest funding round, sources say
The round will make Mistral the most valuable AI company in Europe with a 10-billion-euro pre-money valuation in its latest Series C funding round, sources said.
https://www.reuters.com/world/europe/asml-becomes-mistral-ais-top-shareholder-after-leading-latest-funding-round-2025-09-07/
4
61
30
reposted by
Nicolò Fornari
Matt Burgess (WIRED)
18 days ago
Wow "Flashlights from the bow swept over the water. Fearing that they had been spotted, the SEALs opened fire. Within seconds, everyone on the North Korean boat was dead."
loading . . .
How a Top Secret SEAL Team 6 Mission Into North Korea Fell Apart
https://www.nytimes.com/2025/09/05/us/navy-seal-north-korea-trump-2019.html
9
103
58
reposted by
Nicolò Fornari
CSCS - Swiss National Supercomputing Centre
21 days ago
EPFL, ETH Zurich, and CSCS released Apertus, Switzerland's first large-scale, multilingual language model (LLM). As a fully open LLM, it serves as a building block for developers and organizations to create their own applications:
www.cscs.ch/science/comp...
@ethz.ch
#AI
#Apertus
#AIforGood
0
5
3
reposted by
Nicolò Fornari
Simon Willison
about 1 month ago
ChatGPT just shipped the exact memory feature I've always wanted - automatic memory that's scoped to a specific project
simonwillison.net/2025/Aug/22/...
loading . . .
ChatGPT release notes: Project-only memory
The feature I've most wanted from ChatGPT's memory feature (the newer version of memory that automatically includes relevant details from summarized prior conversations) just landed: With project-only...
https://simonwillison.net/2025/Aug/22/project-memory/
8
130
12
reposted by
Nicolò Fornari
buherator
27 days ago
In a somewhat better world this ChatGPT suicide case should at minimum trigger resignations from OpenAI top brass. This won't happen of course, showing what kind of people we are dealing with there. And yes, this case is different from finding similar information via search 1/2
1
0
1
reposted by
Nicolò Fornari
TJ McIntyre
27 days ago
Still more evidence that the US under Trump is an enemy of Europe.
add a skeleton here at some point
0
8
5
This is a magnificent read. "Every warning about AGI danger is also a pitch deck for more funding" "The future is already here. You just have to stop looking for it in the wrong place."
add a skeleton here at some point
about 1 month ago
0
1
0
I never managed to do any meaningful work on the train, I need a comfortable setup for it. With chatpgt I can (let it) work on small side projects I never allocated time for.
about 2 months ago
0
0
0
UK is beta testing all the shittiest ideas, first brexit and now this. At least other countries will see the consequences before wanting to follow.
add a skeleton here at some point
about 2 months ago
0
0
0
reposted by
Nicolò Fornari
Nicolas Grégoire
about 2 months ago
AppSec Ezine - 597th edition
#AppSec
#Security
pathonproject.com/zb/?0f5e45f0...
loading . . .
AppSec Ezine
https://pathonproject.com/zb/?0f5e45f02f22bea6#/CO7+8GrXMervN0SpU25jS6SQX0+dcW1GfW6KgwcbSo=
0
2
2
To keep up to date on AI topics without being on twitter I recommend
news.smol.ai
(Newsletter & RSS feed)
loading . . .
AINews | AINews
Weekday recaps of top News for AI Engineers
https://news.smol.ai/
2 months ago
0
0
0
reposted by
Nicolò Fornari
2 months ago
One of my coworkers refers to Open Source as “the most incredible thing humanity has ever accomplished.” When he says that, he’s not making a socioeconomic or political statement, nor is he ignoring technical shortcomings. Rather, he is making an observation about how millions of people have […]
loading . . .
Original post on fosstodon.org
https://fosstodon.org/@djspiewak/114831647604435802
7
8
104
reposted by
Nicolò Fornari
James Kettle
2 months ago
We've just released a massive update to Collaborator Everywhere! This is a complete rewrite by
@compass-security.com
which adds loads of features including in-tool payload customization. Massive thanks to Compass for this epic project takeover. Check out the new features:
1
19
8
reposted by
Nicolò Fornari
buherator
2 months ago
Many static site generator templates don't include meta tags for
#RSS
/
#Atom
feeds, but the data is generated by default. It's worth to check: /index.xml /feed.xml
#syndication
Original->
0
1
1
reposted by
Nicolò Fornari
CSCS - Swiss National Supercomputing Centre
3 months ago
ETH Zurich and EPFL will release a large language model (LLM) developed on public infrastructure. Trained on the
#Alps
supercomputer at
#CSCS
, the new LLM marks a milestone in open-source AI and multilingual excellence:
www.cscs.ch/science/comp...
0
4
3
reposted by
Nicolò Fornari
Compass Security
3 months ago
LLM-based vuln hunting just leveled up with xvulnhuntr - a fork of vulnhuntr with support for: C#, Java, Go. Read
@rationalpsyche.bsky.social
's blog post and go grab the project on GitHub.
blog.compass-security.com/2025/07/xvul...
0
3
2
reposted by
Nicolò Fornari
Simon Willison
3 months ago
We ditched CGI in the late 1990s because of the overhead of starting, executing and stopping a process for every incoming request... turns out modern servers (plus languages like Go or Rust with a fast startup time) mean CGI isn't such a bad idea any more!
simonwillison.net/2025/Jul/5/c...
loading . . .
Serving 200 million requests per day with a cgi-bin
Jake Gold tests how well 90s-era CGI works today, using a Go + SQLIte CGI program running on a 16-thread AMD 3700X. Using CGI on modest hardware, it’s possible to …
https://simonwillison.net/2025/Jul/5/cgi-bin-performance/
10
132
24
reposted by
Nicolò Fornari
Andrea Pitzer
3 months ago
I wrote about how the Everglades experiment fits into the history of concentration camps in the US and abroad, and how it will connect a domestic network of camps to an international one. We’re watching the imposition of a global concentration camp network.
loading . . .
Opinion | Don’t call it ‘Alligator Alcatraz.’ Call it a concentration camp.
This facility’s purpose fits the classic model, and its existence points to serious dangers ahead for the country.
https://www.msnbc.com/opinion/msnbc-opinion/immigration-alligator-alcatraz-concentration-camp-rcna216874
269
7633
3490
reposted by
Nicolò Fornari
Marco Ivaldi
3 months ago
A new @OpenSecurityTraining2 course just dropped!
#fuzzing
1001: Introductory white-box fuzzing with AFL++
https://p.ost2.fyi/courses/course-v1:OpenSecurityTraining2+Fuzz1001_Intro_AFL+2025_v1/about
loading . . .
Fuzzing 1001: Introductory white-box fuzzing with AFL++
Are you looking for an automated way to find bugs in your code? In this course, you'll learn how to use AFL++ to test and identify vulnerabilities, leveraging a white-box approach to make your testing more efficient and targeted. By the end, you'll be ready to start fuzzing real-world software and contribute to improving its security.
https://p.ost2.fyi/courses/course-v1:OpenSecurityTraining2+Fuzz1001_Intro_AFL+2025_v1/about
0
2
1
reposted by
Nicolò Fornari
Compass Security
3 months ago
Exploiting the
@ubiquiti.bsky.social
AI Bullet camera for
#Pwn2Own
made us sweat more than once. But persistence paid off. Our detailed blog post is now live:
blog.compass-security.com/2025/06/pwn2...
#penetrationtest
#pentest
#iot
#embedded
#cybersecurity
www.compass-security.com/en/services/...
1
5
2
reposted by
Nicolò Fornari
buherator
3 months ago
[RSS] RedirectionGuard: Mitigating unsafe junction traversal in Windows
msrc.microsoft.com ->
Original->
0
1
1
reposted by
Nicolò Fornari
Compass Security
3 months ago
Thrilled for
#TROOPERS25
Thursday! Emanuele &
@yvesbieri.bsky.social
share
#Pwn2Own
wins on
#surveillance
cams. Method,
#exploit
, lessons. Drop in, trade war-stories! Talk:
troopers.de/troopers25/t...
Compass pentest:
www.compass-security.com/en/services/...
#cybersecurity
#iot
#hw
#fw
#ot
0
8
5
reposted by
Nicolò Fornari
Ethan Mollick
3 months ago
When you watch people use AI, you see how absolutely confusing things are, not just the obvious (o3 is better than 4o?), but also how ill-explained features are. For most people, just realizing that you need to switch models to get more serious work done is a major revelation.
1
30
4
reposted by
Nicolò Fornari
3 months ago
3) Summarizing search results. Gemini 2.5-pro has a "grounding" feature where it provides non-hallucinated search results on which the response is based. There are more. It is a very strangely shaped tool indeed, but the job of the artisan is to figure out what the tool can be used for...
0
2
1
reposted by
Nicolò Fornari
4 months ago
My short impulse presentation from Cycon is online:
youtu.be/qllU_B_Rmis?...
loading . . .
Fireside Chat: Gentleman Hackers with Thomas Dullien
YouTube video by natoccdcoe
https://youtu.be/qllU_B_Rmis?si=zgAFL5jy3QDPP0AN
4
21
14
[IT] There's still hope: smartphones banned in italian high schools from next year.
loading . . .
Arriva la circolare, stop ai cellulari alle superiori - Notizie - Ansa.it
Valditara: 'Improcrastinabile'. Sanzioni per chi viola divieto (ANSA)
https://www.ansa.it/canale_legalita_scuola/notizie/2025/06/16/arriva-la-circolare-stop-ai-cellulari-alle-superiori-_3ec5876c-b834-44dd-a438-cb7e43ac7619.html
3 months ago
0
0
0
Whatsapp introduces adds. Take this as an opportunity to install Signal
play.google.com/store/apps/d...
loading . . .
WhatsApp Introduces Ads in Its App
https://www.nytimes.com/2025/06/16/technology/whatsapp-ads.html
3 months ago
0
0
0
reposted by
Nicolò Fornari
Dominic White
3 months ago
The change in tenor from European clients before and after the ICC getting cut off from their MS services is palpable.
add a skeleton here at some point
0
0
1
trustedsec.com/blog/teachin...
loading . . .
Teaching a New Dog Old Tricks - Phishing With MCP
As AI evolves with MCP, can a new “dog” learn old tricks? In this blog, we test Claude AI’s ability to craft phishing pretexts—and just how much effort it…
https://trustedsec.com/blog/teaching-a-new-dog-old-tricks-phishing-with-mcp
3 months ago
0
0
0
fly.io/blog/youre-a...
loading . . .
My AI Skeptic Friends Are All Nuts
My smartest friends have bananas arguments about LLM coding.
https://fly.io/blog/youre-all-nuts/
3 months ago
0
0
0
reposted by
Nicolò Fornari
Nicolas Grégoire
4 months ago
Welcome on Bluesky
@blaklis.bsky.social
👋
0
10
3
If you pentest web apps this is a great explanation of HTTP/1.1, HTTP/2, and HTTP/3
www.netmeister.org/blog/http-12...
loading . . .
Bootstrapping HTTP/1.1, HTTP/2, and HTTP/3
How do we get from HTTP/1.1 all the way to 11... I mean, to HTTP/3? Let's look at the path browsers take.
https://www.netmeister.org/blog/http-123.html
4 months ago
0
1
0
reposted by
Nicolò Fornari
jvoisin
4 months ago
My experience with Canonical's interview process —
dustri.org/b/my-experie...
loading . . .
My experience with Canonical's interview process
Personal blog of Julien (jvoisin) Voisin
https://dustri.org/b/my-experience-with-canonicals-interview-process.html
1
3
3
reposted by
Nicolò Fornari
4 months ago
A small slide deck for a 15 minute impulse talk at Cycon 2025 in Talinn:
docs.google.com/presentation...
loading . . .
A walk down the learning curve
A walk down the learning curve (and memory lane) Thomas Dullien (“Halvar Flake”) Computing Mathematician
https://docs.google.com/presentation/d/1_3Iu74UijAjfSLHzqWDkDEaIwoB6WBSo9-mY5e0u0HM/edit?usp=drivesdk
1
23
12
Without js I always relied on iframes but meta tag is indeed better with respect to X-Frame-Options
add a skeleton here at some point
4 months ago
0
1
0
reposted by
Nicolò Fornari
Nicolas Grégoire
4 months ago
Tons of good tips there ⬇️💎
add a skeleton here at some point
0
5
3
reposted by
Nicolò Fornari
Ethan Mollick
4 months ago
At some point, the fact that over a billion people use this technology and that they self-report high utility has to mean something. There is lots to criticize about AI and plenty of real issues caused by AI, but the narrative that this is all a fake thing that will disappear doesn't help anyone.
4
47
8
reposted by
Nicolò Fornari
Hans-Martin Münch
4 months ago
OffensiveCon 25 videos are out. Thank you @offensivecon
www.youtube.com/watch?v=goEb...
loading . . .
OffensiveCon25 - Cedric Halbronn and Jael Koh
YouTube video by OffensiveCon
https://www.youtube.com/watch?v=goEb7eKj660&list=PLYvhPWR_XYJk0p40BrX7K2z-_j_tJmvhc
0
7
2
I don't listen to podcasts because I like to consume raw information. I just realized that with text2speech I can create my own "blogpost as audiobook". My mind is blown.
4 months ago
0
0
0
Certipy v5 release
github.com/ly4k/Certipy...
loading . . .
The Future of Certipy and the Release of v5 & ESC16 · ly4k Certipy · Discussion #270
Certipy has been quiet for a while - but not forgotten. After two years without active maintenance, I'm happy to say that changes are coming. Today, I'm releasing Certipy v5. It's been two years si...
https://github.com/ly4k/Certipy/discussions/270
4 months ago
0
0
0
"The International Criminal Court ’s chief prosecutor has lost access to his email, and his bank accounts have been frozen. Microsoft cancelled Khan’s email address [...] "Trump sanctioned the court after a panel of ICC judges in November issued arrest warrants for Israeli Prime Minister Netanyahu"
loading . . .
Trump's sanctions on ICC prosecutor have halted tribunal's work
Nearly three months ago, U.S. President Donald Trump slapped sanctions on the International Criminal Court's chief prosecutor, Karim Khan.
https://apnews.com/article/icc-trump-sanctions-karim-khan-court-a4b4c02751ab84c09718b1b95cbd5db3
4 months ago
0
0
0
reposted by
Nicolò Fornari
Bert Hubert 🇺🇦🇪🇺🇺🇦
5 months ago
I've written lots of words on "the cloud" and specifically Europe's woes. In the post below I tie many articles together into a hopefully useful overview. It may be good to know that nothing I write on the cloud is original, I mostly hope to report things as they are:
berthub.eu/articles/pos...
loading . . .
Cloud Overview - Bert Hubert
Over the past few years I’ve written a lot about the cloud, and what it means for Europe. Here I want to pull the various articles together into a coherent story. Note, nothing what follows is in any ...
https://berthub.eu/articles/posts/cloud-overview/
1
26
12
Having participated in the MSC AI-Cybersecurity competition, I was curious to check the winning entries. The second place essay is imho the best one. Here is a summary thread to invite you to read it in full. Problem: it is increasingly difficult to tell human and computers apart.
loading . . .
Combatting AI cybersecurity risks with digital identity verification - Binding Hook
As humans and AI become harder and harder to tell apart, there is room for Europe to lead the way in creating secure, democratic digital spaces
https://bindinghook.com/articles-binding-edge/combatting-ai-cybersecurity-risks-with-digital-identity-verification/
5 months ago
1
0
0
Load more
feeds!
log in