/Future/Billionaire/Hacker/Web2/Web3/Trader/Crypto/Forex/NFT/Maker/SaaS/AI/IT/Services/Provider/

AI
Pinned Tweet
I just published How I Hacked Intigriti’s Christmas SantaCloud CTF Admin Panel in 10 Minutes @intigriti medium.com/p/how-i-hacked-in…
1
3
234
HUNTER retweeted
Blog post about From header smuggling in Apple iCloud just dropped. Sending emails as tim.cook@icloud.com, exotic parsing, and a $15,000 bounty. sec-consult.com/blog/detail/…
8
95
444
40,825
Chrome added a <camera> tag. @omidxrz made it an XSS vector: Now in our XSS cheat sheet.
2
26
164
5,474
HUNTER retweeted
From AI Agents to RCE - Building a Vulnerability Research Workflow blog.quarkslab.com/from-ai-a…
2
78
417
27,379
$12,000 Mozilla Bug Bounty 🤑 Unauthenticated RCE in Taskcluster web-server via GraphQL filter argument (sift $where) by Griffin 🤯🔥 👨‍💻 Griffin (x/aussinfosec) 🔗 hackerone.com/reports/378270… 🔗 For more learning materials and tools join team 👉t.me/luckyhacker42
1
29
230
11,205
FUCK-CDN — 一键绕过CDN获取真实IP ktp.sh/6IENDxlUzU
2
22
217
22,840
SQL Injection: The Bug That Still Pays in 2026 SQLi isn't dead. It's hiding behind APIs, forgotten endpoints, and poorly written database queries. 7 things every bug bounty hunter should test: 1. Login forms – Authentication bypass 2. Search parameters – Error-based SQLi 3. Numeric IDs – Boolean-based blind SQLi 4. Filters & sorting – Dynamic query injection 5. API endpoints – JSON parameter injection 6. Headers & cookies – Hidden injection points 7. Time-based testing – Detect blind SQLi Pro tip: Don't just test id=1. Understand how the application builds SQL queries. Tools: Burp Suite + SQLMap One vulnerable parameter can expose an entire database. Test only authorized targets. Follow responsible disclosure. #BugBounty #SQLInjection #WebSecurity #CyberSecurity
2
20
179
5,832
HUNTER retweeted
I earned $7,500 for my submission on @Bugcrowd 🎉 Mass disclosure of customers’ PII #ItTakesACrowd
25
9
495
8,336
HUNTER retweeted
A €5,000 SQL injection in a SOAP integration oxship.github.io/writeups/so… #bugbounty #writeups #infosec
Made with AI
2
39
385
14,713
HUNTER retweeted
The dev hid a 4096-bit RSA private key as an audio file, that doesn't play music - but it does unlock every credential in the app. I found it and reported with token generation response ==> /users returning 700+ records and ==> /teams returning team names etc 😂😂😂. #BugBounty
24
47
873
43,427
recently i hired 4822 sales managers for my saas. i'm the technical cofounder. i should be in the repo, not in the inbox. Claude agents. you drop a website, they work 105m company profiles and write personalised emails. $30 free 👇 explee.com/auto-gtm/x/tw-ag3…
206
184
1,671
1,420,997
HUNTER retweeted
at least tag him in the post. it's @efaav!
‼️ BREAKING: A 16-year-old hacker broke into an internal Microsoft analytics service with a forged, unsigned login token and ran SQL as admin, reaching databases that held over 17 trillion rows, including Bing search analytics and 17,990 employee email records. The service, called Titan, checked every field on the token except its signature, so just claiming to be "admin" got him in, writes the researcher, who goes by Faav. He says he only pulled metadata and two single rows of Bing data, never touched customer data, and reported the flaw to Microsoft the same night. Microsoft locked the endpoint four days later, paid him $5,000, and had editorial control over his write-up, cutting sections and figures and reshaping how the impact was described before it went public.
3
17
316
21,711
HUNTER retweeted
9-5 is a trap
1,516
4,691
56,983
13,064,178
HUNTER retweeted
Waking up with $20k RCE payout HackerOne. Spent a week chaining SQLi to RCE.
27
13
762
17,288
HUNTER retweeted
Google awarded $113,337 USD for a Linux vulnerability discovered by Indonesian security researcher Muhammad Alifa Ramdhan (@n0psledbyte), who works as a Principal Vulnerability Researcher at @starlabs_sg. 🤯 Ramdhan discovered a Linux Local Privilege Escalation (LPE) vulnerability involving a race condition in AF_ALG, the same subsystem later exploited in the famous Copy Fail vulnerability in 2026. He found the issue in 2025 without AI assistance and it was assigned CVE-2025-39964. His coworker, Bing-Jhong Billy Jheng, was also credited for completing the exploit chain, which enabled both privilege escalation to root and escape from a Docker container. They submitted the exploit to Google kernelCTF and received its highest reward. 💰 Ramdhan is from Tangerang, Indonesia. He graduated from Diponegoro University (@undip) in 2023 and later moved to Singapore to work full time as a vulnerability researcher. 🇮🇩 🇸🇬 idnsec.com/research/linux-lo…
1
31
160
8,583
HUNTER retweeted
Dont be sleeping on Heif Heist! Meta paid 100k for my RCE on FB/Instagram! heif-heist.com/
110
210
4,962
530,599
❗️ A security researcher was paid a 115k bounty for reporting a vulnerability to Facebook. It's one of many "HEIF Heist" remote attack paths reported, targeting services that decode attacker-controlled HEIF, HEIC, or AVIF images.
21
138
2,145
123,400
It blew my mind - someone got 133700*3 !
15
17
513
60,655
HUNTER retweeted
Every once in a while, you come across one of those rare bugs - an SQL injection in a mobile app. #SQLi #BugBounty
3
20
305
9,498
received 2000$ bounty for an idor #bugbounty #cybersecurity
12
6
301
8,564
HUNTER retweeted
I finally got around to the writeup for my 2nd $20,000 bounty from @Apple here: github.com/petermalone/CVE-2… @gergely_kalman I know you had specifically asked for this so here you go. I learned so much playing around with this. I'll document the first later this week. Enjoy! Thanks again to @Apple - the bounty announcement took just 11 days for this one. Crazy.
Thanks again Apple for another accelerated bug bounty payment. 🎯🎯
6
51
529
30,979