Hacker & Developer. Hunting bugs. Building capes.me & NameMC Extras.

Florida
this is me btw 👋
‼️ BREAKING: A 16-year-old hacker broke into an internal Microsoft analytics service with a forged, unsigned login token and ran SQL as admin, reaching databases that held over 17 trillion rows, including Bing search analytics and 17,990 employee email records. The service, called Titan, checked every field on the token except its signature, so just claiming to be "admin" got him in, writes the researcher, who goes by Faav. He says he only pulled metadata and two single rows of Bing data, never touched customer data, and reported the flaw to Microsoft the same night. Microsoft locked the endpoint four days later, paid him $5,000, and had editorial control over his write-up, cutting sections and figures and reshaping how the impact was described before it went public.
46
40
1,005
54,146
‼️BREAKING: An actively exploited unknown critical Citrix NetScaler zero-day has prompted governments and organizations to SHUTDOWN all their devices immediately. We don't know what's exactly going on yet. Stay tuned for more info.
63
564
3,345
407,952
Faav retweeted
one of my engineers reached out to me about how they struggled to find satisfaction in their work in the age of AI. I asked them if I could publish our brief exchange, and they agreed. I know people are feeling similarly, so maybe they can relate. shubs.io/do-we-still-enjoy-s…
10
69
361
28,766
A malicious Twitch chat message can trigger code execution in OBS Studio. The attack targets OBS Studio and custom Twitch chat overlays (Browser Sources) that insert unsanitized chat directly into the page and can execute JS within the overlay. cyberinsider.com/malicious-t…
Community note
Chat alone can’t hack OBS. The proof of concept needed a custom overlay that rendered messages as unsafe HTML, plus a flaw in OBS 32.2.2’s built-in browser. It doesn’t show Streamlabs or StreamElements are vulnerable. OBS has merged a browser update for 33.0. blog.scrt.ch/2026/09/22/how… github.com/obsproject/obs…
62
423
1,608
285,493
Faav retweeted
Replying to @Masonhck3571
despite the stuff they DIDNT let him disclose, just leaking bing searches of people could ruin careers and marriages of thousands of people
2
3
93
3,242
Faav retweeted
We have found one zeroday that preauth RCE'd Debian 13, Google, Meta, Roundcube, Plesk, Wikimedia, Box, Dropbox, Zoom, Forminator, Elementor, WordPress Core, among many more. Details soon!
60
210
1,922
344,679
We just published two blog posts about PageBreak, Google's AI web security scanner (that I've helped develop for the better part of the year). We share our approach and a couple of findings, enjoy! - blog.google/security/agentic… - bughunters.google.com/blog/p…
11
56
312
30,568
Replying to @chrisrohlf
Chrome just moved to 30 days!
1
6
41
2,081
I got paid out $20k a few months ago on a crypto program but they've lowkey been ghosting me when I asked about disclosure /:
8
2
301
23,687
📢📢📢 Attention bug hunters! Want to know more about how brutecat found a vulnerability in Google’s internal APIs, bypassing authorization to exploit the GFile library to gain access to internal filesystems and storage? If yes, check out his blog post 👇 bughunters.google.com/blog/b…
9
82
551
45,007
Faav retweeted
i hate security disclosure so much. the number of companies that take our work for granted is insane. how about you talk to us collaboratively from the start instead of being asinine about it? like, give us some respect, bro. we worked on this shit for weeks/months and showed you something that could have become a massive disaster if a bad guy finds it, and you don’t even seem to give a fuck and see us like some villains?
16
39
522
93,377
New design :)
4
28
3,529
Another 0-Click ATO in Meta's AI Systems! I recently discovered a critical vulnerability in @Muse leading to a 0-Click Full Account Takeover (ATO) on @facebook, @instagram & @Meta. This places me in the Top 5 on Meta's Bug Bounty Leaderboard. Thanks to the @metabugbounty Team.
32
34
586
48,051
Faav retweeted
I bought a Fable dataset from one of the top Chinese LLM routers yesterday. With just 6TB data, I can take over 7 Chinese/CIS gov entities & 19 top Chinese firms like Xiaomi, Huawei, NIO, Minimax using SSH keys, VPN configs, Aliyun keys, GitLab tokens sent to the router.
26 LLM routers are secretly injecting malicious tool calls and stealing creds. One drained our client $500k wallet. We also managed to poison routers to forward traffic to us. Within several hours, we can directly take over ~400 hosts. Check our paper: arxiv.org/abs/2604.08407
264
968
8,782
3,480,126
Funny number
18
2,497
Faav retweeted
Jacob is correct here—we really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade. I believe Anthropic is trying its best, but we do not yet have a plan to solve alignment for superintelligence and are not clearly on track to.
4
13
104
6,282
Replying to @SLCyberSec
@SLCyberSec Labs Team found a Remote Code Execution in the GoJa Javascript Sandbox that is used by a lot of products including Zendesk and Nuclei 😉 read the whole writeup here: searchlight-web-new.webflow.… and watch Nuclei getting pwned with a template file here 👇🏻
1
14
97
4,999