Hacktron is an autonomous vulnerability hunter for ambitious engineering teams. Built by world-class security researchers. Powered by one principle: PoC || GTFO

Joined April 2025
30 Photos and videos
Pinned Tweet
Introducing Hacktron Review: an AI security reviewer for your pull requests. It understands your whole codebase, builds a threat model, takes your feedback, and catches exploitable vulnerabilities before they reach production. Try for free: app.hacktron.ai
20
39
209
45,829
Hacktron AI retweeted
RCE in Warp Terminal! I believe the attack surface is broadening with every new tool you use. Every OAuth app you authorise with elevated scopes.. we'd see more breaches via targeting tools/SaaS.. the attack surface is everyone and everything now - hacktron.ai/blog/the-attack-…
1
12
46
3,069
Hacktron AI retweeted
warp also supports this escape sequence, but unlike iTerm, its inline=0 path handling lets attacker-controlled terminal output write attacker-controlled content into attacker-controlled locations. so @HacktronAI found this arb file write. source: github.com/warpdotdev/warp/b…
1
1
5
919
Replying to @S1r1u5_
Really hope more people get to try Hacktron. You guys are doing great so far and I love the open source initiative
6
545
Hacktron AI retweeted
So @Doyensec recently published a report comparing @xbow and @AikidoSecurity, two AI pentest platforms. I figured, why not run @HacktronAI on the same test? So I ran a pentest on one of the target. Hacktron cost $350, while XBOW and Aikido cost $4,000 each. We did pretty well!
8
20
235
14,983
Introducing Hacktron Whitebox: get white-box security assessments with audit-ready reports without waiting on a traditional pentest cycle. AI has roughly tripled the rate of code shipped in the past year. But penetration testing has not kept pace, often taking weeks to months.
1
5
52
10,768
The outcome: a faster, more cost-effective security assessment that does not compromise on quality. This is not just checkbox compliance. Hacktron Whitebox helps teams generate evidence for SOC 2 and ISO 27001, while giving engineers valuable, actionable findings they can fix.
1
4
661
Hacktron AI retweeted
Nice overview of the vulnerability discovery landscape! Very proud of the work we've done at @HacktronAI, as well as that of our peers at Anthropic and AISLE. AI has sped up vulnerability discovery, but coverage and signal remain to be important metrics we optimize for.
Agents are finding more vulnerabilities than ever. But it turns out there are gaps in existing vulnerability discovery. Over the past 90 days vs. a year ago, web vulnerabilities (XSS/SQLi/CSRF) are down 66% and memory safety exploitability is down 3.5x. We built the Agentic Vulnerability Coverage Map to track it all, updated daily. Introducing the Berkeley Vulnerability Initiative: vuln.cs.berkeley.edu. ⤵️
1
1
15
2,120
Hacktron AI retweeted
Who's finding what? @AnthropicAI owns critical count. @HacktronAI leads on severity exploitability. AISLE covers the most CWE types. There’s no clear overall winner.
1
4
23
12,867
Hacktron Review plugs into your pull requests and catches exploitable vulnerabilities other scanners walk straight past. Find real security issues within 24 hours of onboarding. Try it free → hacktron.ai
3
10
1,047
Hacktron AI retweeted
When Your VPN Opens Your Private Network to the Public! An auth bypass in Palo Alto PAN-OS CAS Auth (CVE-2026-0265) that lets an attacker connect to the company's GlobalProtect VPN. Blog - hacktron.ai/blog/cve-2026-02…
4
75
260
118,247
what can go wrong?
This is a critical auth bypass (affecting GlobalProtect VPN), not sure why this was marked as high. I have already managed to get VPN access to major corps! Unlike the buffer overflow this isn't limited to PAN OS. Will be disclosing full details later next week on @HacktronAI blog. security.paloaltonetworks.co…
1
1
19
16,241
Check out our security work on Next.js. We’re also offering free security scans for open source projects. Apply here: hacktron.ai/blog/hacktron-re…
Last week's Next.js stable release patches multiple vulnerabilities found by @HacktronAI CVE-2026-44578: SSRF via WebSocket upgrade. It is the most impactful of all, it lets an attacker read internal hosts such as cloud metadata endpoints on self-hosted next.js applications. curl -H "Connection: Upgrade" -H "Upgrade: websocket" \ -H "Sec-WebSocket-Version: 13" \ -H "Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ==" \ "http://target:3000" \ --request-target "http://169.254.169.254/latest/meta-data/"
3
13
2,443
Hacktron AI retweeted
I've seen enough fundraising announcement videos. This isn’t one of them. At @HacktronAI, we do security, and we do it well. That’s what matters to us. We solve real problems for our customers. On average, they uncover real vulnerabilities missed by other tools within 24 hours of onboarding. Just this year, we've already responsibly disclosed vulnerabilities in Vercel's Next.js, Grafana, Jetbrain's YouTrack, OpenAM, Metabase, and BeyondTrust's Remote Support Software. No unearned, bullshit hype. Just security that works.
4
12
89
14,860
Hacktron ❤️ Open Source TL;DR: If you maintain an open source project, we want to give you Hacktron Review for free. Because giving maintainers the same capabilities as attackers would otherwise use against them felt like the right thing to do. hacktron.ai/blog/hacktron-re…
10
27
3,147
Hacktron AI retweeted
Next.js v16.2.5 fixes a bunch of vulnerabilities reported by @HacktronAI. Patch ASAP, especially if you’re running self-hosted Next.js that SSRF might affect you CVE-2026-44574: Middleware / Proxy bypass via dynamic route parameter injection CVE-2026-44578: SSRF in applications using WebSocket upgrades CVE-2026-44581: XSS in App Router applications using CSP nonces
17
141
12,524
Hacktron AI retweeted
when react2shell hit last year, i think vercel handled it brilliantly. to protect their users, they paid $50,000 for every bypass researchers could find. we decided to participate, and ended up earning $170,000. read how we did it here: hacktron.ai/blog/react2shell…
5
69
383
19,747