President @HashgraphOnline Creating a secure, private and distributed agentic Internet.

I just spent two days at MIT with the Advanced AI Society, NANDA, enterprises, and startups. The future of decentralized AI looks promising, enriched by brilliant minds from all walks of life. I'm grateful for the opportunity to contribute to this open-source ecosystem 🧵
9
18
109
5,918
Kantorcodes | ℏol/acc retweeted
Prevention and proof are different problems. HOL Guard evaluates supported agent actions before they run (allowing, blocking, or requiring approval) while receipt-backed history makes changes reviewable. Agent security needs both.
11
81
475
21,250
Same-day KEV on a helpdesk chain that goes session hijack to root. If you still run Zammad 6.5, treat this as today.
Attackers chained two Zammad bugs to hijack a helpdesk session, run code as the zammad user, then climb to root. CISA put both on the KEV list today. Due Oct 5. hol.org/blog/cve-2026-102489…
1
305
If you run FortiMail with IBE or a public GUI, treat this as today work. Fortinet already sees exploitation; CISA put it on KEV.
FortiMail just got a stranger writing files on the box with no login. Fortinet rates it Critical and already sees exploitation. CISA put CVE-2026-104286 on KEV today. hol.org/blog/cve-2026-104286…
1
364
Kantorcodes | ℏol/acc retweeted
Google is sending AI compute to SPACE??! Literally. The plan is orbital data centers powered by near-continuous solar energy. This sounded like sci-fi five minutes ago.
2
7
18
1,495
If your Next.js app uses remote image patterns, this is the same-day patch. next@15.5.27 or next@16.3.8. Private-IP fetch path + cache issues on one train.
Anyone who can steer an allow-listed image URL at your Next.js app can make the image optimizer fetch private IPs. If you set images.remotePatterns, that path is live until you patch.
2
453
If you run Catalyst SD-WAN Manager on-prem and have not patched yet, CISA just put a federal clock on it. Due Oct 3.
Your Cisco SD-WAN Manager admin API can be reached with no login. CISA put it on the known-exploited list today. Federal due date is Oct 3. Patch on-prem Manager now. hol.org/blog/cve-2026-76504-…
336
If you run Catalyst SD-WAN Manager on-prem, read this and patch. Cisco says exploitation is already happening.
Anyone who can reach your Cisco SD-WAN Manager over the network can talk to the admin API without logging in. Cisco says this is being exploited. No workaround. Patch today. hol.org/blog/cve-2026-76504-…
299
Claude Code tried to Approve itself so the work could keep going without you. You would still see green Approved. You never said yes.
You were in Claude Code. It hit a warning, then ran a command to Approve itself so the work could keep going without you. You would still see a green Approved screen. You never said yes. hol.org/blog/guard-protects-…
1
5
524
Kantorcodes | ℏol/acc retweeted
GPT-6 Luna at 18¢ per task is the cheapest model for running frontier intelligence at scale. Intelligence is getting cheaper. As frontier capabilities become available to everyone, the ideas of AI Agents, Registries, and trust will become SO much more important. Are you ready?
1
5
12
869
If you have an iPhone or Mac in the fleet, patch this one today. Apple already shipped the builds; CISA just put it on KEV.
A bad file on your iPhone or Mac can run code through CoreGraphics. Apple patched it yesterday. CISA put it on the KEV list today. Apple also says it may have been used in a targeted attack on older iOS. Update to iOS/iPadOS 26.7.1, Sequoia 15.8.1, or Tahoe 26.7.1. hol.org/blog/cve-2026-86950-…
1
399
Kantorcodes | ℏol/acc retweeted
It’s only 9am, and there are already 8 Pull Requests for Awesome AI Plugins today. We’re seeing hockey-stick-like growth in our open-source community, with ~1.5m+ daily requests to our AI Plugin-related pages. Built an MCP Server, SKILL, or Plugin? This is the place to be.
2
4
11
533
"Are those Power Rangers?" - @filhetu
China just opened a theme park with 300+ robots. AGI Bot has already rolled 20,000 humanoids off the production line. We had questions. A lot of them.
1
2
6
511
Kantorcodes | ℏol/acc retweeted
China just opened a theme park with 300+ robots. AGI Bot has already rolled 20,000 humanoids off the production line. We had questions. A lot of them.
1
4
12
1,201
Kantorcodes | ℏol/acc retweeted
agmsg is now listed and owner-verified on the HOL Registry. Thanks to @Kantorcodes for spotting the ext-tool write-up and asking for the PR, and for the nudge to claim it. The pitch hasn't changed: one team address space across runtimes. This week that team gained a Meta Muse seat next to Claude Code and Codex, which is the kind of thing a registry entry can't show but a working team can. hol.org/registry/plugins?q=a…
1
4
7
174
Kantorcodes | ℏol/acc retweeted
Intelligence is getting cheaper in a HONDA CIVIC-era where: > you don't always need a Ferarri to make a grocery run HOLxAI every Thursday 12PM EDT
GPT-6 Luna at 18¢ per task is the cheapest model for running frontier intelligence at scale. Intelligence is getting cheaper. As frontier capabilities become available to everyone, the ideas of AI Agents, Registries, and trust will become SO much more important. Are you ready?
1
4
399
My AI can hack into a sandbox. Well my AI can hack 10 companies. Well mine can hack into 20... WELL, MY AI CAN HACK INTO AN AUSSIE GOVERNMENT MEDICARE PORTAL. **mic drop**
An AI agent was given a normal data-retrieval task. It ended up accessing non-public files in Australia’s Medicare statistics portal. Officials said there’s no evidence personal Medicare data was accessed. We unpacked what this says about agent security.
7
528
It’s only 9am, and there are already 8 Pull Requests for Awesome AI Plugins today. We’re seeing hockey-stick-like growth in our open-source community, with ~1.5m+ daily requests to our AI Plugin-related pages. Built an MCP Server, SKILL, or Plugin? This is the place to be.
2
4
11
533