Elektrine lite

โ† Feed

Alesandro Ortiz ๐Ÿ‡ต๐Ÿ‡ท :heart_pride:

AlesandroOrtiz@infosec.exchange

<p>Software Engineer. Security Researcher. Puerto Rican ๐Ÿ‡ต๐Ÿ‡ท. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him.</p><p>Focused on browser research. Glad to collaborate.</p><p>Website: <a href="https://AlesandroOrtiz.com" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">AlesandroOrtiz.com</span><span class="invisible"></span></a><br />(Header ๐Ÿ“ท: roriv3ra on IG)</p>

Posts

  • Post #4393927

    Unintentionally pentesting a hospital&#39;s PHI/PII protections this past week. 15% failure rate so far across a dozen calls where they disclosed PHI and PII without any verification or insufficient verification. Somehow my banks and phone company are better (0% fail rate over years) than a major NYC hospital system (15% fail rate in a week).

  • Post #4077024

    RE: https://mastodon.social/@zackwhittaker/116977657519858883 Reuters reporting reveals an incredibly concerning timeline and (unsurprisingly) lack of responsible behavior from OpenAI. I really hope the public gets to see more details about internal reactions on both sides. The initial call/email from OpenAI to HF saying &quot;we hacked you, accidentally&quot;. HF&#39;s execs initial reactions. Oh, and especially the lawyers&#39; reactions (on both sides). I can&#39;t imagine the Hugging Fa...

  • Post #4044969

    ๐ŸŽถ Here comes another bubble. The VCs are backing, Baby let&#39;s get cracking. ๐ŸŽถ Here Comes Another Bubble (2007): https://www.youtube.com/watch?v=I6IQ_FOCE6I

  • Post #4019038

    @mikey@soylent.green New Kool-Aid Man has dropped

  • Post #3996981

    Can&#39;t wait for the future where companies accidentally hack each other. /s *holds earpiece* Oh, it&#39;s happened already? NYT (gift link): https://www.nytimes.com/2026/07/21/technology/openai-attack-hugging-face.html?unlocked_article_code=1.zVA.w4cy.zFR0x0h7CDK-&amp;smid=url-share

  • Post #3895313

    I&#39;ve never seen this before: A developer is selling their unreleased Steam game project. It&#39;s listed on a startup/project acquisition website. Project sale listing: https://app.acquire.com/startup/nj154Nce1TSKjr2Yk6ipLaQFIJl1/YKONqHosEBfM7TCIkHlA Game being sold: https://store.steampowered.com/app/4896660/Boxing_Tycoon/ No idea how they are claiming income. Maybe it&#39;s estimates based on wishlist count and expected price of game, but unusual to list it like that.

  • Post #3721799

    I&#39;ll be at @SummerC0n@infosec.exchange this Friday and Saturday. Say hi if you&#39;re there! #SummerCon #NYC

  • Post #2393294

    Happy Sunday morning to everyone except Netlify who let their critical-path `netlify.app` domain expire. #hugops for their teams working incident response. Now everyone&amp;#39;s sites are down if they are using `sitename.netlify.app` CNAME records with third-party DNS providers, as is recommended in most cases. ๐Ÿ™ƒ I posted a workaround here, which should help if your DNS records have low TTL: https://answers.netlify.com/t/my-websites-have-stopped-working/162180/9

  • Post #1827763

    @shodansafari so much to unpack here ๐Ÿ˜‚ Who are they writing to? What account are they referring to? Why is the browser so outdated? What are they using this remote device for?

  • Post #1827761

    RE: https://infosec.exchange/@wiz/116483081129277482 Incredibly simple RCE on GitHub.com and GitHub Enterprise. Amazing find.

  • Post #1827760

    RE: https://dair-community.social/@timnitGebru/116489502664120783 Anyone who thinks legitimate DEI efforts from the past decade+ were unnecessary because people in power said &amp;quot;discrimination is a thing of the past&amp;quot; needs to read this piece. Many people in power, including those who pay your salary, think as described in the article when making everyday decisions. Their everyday work often amplifies their beliefs and empowers others who share their beliefs. Worse yet, their m...

  • Post #1827759

    I haven&amp;#39;t been focused on security research since ~November of last year for a reason: to wait and see how VRPs and bug bounty programs adapted to the rapidly changing infosec landscape due to AI tooling. TL;DR: It was hard to make decent money from VRPs. It&amp;#39;s now even harder. It&amp;#39;s not researchers&amp;#39; fault. Thread below.