Alesandro Ortiz ๐ต๐ท๐ณ๏ธโ๐
AlesandroOrtiz@infosec.exchange
<p>Software Engineer. Security Researcher. Puerto Rican ๐ต๐ท. New Yorker. Bilingual. LG(B)TQ ๐ณ๏ธโ๐. He/him.</p><p>Focused on browser research. Glad to collaborate.</p><p>Website: <a href="https://AlesandroOrtiz.com" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">AlesandroOrtiz.com</span><span class="invisible"></span></a><br />(Header ๐ท: roriv3ra on IG)</p>
Posts
-
View post
Unintentionally pentesting a hospital's PHI/PII protections this past week. 15% failure rate so far across a dozen calls where they disclosed PHI and PII without any verification or insufficient verification. Somehow my banks and phone company are better (0% fail rate over years) than a major NYC hospital system (15% fail rate in a week).
-
View post
RE: https://mastodon.social/@zackwhittaker/116977657519858883 Reuters reporting reveals an incredibly concerning timeline and (unsurprisingly) lack of responsible behavior from OpenAI. I really hope the public gets to see more details about internal reactions on both sides. The initial call/email from OpenAI to HF saying "we hacked you, accidentally". HF's execs initial reactions. Oh, and especially the lawyers' reactions (on both sides). I can't imagine the Hugging Fa...
-
View post
๐ถ Here comes another bubble. The VCs are backing, Baby let's get cracking. ๐ถ Here Comes Another Bubble (2007): https://www.youtube.com/watch?v=I6IQ_FOCE6I
-
View post
Can't wait for the future where companies accidentally hack each other. /s *holds earpiece* Oh, it's happened already? NYT (gift link): https://www.nytimes.com/2026/07/21/technology/openai-attack-hugging-face.html?unlocked_article_code=1.zVA.w4cy.zFR0x0h7CDK-&smid=url-share
-
View post
I've never seen this before: A developer is selling their unreleased Steam game project. It's listed on a startup/project acquisition website. Project sale listing: https://app.acquire.com/startup/nj154Nce1TSKjr2Yk6ipLaQFIJl1/YKONqHosEBfM7TCIkHlA Game being sold: https://store.steampowered.com/app/4896660/Boxing_Tycoon/ No idea how they are claiming income. Maybe it's estimates based on wishlist count and expected price of game, but unusual to list it like that.
-
View post
I'll be at @SummerC0n@infosec.exchange this Friday and Saturday. Say hi if you're there! #SummerCon #NYC
-
View post
Happy Sunday morning to everyone except Netlify who let their critical-path `netlify.app` domain expire. #hugops for their teams working incident response. Now everyone&#39;s sites are down if they are using `sitename.netlify.app` CNAME records with third-party DNS providers, as is recommended in most cases. ๐ I posted a workaround here, which should help if your DNS records have low TTL: https://answers.netlify.com/t/my-websites-have-stopped-working/162180/9
-
View post
@shodansafari so much to unpack here ๐ Who are they writing to? What account are they referring to? Why is the browser so outdated? What are they using this remote device for?
-
View post
RE: https://infosec.exchange/@wiz/116483081129277482 Incredibly simple RCE on GitHub.com and GitHub Enterprise. Amazing find.
-
View post
RE: https://dair-community.social/@timnitGebru/116489502664120783 Anyone who thinks legitimate DEI efforts from the past decade+ were unnecessary because people in power said &quot;discrimination is a thing of the past&quot; needs to read this piece. Many people in power, including those who pay your salary, think as described in the article when making everyday decisions. Their everyday work often amplifies their beliefs and empowers others who share their beliefs. Worse yet, their m...
-
View post
I haven&#39;t been focused on security research since ~November of last year for a reason: to wait and see how VRPs and bug bounty programs adapted to the rapidly changing infosec landscape due to AI tooling. TL;DR: It was hard to make decent money from VRPs. It&#39;s now even harder. It&#39;s not researchers&#39; fault. Thread below.