Hooked on tech, I've been hacking away since '09! 🏳️☠️🇵🇭

Joined December 2015
2,618 Photos and videos
Pinned Tweet
🚀 Excited to share my new tool: NullSec Framework! 🐛🔍 ​A complete 12-phase bug bounty reconnaissance & automation pipeline written in Bash and built for real engagements. Automate everything from passive discovery to active vulnerability confirmation! ​🔥 Key Features: ⚙️ 3 Scan Modes: Fast, Normal & Deep 💾 Checkpoint & Resume (never lose scan progress!) 🎯 Smart Asset Scoring (focus on targets with the highest attack potential) ☁️ Cloud Storage Enumeration (AWS, GCS, Azure) 🔑 JS Secret Extraction & Telegram Alerts ​Whether you need quick hourly scans or thorough weekly audits, NullSec has you covered. ​Check out the repo, drop a ⭐️, and let me know what you think! 👇 🔗 github.com/NullSecHQ/nullsec…#BugBounty #InfoSec #CyberSecurity #Recon #OffensiveSecurity #NullSec
1
253
NOOOOOO!!!?
I’ve never run agents before, but the talk about your laptop needing to stay open while they run is actually true… anyways, how to piss off devs running agents 😁
1
29
Not sure why this surprises people lol. If you've actually built real AI stuff, you already know this is exactly how it works. The model is just the tiny smart piece in the middle. The other 98% is all the boring-but-critical scaffolding: sandboxes, permission layers, context management, tool isolation, and a ton of guardrails so it doesn't burn the house down. @AnthropicAI just did solid engineering instead of treating the LLM like magic.
Researchers show that Claude Code is 98% not AI. Anthropic never gave us the architecture for Claude Code. There were no docs. Just a tool that every developer is currently obsessing over. Until it leaked recently. A research team pulled the source code, analyzed all 500,000 lines, and found something ridiculous. Only 1.6% of the codebase actually interacts with the AI model. The core of Claude Code is literally just a simple while-loop. It asks the model what to do, runs a tool, and repeats. So what is the other 98.4%? It is hardcore, traditional software engineering. The researchers found a massive, complex infrastructure designed entirely to babysit the AI and keep it from hallucinating or destroying your computer: - A 7-mode permission system acting as a security bouncer. - A 5-layer context compaction pipeline so the AI doesn't forget its goal. - A subagent delegation mechanism with strict worktree isolation. - Four different extensibility hooks to manage external tools safely. Every startup right now is trying to build a better AI model to get better results. Anthropic did the exact opposite. They took an existing model and built a fortress of deterministic software around it. They realized that the AI doesn't need to be smarter. It needs to be managed.
75
Not sure why this surprises people lol. If you've actually built real AI stuff, you already know this is exactly how it works. The model is just the tiny smart piece in the middle. The other 98% is all the boring-but-critical scaffolding: sandboxes, permission layers, context management, tool isolation, and a ton of guardrails so it doesn't burn the house down. @AnthropicAI just did solid engineering instead of treating the LLM like magic.
Researchers show that Claude Code is 98% not AI. Anthropic never gave us the architecture for Claude Code. There were no docs. Just a tool that every developer is currently obsessing over. Until it leaked recently. A research team pulled the source code, analyzed all 500,000 lines, and found something ridiculous. Only 1.6% of the codebase actually interacts with the AI model. The core of Claude Code is literally just a simple while-loop. It asks the model what to do, runs a tool, and repeats. So what is the other 98.4%? It is hardcore, traditional software engineering. The researchers found a massive, complex infrastructure designed entirely to babysit the AI and keep it from hallucinating or destroying your computer: - A 7-mode permission system acting as a security bouncer. - A 5-layer context compaction pipeline so the AI doesn't forget its goal. - A subagent delegation mechanism with strict worktree isolation. - Four different extensibility hooks to manage external tools safely. Every startup right now is trying to build a better AI model to get better results. Anthropic did the exact opposite. They took an existing model and built a fortress of deterministic software around it. They realized that the AI doesn't need to be smarter. It needs to be managed.
36
Congrats UK gov, you didn't protect anyone, you just drove them into darker corners of the internet.
15
Found a lame P4 open redirect a while back and instantly remembered that chaining video you dropped, turned that shit into a clean P1 takeover. Seeing you chain 5 broken access controls into $30k is crazy. Saving this one for sure. Keep killing it @NahamSec! 🙌🏽
I've made $30,000 from ONE bug class on a single program: broken access control. Not by spamming lows by chaining them. New vid: 5 BAC bugs → 1 full account takeover, live. And I built a free lab on @HackingHub so you can follow along. youtu.be/6v3B3FxDHbo
3
29
2,467
Quick break, smashing some sausage for dinner 🍖🍽️ Back in 15 to keep grinding that manual recon. This stuff ain't gonna find itself lol
Framework just dropped a bunch of fresh leads on me. 😅 Time to turn off the autopilot and get my hands dirty with some manual recon, deep OSINT, credential stuffing checks, and proper verification. 🐛
16
Jonaski retweeted
What is an IDOR? Google and Uber got hacked this way. Discover how a simple IDOR vulnerability can dump an entire database. Learn why this basic API bug still earns massive bug bounty payouts in 2026 from tech giants like Google and Meta. This video is sponsored by @ThreatLocker
3
15
87
4,181
Jonaski retweeted
They are free on our website.
1
2
37
Framework just dropped a bunch of fresh leads on me. 😅 Time to turn off the autopilot and get my hands dirty with some manual recon, deep OSINT, credential stuffing checks, and proper verification. 🐛
46
Time to get my ass back to work.
17
Jonaski retweeted
tweeps, would you consider a missing laptop a cyber incident, an IT Ops incident, or both?
12% cyber
25% IT Ops
59% Both
4% Other
73 votes • 3 days
30
2
16
8,539
This CORS vulnerability can lead to token leaks, exposing state, and completely bypassing cross-origin protections at the infrastructure level. Unlike backend bugs that need sessions, this hits before you even log in, making it a lot more dangerous for sensitive apps.
34
Jonaski retweeted
As a result of a US government directive, we are suspending access to Claude Fable 5 for all users. You can continue to use all other Claude models. Here’s what this means for you: Across Claude products, new sessions will run on your selected default model or Opus 4.8, and existing Fable 5 sessions will end with an error. On the Claude Platform, requests to Fable 5 will also return an error. Please update your integrations to other Claude models. We know this is a disruption to your workflows; we appreciate your patience and support.
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees. The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance. Access to all other Claude models is not affected. We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible. Read our full statement: anthropic.com/news/fable-myt…
3,671
7,275
44,660
12,911,210
I'm going to figure out if this directive is even enforceable without some shady backdoors or telemetry that Anthropic is hiding. That whole "misunderstanding" bullshit makes it seem like their legal team was totally caught off guard. This shit's a disaster for security, a mess for industry, and ruins due process. Buckle up for some lawsuits or an emergency stay coming in the next 48 hours. 🤡
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees. The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance. Access to all other Claude models is not affected. We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible. Read our full statement: anthropic.com/news/fable-myt…
53
Jonaski retweeted
Stealthy /s
5
1
35
2,111
Attack plan: 1. Configure Burp 2. Map staging 3. Read auth configs 4. Test BOLA 5. Verify SQLi 6. Probe XSS 7. Chain redirects 8. Ping SSRF via collaborator
34
Let's get those shit mapped out.
10
It's 10:54 and I just stuffed my face with breakfast. I'm about to brush my teeth and hit the sack since tonight's session is gonna be a long one. 🐛🏦
28
You should think about staying independent, because that "consistent relationship" crap usually just means they want reliable, budget-friendly access to your talents.
Bug hunters i got this message after reporting 100 plus bugs in this program. You guys also can try this bug bounty target. Magic of 100 plus reports.
1
110
Pattern locks are meant for keeping shit convenient, not for making you rich.
Bir adam, 2013 yılında telefonunun şifresini unuttu. Telefonun içinde 150 adet Bitcoin vardı. Telefonun sahibi, 2013'den bu yana belirlediği desen şifreyi hatırlamaya çalışıyor...
8