• 0 Posts
  • 14 Comments
Joined 5 months ago
cake
Cake day: December 28th, 2025

help-circle



  • This wasn’t even a prompt-injection or context-poisoning attack. The vulnerable infrastructure itself exposed everything to hack into the valuable parts of the company:

    Public JS asset  
        → discover backend URL  
            → Unauthenticated GET request triggers debug error page  
                → Environment variables expose admin credentials  
                    → access Admin panel  
                        → see live OAuth tokens  
                            → Query Microsoft Graph  
                                → Access Millions of user profiles  
    

    Hasty AI deployments amplify a familiar pattern: Speed pressure from management keeps the focus on the AI model’s capabilities, leaving surrounding infrastructure as an afterthought — and security thinking concentrated where attention is, rather than where exposure is.






  • From the article:

    J1007+3540 lives inside a massive galaxy cluster filled with extremely hot gas. This environment creates enormous external pressure—far higher than what most radio galaxies experience. As the revived jets push outward, they are bent, squeezed, and distorted by the interaction with the dense medium.

    Seems to me that it’s not the black hole itself was turned off and on again, but rather that it’s jet was suppressed by the colossal gravitational (?) pressure of the surrounding galactic core.