Advertisement · 728 × 90

Posts by r (cycloarcane)

A conversation with claude code where the user asks "why world so scary" and Claude responds "Because attack surfaces are everywhere and people are creative. But you just made yours a tiny bit smaller, so that's something."

A conversation with claude code where the user asks "why world so scary" and Claude responds "Because attack surfaces are everywhere and people are creative. But you just made yours a tiny bit smaller, so that's something."

Daily CC activities

5 days ago 0 0 0 0

"I've seen all of those"
"Rough. You've burned through everything good. At that point I'd say either branch into adjacent stuff—Korean thrillers, European sci-fi—or go back to older films you might have missed. But that's not really what you asked for.
Enjoy whichever film you pick. Good night!"

5 days ago 0 0 0 0
Preview
HackerOne Employee Data Exposed in Massive Navia Breach HackerOne is notifying nearly 300 employees that their personal information was exposed in a data breach recently disclosed by Navia.

Ahhhh 😭

www.securityweek.com/hackerone-em...

3 weeks ago 0 0 0 0
roan.lol - Reproducing the Trivy-LiteLLM Supply Chain Kill Chain

roan.lol/content/2026...

3 weeks ago 0 0 0 0

People saying the LiteLLM breach is a problem with pip or AI or random other things lol. It is a problem with using ci/cd workflows with components you don't control who themselves are using dangerous options like pull_request_target. hackerbot-claw being the perpetrator is pretty crazy though.

3 weeks ago 0 0 0 0

OS-level age verification broooooo 😭

leginfo.legislature.ca.gov/faces/billTe...

3 weeks ago 0 0 0 0

Two sentence horror:

Hunter:
"Please find below a PoC video that shows all the steps required:
https://www.youtube.com"

Triage:
"Please immediately remove this video from youtube as that violates the code of conduct of H1. Any videos should be uploaded directly to the report as an attachment."

1 month ago 0 0 0 0
Advertisement

reading @hacker0x01.bsky.social reports makes you realise both that there are still plenty of bug bounties to be found even in the AI age, and that you are ultimately responsible for vetting everything within your control in requests because as successful as bounties have been there are still holes.

1 month ago 0 1 0 0
Post image

yay

1 month ago 0 0 0 0
roan.lol - Vibe Coding and Git Secrets: What AI Assistants Won't Tell You

AI coding agents love git add -A. They don't love your .env file staying private. New post on what actually happens when secrets end up in git and how to fix it properly.

roan.lol/content/2026...

1 month ago 0 0 0 0

Firefox completely silently removed support for animated gif fav icons and I had to convert it so svg and css does the cruelty of this world ever relent

1 month ago 1 0 0 0
Preview
GitHub - cycloarcane/cybersecurity-revision-quizzes: This repository contains quiz resources to accerstain competency for various standards and certifications. This repository contains quiz resources to accerstain competency for various standards and certifications. - cycloarcane/cybersecurity-revision-quizzes

I was revising for some cyber certs recently and found free revision tests/quizzes a bit hard to come by, so I've been making an in-browser app. I also made an android-wrapper app so I can have something to do on the tube when there's no signal lol

github.com/cycloarcane/...

1 month ago 0 0 0 0
Unsupported Browser | HackerOne

I love thinking about the dead ends

"An attacker in a multi-tenant cluster with permission to create/modify ingresses can inject content into the connection-proxy-header annotation and read arbitrary files from the ingress controller (including the service account)."

hackerone.com/reports/2701...

1 month ago 0 0 0 0
Preview
Keep Android Open Advocating for Android as a free, open platform for everyone to build apps on.

178 days remain until stores like F-droid no longer function on Android and the platform is locked down with verification for all developers. #android #digitalrights

keepandroidopen.org

1 month ago 0 0 0 0
Advertisement
Post image

AI generated duplicate reports on hacker one must be really annoying to deal with, clearly happening as recently as January. Also just responding 'copy' 💀 unless I'm missing something...

1 month ago 0 0 0 0
Post image

"Kali Linux ships an official package called mcp-kali-server that exposes the Kali toolset to AI clients over the Model Context Protocol. Combined with Claude Code, this means you can ask Claude to run nmap, nikto, or any other Kali tool..."

roan.lol/content/2026...

1 month ago 2 0 0 0

I use netlify protected by cloudflare lmao, extra fun

1 month ago 1 0 0 0

Claude code is highly capable so I think even if the mcp server presented limitations it would find a way around them

1 month ago 1 0 1 0
Post image

I guess being an anime anon doesn't work anymore.

"Large-scale online deanonymization with LLMs"

They show that large language models can be used to perform at-scale deanonymization. With full Internet access, our agent can re-identify Hacker News users and

1 month ago 52 22 3 8
Post image

Introducing VulnHive a collection of vulnerable docker containers mapped to the OWASP top 10, with a SOC to observe incoming attacks. Perfect for testing automated hacking frameworks. github.com/cycloarcane/...

1 month ago 0 0 0 0

3/ end result: full -A scan across 65535 ports in one prompt. recon use case is obvious

1 month ago 0 0 0 0

2/ gotchas: VirtualBox NAT blocks the VM by default, SSH service is off out of the box, generate a dedicated key and lock it to only invoking mcp-server in authorized_keys

1 month ago 0 0 0 0
Post image

been messing with AI pentesting tools (strix, artemis, shannon) but mcp-kali-server might just be the meta. kali now ships it officially. apt install mcp-kali-server, forward a port, drop 1 SSH command in your claude config. Claude Code is the right client, the AUR desktop app is just a site wrapper

1 month ago 1 0 3 0
Advertisement
Preview
Online Tracking is Out of Control—Privacy Badger Can Help You Fight Every time you browse the web, you're being tracked. That’s why EFF created Privacy Badger, a free, open source browser extension used by millions to fight corporate surveillance and take back

The rampant data sharing fueled by online tracking has serious consequences. Privacy Badger blocks online tracking to prevent your browsing data from being used against you. www.eff.org/deeplinks/2...

1 month ago 128 40 4 3
Post image

70% of the models on Ollama are now...cloud based? I get that they're open(ish) ones still but doesn't this mostly defeat the purpose of local models and availability.

1 month ago 0 0 0 0
R̶̼̘͌͊̄̉̒O̵̰̿͆͊̅̈Ȃ̵̖̲͍͎̲̎̐̇͐͠N̸̯̲̝̥̲̚͝ͅ.̵̣̔L̴̫̩̻̘̀̒̓̑Ó̴̤L̵̡̰͚̮̃̑̕̚ - Hacking Labs

Got around to posting some hacking labs write-ups to my domain!

roan.lol/content/labs...

1 month ago 0 0 0 0
Preview
Breaking NVIDIA Triton: CVE-2025-23319 - A Vulnerability Chain Leading to AI Server Takeover | Wiz Blog Wiz Research discovers a critical vulnerability chain allowing unauthenticated attackers to take over NVIDIA's Triton Inference Server.

Critical vulnerability in Nvidia Triton servers, immediate action required

www.wiz.io/blog/nvidia-...

8 months ago 0 0 0 0
Post image

check out my latest article on automated hacking agents and CAI!!

roan.lol/content/2025...

8 months ago 1 0 0 0
Teen Warned Not To Accept Group Chat Invites From National Security Advisors She Doesn’t Know

Teen Warned Not To Accept Group Chat Invites From National Security Advisors She Doesn’t Know

Teen Warned Not To Accept Group Chat Invites From National Security Advisors She Doesn’t Know

1 year ago 45774 10080 350 519
Post image

Got the @eff.org #Rayhunter tool working on the Verizon Orbic and now happily hunting stingrays around SF 🥰

1 year ago 0 0 0 0