i used to love reading security writeups, i found it really interesting to see the thinking process behind how they found really impressive vulnerabilities. nowadays security writeups consist of prompting AI and effortlessly finding vulnerabilities with zero effort
9
28
399
13,584
http desync attack on discord !!
Spying on everybody's Discord attachments with HTTP desync tmctmt.com/posts/http-desync…
3
10
293
41,720
You aren't "Building" anything when you just tell claude what to do, if you have a bot write a whole codebase for you it is no different than looking at someone elses code. If you have no idea what's where or how it's implemented it simply isn't Your code.
12
67
1,069
32,389
daniel retweeted
the watchers: how openai, the US government, and persona have been secretly running an identity surveillance system since nov 2023. vmfunc.re/blog/persona researched by @vmfunc, @MDLcsgo, @DziurwaF
124
829
4,201
499,508
we pwned x, vercel, cursor, and discord through a supply-chain attack news.ycombinator.com/item?id…
how to hack discord, vercel and more with one easy trick kibty.town/blog/mintlify/
16
62
1,426
212,531
daniel retweeted
CVE-2025-67842 CVE-2025-67843 CVE-2025-67844 CVE-2025-67845 CVE-2025-67846 w/ @hackermondev, @MDLcsgo
17
14
312
33,310
back in 2023, i found a vulnerability on Discord to grab a support ticket details using just it's id. ticket ids are incremental so an attacker could have enumerated the entire platform and stolen everything. i reported it to their bug bounty program. they marked it as an "High", refused to upgrade its severity, and then silently fixed it.
35
231
6,205
290,691
the recent Discord breach shows just how critical of a vulnerability this was. if someone else had stumbled upon this vulnerability, they could have very easily stolen thousands of government IDs and confidential data this is another classic example of how bug bounties are very scammy. Discord's response to the recent data breach shows just how severe this vulnerability could have been.
7
24
1,835
72,031
the hackerone employee who decided to change the dark theme needs to be fired
16
4
142
19,013
you could essentially bypass any turnstile challenge during the outage. next cloudflare outage gonna be crazy
Multiple Cloudflare services, including Workers KV, Access, WARP and the Cloudflare dashboard, experienced an outage for up to 2 hours and 28 minutes earlier today. Here's a detailed breakdown of what happened: blog.cloudflare.com/cloudfla…
1
2
38
5,868
i've been working on a security tool that i genuinely think will revolutionize web security research just a few more things to do..
5
2
142
12,260
daniel retweeted
how to gain code execution on millions of people and hundreds of popular apps and of course, firebase was (partially) the cause kibty.town/blog/todesktop/
99
276
3,192
698,422
the creator of doxbin was pwned through a calorie counter app
20
102
2,793
138,448
long article but its a really interesting OSINT investigation into Doxbin's original owner nacha.sh/
3
7
244
21,850
A bug in Cloudflare (and just the nature of how CDNs work) let an attacker learn the broad location of Discord, Signal, Twitter users by just sending them an image, according to a researcher. It works because you check which data center cached the image 404media.co/cloudflare-issue…
37
498
1,824
116,771
#MerryChristmas, yearly reminder that bug bounties are still a scam
25
38
1,239
66,592
my 18y/o friend makes $100/week working at GIANT, restocking items, and other physical work. I can make nearly $1000+ from an hour of bug hunting in my bedroom with a laptop. it's crazy how specific knowledge can put you ahead of most people.
11
18
421
35,698