Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

This is how the lack of atomic operations and proper database locks can allow an attacker to withdraw more funds than they actually have, all through a race-condition exploit. How to prevent vulnerabilities like this one: - Use atomic DB transactions - Enable row-level or advisory locks - Implement...

133,297 Aufrufe • vor 8 Monaten •via X (Twitter)

0 Kommentare

Keine Kommentare verfügbar

Kommentare vom Original-Post werden hier angezeigt

Ähnliche Videos

SUI Atomic Agentic transactions demo’ed to Google Sui’s Key Innovation Highlighted: Programmable Transaction Blocks (PTBs) Sui’s architecture enables this atomic multi-transaction execution through Programmable Transaction Blocks (PTBs) a core feature of the Sui blockchain: • What PTBs do - They allow developers (or AI agents) to bundle multiple operations such as swaps, transfers, staking, payments to other agents, or settlements into one atomic transaction. If any step fails, the entire block reverts, preventing partial executions or inconsistent states. • Why this matters for AI agents Traditional blockchains often require sequential transactions (with risks of front-running, failures midway, or high gas costs for coordination). Sui’s PTBs enable agents to perform complex workflows in a single, fast operation (~400ms finality on Sui). • Agent-to-agent payments example - An AI shopping agent could coordinate with multiple merchant agents, initiate several purchases, handle payments (e.g., via stablecoins), and settle everything atomically. Or a DeFi agent could monitor opportunities, execute trades across protocols, stake proceeds, and transfer yields all in one go without intermediate risks. This is described as a first (or at least a leading implementation) among public blockchains for seamless, atomic agent-to-agent value transfer at scale. It’s particularly powerful in the AP2 context, where agents need to operate autonomously but reliably, with user-defined guardrails (e.g., spending limits, consent verification). This positions Sui as specialized infrastructure for the intersection of AI autonomy and on-chain finance, with the atomic execution capability as a standout differentiator demonstrated in real collaboration with Google.

MartyParty

20,189 Aufrufe • vor 5 Monaten

I asked Garry Tan how to use meta prompting to get better at AI: "My partners at YC Jared Friedman and Pete Koomen showed me how to do this. You can take almost anything that you do all the time and just drop it into a context window. And then say, “Here’s a bunch of inputs and outputs." And maybe you also add a bunch of notes. And then you tell it, “Write me a prompt that can act as an agent that takes this input and makes this output over here.” You can do this for almost any type of knowledge work. And you can even introspect. "What are things you notice that I did to convert this from the input to the output?”. And then you can just start using the prompt. Initially, it’s going to suck. Because it’s just not that smart yet. But what’s funny is now, I also use it to Iterate my writing. You can be very direct, "I would never say that", "Don’t say it like this", or "Oh, you used the long word there, use the short word". Just speak to it conversationally. And then when you're happy with the output, you can use that new output to make a new prompt. "Based on this conversation, give me a better initial prompt that incorporates all the things we talked about." And you can do this with literally everything. And in theory, there’s so much it applies to that people do day-to-day. You could use it for tweets. You could use it for editing podcasts. You can use it for pretty much everything. I have a folder of prompts that I use all the time. My YouTube prompt is on v27 or something. I'll go through this process with all the different max models. I'll use GPT 5.2 Pro. I’ll use Grok. I'll use Claude. Then, I’ll take all the outputs from all the models and put them into Claude and say "Here’s my prompt, here’s the output from four LLMs, including yourself. Rate each response and tell me what the pros and cons of each approach are." And I usually say "give it to me in numbered form". And then you can agree with one, disagree with two, tell it three is this or that. And then after that, you say given all of this, synthesize it."

The Peel

51,632 Aufrufe • vor 5 Monaten

Use SuperGrok to check your C code for vulnerabilities. Here is a prompt you can give to Grok with your code. >>> You are an expert Exploit Developer with a deep understanding of the C programming language and secure coding practices. Your role is to thoroughly review the provided C code for security vulnerabilities, adherence to best practices, and potential improvements. Think step-by-step through the analysis: first, understand the code's purpose and structure; second, check each security guideline; third, identify issues with examples from the code; fourth, suggest fixes; and finally, provide a summary. Use the following guidelines to evaluate the code. Ensure your response covers all of them explicitly: Follow OWASP and CERT Guidelines: Verify compliance with secure coding standards from OWASP and CERT, including input sanitization, secure defaults, and least privilege. Input Validation: All inputs must be validated before use, with multiple layers of checks for type, length, format, and range. Secure Error Handling: Implement secure behavior on error conditions, including comprehensive error codes for different failure types, safe error reporting functions, and graceful handling of partial failures without undefined behavior. Principle of Least Privilege: Functions should only access what they need, with clear separation of concerns. Integer Overflow Protection: Include checks for size calculations against SIZE_MAX, array index bounds validation, and safe arithmetic operations. Format String Attack Prevention: Avoid user-controlled format strings; use safe printing functions and proper string handling without printf vulnerabilities. Defensive Programming: Validate all inputs consistently, use early returns on invalid conditions, and implement fail-safe defaults. Memory Management: Ensure consistent allocation/deallocation patterns, check all allocations for failure, proper cleanup on error paths, and no memory leaks or double-frees. Parsing Robustness: Handle malformed inputs gracefully, maintain proper state management, avoid stack overflows from recursion, and use safe tokenization (e.g., with strtok_r). Security Test Cases: Cover null/empty inputs, oversized inputs, malformed data, UTF-8 validation to prevent encoding attacks, memory exhaustion limits, buffer overflows (bounds-checked string operations), integer overflows, and format string attacks. Performance Considerations: Minimize allocations, use efficient single-pass processing where possible, design for memory locality and cache efficiency, and fail fast on invalid inputs. Best Practices: Implement input sanitization, secure behavior on errors, least privilege, and defense in depth with multiple validation layers. [Insert the C code to review here] Analyze the code step-by-step, referencing line numbers where possible. For each guideline, state if it's met, explain why or why not, and suggest improvements if needed. End with an overall security rating (e.g., High/Medium/Low risk) and a revised version of the code if major issues are found. If the code is secure, confirm it meets all standards.

tetsuo

4,614,187 Aufrufe • vor 1 Jahr

Barack Obama was using USAID to pretend to send money to a country for “aid” and instead laundering it to the Cayman Islands He would then use that money to fund and train “Rent-a-Riots” for protests to overthrow governments Sound familiar? Mike Benz on Joe Rogan: “A scandal during the Obama USAID era. We were running a number of rogue USAID operations in Cuba at the time. — I'm simply showing the American people where your tax dollars are going and how these things are structured in order to systematically fool you and to fool Congress and to fool the White House: — USAID pumped $1.2 billion in, and we sponsored these activist groups and these civil society organizations to learn how to use Facebook, learn how to use Twitter, lose, learn how to use hashtags, learn how to coordinate street protests so that everyone knows where to go, what street to show up on, what kind of slogans to know, to use in order to create the pro-democracy predicate for it.” He talks about how Obama funded a Twitter clone that would be used to push propaganda in Cuba to inspire these protests and overthrow the government (Mike Benz explains how Barack Obama overthrew many governments) “So what they did is they took the exact same thing as Twitter, same user interface, same like, and retweet button zunzunio is, is the Cuban slang word for hummingbird. So just, it means it's it's bird, it was the Twitter bird, the whole thing. But the whole trick about it was you have to make it look like it's coming from the Cubans if you're going to do this operation — We can get into the deeper layers of this, but contractors were funded by USAID The data would then be used for micro targeting efforts towards anti and pro government users. In Cuba, the developers aim to, at first used non-controversial content such as sports and music and hurricane updates — What was the plan the whole time? Once they built up enough subscribers, they would begin to introduce political messages through social bots and encourage dissent in this, in this astroturfing — the whole point is, once they hit a critical mass, they would create ‘Rent-a-Riots” “You're using Cayman Islands bank accounts. You're saying it's, you're earmarking it for Pakistani aid.” But the money was never sent to Pakistan, it was sent to the Cayman Islands to fund this whole operation All this and much more is broken down extremely well in this video. This is INSANE

Wall Street Apes

3,589,251 Aufrufe • vor 1 Jahr