Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
IT Security NachrichtenOnePlus/OxygenOS: Schad-App erhält Root-Zugriff ohne Berechtigungen(24.09.2026 um 23:38 Uhr)
•
IT Security NachrichtenRyuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison(24.09.2026 um 22:50 Uhr)
•••••
Hacking & PentestingRyuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison(24.09.2026 um 22:50 Uhr)
•
AI & KI NachrichtenWhy the U.N. Still Matters(24.09.2026 um 23:00 Uhr)
•••
IT Security NachrichtenOnePlus/OxygenOS: Schad-App erhält Root-Zugriff ohne Berechtigungen(24.09.2026 um 23:38 Uhr)
•
IT Security NachrichtenRyuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison(24.09.2026 um 22:50 Uhr)
•••••
Hacking & PentestingRyuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison(24.09.2026 um 22:50 Uhr)
•
AI & KI NachrichtenWhy the U.N. Still Matters(24.09.2026 um 23:00 Uhr)
•••
Intelligence View
⚡ tsecurity.de Intelligence

starting up firstly.academy

So, today was less about the big dream and more about actually getting stuff done. I've got this idea for an AI language platform, and with Gemini 2.5 and Cursor I started hammering it into shape – something real I can actually test. No m…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

So, today was less about the big dream and more about actually getting stuff done. I've got this idea for an AI language platform, and with Gemini 2.5 and Cursor I started hammering it into shape – something real I can actually test. No more trying to do everything at once; we went lean and focused.



1. Finding the Starting Line



First thing, I ditched the vague "everyone learning languages" target. That just doesn't work. I narrowed it way down:



Who: FCE Exam takers, specifically teens (14-20). They have a clear goal (pass the test), and their parents are likely the ones paying. Much better.



Problem: They need good, targeted speaking practice and feedback, which is hard to get consistently.



First Product (V0.1): Cut everything non-essential. Forget the whole course for now. We're starting only with the FCE Speaking Part 2 AI tool. That's the MVP – the smallest thing I can build to see if the core idea even works.



2. Getting the Basics Sorted



Needed some groundwork:



The Name: Grabbed the firstly.academy domain. It fits the exam focus, sounds decent, and was cheap (€17!). Skipped all the extra .store, .world stuff they tried to sell me.



3. Teaching the AI Some Manners



This was the main event. I had recordings of real FCE exams with examiner comments – absolute gold.



Organized It: Put the transcripts and comments into a structured format (started with a Google Doc, thought about JSONs – good for later, but kept it simple for now).



Tested the AI: Ran the real examples through my current AI tool. The verdict? Way too strict compared to the human examiners.



Made it Smarter (Iterated):



Figured out why it was too strict by looking at how lenient B2 examiners actually are with minor mistakes.



Tweaked the AI's instructions (the prompt): Told it to act like a B2 examiner, focus on task completion and clarity, and tolerate typical B2 errors. Added a couple of real examples directly into the prompt to show it what I meant.



Made a key decision: Got rid of the numerical scores. They weren't reliable based on just text (especially pronunciation!), and good written feedback is more valuable right now.



Added a new feature: An "Examiner Summary" paragraph at the end to give a quick overview.



Final touch: Made the summary address the student directly ("You did this well..." instead of "The candidate did...") to make it feel more personal.



Fixed Bugs: Had to squash some backend (TypeError, ValidationError) and frontend (undefined variable) bugs that popped up after changing the data structure (removing scores, adding summary). Eventually tracked it down to needing to update the data model definition (FCEAnalysisResponse) in the backend and clearing stubborn browser cache.



4. Where I'm At Now



So, after all that, the V0.1 feature is actually working! The AI gives feedback on Speaking Part 2, it includes the summary, it's less harsh, it addresses the student directly, and it shows up correctly on the webpage.



Is it the final perfect version? Definitely not. But is it ready for the most important step? Yes.



Now it's all about validation. I need to get this in front of those actual students and parents next week. I'll demo this feedback and ask straight up: "Honestly, is this helpful enough that you'd pay something small, like €5 a month, for it?"



The technical side feels pretty much ready for this first test (just waiting on that SSL to fully sort itself out). Time to brace for some real user feedback.

CTI Threat Relationship Graph2 Knoten / 1 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
SOC Incident Playbook: Vulnerability Remediation & Verification
Syntax validiert (0 Fehler)
title: Detect Exploitation - starting up firstly.academy
id: d4251e0f-7815-4b2a-81c5-99c313795b52
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
Syntax validiert (0 Fehler)
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-24"
        description = "YARA Signature for "
    strings:
        $str = "starting up firstly.academy" ascii wide
    condition:
        any of them
}
Syntax validiert (0 Fehler)
index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("starting up firstlyacademy")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - count
Syntax validiert (0 Fehler)
message: "*starting up firstlyacademy*"
Syntax validiert (0 Fehler)
CommonSecurityLog
| where Message has "starting up firstlyacademy"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc
🎯
MITRE ATT&CK Matrix Navigator 14 Taktiken
Reconnaissance
-
Resource Development
-
Initial Access
Execution
Persistence
-
Privilege Escalation
Defense Evasion
Credential Access
-
Discovery
-
Lateral Movement
-
Collection
-
Command and Control
Exfiltration
-
Impact
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich starting up firstly.academy.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten starting up firstly.academy

Thematisch verwandte Begriffe: starting, firstlyacademy · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-81473 | Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an …
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel • Rechts: nächster Artikel • unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...
↗ Original-Quelle