Security Researcher @rapid7 😈 Hacking Content @ yt.cryptocat.me 💜

Not Here
Want to become an ethical hacker? 🥷 Here's a list of my favourite [mostly practical] resources 📚 They are all free (or have a free option) and there's more high quality material here than anybody realistically has the time to complete ⏳
28
326
1,257
131,938
😎
1
3
287
Never seen a con upload talks as fast as @brucon 🔥 I was super nervous for this ngl. Planning to record a better run at some stage, but for now if you wanna check out the live one - here it is! 💌 piped.video/NkM4UT2z0wc
1
3
20
1,192
Presented my @rapid7 research at @brucon today! Thank you to everyone for listening, hope you enjoyed it 🙂
2
45
955
Hacker hangout with @ahmed_vapt 💜
3
1
37
2,517
Excited (and nervous) to announce that I'll be presenting some of my (@rapid7) 0day research @brucon on Thursday, 2:30pm 💌 "Signed, Sealed, Compromised: Weaponizing Enterprise Mail Infrastructure"
4
4
53
2,229
5 min from the airport and @KLM cancel my direct flight to Amsterdam, exchange it for a non-direct flight 24 hours later.. So, I lose my accommodation and miss my train to Belgium tomorrow. I hate airlines so much 👎
6
6
1,651
Back in the airport, let's try again! 🤞
1
1
162
Found an SQL injection in WCFM Marketplace, the WooCommerce multivendor plugin. A guest's checkout coordinates flow straight into a store-distance query, enough to read WordPress password hashes. CVE-2026-18442, fixed in 3.8.2, $134 bounty. cryptocat.me/blog/research/a…
3
4
31
1,573
CryptoCat retweeted
On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
356
1,398
11,858
2,788,693
CryptoCat retweeted
> builds technology that could literally destroy the world > max bounty: $10k ($0 for model safety issues) we're cooked 💀💀💀
4
13
255
14,685
Got my first bounties today on @hackrate 🥳 Shout-out to the team, they've been awesome! 💜
4
21
1,428
CryptoCat retweeted
> ShinyHunters attacker also claimed to have collected legitimate HackerOne payouts of $2k and $5k from 2 of the companies they infiltrated and extorted, treating BugBounty programs and intrusion as additional revenue streams against the same targets they were compromising. 💀
We're publishing our most detailed threat intelligence report to date. It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them. We disrupted every operation in the report, and used the lessons from them to strengthen our safeguards. Where appropriate, we also shared what we found with authorities and other AI companies. These cases are not typical: we’re highlighting some of the most sophisticated misuse we’ve seen. But they’re especially important to discuss, because they show us where AI misuse is headed, where our safeguards work, and where they need to improve. We’re publishing this report so others can spot the same activity on their own platforms, and so we can give the public a clearer view of how emerging threats develop. Read the report: anthropic.com/threat-intelli…
3
14
280
35,260
In the latest episode of the @Rapid7 podcast, we caught up with the amazing @PinkDraconian to hear all about his new Meccha Chameleon RCE exploit.. Check it out! 🔥 piped.video/G9XjR37_fsI
3
2,134
So nice to meet @LambdaMamba at @bsidesbelfast 🥰
3
12
695