Joined November 2024
39 Photos and videos
"brutecat is super talented", "luckily I'm not oncall ;)", "incredible" These are all real quotes from Googlers after seeing this blog post. Amazing work @brutecat, thank you for sharing!
Jun 11
Hacking Google with A.I. for $500,000 brutecat.com/r/hacking-googl…
2
25
550
33,358
Faav retweeted
I wrote a short article about my research on Chromium, it's not too technical, but still relevant. I hope you guys like it. I plan to release the technical article in a few weeks (or days). davi-1337.github.io/posts/ou…

8
12
81
5,753
$600k in ONLY 6 MONTHS? Let's chat more about @brutecat's journey hacking one of the most hardened companies in the world! youtu.be/xZe7bBC17TM
19
127
12,413
Faav retweeted
Whoa! Big bounty! 🎉
74
49
2,663
223,247
Not even Google is safe from RCEs, and we brought @brutecat on the pod to talk about his hacking journey on Google! youtu.be/ZpEeWsqPy6g
1
12
95
10,319
Faav retweeted
New short article on a real-world exploitation case rather than pure research, demonstrating how a specific mistake in Next.js can lead to a systematic zero-click SXSS on its latest versions (w/@inzo____): Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js zhero-web-sec.github.io/rese…
6
67
355
19,796
Faav retweeted
Yay, I was awarded a $143,000 bounty on @Hacker0x01! hackerone.com/njcve #TogetherWeHitHarder It was worth waiting for ;)
114
51
1,161
109,332
Jun 1
RT @Hacker0x01: A 100% surge in submissions changed how we think about triage. We're rolling out new changes, including TriageOne Smart Ro…

6
Azure post 1 of 2 is live now, covering traffic hijacking via Smuggle Caching. Post 2 will focus on a Azure Front Door 0-click XSS that worked on HTTP/1.x and HTTP/2. Smuggling Through the Front Door... Achieving Global Redirect Poisoning at the Edge malicious.group/smuggling-th…
8
19
113
5,966
May 28
. @brutecat posts some of the most high quality interesting blog posts in bug bounty imo brutecat.com/articles/
8
40
1,411
Faav retweeted
Here we go. my DEF CON CTF writeup, a little different from the others. Also, thanks to Pwn de Queijo for letting me play with you guys. davi1337.gitbook.io/public/d…
12
95
8,265
May 26
Well I'm #10 on the USA Leaderboard now!
May 25
Been grinding out on HackerOne and I beat @rez0__ somehow, not sure how long this'll last though... 😅 (USA Leaderboard)
6
66
3,132
Faav retweeted
Faav is a beastttttt. Keep going bro!!
May 25
Been grinding out on HackerOne and I beat @rez0__ somehow, not sure how long this'll last though... 😅 (USA Leaderboard)
1
83
5,974
May 25
Been grinding out on HackerOne and I beat @rez0__ somehow, not sure how long this'll last though... 😅 (USA Leaderboard)
7
120
13,553
Faav retweeted
Adam (@hash_kitten) posted the solution for the XSS challenge he made earlier in the week on our Searchlight Cyber blog here: slcyber.io/research-center/t… - pretty interesting behaviour in Chrome's sanitizer API!
Thanks everyone for playing! I talk about the solution here, as well as how I discovered this behavior while looking into the Chrome Sanitizer API: slcyber.io/research-center/t…
7
99
11,746
Faav retweeted
May 21
I managed to RCE Fortune 500 companies and made over $50,000 with this technique. A new npm supply chain technique we just disclosed. The trick is dumb-simple. We call it npx Confusion. 🧵
10
56
391
25,450
Faav retweeted
A few months ago I found an SSTI on a large media company's bug bounty program. I got duped on the original report by four minutes, but came back a few months later and found a bypass that ended up being writeup worthy. phsi.se/posts/chaining-razor…

5
15
140
6,814