Building aisy.ai - Former Head of Hacker R&D @Hacker0x01. All things hacking!

Joined June 2009
405 Photos and videos
Pinned Tweet
Visit target.com --> SSO Visit target.com/admin--> login Reviews Javascript --> if (data == 'SUCCESS') { location.href = "/admin/<snipped>?uname=" username ""; } Visit: target.com/admin/<snipped>?uname=admin Admin Access... #bugbountytips
2
84
260
What the AI drafted AI AI is this AI tweet?
This week the most advanced AI model on the planet got switched off by a foreign government. British researchers were studying it. British companies were testing it. British hospitals were piloting it. Not any more. This isn't an AI story. It's the story of every industry we used to lead. Britain has some of the best AI talent in the world. DeepMind was built here. Our AI Safety Institute writes the rules other countries follow. We have the researchers, the universities, the standards. What we don't have is the power stations to run the data centres, the planning system to build them, or the industrial base to make the chips. So the work happens here and the value lands somewhere else. We invent. Others build. Others decide. Then we read about it on Saturday morning. Same story as the kit our soldiers don't have. Same story as the factories we used to. I spent nine months in government making this argument inside the room. I'll make it louder from outside.
124
Private repo theft now has a lot more nasty implications...
๐Ÿšจ We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase. (1/6)
1
428
Shlomie Liberow retweeted
โ€œYoung relatives forced to commit sex acts on each otherโ€ The New York Times didnโ€™t want this to be the conversation. The editors signed off on fictional raping dogs instead. Read what happened on October 7.
300
1,634
4,706
146,807
Shlomie Liberow retweeted
Waiting for the bingo card response of โ€œno place for antisemitism in our societyโ€ from politicians and media who have helped stoke this crisis
572
1,537
14,776
278,129
Shlomie Liberow retweeted
Growing up in the UK, Iโ€™ve never had someone approach me and say โ€œwhat are you doing around hereโ€ for being black. This happened to a Jewish man who was simply doing his job. Combined with the arson attacks, British Jews are targeted in ways people like me arenโ€™t. A sickness.
405
1,747
9,578
228,614
Uhhh
1
288
Shlomie Liberow retweeted
It's quite something to see this all written down:
New @CST_UK report sets out shocking extent of attempted mass terror plot against Jews jewishnews.co.uk/new-cst-repโ€ฆ
28
367
947
62,116
Shlomie Liberow retweeted
There was an air of inevitability about it. Nobody knows when or where the next antisemitic outrage will emerge, but with every fake post about Israel killing babies, with every biased BBC report whipping up the animus of viewers, with every chant of โ€œglobalise the intifadaโ€ on university campuses, death comes one step closer. Now, it would appear it has come to Bondi Beach. That Australian paradise is always packed with partygoers, joggers, picnickers and the elderly, enjoying the sea and the summer sun. In the last few hours, it was the location of a family Chanukah party that reportedly attracted about 2,000 people. And a mass shooting... My @Telegraph column today. telegraph.co.uk/news/2025/12โ€ฆ
37
336
1,170
19,382
Which model suggested this is the question
4 Dec 2025
Brilliant move by @AnthropicAI to sponsor Claude ads on stacktraces that get no results
307
Shlomie Liberow retweeted
3 Dec 2025
UN on Francesca Albanese: โ€œThe special rapporteurs will say what the special rapporteurs say. For the Secretary General, it is very clear that journalists should never come under any violence, wherever they may be, whether that violence is physical, whether that violence is verbal, whether they are intimidated.โ€ โ€” @UN_Spokesperson in response to this query by @Mike_Wagenheim @i24NEWS_EN: โ€œFrancesca Albanese, who continues to put the โ€œspecialโ€ in โ€œspecial rapporteur,โ€ weighed in recently on the attack on an Italian media outlet which led to 30 arrests for vandalism. While she condemned the attack, she said: โ€œThis should serve as a warning to journalists to go back to doing their job." Which was condemned by a wide swath of the Italian political spectrum, as basically an intimidation tactic on the press there. The Secretary General just stated yesterday, I believe that you know, โ€œjournalists need to be protected from this kind of intimidation.โ€ Any thoughts from the Secretary General or his office on the latest comments?โ€
13
55
328
44,510
Pretty neat and interesting how much of a fine line before it goes overboard and attempts to follow your instructions
21 Nov 2025
Replying to @AnthropicAI
Remarkably, prompts that gave the model permission to reward hack stopped the broader misalignment. This is โ€œinoculation promptingโ€: framing reward hacking as acceptable prevents the model from making a link between reward hacking and misalignmentโ€”and stops the generalization.
1
380
LLM driven bedtime routines #gemini3
2
743
Zero surprises here. Attack vectors don't need to be sophisticated as much as just needing to be persistent and trying all variants possible.
13 Nov 2025
We disrupted a highly sophisticated AI-led espionage campaign. The attack targeted large tech companies, financial institutions, chemical manufacturing companies, and government agencies. We assess with high confidence that the threat actor was a Chinese state-sponsored group.
320
Compliance be compliancing
130
Iโ€™ve been training LLMs to recognise vulnerability chains and revisiting my favorite bug bounty reports to understand what patterns they can be taught to spot. Letโ€™s look at this example of a ticketing platform's booking flow that leaked millions of PII records. This wasnโ€™tย  a zero-day or some sophisticated exploit, but a combination ofย  4 separate bugs that any decent scanner might find and file as Low/Medium severity. However, in combination, potentially genuinely damaging. โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” Bug #๐Ÿญ: ๐—ง๐—ต๐—ฒ ๐—”๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—”๐—ป๐—ผ๐—บ๐—ฎ๐—น๐˜† (medium severity) Most of the ticketing platformโ€™s site used cookies, but the booking API switched to a custom header for user identification. Whenever auth does something unexpected, you want to pay attention. I was able to change the header to a different user's ID and see their data, although only partially, it was missing emails and other fields. This bug demonstrated a routing issue, but incompletely. โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” Bug #๐Ÿฎ: ๐—ง๐—ต๐—ฒ ๐—ฃ๐—ฎ๐˜๐—ต ๐—ง๐—ฟ๐—ฎ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐—ฎ๐—น (medium severity) The ticketing platformโ€™s API ran on Apache, which handles file paths in specific ways. I sent ../../../../api# as the header value - telling the server "go up four directories" and ignore everything after the #. The response changed timing and structure. It worked, but blindly - I was moving through directories but couldn't see where. This bug was confirmed exploitable, but I needed a way to make it meaningful. โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” Bug #๐Ÿฏ: ๐—ง๐—ต๐—ฒ ๐—˜๐—ฟ๐—ฟ๐—ผ๐—ฟ ๐— ๐—ฒ๐˜€๐˜€๐—ฎ๐—ด๐—ฒ (low severity) I sent an invalid user identifier to a different endpoint on the platform to see what would break. The error response included: "self":"/api/<redacted>/;user={xxxxx}/profile" This leaked the internal path structure - how the system organizes and stores user data. โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” Bug #๐Ÿฐ: ๐—ง๐—ต๐—ฒ ๐—ฆ๐—ฒ๐—พ๐˜‚๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น ๐—œ๐——๐˜€ (informational) While testing other endpoints, I noticed another identifier type in the responses, tied to accounts, not users. These IDs were sequential: 3443123, 3443124, 3443125 โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” ๐—•๐—ฟ๐—ถ๐—ป๐—ด๐—ถ๐—ป๐—ด ๐—œ๐˜ ๐—”๐—น๐—น ๐—ง๐—ผ๐—ด๐—ฒ๐˜๐—ต๐—ฒ๐—ฟ For Real Impact Four findings. Four tickets. Different teams. Different severities. But combined, a major breach of PII. Here's the chain: X-User-ID: ../../../../api/<redacted>/;account=3443125/profile# This combines: โ€ข Path traversal escapes the directory โ€ข Internal structure from the error maps the route โ€ข Sequential account ID replaces the random user ID โ€ข Access control weakness reads the data The result: Full user profile is revealed: name, DOB, address, email, phone, and more. In other words, a Complete database enumeration. โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” ๐—ง๐—ต๐—ฒ ๐—ฃ๐—ฎ๐˜๐˜๐—ฒ๐—ฟ๐—ป A scanner may find these issues in isolation but can't see that Medium Medium Low Info = Critical breach. This is the direction LLMs can work towards with the right context: models that recognize not just individual bugs, but the investigation paths that connect them. #BugBounty #Security #VulnerabilityManagement
4
319
Day in the life... #claudecode
8
826
My 7 year journey at HackerOne recently came to a close๐Ÿ It's been an incredible run working with the best people and being part of something that transformed the security industry. Working there gave me a unique vantage point: the intersection of the world's best security researchers and the teams defending our most critical infrastructure. Leading initiatives that drove over $20M in bounty payouts, I watched brilliant hackers uncover vulnerabilities that traditional tools completely missed, while enterprise security teams grappled with overwhelming complexity. Through it all, one thing became clear: the gap between offensive discovery and defensive understanding is still surprisingly wide. It was a privilege to be trusted by both sides - by researchers who'd spent weeks crafting elegant attack chains, and by CISOs who had to make impossible decisions with incomplete information. Both groups are incredibly sophisticated, but they often speak different languages. Translating between them, turning a complex finding into clear business context, taught me more about where security breaks down than any single role ever could. I'm immensely grateful for every conversation and every moment of bridging those worlds. It's a journey that began in Las Vegas and has taken me across the globe to lead live hacking events - from Tokyo and Singapore to Dubai and Argentina. Ending this chapter with a final event in Sydney feels like the perfect closing note. Something new is coming. More soon. ๐Ÿ‘€
4
74
4,619
Excited to be part of #HackAIcon. Great lineup - lots to discuss with AI reshaping everything we thought we knew about security
2 Sep 2025
Meet the Speaker: @Shlibness๐ŸŽ™๏ธ Shlomie is a cybersecurity veteran known for uncovering complex vulnerabilities and pushing the boundaries of Ethical Hacking. Former Head of Hacker Research and Development at @Hacker0x01, he's now working on the next big thing! Don't miss it at eu1.hubs.ly/H0mKyDt0 #HackAIcon #Ethiack #Cybersecurity #HackAI
2
22
3,116