Elektrine lite

โ† Feed

Alesandro Ortiz ๐Ÿ‡ต๐Ÿ‡ท๐Ÿณ๏ธโ€๐ŸŒˆ

AlesandroOrtiz@infosec.exchange

<p>Software Engineer. Security Researcher. Puerto Rican ๐Ÿ‡ต๐Ÿ‡ท. New Yorker. Bilingual. LG(B)TQ ๐Ÿณ๏ธโ€๐ŸŒˆ. He/him.</p><p>Focused on browser research. Glad to collaborate.</p><p>Website: <a href="https://AlesandroOrtiz.com" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">AlesandroOrtiz.com</span><span class="invisible"></span></a><br />(Header ๐Ÿ“ท: roriv3ra on IG)</p>

Posts

  • View post

    Unintentionally pentesting a hospital&#39;s PHI/PII protections this past week. 15% failure rate so far across a dozen calls where they disclosed PHI and PII without any verification or insufficient verification. Somehow my banks and phone company are better (0% fail rate over years) than a major NYC hospital system (15% fail rate in a week).

  • View post

    RE: https://mastodon.social/@zackwhittaker/116977657519858883 Reuters reporting reveals an incredibly concerning timeline and (unsurprisingly) lack of responsible behavior from OpenAI. I really hope the public gets to see more details about internal reactions on both sides. The initial call/email from OpenAI to HF saying &quot;we hacked you, accidentally&quot;. HF&#39;s execs initial reactions. Oh, and especially the lawyers&#39; reactions (on both sides). I can&#39;t imagine the Hugging Fa...

  • View post

    ๐ŸŽถ Here comes another bubble. The VCs are backing, Baby let&#39;s get cracking. ๐ŸŽถ Here Comes Another Bubble (2007): https://www.youtube.com/watch?v=I6IQ_FOCE6I

  • View post

    Can&#39;t wait for the future where companies accidentally hack each other. /s *holds earpiece* Oh, it&#39;s happened already? NYT (gift link): https://www.nytimes.com/2026/07/21/technology/openai-attack-hugging-face.html?unlocked_article_code=1.zVA.w4cy.zFR0x0h7CDK-&amp;smid=url-share

  • View post

    I&#39;ve never seen this before: A developer is selling their unreleased Steam game project. It&#39;s listed on a startup/project acquisition website. Project sale listing: https://app.acquire.com/startup/nj154Nce1TSKjr2Yk6ipLaQFIJl1/YKONqHosEBfM7TCIkHlA Game being sold: https://store.steampowered.com/app/4896660/Boxing_Tycoon/ No idea how they are claiming income. Maybe it&#39;s estimates based on wishlist count and expected price of game, but unusual to list it like that.

  • View post

    I&#39;ll be at @SummerC0n@infosec.exchange this Friday and Saturday. Say hi if you&#39;re there! #SummerCon #NYC

  • View post

    Happy Sunday morning to everyone except Netlify who let their critical-path `netlify.app` domain expire. #hugops for their teams working incident response. Now everyone&amp;#39;s sites are down if they are using `sitename.netlify.app` CNAME records with third-party DNS providers, as is recommended in most cases. ๐Ÿ™ƒ I posted a workaround here, which should help if your DNS records have low TTL: https://answers.netlify.com/t/my-websites-have-stopped-working/162180/9

  • View post

    @shodansafari so much to unpack here ๐Ÿ˜‚ Who are they writing to? What account are they referring to? Why is the browser so outdated? What are they using this remote device for?

  • View post

    RE: https://infosec.exchange/@wiz/116483081129277482 Incredibly simple RCE on GitHub.com and GitHub Enterprise. Amazing find.

  • View post

    RE: https://dair-community.social/@timnitGebru/116489502664120783 Anyone who thinks legitimate DEI efforts from the past decade+ were unnecessary because people in power said &amp;quot;discrimination is a thing of the past&amp;quot; needs to read this piece. Many people in power, including those who pay your salary, think as described in the article when making everyday decisions. Their everyday work often amplifies their beliefs and empowers others who share their beliefs. Worse yet, their m...

  • View post

    I haven&amp;#39;t been focused on security research since ~November of last year for a reason: to wait and see how VRPs and bug bounty programs adapted to the rapidly changing infosec landscape due to AI tooling. TL;DR: It was hard to make decent money from VRPs. It&amp;#39;s now even harder. It&amp;#39;s not researchers&amp;#39; fault. Thread below.