Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Alesandro Ortiz 🇵🇷 :heart_pride:

@AlesandroOrtiz@infosec.exchange
  • Open on infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him.

Focused on browser research. Glad to collaborate.

Website: https://AlesandroOrtiz.com
(Header 📷: roriv3ra on IG)

0 Followers
0 Following
50 Posts
Joined November 05, 2022
Website:
https://AlesandroOrtiz.com
Location:
Queens, NY / Puerto Rico
Infrequent Newsletter:
https://AlesandroOrtiz.com/subscribe
Twitter (unused):
https://twitter.com/AlesandroOrtizR

Posts

Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Aug 05, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @thisemailfindsyou@mastodon.social
@thisemailfindsyou@mastodon.social damn, are we in the hunger games or something?
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Aug 05, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Unintentionally pentesting a hospital's PHI/PII protections this past week. 15% failure rate so far across a dozen calls where they disclosed PHI and PII without any verification or insufficient verification. Somehow my banks and phone company are better (0% fail rate over years) than a major NYC hospital system (15% fail rate in a week).
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Aug 04, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @zackwhittaker@mastodon.social
@zackwhittaker@mastodon.social Has this been happening for months everywhere, but now more orgs are looking and disclosing? e.g. Anthropic didn't know about their attacks from 3+ months ago until they looked in late July. Customers didn't know who hacked them until their disclosure. Some didn't even realize they had been compromised. If it's happening more widely, even at a very small scale compared to human attacks (in line with GossiTheDog's recent industry survey), it's possible most victim orgs aren't detecting these attacks or are not able to attribute them to major AI agents.
1
0
2
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Aug 04, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @AlesandroOrtiz@infosec.exchange
@benjojo@benjojo.co.uk I actually did not realize that Adaptive Pricing fees for customers were so high until now. It does increase conversion rates, but now I feel bad that I'm passing on extra costs to customers. I previously thought it was shifting the same conversion fees that merchants used to pay over to the customer.
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Aug 04, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @benjojo@benjojo.co.uk
@benjojo@benjojo.co.uk From a merchant's perspective, it's quite bad too, whether they use Adaptive Pricing or not. Merchants can set fixed local currency price or use Adaptive Pricing. If you saw the conversion rate and fee disclosure on the checkout page, then it's Adaptive Pricing. Stripe adds 2-4% fees to customers: https://docs.stripe.com/payments/currencies/localize-prices/adaptive-pricing?payment-ui=stripe-hosted#pricing Merchants still must pay 1.5% fee for non-US cards, with or without local/adaptive pricing. (AFAIK this also applies to non-US Stripe merchant accounts.) Merchants also pay 1% for currency conversion when not using Adaptive Pricing. (With Adaptive Pricing, cost is passed on to customers.)
Adaptive Pricing
docs.stripe.com

Adaptive Pricing

Adaptive Pricing lets your customers pay in their local currency in more than 150 countries. Learn how to test local currency presentment for both Checkout and Payment Links.

0
1
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 30, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @zak@infosec.exchange
@zak@infosec.exchange Ooh, TIL about GameNative and the neat the underlying emulators. Will keep an eye on GameNative development, looks promising.
0
1
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 29, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @sundogplanets@mastodon.social
@sundogplanets@mastodon.social I'll yell this from the rooftops: Put timezones on all times unless you absolutely know the person is local to your TZ and will physically be in said TZ. When in doubt, add the TZ! Also, ET/CT/MT/PT is good year-round for U.S. TZs! Unless you're planning across a Daylight Savings change, no need to specify EDT or EST.
1
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 28, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @Ryanbigg@ruby.social
@Ryanbigg@ruby.social You joke, but I have actually done this.
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 26, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @slightlyoff@toot.cafe
@slightlyoff@toot.cafe I don't have to use their app?! Also news to me. I was also moving away from random devices on SmartThings and moving everything to HA sometime this year.
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 26, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @AlesandroOrtiz@infosec.exchange
@SecureOwl@infosec.exchange We were even a flagship tenant at our 4th office, and moved out of there in less than 3 years IIRC. 😅
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 26, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @SecureOwl@infosec.exchange
@SecureOwl@infosec.exchange I remember this happening often at several startups in the previous decade: weekday stays in company apt, train or flights, multiple office leases (often 10+ years in NYC because landlords wouldn't want less). I remember one of our CEOs joking we were more of a real estate company since we were forced to take 10+ year leases on all our offices, and we had ~5 prior offices that we outgrew and then sublet to others. We lasted about 9 years before fire sale acquisition, not even a full lease term. Startup VCs mostly are commercial lease portfolios if you think about it.
0
1
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 26, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @Jdm2@boriken.social
@Jdm2@boriken.social Sería buen nombre para un bot y website simple con titulares satíricos de Sin Comillas. 😂
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 25, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
RE: https://mastodon.social/@zackwhittaker/116977657519858883 Reuters reporting reveals an incredibly concerning timeline and (unsurprisingly) lack of responsible behavior from OpenAI. I really hope the public gets to see more details about internal reactions on both sides. The initial call/email from OpenAI to HF saying "we hacked you, accidentally". HF's execs initial reactions. Oh, and especially the lawyers' reactions (on both sides). I can't imagine the Hugging Face team being anything but furious about this, despite what they're projecting externally. Had OpenAI hacked any other company outside its sphere of influence, I don't think things would have gone as well as with HF.
Quoting
Zack Whittaker @zackwhittaker@mastodon.social
Incredibly detailed reporting by @razhael@infosec.exchange et al at Reuters on the OpenAI hack of Hugging Face, revealing new details on how it went down and how it took a week for OpenAI to notice one of its AI models was hacking into another company, citing multiple sources. More: https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/
Open quoted post
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 24, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @SecureOwl@infosec.exchange
@SecureOwl@infosec.exchange And people wonder why startup sales teams win. They'll do anything for a sale.
1
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 23, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
🎶 Here comes another bubble. The VCs are backing, Baby let's get cracking. 🎶 Here Comes Another Bubble (2007): https://www.youtube.com/watch?v=I6IQ_FOCE6I
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 22, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to on soylent.green
@mikey@soylent.green New Kool-Aid Man has dropped
1
2
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 22, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @zackwhittaker@mastodon.social
@zackwhittaker@mastodon.social I really hope the public gets to see what happened internally some day. The initial call/email from OpenAI to HF saying "we hacked you, accidentally". HF's execs initial reactions. Oh, and especially the lawyers' reactions (on both sides). I can't imagine a calm reaction from anyone on either side, despite what they're projecting externally. Had OpenAI hacked any other company outside its sphere of influence, I don't think things would have gone as well as with HF.
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 21, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Can't wait for the future where companies accidentally hack each other. /s *holds earpiece* Oh, it's happened already? NYT (gift link): https://www.nytimes.com/2026/07/21/technology/openai-attack-hugging-face.html?unlocked_article_code=1.zVA.w4cy.zFR0x0h7CDK-&smid=url-share
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 21, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @nelson@tech.lgbt
@nelson@tech.lgbt This Apple Hide My Email issue feels similar to what you posted about Google Workspace: https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 20, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @Katharine@mas.to
@Katharine@mas.to Wow, this is quite the throwback!
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 19, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @gsuberland@chaos.social
@gsuberland@chaos.social I got exponential numbers.
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 17, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @AlesandroOrtiz@infosec.exchange
Initially I was concerned this was a live game, which meant it was up for grabs by bad actors. But given there is no demo or early access release, probably not attractive for them. In the browser extension ecosystem, public sale of an established extension usually means a bad actor will acquire it. Especially if it can be bought under $50k USD.
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 17, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
I've never seen this before: A developer is selling their unreleased Steam game project. It's listed on a startup/project acquisition website. Project sale listing: https://app.acquire.com/startup/nj154Nce1TSKjr2Yk6ipLaQFIJl1/YKONqHosEBfM7TCIkHlA Game being sold: https://store.steampowered.com/app/4896660/Boxing_Tycoon/ No idea how they are claiming income. Maybe it's estimates based on wishlist count and expected price of game, but unusual to list it like that.
0
1
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 16, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @zhuowei@notnow.dev
@zhuowei@notnow.dev Figma still does this? Gist is from 2020.
0
1
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 10, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @AlesandroOrtiz@infosec.exchange
At #SummerCon today, great talks and folks so far! #NYC
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 08, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
I'll be at @SummerC0n@infosec.exchange this Friday and Saturday. Say hi if you're there! #SummerCon #NYC
0
1
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 08, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @scream@bots.robots.rodeo
@scream@bots.robots.rodeo Now, subtly signaling to your significant other that you want to leave the party
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 08, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @scream@bots.robots.rodeo
@scream@bots.robots.rodeo Now, answering a Miss USA pageant question
0
1
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 08, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @scream@bots.robots.rodeo
@scream@bots.robots.rodeo Now, introducing a vaudeville act
0
1
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 08, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @scream@bots.robots.rodeo
@scream@bots.robots.rodeo Now, threatening a hostile takeover
0
6
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 08, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @scream@bots.robots.rodeo
@scream@bots.robots.rodeo A little more
0
1
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 08, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @scream@bots.robots.rodeo
@scream@bots.robots.rodeo Give me a little bit more
0
1
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 07, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @SecureOwl@infosec.exchange
@SecureOwl@infosec.exchange Reminds me of this news report of a person who broke into a store while his car was running with keys, had car stolen during burglary, and then called the cops while at the scene to report his car was stolen. https://youtu.be/XFkmAlUHttc
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 07, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @simplenomad@rigor-mortis.nmrc.org
@simplenomad@rigor-mortis.nmrc.org Many have to do this due to their employers prohibiting payments from other companies. These policies are usually in place to avoid ethical or contractual issues. Others donate out of generosity. A good example of this is Seunghyun Lee, who has made large donations to picoCTF: https://www.cmu.edu/news/stories/archives/2025/january/student-bug-bounty-discovery-supports-picoctfs-cybersecurity-education-efforts-with-462000-gift If you search the Chromium issue tracker, there are multiple cases of folks donating rewards to EFF and other charities for either of the reasons I mentioned.
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 05, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @clark@hachyderm.io
@clark@hachyderm.io @SwiftOnSecurity@infosec.exchange "not again"? 😂
3
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Jul 03, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @SecureOwl@infosec.exchange
@SecureOwl@infosec.exchange Also can be recruitment pipeline.
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · May 29, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @SwiftOnSecurity@infosec.exchange
@SwiftOnSecurity@infosec.exchange 🎉 I was just telling my Dad over the phone to install Paint.net but NOT to go to Paint.net, and to not Google "paint.net" because they might click on a malicious ads.
5
7
1
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · May 17, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @SwiftOnSecurity@infosec.exchange
@SwiftOnSecurity@infosec.exchange Thought this was one of @gsuberland@chaos.social's Unsafe Warnings stickers. :D
2
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · May 13, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @GossiTheDog@cyberplace.social
@GossiTheDog@cyberplace.social Do you think U.S. authorities could be investigating NightmareEclipse due to their disclosures? I imagine Microsoft is investigating internally to determine if it's someone with previous/current access to internal info that is still legally protected (by contract or law). Based on their posts, MS might already know their identity if they have interacted with this person via MSRC and have their payment info for the bug bounty programs.
0
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · May 12, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @briankrebs@infosec.exchange
@briankrebs@infosec.exchange We may need a "safetime" tracker that lets us know when there were no known widely-used packages that were compromised in a repository. Retroactive, of course, but might be interesting like uptime. e.g. npm might have 98.5% safetime this week based on known compromised packages being available for X hours.
4
0
1
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · May 10, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange

Happy Sunday morning to everyone except Netlify who let their critical-path `netlify.app` domain expire. #hugops for their teams working incident response.

Now everyone's sites are down if they are using `sitename.netlify.app` CNAME records with third-party DNS providers, as is recommended in most cases. 🙃

I posted a workaround here, which should help if your DNS records have low TTL: https://answers.netlify.com/t/my-websites-have-stopped-working/162180/9

7
1
7
2
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · May 07, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @freddy@social.security.plumbing
@freddy@social.security.plumbing Less? That's very surprising. Thought it would continue increasing despite *gestures wildly* everything.
0
1
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · May 07, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @freddy@social.security.plumbing
@freddy@social.security.plumbing Ah, forgot about those changes. (It's been a _very long_ 2 months.) Reward amounts seem unchanged and Firefox still pays for reasonable moderate impact vulns, which is appreciated. Hope reward amounts aren't lowered given the new landscape, especially since FF rewards were much lower than other browser VRPs (now about the same).
1
1
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · May 07, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @freddy@social.security.plumbing
@freddy@social.security.plumbing Thanks for sharing and making those reports public early. Great insight into what's happening with browser VRPs. Is Mozilla planning changes to the Firefox VRP in response to this, similar to recent changes to the Chrome VRP? (Or have changes already been made? I'm not closely following the Firefox VRP, unfortunately.)
0
1
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · May 01, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @sstephenson@indieweb.social
@sstephenson@indieweb.social SSO knew better but could have been on this list.
1
1
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · May 01, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @SecureOwl@infosec.exchange
@SecureOwl Now try some blind XSS payloads...
13
2
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Apr 30, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @AlesandroOrtiz@infosec.exchange
The tech industry is now reaping what it started sowing years ago with irresponsible AI rollouts and AI-centric budgets. There's a lot of macroeconomic reasons, but within tech I mainly blame the higher-level executives pushing for limited budgets for humans and treating everything as a problem that AI can solve. That's not even mentioning the limited upsides of most AI deployments, compared to the impact on Earth's environment and the impact to human life and economic systems. But the impacts of AI have been discussed at length. I've generally been pessimistic about where tech and capitalism is going, so I'm not going to pretend things are going to get better as a society if current trends continue.
1
0
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Apr 30, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @AlesandroOrtiz@infosec.exchange
An avalanche of reports (both good and bad quality) had strained existing processes and teams. On the other hand, improved tooling also helped defenders do better internal research and speed up patching, among other processes. Overall, security research might be better with AI tooling, but we also need to throw more humans at the problem. And pay them well. Recent trends are generally good for users (better security, hopefully). But it's bleak for security researchers who focus on bug bounties, myself included. I can probably no longer make decent income from VRPs. I don't know how many others can too, given the widespread suspension of VRPs or narrower scopes of higher-difficulty issues (~good) with historically-low rewards (awful). While I had seen this coming for a year or so, it's still disappointing.
1
2
1
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Apr 30, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange

I haven't been focused on security research since ~November of last year for a reason: to wait and see how VRPs and bug bounty programs adapted to the rapidly changing infosec landscape due to AI tooling.

TL;DR: It was hard to make decent money from VRPs. It's now even harder. It's not researchers' fault.

Thread below.

0
1
0
0
Open post
AlesandroOrtiz
Alesandro Ortiz 🇵🇷 :heart_pride: @AlesandroOrtiz@infosec.exchange · Apr 29, 2026
Alesandro Ortiz 🇵🇷 :heart_pride:
@AlesandroOrtiz@infosec.exchange

Software Engineer. Security Researcher. Puerto Rican 🇵🇷. New Yorker. Bilingual. LG(B)TQ :heart_pride:. He/him. Focused on browser research. Glad to collaborate. Website: https://AlesandroOrtiz.com (Header 📷: roriv3ra on IG)

infosec.exchange
Replying to @mttaggart@infosec.exchange
@mttaggart Detailed analysis by Watchtowr: https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
9
1
3
0

Remote instance

infosec.exchange
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 23:03:54 UTC