x cyber Space retweeted
And now Anthropic’s Claude Mythos will soon be available in select H1 Platform products.
We’re making frontier cyber AI models and the creativity and adversarial expertise of our security researcher community available to defenders.
Because staying ahead takes both.
To reiterate: HackerOne does not use or permit use of confidential researcher submissions or customer vulnerability data to train, fine-tune, or otherwise improve generative AI models.
Check out the latest announcement: bit.ly/4hnvJYL
x cyber Space retweeted
A list of ~3000+ payloads
github.com/zapstiko/wordlist…
x cyber Space retweeted
I published my private bug bounty tool for HackerOne reports, document your hunts, and ship new reports via API script.
Built to be used with any LLM.
Check it out👉github.com/skraft9/quarry-vr…
#TogetherWeHitHarder #BugBounty #CVE
x cyber Space retweeted
Login asked for password + SMS code every time. Looked locked down. So we
@imfaiqu3
killed 2FA from inside the challenge meant to stop us. Password only, no code entered.
Full writeup
medium.com/@asharm.khan7/150…
HE ENCONTRADO COMO CONSEGUIR CHATGPT PLUS GRATIS DURANTE 1 AÑO
Incluso si no eres estudiante de EE. UU.
Aquí tienes la guía completa: nitter.cf/suu766/status/20955119…
Guarda este tweet para no perderlo 🏷️
Este tipo en 47 minutos te enseña cómo monetizar un canal de YouTube con IA sin mostrar tu cara.
🔖 Guárdalo, te será útil.
This video is larger than Cloudflare's 512 MB cache, so it can't be played through. More donations are needed to cover a larger cache. Donate
I just dropped a new video on Prompt Injection & Jailbreaking, where I break down and demonstrate the techniques practically, step by step in my own way.
There are a few interesting techniques you definitely don’t want to miss.🔥
youtu.be/vJ5Ha35F37s
x cyber Space retweeted
You tested that target for cache poisoning, the response came back private and no-store, and you moved on. That answer was honest. It just came from the wrong cache.
In this video, I go after the response cache your framework ships and your CDN never sees. One unauthenticated header turns a no-store route into a shared entry on disk, your cache buster never reaches its key, and on current Next.js the same idea ends in stored XSS with nothing in the URL and no click.
Cache Poisoning: The Cache You Can't Purge youtu.be/WOeLT_KLnws
#BugBounty #WebSecurity #EthicalHacking #AmrSec #CachePoisoning #XSS #NextJS #AppSec
x cyber Space retweeted
i uploaded pdf.js exploits including domain alert,cookie popup+calculator rce.i hope it will help you ❤️
github.com/coffinxp/pdFExplo…
youtu.be/VxgEYQyx5EU
x cyber Space retweeted
writeup of critical SQL injection is available check it now
medium.com/@edemzayaniyt/how…
#bugbounty #CyberSecurity
Critical (10.0) SQL Injection bug i love wordpress targets🫠
lnkd.in/p/dqbTdmgs
#bugbounty #CyberSecurity
x cyber Space retweeted
First of all, Alhamdulillah. Earned a $3,000 bounty for an Authentication Bypass vulnerability
Writup: linkedin.com/posts/abdalkree…
#bugbounty #bugbountytips #hackerone #cybersecurity
x cyber Space retweeted
Writeup: b3ard.blog/posts/2050-shoppi…
Yay, I was awarded €2,050!
Finally got my RCE accepted and resolved.
Got dozens of dupes along the way,
but the more manual hacking you do, the fewer dupes you get.
Thanks @intigriti for the opportunity!!
x cyber Space retweeted
JWT attacks are one of the most underrated vulnerabilities in bug bounty. Most hackers scroll right past them, but if you control the JWT, you control the authentication of the whole website.
Change one header value and you can become admin. Sign with a public key and the app treats you like a CEO. Most apps still trust tokens blindly, and the programs that pay are waiting for someone who actually knows this.
This is what separates hunters who collect bugs from hunters who get paid. Save this before you forget it.
x cyber Space retweeted
GPT-5.6 Sol found a very cool authentication bypass.
- you submitted the uuid as password, pass confirmation and erp_code and it spilled out the access token for that user.
I couldn't enum uuids so CVSS only 7.4.
x cyber Space retweeted
Tutorials and Things to Do while Hunting Vulnerability
github.com/KathanP19/HowToHu…
#infosec #bughunting #vulnerability #hunting
#cybersecurity #bugbounty #bugbountytip #bugbountytips #penetrationtesting #jwt #csrf
x cyber Space retweeted
From IDOR to Admin: How a Simple ID Parameter Led to Full Platform Takeover
Bug Bounty Reward: $4,500 (Critical Severity)
medium.com/@pankaj_73968/fro…
x cyber Space retweeted
Second bounty. Everyone chains SSTI to RCE — I chained it to account takeover instead. $1,000.
Write-up 👇
medium.com/@HariHax/everyone…
#bugbounty #cybersecurity #infosec