Software security, cryptography, etc

Joined August 2009
114 Photos and videos
Pinned Tweet
10 Nov 2024

1
2,050
erbbysam ㋬ retweeted
"brutecat is super talented", "luckily I'm not oncall ;)", "incredible" These are all real quotes from Googlers after seeing this blog post. Amazing work @brutecat, thank you for sharing!
Jun 11
Hacking Google with A.I. for $500,000 brutecat.com/r/hacking-googl…
2
24
550
33,550
erbbysam ㋬ retweeted
In April 2026, we held the latest edition of bugSWAT (our live event for security researchers) in Seoul, South Korea. For more information on this edition's focus, its impact & winners, as well as bugSWAT in general, see 👇 bughunters.google.com/blog/b…
2
13
78
7,232
erbbysam ㋬ retweeted
For Google VRP, inject the full invalid reports guide as system context for your agent. It’s a cheap way to teach it what Google won’t reward, cutting false positives at the source. bughunters.google.com/learn/…
I have been using Claude Code for bug bounty a lot and I see this pattern a lot in my workflow. Me: Scan for vulnerabilities in this target CC: This is interesting. I found 10 vulnerabilities. 2 Critical. 5 High. 1 Medium. 1 Low. Me: I am interested in only Medium CC: Now we have 9 valid vulnerabilities. Me: Reassess all 9 like an H1 triager CC: Good suggestion. Let me do that. After reassessment I can see there are only 3 valid ones left. Most of them were by design. Me: Reassess the pending valid ones with the assumption that the attacker is an external user and does not have access to internal systems. CC: All the findings are invalid. Sorry about that, I should have analyzed it correctly. I will be careful from the next target onwards. This happens every time 🤣🤣 and every time Claude Code's confidence level is 2000%. I have been trying to add these instructions in CLAUDE.md but it seems to not care about them at all. 😅😅😅😅 Jokes aside, Claude Code is really good if you use it correctly. I have already reported 2-3 reports fully found by Claude Code (using the above conversation workflow). I am still working on getting a perfect workflow setup.
1
4
55
6,577
erbbysam ㋬ retweeted
I'm so happy to have won the MVH at the latest Google LHE (Seoul 2026). Thank you, @GoogleVRP, for the amazing event!
17
11
227
31,683
erbbysam ㋬ retweeted
📢 Open source security researchers, take note: we've updated the OSS VRP rules! We're emphasizing the need for actionable reports and verifiable reproduction steps – to allow us to focus on critical threats with real-world impact. For more details 👇 bughunters.google.com/blog/o…
1
13
78
8,131
erbbysam ㋬ retweeted
Google VRP - Built different 💪 Full talk here: youtu.be/t0-oXbczPLs
8
47
3,715
erbbysam ㋬ retweeted
Feb 10
People are now putting AI in their CI/CD deployment pipeline, making them vulnerable to a simple Prompt Injection. My good friend @adnanthekhan managed to prove that @cline could have been backdoored like this 🤯 adnanthekhan.com/posts/cline…
6
19
100
6,634
erbbysam ㋬ retweeted
Jan 30
In the last 30 days, Google has rewarded me $33,760 via its Bug Bounty Program. However, Google's VRP is a different beast compared to other programs. Here are 5 things you need to know before getting started with Google VRP: 🧵👇
2
12
180
14,024
erbbysam ㋬ retweeted
📢📢📢 Our Patch Rewards Program rules were updated to explicitly encourage batched submissions, and place every Google-filed OSS vulnerability explicitly into scope (thanks for your feedback). Interested in getting rewarded for your awesome OSS security work? g.co/prp
29
135
21,595
25 Nov 2025
Finally done refinishing this 1935 chest that was covered in scratched lacquer and had a bit of water damage. Pretty happy with the results.
2
574
erbbysam ㋬ retweeted
24 Nov 2025
I wrote a post that has a bunch of me and my friends arguing lolllll do you think Prompt Injection is a bug? josephthacker.com/ai/2025/11…
19
22
104
30,827
erbbysam ㋬ retweeted
I'm really excited to share my first research article related to hacking Google Gemini! buganizer.cc/hacking-gemini-… #bugSWAT #GoogleVRP
9
104
487
65,861
erbbysam ㋬ retweeted
📣 We're delighted to announce our new, dedicated AI Vulnerability Reward Program 🥳 🎉! Join us in taking a look back at two years of AI bug bounties at Google and exploring the new AI VRP 👇 bughunters.google.com/blog/6…
4
38
202
23,399
erbbysam ㋬ retweeted
Replying to @busf4ctor
@busf4ctor and I took home 2nd place and Best AI VRP Researcher(s) at the Google’s Mexico Bugswat LHE! Had an amazing time here, thank you to the Google Security Team!
10
5
98
8,626
erbbysam ㋬ retweeted
Today was huge! @monkehack and I took 2nd place in the @GoogleVRP Mexico BugSwat and won Best AI VRP Researchers!
14
10
199
25,912
erbbysam ㋬ retweeted
PSA for bug hunters 🔔 ! We've updated the report quality framework for the Google, Cloud, and Abuse VRPs: clearer guidelines ensure more consistency, and make it easier than ever to qualify for the bonus for exceptional reports 💰 goo.gle/4nj5Ta2
1
7
49
4,636
erbbysam ㋬ retweeted
12 Aug 2025
Don’t post here much, but this one’s worth it. Managed to win the MVH award at the @GoogleVRP 0x0g bugSWAT event in Vegas 🤩
7
5
92
10,137
What's strange about go.dev/play/p/4fc3YX8m4xj 👀 Attend my presentation in @BugBountyDEFCON today at 5pm to learn more!
1
5
38
4,790