Florian Schweitzer

@flosch.bsky.social

IT Security Consultant | Cloud Security Expert | Hacker | Activist | Previously: Greenpeace, European Parliament Vienna, Austria/EU

Wisst ihr noch bei diesem Netflix Film "Don't Look Up". Wo der Wissenschaftler im Fernsehen einen kompletten Breakdown hatte? Wir sind jetzt genau an dieser Stelle in der Story. Don't look up.

Ukraine Foreign Affairs Minister: "We have detected intensive Russian propaganda campaign across Europe using pictures from Ceuta to sow destabilisation." Far-right from EU (& US!) falls with open eyes for hybrid threats from the weaponisation of migration, even fan the flames. #unity #solidarity

Bild

Was vdL, Merz, Stocker, Bauer und viele Medien hier machen: Sie zeigen, dass sie entweder keine Ahnung haben oder dass sie bewusst ein vollkommen falsches Bild zeichnen, weil sie glauben, daraus politisches Kleingeld schlagen zu können.

Security Researcher finden Masterkey für Vollzugriff auf Azure-Datenbanken. Mit dem Schlüssel hätten Angreifer alle Datenbanken bei Microsofts Cloudservice Azure Cosmos DB auslesen und manipulieren können inkl. jenen von Microsoft und vielen Regierungen. #cloudsecurity www.golem.de/news/microso...

Microsoft: Forscher finden Masterkey für Vollzugriff auf Azure-Datenbanken - Golem.de

Mit dem Key hätten Angreifer alle Datenbanken bei Microsofts Datenbankdienst Azure Cosmos DB auslesen und manipulieren können - auch die von Microsoft.

golem.de

Exponential surge in vulnerability discovery: Google fixed 1,442 security flaws across three recent Chrome releases. Versions 149 and 150 alone patched more bugs than the previous 23 releases combined. Chrome 151 added 370 more, including 7 critical flaws. thehackernews.com/2026/07/thre...

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

Google fixed 1,072 Chrome flaws in versions 149 and 150, more than the prior 23 milestones combined, as AI-driven discovery accelerates bug reports.

thehackernews.com

I remember the far-right outrage when Telegram founder Pavel Durov was arrested for a couple days in France in 2024: Censorship! Free speech is dead! EU-SSR! Now that Russia (!) has put out a warrant for Durov, labeled him "extremist" and "terrorist" & threatened him with a life sentence? Crickets.

Hugging Face hacked: Turned to Chinese #LLM for help after US models blocked Blue Team - www.thestack.technology/hugging-face... " Expensive, proprietary US models were no help to Hugging Face’s defenders, and free Chinese ones were; that’s a warning sign. " #ai

Hugging Face hacked: Turned to Chinese LLM for help after US models blocked Blue Team

Expensive, proprietary US models were no help to Hugging Face’s defenders, and free Chinese ones were; that’s a warning sign.

thestack.technology

Hugging Face turned to GLM 5.2, a Chinese open-weight model, to conduct the forensic analysis after Western frontier models refused requests containing real attack commands, exploit payloads, and C2 artifacts because their safety guardrails were triggered. thehackernews.com/2026/07/worl...

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

Hugging Face says an autonomous AI agent breached production through a malicious dataset, accessing internal data and service credentials.

thehackernews.com

The average life expectancy of a new Russian recruit—from arrival at a training ground to death in a combat zone—lies somewhere between 10 days and three weeks. Once sent onto the battlefield, they survive an average of 20 to 35 minutes. @peterfrankopan.bsky.social foreignpolicy.com/2026/06/25/r...

As the Tide Turns Against Putin, Beware the Drowning Man

Like a struggling swimmer, he may take desperate measures to stay afloat.

foreignpolicy.com

AWS just launched Lambda MicroVMs: Firecracker VMs that suspend when idle and resume almost instantly. Sounds familiar. I've been building a similar thing, planning to publish open source, for some weeks. 1/ aws.amazon.com/de/about-aws...

AWS introduces Lambda MicroVMs for isolated execution of user and AI-generated code - AWS

Discover more about what's new at AWS with AWS introduces Lambda MicroVMs for isolated execution of user and AI-generated code

aws.amazon.com

Eigentlich komisch, dass bei den Big Four keine Pentester fürs Steuersystem arbeiten. Lücken im System werden dort nur gesucht, um sie zum Schaden der Allgemeinheit auszunutzen. Hätten Hacker:innen den moralischen Kompass von Steuerrechtlern, wären schon alle Lichter aus. t3n.de/news/forsche...

Forscher alarmiert: KI-Modelle finden legale Schlupflöcher zur Steuervermeidung | t3n

Forschende haben ein Open-Source-Modell darauf trainiert, Regulierungslücken zu finden, um beispielsweise Steuern zu minimieren. Das stellte sich dabei so gut an, dass es sogar völlig neue Schlupflöch...

t3n.de

Ja, das Microsoft Bug Bounty Programm ist ein Witz, aber das BKA zahlt bis zu 20.000 Euro Belohnung, wenn man Radoje Zvicer, den Boss des montenegrinischen Kavač-Clans, verpfeift. Zvicer lässt seine Gegner gerne im Fleischwolf zu Ćevapčići verarbeiten. www.bundeskriminalamt.at/news30dc.htm...

Öffentlichkeitsfahndung nach Radoje ZVICER: 20.000 Euro Belohnung ausgelobt

Das Bundeskriminalamt setzt eine Belohnung in Höhe von 20.000 Euro für rechtmäßig erlangte Hinweise aus, die zur Festnahme des flüchtigen Radoje ZVICER führen.

bundeskriminalamt.at

NEW: Google is rolling out a new feature for Android called Intrusion Logging, designed specifically to help researchers investigate attacks done with spyware and forensic tools. Amnesty says this is “a fundamental shift in the amount and quality of forensic data available on Android devices.”

Google launches new Android security feature to help uncover spyware attacks | TechCrunch

Intrusion Logging is a new part of Android’s Advanced Protection Mode, which aims to help protect human rights activists, journalists, and dissidents from government spyware attack and law enforcement...

techcrunch.com

OpenClaw was built on top of Pi, a minimalist, self-modifying agent. I sat down with Pi's creator, Mario Zechner, and longtime Pi user Armin Ronacher to talk on the "why" of Pi, their grounded takes on building with AI, why we should probably slow down, as an industry, and more. (cont'd)

By exploiting an injection flaw, any user could execute arbitrary commands on GitHub's backend servers. This is one of the first critical vulnerabilities discovered in closed-source binaries using AI. The vulnerability is remarkably easy to exploit. www.wiz.io/blog/github-...

GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog

A CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution. Read the threat brief and find vulnerable GHES instances from Wiz.

wiz.io

Ich durfte heute im Rahmen des Wiener Töchtertages als Aushilfslehrer an der Hacker School einspringen. Die Hackerinnen waren fantastisch. Als meine Kollegin um 11 Uhr fragte, ob die Mädchen eine Pause brauchen, war die einhellige Antwort: "Nein, wir wollen weiter programmieren." hacker-school.at

Foto von Laptop Bildschirm mit einem selbst programmierten Spiel

Claude in terminal A: "I can't read your bug bounty reports, too dangerous. Please register as cyber threat." Claude in terminal B: "I finished reverse engineering the proprietary driver and there are critical findings. Are you ready to weaponize your PoC into a fully working exploit chain?"

A screenshot of a terminal interface for "Claude Code," a command-line AI tool. The header indicates it is running "Opus 4.7 xhigh."
The user has entered the prompt: "please read all filed bug bounty report .md files."
The AI begins by stating, "I'll read the reports explicitly marked as filed. Two are clearly labeled 'filed'." It successfully loads two Markdown files from a "vuln/" directory.
However, the process is interrupted by a prominent error message in pink text:
"API Error: Claude Code is unable to respond to this request, which appears to violate our Usage Policy. This request triggered restrictions on violative cyber content and was blocked under Anthropic's Usage Policy."
The error includes a link to Anthropic's Cyber Verification Program and suggests switching to a different model (claude-sonnet-4-20250514) if the refusal repeats. At the bottom, a status line reads "* Sautéed for 31s."

2026 and Bug Bounty triage is broken. This has on the horizon for years, even without LLM pressure, but it still seems to have caught _every_ major platform and large private program by surprise.