@PapsSeci
iAccount based inCameroon!
About this account
- Account based in
- Cameroon
- Connected via
- United Arab Emirates App Store
! X says this location may be affected by a proxy or VPN.
Account-level information from X, not a live location or the device used for a specific post.
IT Enthusiast. I love everything Hacking, pen testing and I'm more than ready to explore the exciting world of bug bounty hunting.
Joined February 2021
- Tweets2.7K
- Following2.1K
- Followers133
- Likes2.7K
D@mi3n retweeted
In response to the deteriorating security situation, 🇨🇭 has three objectives: strengthen resilience, improve protection and enhance defence capabilities. The Federal Council has adopted Switzerland’s Security Policy Strategy 2026. admin.ch/en/newnsb/zR3tvgIy1… @vbs_ddps
D@mi3n retweeted
Phishing investigation gets easier when you know where to look.
Here are some anti-phishing tools worth keeping in your toolkit.
Save this for later.
D@mi3n retweeted
Hacking OpenAI hacktron.ai/blog/hacking-ope…
D@mi3n retweeted
Good series on Pwning AI Agents
Part 1: Exploiting AI Coding Agents m10x.de/posts/2026/04/pwning…
Part 2: RCE and Data Exfiltration m10x.de/posts/2026/06/pwning…
Part 3: Read Only Bypass m10x.de/posts/2026/07/pwning…
Part 4: Exploiting MCP Hosts with a Malicious MCP Server m10x.de/posts/2026/08/pwning…
D@mi3n retweeted
This is crazy. In late July, "three guys with Claude and Codex subscriptions" were able to use Opus 5 to access OAI auth tokens and gain write access to OpenAI's monorepo openai/openai over the course of two days.
wsj.com/tech/ai/hackers-used…
On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
D@mi3n retweeted
As a man,
You can grind for years with nothing to show.
Family thinks you're crazy.
You'll lose friends.
Then, one year, everything explodes.
Dear bro, keep going; it's just a matter of time.
D@mi3n retweeted
damn, @brutecat got $100k from Google for an arbitrary file read 🔥
interesting writeup to see how he approached the bug starting from analysing Google's RPC endpoints and deep diving into them 👇
bughunters.google.com/blog/b…
D@mi3n retweeted
🔥 Active Directory Basics — Enterprise Identity Management
🔥 Telegram: t.me/hackinarticles
✴️ Twitter: nitter.cf/hackinarticles
🏢 Active Directory is the backbone of identity and access management in many Windows enterprise environments.
If you're learning AD Security, SOC, Pentesting or Red Teaming, start with these fundamentals:
🖥️ Domain Controller (DC)
→ Authenticates users & manages directory data
👥 Users & Groups
→ Organize identities and manage permissions
📁 Organizational Units (OUs)
→ Structure users, groups & computers
⚙️ Group Policy (GPO)
→ Apply configurations and security policies
🌐 DNS
→ Essential for AD communication and service discovery
🔐 How AD Works
👤 User Login
⬇️
🖥️ Domain Controller
⬇️
🗄️ AD Database
⬇️
✅ Authentication & Authorization
🚨 Why AD is a major security focus:
⬆️ Privilege Escalation
🔑 Credential Theft
↔️ Lateral Movement
♾️ Persistence
🎯 Master these concepts before diving into advanced Active Directory security.
📌 Save this cheat sheet for your AD learning journey.
🔁 Repost to help another cybersecurity professional.
#ActiveDirectory #CyberSecurity #ADSecurity #RedTeam #Pentesting #SOC #WindowsSecurity #BlueTeam #InfoSec #CyberDefense
THIS IS F**KING DANGEROUS
SOMEONE JUST TURNED CLAUDE INTO AN AUTONOMOUS PENTESTER.
HexStrike AI connects an LLM to 150+ professional cybersecurity tools through MCP.
You get:
→ 12 specialized AI agents
→ 150+ security tools
→ Network & web security testing
→ Automated pentesting workflows
→ Local execution on Kali Linux
The wild part?
Claude autonomously generated a SQL injection payload, ran the test, and solved a PortSwigger lab.
AI + real security tooling is getting serious.
REPO BELOW
I wasted four years.
Four years of "next month."
Four years of waiting to feel ready.
Four years of watching people I started with pass me.
I blamed the economy.
I blamed the government.
I blamed my background.
But every night, I knew the truth.
It was me.
I owed my younger self an apology.
He had all the time I wasted.
So I sat down and wrote a plan.
Not a dream.
Not a vision board.
A plan. With dates. With numbers. With deadlines.
And I stopped apologizing to the past.
I started answering to the future.
You owe your younger self an apology.
And your older self a plan.
One heals the past.
The other protects the future
D@mi3n retweeted
BUG BOUNTY → REMOTE SECURITY JOB
Want to turn bug hunting into a security career?
Don't just collect reports. Build evidence that you can solve real security problems.
1. Pick one niche
→ API Security
→ Web Security
→ Cloud Security
→ Mobile Security
→ AI Security
2. Build a portfolio
→ Sanitized write-ups
→ GitHub tools
→ CTF/lab solutions
→ Security research
→ Automation scripts
3. Show your methodology
Recon → Attack Surface → Hypothesis → Testing → Validation → Impact → Report
4. Learn to communicate impact
A good finding explains:
→ What is vulnerable?
→ Why does it matter?
→ Who can exploit it?
→ What can an attacker achieve?
→ How should it be fixed?
5. Build developer skills
Learn:
→ HTTP
→ JavaScript
→ APIs
→ Authentication
→ Databases
→ Git
→ Docker
→ Cloud fundamentals
6. Network with security teams
Share useful research.
Contribute to open source.
Discuss vulnerabilities responsibly.
7. Target roles like:
→ Application Security Engineer
→ Product Security Engineer
→ Security Researcher
→ Pentester
→ Vulnerability Researcher
→ Offensive Security Engineer
Bug bounty proves you can find vulnerabilities.
Your portfolio should prove you can understand, validate, communicate, and help fix them.
#BugBounty #CyberSecurity #SecurityResearch #AppSec #Pentesting #EthicalHacking #InfoSec #WebSecurity #APIsecurity #RemoteJobs #CyberSecurityJobs #SecurityEngineer #BugBountyHunter #Career
D@mi3n retweeted
🚨 AI agents can behave incorrectly even when their instructions look secure. Poisoned context, broad tool permissions, and persistent memory are where the real risks live 👉 tryhackme.com/room/agenthard…
D@mi3n retweeted
Built a custom Claude skill to encode my own bug bounty methodology, the same one that got me paid.
Full breakdown of how I wrote it, and what to avoid when you write your own, new video dropping for Cyber Serpents members 🔥
youtu.be/SnIaMgWybBY?si=nKei…
D@mi3n retweeted
Here is how i found a 5K SQLI ! 👀
💰 This is what a $5,000 SQLi looks like! 💀🔥
Want to learn **ethical hacking & bug bounty hunting** and find vulnerabilities like this?
🚀 Join the community: hackerz.space
D@mi3n retweeted
20 Bug Bounty Recon Tools Every Security Researcher Should Know
Useful tools for reconnaissance, asset discovery, enumeration, and attack-surface mapping:
1. Subfinder — Passive subdomain enumeration
github.com/projectdiscovery/…
2. Amass — Attack-surface mapping & asset discovery
github.com/owasp-amass/amass
3. Assetfinder — Find related domains and subdomains
github.com/tomnomnom/assetfi…
4. Findomain — Fast cross-platform subdomain discovery
github.com/Findomain/Findoma…
5. httpx — Probe and identify live HTTP services
github.com/projectdiscovery/…
6. Naabu — Fast port scanning
github.com/projectdiscovery/…
7. Katana — Fast web crawling and endpoint discovery
github.com/projectdiscovery/…
8. GAU — Fetch known URLs from multiple sources
github.com/lc/gau
9. Waybackurls — Extract URLs from Wayback Machine
github.com/tomnomnom/wayback…
10. FFUF — Web fuzzing and content discovery
github.com/ffuf/ffuf
11. Arjun — Discover hidden HTTP parameters
github.com/s0md3v/Arjun
12. Nuclei — Template-based vulnerability scanning
github.com/projectdiscovery/…
13. Nuclei Templates — Community security-testing templates
github.com/projectdiscovery/…
14. DNSx — DNS resolution and analysis
github.com/projectdiscovery/…
15. MassDNS — High-performance DNS resolution
github.com/blechschmidt/mass…
16. Uncover — Search multiple search engines for exposed assets
github.com/projectdiscovery/…
17. Puredns — Fast DNS brute-forcing & resolution
github.com/d3mondev/puredns
18. Hakrawler — Crawl websites for endpoints
github.com/hakluke/hakrawler
19. Gospider — Fast web spidering
github.com/jaeles-project/go…
20. RustScan — Fast port discovery
github.com/RustScan/RustScan
Workflow:
Subdomains → DNS → Ports → Live Hosts → URLs → Crawl → Parameters → Scan → Manual Validation → Report
Build your own recon pipeline instead of running tools individually.
Only scan assets that are explicitly authorized and within the program scope.
#BugBounty #CyberSecurity #SecurityResearch #EthicalHacking #Recon #OSINT #WebSecurity #Pentesting #InfoSec #AppSec #Nuclei #BurpSuite #GitHub
D@mi3n retweeted
Day 15/999 — Bug Bounty Tip
Test HTTP method inconsistencies.
An endpoint protected for "GET" might behave differently with:
"POST"
"PUT"
"PATCH"
"DELETE"
"OPTIONS"
Compare:
→ Authentication
→ Authorization
→ Input validation
→ Response data
→ CSRF protections
→ Rate limits
For example:
"GET /api/profile"
may correctly enforce authorization, while another supported method reaches the same functionality with weaker controls.
Don't assume:
Same endpoint = same security controls.
A strong methodology is:
Discover → Compare methods → Identify security differences → Prove impact
Only test methods and endpoints that are authorized by the bug bounty program.
#BugBounty #APIHacking #WebSecurity #AccessControl #AppSec #BugBountyTips