@dan_covici
iAccount based inEurope!
About this account
- Account based in
- Europe
- Connected via
- Europe App Store
! X says this location may be affected by a proxy or VPN.
Account-level information from X, not a live location or the device used for a specific post.
ServiceNow consultant | Enthusiastic with cybersecurity, AI/ML, cloud computing & business | Love exploring new ideas
Joined November 2016
- Tweets6K
- Following3.2K
- Followers526
- Likes67.4K
Dan Covic retweeted
I've decided to finally release my vulnerability hunting methodology that I've been using for several months now, both in testing as well as live engagements with great success.
I was inspired by (and huge congrats to) the @Blackfrost_AI team open-sourcing Cyber-Frost Harness, their reproducible security-agent runtime with procedural skills, an evidence ledger, and isolated Docker targets for red/blue/purple work. 🎉
If you like the Cyber Frost Harness, and want some out of the box vulnerabilty hunting and POC development kit to go along with it - check out my VulnHunter.
It's already loadable: their harness reads standard SKILL.md skills. Point skill_dir at VulnHunter's (or run its installer), and the hunting, falsification, and PoC disciplines load immediately.
Repo: github.com/nealbridges/VulnH…
CREDITS: This is fork of @CapitalOne original repo. I simply took it a step further on POC development and model agnostic. I'm also actively developing in my forked repo as I make more changes to it and welcome the contributions from the community as well.
I think I'm doing the whole "respect who you give credit to" drama, and I asked my model to double and triple check it. So i can blame the model if its wrong. Otherwise, dont put me on blast on X if i suck at credits. /s
Looking forward to developing on this further with the community.
1/ How I infiltrated a Chinese organized crime syndicate that has laundered $1B+ across multiple exploits for Lazarus Group.
Posing as a client, I gathered intel that helped action freezes for the Feb 2025 Bybit exploit and attribute illicit activity onchain.
Dan Covic retweeted
Funnily enough, I broadly agree with Mr. @DeGatchi. For vulnerabilities like this one which impacts everybody using KVM (read every hyperscaler, every AI lab, every company on the planet really), there should be a fund that pays from all of them.
As Vercel we are trying to do our part here. And all credit to @PaulosYibelo for going down the pass of responsible disclosure!
Dan Covic retweeted
Yesterday, someone asked me for a framework for understanding offensive cybersecurity.
I only entered cybersecurity three years ago. AI accelerated my learning dramatically, but the most important thing I learned was how to think in attack paths. A vulnerability in itself is not that important, if you can't chain it to go much deeper.
So I’m going to create a practical series explaining how you can move from a public URL to real organizational impact -- recon, vulnerable inputs, footholds, privilege escalation, lateral movement and Remote Code Execution (RCE). It'll be a combination of blog posts and videos.
No assumed cybersecurity background. We’ll start with what you already know: an AI and a coding agent. But before we get to the practical stuff, you will benefit from us setting the foundation.
Here's Article #1, Fundamentals: learn.drost.ai/articles/fund…
Follow along if you're interested in learning offensive cybersecurity with AI.
Dan Covic retweeted
I have open-sourced the full bug bounty workflow behind my hunting system.
It covers everything from initial recon to final duplicate convergence, including access, authenticated testing, browser workflows, evidence handling, escalation, triage, independent validation, and report preparation.
This is reference material for people who want to build.
It is not plug and play.
I am not providing setup support.
You will need to adapt every integration to your own environment.
If you put in that effort, it should give you a serious foundation and a lot of ideas for what an end-to-end AI hunting workflow can look like.
This took a lot of work to build and prepare for release.
If you find value in it, please leave a comment so more builders see it.
Dan Covic retweeted
We'll be spending a lot more time trying to understand the outputs of language models. A few thoughts, tips & tricks:
Writing. Something I've had success with: Ask your LLM to explain something in ASD-STE100, it's a controlled language specification originally developed for aerospace maintenance documentation. LLMs well-versed in this language and it comes with heavy constraints on clean writing style that I often find a lot more readable. Sometimes I've tried to soften it a bit e.g. ask for "80% of the way to ASD-STE100" because the spec is quite stringent. But even better:
Diagrams / images. Instead of writing, ask your LLM to create a diagram. These can be a lot easier to process, parse, and understand. But even better:
Web pages. Ask for output "in HTML" to get a beautiful, interactive webpage. LLMs are getting really good at frontend and can create beautiful experiences, animations, etc. But even better:
Explainer videos. The output format I am most bullish on is fully custom / bespoke explainer videos generated on any arbitrary topic. Experiment with things like "Create a 3b1b style video explainer on X. Use my ElevenLabs API key for audio narration". (you'd need an API key for the latter or you can ask your LLM to find you decent free alternatives that use your local compute). This is actually starting to work!
In summary:
- As LLMs get better, they will do more and more of the legwork autonomously, and a lot more of our work will rise up the abstractions into oversight and understanding.
- Luckily, LLMs can help here too because as intelligence and code are increasingly abundant, you can ask for large, custom, discardable software artifacts (e.g. web apps, video explainers) that would have never made sense to create before. Push the boundaries here and you'll be surprised.
Dan Covic retweeted
I'm 38.
Solo founder from Germany.
Looking to connect with more builders & indie hackers!
Flounder is an autonomous white-hat security audit framework that transforms Al agents like Codex and Claude Code into an end-to-end auditing system. It supports target preparation, attack surface mapping, deep probing, exploit construction, sandbox validation, and reporting,
如果你的 token 用不完,可以试试用 Flounder 来挖漏洞,配合最先进的 GPT-6 Astra 模型,也许什么时候就中彩票了呢。 github.com/adshao/flounder
PentestGPT: LLM-driven automated penetration framework with multiple stages from reconnaissance to exploitation.
VulnHunter: Capital One's agentic code security tool that analyzes exploitable flaws from an attacker's perspective and suggests fixes.
Dan Covic retweeted
GPT-5.6 Sol went bug hunting blind. We set the destination and let Codex find the route 🧭
Within 1m 14s, it found a JWT flaw, forged an admin session and proved access 🔍
But turning that into a valid report is still on us 👀
Our guide to Codex for Bug Bounty 👇
yeswehack.com/learn-bug-boun…
Dan Covic retweeted
I’m excited to finally announce the newest edition my Stanford course 𝗧𝗵𝗲 𝗠𝗼𝗱𝗲𝗿𝗻 𝗦𝗼𝗳𝘁𝘄𝗮𝗿𝗲 𝗗𝗲𝘃𝗲𝗹𝗼𝗽𝗲𝗿. It has been 9 months in the making.
Last November, with the release of Claude Opus 4.5, coding agents experienced a step function improvement in capability. We all felt it. The LLMs were more powerful, could reason for longer, solve harder tasks.
This year’s iteration of my course reflects the 2026 metamorphosis of software engineering.
My core belief is simple: AI-native developers of the LLM era are going to become the most important members of any software organization. I have designed my course to train this next generation of engineers.
𝗪𝗵𝗮𝘁’𝘀 𝗱𝗶𝗳𝗳𝗲𝗿𝗲𝗻𝘁 𝘁𝗵𝗶𝘀 𝘁𝗶𝗺𝗲 𝗮𝗿𝗼𝘂𝗻𝗱
First, 85% of my Fall 2025 class material is being thrown out. The Fall 2026 syllabus reflects the core capabilities AI-native engineers must have: agent skills, advanced context engineering, MCP portals, agent-ready codebase principles, agentic code review, security, parallelizing background agents, software factories, and more.
Second, I am going to teach my students how to have software taste. Every student will be required to ship pull requests to production-grade, real-world codebases. The course is collaborating with the top open-source AI repos who will offer support and mentorship to students on how to meaningfully contribute to their projects.
This has never been done before in any university course so I am incredibly grateful to our OSS Partners: @browserbase, @HeyGen, @CopilotKit, @semgrep, @OpenHandsDev, @milvusio, @marimo_io, Pi, @crewAIInc, @warpdotdev, @vercel, @cmux, @arizeai, @UnslothAI, and @anyscalecompute.
𝗪𝗵𝗮𝘁’𝘀 𝘀𝘁𝗮𝘆𝗶𝗻𝗴 𝘁𝗵𝗲 𝘀𝗮𝗺𝗲
I’m fortunate to again have AI software engineering leaders and founders as guest speakers to share their learnings from building top coding agent products. Thank you to @leerob from @cursor_ai, @bcherny of @claudeai code, @EnoReyes of @FactoryAI, @silasalberti of @cognition, @0xine of @semgrep, Rajesh Bhatia of @Cloudflare , @amasad of @Replit, and @eladgil.
All resources will be available online. All classes will be available to the public.
9/22 on Stanford campus. See you in class.
themodernsoftware.dev/
How to use Claude Code for Bug Bounty: find fast, validate manually
Blog: yeswehack.com/learn-bug-boun…
Author: @yeswehack
Dan Covic retweeted
I created a FREE 30+ video XSS playlist that takes you from the basics of XSS all the way to XSS → RCE!
I’ve always felt that XSS is one of those vulnerabilities that people learn by memorizing payloads, without really understanding what is happening underneath.
You learn a few payloads, find a reflected XSS, maybe bypass a filter — and that’s where it usually ends.
But there’s a lot more to XSS.
So I decided to put together a complete playlist that starts from the fundamentals and gradually moves into advanced exploitation, including XSS → RCE and using AI for security research.
I’ve also covered how you can fine-tune your own AI model to detect XSS, rather than simply relying on existing tools.
It’s 30+ videos and completely free, and the goal is to take you from understanding XSS to actually thinking like someone who exploits it.
Playlist link: youtube.com/watch?v=4_VbPem6…
Dan Covic retweeted
I stopped doing recon by hand.
Built 4 AI agents to do it for me instead, one to enumerate, one to map, one to track scope, one to write the report. Tested it live against a real HackerOne target.
Full methodology + how I set it up 👇
youtu.be/ieKufTuVEYw?si=0DCN…
Dan Covic retweeted
Been using DeepSeek lately. Spent around 7 billion tokens and it made me around $3,000 so far.
But how?
1. I stopped just pointing my agent at random targets and telling it to hack everything blindly.
2. First I map the target myself. Normal recon basically. I want to understand the assets, what the app does, what tech it's using, how the different functions work, etc.
3. Then I give the AI a specific thing to look at. I still do most of the hacking manually. If I find something interesting, I'll tell it something like “go check this, I think XYZ might be doing XYZ here” and let it dig deeper.
I also use my own skills for specific stuff:
/rce → check this file upload
/xss → check this JS file
/oauth → check this login flow
and so on.
4. My hackbots aren't fully AI either.
For some stuff I just write scripts. I want the same input to give me the same results every time. AI can overthink things, skip steps or just do something completely different on the next run.
So I use scripts for collecting the data, then AI to analyze the recon data and help with automation.
5. Always validate the findings.
AI gives you a lot of false positives. And sometimes it finds something that's technically a bug but the program won't accept it as a valid bounty.
So I still manually reproduce and validate everything before reporting.
I think that's the biggest difference for me.
I'm not letting AI “hack for me”.
I'm using it where it actually makes me faster.
👇👇👇
#bugbounty #bugbountytips