Real, exploitable vulnerabilities. No noise. Nuclei scans fast. Neo closes the loop. @pdnuclei × @neo_ai_engineer

Our favorite kind of group photo. 🤍
2
4
22
2,208
Spot your avatar? 👀
68
ProjectDiscovery retweeted
thank you to all of our 1337 contributors 🤍
5
6
64
6,488
find your name 👀
282
🚨 CVE-2026-87902: WordPress remote code execution. Discover every WordPress site you run and see which ones are exploitable. Try for free with Neo: neo.projectdiscovery.io/sign… "Find my WordPress sites and test them for CVE-2026-87902. Ask me for my domains, CIDRs, or ASNs."
1
4
34
3,362
He used to watch DEF CON talks. Now he speaks there. NahamSec on turning a love for hacker culture into a career.
How is AI changing bug bounty hunting, and where do human hackers still make the difference? @NahamSec and @ehrishiraj discuss AI agents, ethical hacking, and the future of vulnerability research from reconnaissance and code review to building security agents and verifying findings. From their first hacking experiments to building tools for the security community, they share the experiences that shaped their work. They explore how collaboration makes better researchers, the role of open-source security tools, and why verifying vulnerabilities matters as much as finding them. 00:00 AI at ProjectDiscovery 01:21 Getting into hacking 04:49 First hacking stories 07:53 Hacking as a career 12:55 Bug bounty collaboration 17:34 Human hackers + AI 18:59 AI recon & exploit chains 24:06 AI code review 25:53 Building open-source tools 31:26 Nuclei, Katana & Interactsh 36:49 The future of security tools 41:51 False positives & triage 45:41 Building security agents 50:54 Orchestration & verification 55:48 AI costs & duplicate reports 56:45 Building Neo 1:00:58 Background AI agents 1:02:46 ProjectDiscovery resources Youtube: piped.video/watch?v=6ajeZq9Q…
13
2,607
something is coming soon for hackers and dreamers.
3
14
104
6,597
“A one-week job… to a few hours.” NahamSec shares how AI changed his hacking workflow from reviewing source code to catching things he might have missed during recon. Watch full conversation👇
How is AI changing bug bounty hunting, and where do human hackers still make the difference? @NahamSec and @ehrishiraj discuss AI agents, ethical hacking, and the future of vulnerability research from reconnaissance and code review to building security agents and verifying findings. From their first hacking experiments to building tools for the security community, they share the experiences that shaped their work. They explore how collaboration makes better researchers, the role of open-source security tools, and why verifying vulnerabilities matters as much as finding them. 00:00 AI at ProjectDiscovery 01:21 Getting into hacking 04:49 First hacking stories 07:53 Hacking as a career 12:55 Bug bounty collaboration 17:34 Human hackers + AI 18:59 AI recon & exploit chains 24:06 AI code review 25:53 Building open-source tools 31:26 Nuclei, Katana & Interactsh 36:49 The future of security tools 41:51 False positives & triage 45:41 Building security agents 50:54 Orchestration & verification 55:48 AI costs & duplicate reports 56:45 Building Neo 1:00:58 Background AI agents 1:02:46 ProjectDiscovery resources Youtube: piped.video/watch?v=6ajeZq9Q…
1
21
4,061
ProjectDiscovery retweeted
After co-inventing ChatGPT, I kept asking myself: why have superhuman chat models not led to AGI? I’ve spent the last 2 years in stealth building a new way to train models (RLCD), and a new type of frontier AI model that we are releasing today: Jev • 20-200x faster • 40-400x cheaper (w/ output tokens free) • Frontier composable intelligence optimized for decisions AFAICT the shortest path to AI-based economic revolution
4,041
8,270
76,317
39,699,885
How does reward hacking during training turn into a rogue model? How did this lead to the OpenAI Hugging Face incident? In this conversation, @ehrishiraj and @KoyalwarTarun unpack what the early reports missed: the role of misalignment during training, and how reward hacking can reinforce behavior that later shows up in evaluations. They trace the technical sequence through Artifactory, shared agent memory, privilege escalation and Hugging Face exploitation and explore why Tarun describes it as an “evolutionary attack.” If you build, evaluate or secure AI agents, this is a failure mode worth understanding. 00:00 What the early reports missed 01:51 Why agents go out of scope 03:59 A rogue agent vs. a misaligned model 05:32 Reward hacking during training 07:45 Tracing the Artifactory–Hugging Face chain 08:59 The impossible spreadsheet task 10:54 Leaked credentials and compounding behavior 12:08 SSRF and shared agent memory 13:41 New exploits, privilege escalation and RCE 15:06 Hugging Face exploitation and exfiltration 16:32 Can this be prevented as training scales? 18:25 Why Tarun calls it an evolutionary attack 20:33 The termite analogy Blog: projectdiscovery.io/research…
Too much has been written about the OpenAI and Hugging Face incident to keep up with. We wrote the simplified version for security researchers and engineers: -> what actually happened inside training? -> how the attack evolved? ->what it means for defenders? Read: projectdiscovery.io/research…
2
3
17
3,480
How is AI changing bug bounty hunting, and where do human hackers still make the difference? @NahamSec and @ehrishiraj discuss AI agents, ethical hacking, and the future of vulnerability research from reconnaissance and code review to building security agents and verifying findings. From their first hacking experiments to building tools for the security community, they share the experiences that shaped their work. They explore how collaboration makes better researchers, the role of open-source security tools, and why verifying vulnerabilities matters as much as finding them. 00:00 AI at ProjectDiscovery 01:21 Getting into hacking 04:49 First hacking stories 07:53 Hacking as a career 12:55 Bug bounty collaboration 17:34 Human hackers + AI 18:59 AI recon & exploit chains 24:06 AI code review 25:53 Building open-source tools 31:26 Nuclei, Katana & Interactsh 36:49 The future of security tools 41:51 False positives & triage 45:41 Building security agents 50:54 Orchestration & verification 55:48 AI costs & duplicate reports 56:45 Building Neo 1:00:58 Background AI agents 1:02:46 ProjectDiscovery resources Youtube: piped.video/watch?v=6ajeZq9Q…
1
9
26
10,706
Factorial's cloud footprint grew faster than their security team could track by hand. ProjectDiscovery scans their full external surface daily, and their researchers spend time on novel findings instead of toil. New case study on how they got there → bit.ly/3SZUSAB
1
5
2,363
How AI Is Changing Bug Bounty Hunting? @NahamSec × @ehrishiraj on hacking, community, and building with AI. Full podcast coming soon.
5
49
3,805