Blending AI with Offensive Security Research and Bug Bounty. Creator of crxplorer.com

Close to $149k reward from 15 findings from 6 programs at HackerOne this month with @Paaastha. We have been building a offensive security research product for a few months now and we have put it to test this month at HackerOne across programs. 50 high criticals pending. We are building autonomous browser on top of proxy and data processing engines connected to agentic memory store for fully autonomous flow. long way too go yet before a commercial product. [Benchmarks and detailed statistics soon]
32
23
779
34,798
In my today's testing it looks like @OpenAI Nerfed the GPT 6 SOL to make it refuse offensive security research request. Including any authorised security research
11
70
14,717
Hey @OpenAI @ChatGPT I tried this multiple times its not going through 🙃🙃
8
2
22
3,097
Waking up with $20k RCE payout HackerOne. Spent a week chaining SQLi to RCE.
27
12
759
16,685
Hot take: CVSS is outdated and doesn't account for real world impact. Either it points to higher or lower scoring of a finding.
7
4
80
6,827
Open AI fixed this now. You will not be forced to ReKYC. Just connect keys and enable ACS. Thanks to whoever worked on this.
According to latest email from Open AI, Existing Daybreak users are being forced to do Re-KYC? and no matter what we do its being failed with Persona hence unable to setup Daybreak Can anyone from @OpenAI help?
12
4
94
11,253
According to latest email from Open AI, Existing Daybreak users are being forced to do Re-KYC? and no matter what we do its being failed with Persona hence unable to setup Daybreak Can anyone from @OpenAI help?
45
10
171
34,529
Jenish Sojitra retweeted
Trusted access and cyber verification for AI favour companies over individuals. Maybe that’s better for verification purposes. But the best vuln-finding tools go to whoever has the corporate paperwork. We're watching the slow death of the independent bug bounty researcher.
8
13
108
10,320
Replying to @OpenAI
checklist at chatgpt.com/cyber
9
2,859
GPT 6 SOL feels significant downgrade from GPT 5.6 SOL for security research. Anyone else feeling same?
We ran GPT-6 Luna and Sol on our 32-CVE cyber benchmark and the results were unexpected! 🤯 Luna rediscovered 53.1% Sol reached 68.8% Neither beat GPT-5.6 variants on recall But both got A LOT cheaper per vulnerability found: Luna $3.43 → $2.01/CVE Sol $56.88 → $34.18/CVE 🧵 1/3
19
1
59
7,367
Opus 5.5 is basically useless for cybersecurity what a shame @AnthropicAI even with CVP verified.
33
20
393
26,268
gpt sol 6 today?
1
20
3,072
Is Mythos really a big deal anymore?
16
57
8,805
Loving AI, bug bounty and infosec space lately on X, so many things happening, different opinions, incredible research and payouts, models going vague. everyone trying to bring their A game; interesting times we live in.
6
8
249
7,757
Jenish Sojitra retweeted
I was rewarded a total of $20K from HackerOne, including these two bounties.
16
9
333
6,968
Brilliant work by Mohan, Harsh and Team, this goes to show how underpaid bug bounty hunters are. Though kudos to OpenAI for allowing to publish findings, I wish more companies do it. Research like this deserves to be recognised rather than get buried under program queue
On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
3
5
124
6,603
In my last 3 months of returning to bug bounty, I have been very impressed by @Hacker0x01 triage across programs and live hacking events. Considering the massive amount of both valid and slop reports they are getting, they have been precise, patient, and empathetic in the reports.
10
2
153
6,692
4 RCEs are duplicated in a complex product; imagine the competition
18
4
242
23,523
Looks like something went wrong at @OpenAI , codex started throwing errors for cyber security requested at same time in all accounts including my enterprise account. despite TAC verified.
23
2
111
9,812
Edit-2: having errors again
3
5
792