@PapsSec

IT Enthusiast. I love everything Hacking, pen testing and I'm more than ready to explore the exciting world of bug bounty hunting.

Joined February 2021
In response to the deteriorating security situation, 🇨🇭 has three objectives: strengthen resilience, improve protection and enhance defence capabilities. The Federal Council has adopted Switzerland’s Security Policy Strategy 2026. admin.ch/en/newnsb/zR3tvgIy1… @vbs_ddps
775
4,709
3,091
39,365
29,660,759
Phishing investigation gets easier when you know where to look. Here are some anti-phishing tools worth keeping in your toolkit. Save this for later.
1
14
58
1,755
This is crazy. In late July, "three guys with Claude and Codex subscriptions" were able to use Opus 5 to access OAI auth tokens and gain write access to OpenAI's monorepo openai/openai over the course of two days. wsj.com/tech/ai/hackers-used…
52
116
33
1,094
366,383
D@mi3n retweeted
On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
354
1,396
538
11,835
2,760,541
Amen
156
269
14
2,552
25,644
As a man, You can grind for years with nothing to show. Family thinks you're crazy. You'll lose friends. Then, one year, everything explodes. Dear bro, keep going; it's just a matter of time.
1
8
36
3,040
damn, @brutecat got $100k from Google for an arbitrary file read 🔥 interesting writeup to see how he approached the bug starting from analysing Google's RPC endpoints and deep diving into them 👇 bughunters.google.com/blog/b…
1
39
304
11,801
🔥 Active Directory Basics — Enterprise Identity Management 🔥 Telegram: t.me/hackinarticles ✴️ Twitter: nitter.cf/hackinarticles 🏢 Active Directory is the backbone of identity and access management in many Windows enterprise environments. If you're learning AD Security, SOC, Pentesting or Red Teaming, start with these fundamentals: 🖥️ Domain Controller (DC) → Authenticates users & manages directory data 👥 Users & Groups → Organize identities and manage permissions 📁 Organizational Units (OUs) → Structure users, groups & computers ⚙️ Group Policy (GPO) → Apply configurations and security policies 🌐 DNS → Essential for AD communication and service discovery 🔐 How AD Works 👤 User Login ⬇️ 🖥️ Domain Controller ⬇️ 🗄️ AD Database ⬇️ ✅ Authentication & Authorization 🚨 Why AD is a major security focus: ⬆️ Privilege Escalation 🔑 Credential Theft ↔️ Lateral Movement ♾️ Persistence 🎯 Master these concepts before diving into advanced Active Directory security. 📌 Save this cheat sheet for your AD learning journey. 🔁 Repost to help another cybersecurity professional. #ActiveDirectory #CyberSecurity #ADSecurity #RedTeam #Pentesting #SOC #WindowsSecurity #BlueTeam #InfoSec #CyberDefense
1
51
2
254
10,798
D@mi3n retweeted
THIS IS F**KING DANGEROUS SOMEONE JUST TURNED CLAUDE INTO AN AUTONOMOUS PENTESTER. HexStrike AI connects an LLM to 150+ professional cybersecurity tools through MCP. You get: → 12 specialized AI agents → 150+ security tools → Network & web security testing → Automated pentesting workflows → Local execution on Kali Linux The wild part? Claude autonomously generated a SQL injection payload, ran the test, and solved a PortSwigger lab. AI + real security tooling is getting serious. REPO BELOW
61
262
6
1,576
61,563
D@mi3n retweeted
I wasted four years. Four years of "next month." Four years of waiting to feel ready. Four years of watching people I started with pass me. I blamed the economy. I blamed the government. I blamed my background. But every night, I knew the truth. It was me. I owed my younger self an apology. He had all the time I wasted. So I sat down and wrote a plan. Not a dream. Not a vision board. A plan. With dates. With numbers. With deadlines. And I stopped apologizing to the past. I started answering to the future. You owe your younger self an apology. And your older self a plan. One heals the past. The other protects the future
5
44
49
419
BUG BOUNTY → REMOTE SECURITY JOB Want to turn bug hunting into a security career? Don't just collect reports. Build evidence that you can solve real security problems. 1. Pick one niche → API Security → Web Security → Cloud Security → Mobile Security → AI Security 2. Build a portfolio → Sanitized write-ups → GitHub tools → CTF/lab solutions → Security research → Automation scripts 3. Show your methodology Recon → Attack Surface → Hypothesis → Testing → Validation → Impact → Report 4. Learn to communicate impact A good finding explains: → What is vulnerable? → Why does it matter? → Who can exploit it? → What can an attacker achieve? → How should it be fixed? 5. Build developer skills Learn: → HTTP → JavaScript → APIs → Authentication → Databases → Git → Docker → Cloud fundamentals 6. Network with security teams Share useful research. Contribute to open source. Discuss vulnerabilities responsibly. 7. Target roles like: → Application Security Engineer → Product Security Engineer → Security Researcher → Pentester → Vulnerability Researcher → Offensive Security Engineer Bug bounty proves you can find vulnerabilities. Your portfolio should prove you can understand, validate, communicate, and help fix them. #BugBounty #CyberSecurity #SecurityResearch #AppSec #Pentesting #EthicalHacking #InfoSec #WebSecurity #APIsecurity #RemoteJobs #CyberSecurityJobs #SecurityEngineer #BugBountyHunter #Career
5
26
2
180
14,227
D@mi3n retweeted
🚨 AI agents can behave incorrectly even when their instructions look secure. Poisoned context, broad tool permissions, and persistent memory are where the real risks live 👉 tryhackme.com/room/agenthard…
2
15
1
115
10,090
D@mi3n retweeted
📖A Security Engineer's Guide to MCP Blog: semgrep.dev/blog/2025/a-secu… author: Kurt Boberg (@semgrep)
8
45
1,740
D@mi3n retweeted
Built a custom Claude skill to encode my own bug bounty methodology, the same one that got me paid. Full breakdown of how I wrote it, and what to avoid when you write your own, new video dropping for Cyber Serpents members 🔥 youtu.be/SnIaMgWybBY?si=nKei…
3
13
124
5,044
D@mi3n retweeted
Here is how i found a 5K SQLI ! 👀
💰 This is what a $5,000 SQLi looks like! 💀🔥 Want to learn **ethical hacking & bug bounty hunting** and find vulnerabilities like this? 🚀 Join the community: hackerz.space
1
7
129
6,760
20 Bug Bounty Recon Tools Every Security Researcher Should Know Useful tools for reconnaissance, asset discovery, enumeration, and attack-surface mapping: 1. Subfinder — Passive subdomain enumeration github.com/projectdiscovery/… 2. Amass — Attack-surface mapping & asset discovery github.com/owasp-amass/amass 3. Assetfinder — Find related domains and subdomains github.com/tomnomnom/assetfi… 4. Findomain — Fast cross-platform subdomain discovery github.com/Findomain/Findoma… 5. httpx — Probe and identify live HTTP services github.com/projectdiscovery/… 6. Naabu — Fast port scanning github.com/projectdiscovery/… 7. Katana — Fast web crawling and endpoint discovery github.com/projectdiscovery/… 8. GAU — Fetch known URLs from multiple sources github.com/lc/gau 9. Waybackurls — Extract URLs from Wayback Machine github.com/tomnomnom/wayback… 10. FFUF — Web fuzzing and content discovery github.com/ffuf/ffuf 11. Arjun — Discover hidden HTTP parameters github.com/s0md3v/Arjun 12. Nuclei — Template-based vulnerability scanning github.com/projectdiscovery/… 13. Nuclei Templates — Community security-testing templates github.com/projectdiscovery/… 14. DNSx — DNS resolution and analysis github.com/projectdiscovery/… 15. MassDNS — High-performance DNS resolution github.com/blechschmidt/mass… 16. Uncover — Search multiple search engines for exposed assets github.com/projectdiscovery/… 17. Puredns — Fast DNS brute-forcing & resolution github.com/d3mondev/puredns 18. Hakrawler — Crawl websites for endpoints github.com/hakluke/hakrawler 19. Gospider — Fast web spidering github.com/jaeles-project/go… 20. RustScan — Fast port discovery github.com/RustScan/RustScan Workflow: Subdomains → DNS → Ports → Live Hosts → URLs → Crawl → Parameters → Scan → Manual Validation → Report Build your own recon pipeline instead of running tools individually. Only scan assets that are explicitly authorized and within the program scope. #BugBounty #CyberSecurity #SecurityResearch #EthicalHacking #Recon #OSINT #WebSecurity #Pentesting #InfoSec #AppSec #Nuclei #BurpSuite #GitHub
1
18
93
5,374
Day 15/999 — Bug Bounty Tip Test HTTP method inconsistencies. An endpoint protected for "GET" might behave differently with: "POST" "PUT" "PATCH" "DELETE" "OPTIONS" Compare: → Authentication → Authorization → Input validation → Response data → CSRF protections → Rate limits For example: "GET /api/profile" may correctly enforce authorization, while another supported method reaches the same functionality with weaker controls. Don't assume: Same endpoint = same security controls. A strong methodology is: Discover → Compare methods → Identify security differences → Prove impact Only test methods and endpoints that are authorized by the bug bounty program. #BugBounty #APIHacking #WebSecurity #AccessControl #AppSec #BugBountyTips
4
6
22
1,225