Joined January 2012
611 Photos and videos
Pinned Tweet
Big news! I started @CoastlineCyber, a boutique cyber security consulting firm dedicated to strengthening your organization's security posture. 💪
1
5
30
15,581
I keep reading the state of triage blogs. I will tell you this, I'm sitting on now two 0click rce vulns for two separate phone vendors. One more phone vendor and I have RCE on like 99% of the telco market.
1
7
813
Am I the only one that makes hilarious names on Peleton and try to get in the leaderboards so the instructors say it? "You killed it today Stu Pidas" "Harry Balsonya did work today"
2
417
Anthropic, how many likes do I need to bring back the day-one public release of Claude 4.6? @AnthropicAI
1
5
733
Lol, spent 4 weeks deciding to migrate my Critical to a medium risk because the PII wasnt "sensitive enough". But they patched the vuln in less than 1 hour... Money must be tight. The $50k bounty was too much to pay. I understand 👍 Shareholders don't want to see that stuff.
1
7
950
I'm gonna rant for a second: I found a Zero-Click RCE in the latest Samsung phones in February. Samsung says it's "Out of Scope" because "AOSP Source." So I go to Google, they say it’s High, not Critical, because "AOSP Baseline." My RCE still sitting in the wild, no patch😬
33
38
939
48,772
My new thing is using Jarm to identify shared WAF configs, or confirm multiple subdomains belong to the same tenant without guessing.
1
12
1,661
I have a feeling it's a marketing ploy to make Opus 4.6 dumber for the next few weeks and then they release the new model and it seems drastically smarter.
CLAUDE OPUS 4.6 THINKING REDUCED BY 67% - Data shows Claude Opus 4.6 now thinks 67% less than before, dubbed “AI shrinkflation” - Same price but noticeably dumber; users report more guardrails and restricted output - Anthropic stayed silent until public data dropped; suspected compute-saving for next model (Mythos)
2
895
It's just a tool everyone. If anything mythos will create more jobs. Anthropic and OpenAI are hiring more developers every day, more security people everyday....
1
449
Paul Seekamp retweeted
🔓 CVE-2025-33073: Any domain user → SYSTEM → DC TGT → domain compromise. No admin needed. SMB signing on DCs won’t save you. praetorian.com/blog/cve-2025… #theguardplatform #offensivesecurity
1
52
147
21,920
My wife bought this AI calorie tracker. You take a pic of your food and it counts calories/macros. I reverse engineered it, made a newer robust version and fixed every complaint from customers. All while sitting at my daughter's gymnastics practice. caltrack.hardware-tracker.wo…

8
1,076
I just gave Claude code access to an old qnap I haven't turned on in like 4 years. It noticed it was running RAID 0 and it suggested running RAID 5. When I asked it how it plans to convert to RAID 5 without any data loss, it assured me no backup is required. 💀
2
1
13
3,348
Bug bounty SLAs are not a thing anymore it seems.
1
16
2,603
Im trying to find a good website that lets me set price alerts on GPUs and RAM. This looks good. prices.xricbuzz.com/ Any others?

4
834
Interesting... This site now scans the internet checking subdomain dns records. I have scheduled scans for my top 3 bug bounty domains for changes in DNS records so I can be the first to report. Subscription pays for itself! Cool portal too: domain-security-board.defend…

14
1,743
Sir Reginald Buys The Options is scary good.
1
4
1,067
Paul Seekamp retweeted
Jan 17
Ollama now has Anthropic API compatibility. 🦙 This enables tools like Claude Code to be used with open-source models. 😍 Get started and learn more 👇👇👇
181
761
6,288
590,999
Sir Reginald Buys The Options made a 322% profit today on his second trade of existence: Here is his plan for next week...
11
1,190
Sir Reginald Buys the Options is trying out some Options plays with Opus 4.5 as the brain. Reginald owns 1 call of the following: Time to get the popcorn🍿 out and see what it does.
2
829
Paul Seekamp retweeted
31 Dec 2025
Let's start 2026 with a major Responder update! It now supports: - CLDAP ping pong to SMB auth. - SNMPv3 authentication and hashes. - New rogue Kerberos server forcing AS-REQ when receiving TGS-REQ support for Kerberos type 17/18 hashes. - IMAP support for NTLM authentication. - SMTP support for AUTH PLAIN LOGIN CRAM-MD5 DIGEST-MD5 NTLM authentication. - DCE-RPC server now supports SAMR, SRVSVC, WKSSVC, WINREG, SVCCTL, ATSVC, DNSSERVER - DNS server now supports SOA, MX, SRV, ANY, etc -> SOA -> Appear as the authoritative DNS server -> MX poisoning → Email client connects to rogue SMTP/IMAP → capture credentials -> SRV poisoning → Domain services connect to rogue SMB/LDAP/Kerberos → capture NTLM/AS-REQ - LDAP GSSAPI, GSS-SPNEGO, NTLM, DIGEST-MD5 git pull or git clone github.com/lgandx/Responder.… Happy new year to everyone!
7
132
428
26,398