(Tยณ) Technical Thinking Tinkerer

Joined October 2021
153 Photos and videos
Pinned Tweet
Won a ๐—ณ๐—ฟ๐—ฒ๐—ฒ ๐—ข๐—ฆ๐—–๐—ฃ PEN-200 bundle from @offsectraining by winning ๐Ÿญ๐˜€๐˜ place in their ๐—ฅ๐—ฒ๐—ฝ๐—ผ๐—ฟ๐˜ ๐—ช๐—ฟ๐—ถ๐˜๐—ถ๐—ป๐—ด ๐—–๐—ผ๐—ป๐˜๐—ฒ๐˜€๐˜ โ€” Alhamdulillah, passed #OSCP with ๐Ÿญ๐Ÿฌ๐Ÿฌ/๐Ÿญ๐Ÿฌ๐Ÿฌ on my first attempt! Check out: medium.com/@pakcyberbot/how-โ€ฆ
4
37
1,421
Alhamdulillah, Iโ€™m excited to share that Iโ€™ve received my first bug bounty from Meta ๐ŸŽ‰ I identified a Denial of Service (DoS) vulnerability in one of Metaโ€™s web assets. Itโ€™s currently in the process of being fixed, and once resolved, Iโ€™ll be publishing a detailed write-up. [1/2]
1
4
168
๐Ÿ“Œ The PoC video will be available on my YouTube channel: youtube.com/@PakCyberbot ๐Ÿ“Œ A complete technical breakdown will be published on my Medium: pakcyberbot.medium.com/ My Meta Profile: bugbounty.meta.com/profile/9โ€ฆ [2/2] #Meta #BugBounty #WEB #Pentesting
159
Pak Cyberbot retweeted
Mar 13
โ€œThe vulnerability with the highest CVSS score in this monthโ€™s update is a critical remote code execution flaw in the Microsoft Devices Pricing Program. CVE-2026-21536 (CVSS score: 9.8), per Microsoft, has been fully mitigated [...] Artificial intelligence (AI)-powered autonomous vulnerability discovery platform XBOW has been credited with discovering and reporting the issue.โ€ bit.ly/4s2u8vq
2
34
137
34,789
Pak Cyberbot retweeted
๐Ÿšจ Someone just open sourced a fully autonomous AI hacker and it's terrifying. It's called Shannon. Point it at your web app, and it doesn't just scan for vulnerabilities. It actually exploits them. Real injections. Real auth bypasses. Real database exfiltrations. Not alerts. Not warnings. Actual working exploits with copy-paste proof-of-concepts. Here's what this thing does autonomously: โ†’ Reads your entire source code to plan its attack โ†’ Maps every endpoint, API route, and auth mechanism โ†’ Runs Nmap, Subfinder, and WhatWeb for deep recon โ†’ Hunts for Injection, XSS, SSRF, and broken auth in parallel โ†’ Launches real browser-based exploits to prove each vulnerability โ†’ Generates a pentester-grade report with reproducible PoCs Here's the wildest part: It follows a strict "No Exploit, No Report" policy. If it can't actually break it, it doesn't report it. Zero false positives. It pointed at OWASP Juice Shop and found 20 critical vulnerabilities in a single run including complete auth bypass and full database exfiltration. On the XBOW Benchmark (hint-free, source-aware), it scored 96.15%. Your team ships code daily with Claude Code and Cursor. Your pentest happens once a year. That's 364 days of shipping blind. Shannon closes that gap. One command. Fully autonomous. The Red Team to your vibe-coding Blue team. Every Claude coder deserves their Shannon. 10.6K GitHub stars. 1.3K forks. Already trending. 100% Open Source. AGPL-3.0 License.
210
1,024
8,187
795,321
Pak Cyberbot retweeted
Nothing humbles you like telling your OpenClaw โ€œconfirm before actingโ€ and watching it speedrun deleting your inbox. I couldnโ€™t stop it from my phone. I had to RUN to my Mac mini like I was defusing a bomb.
2,323
1,678
17,444
10,132,107
Pak Cyberbot retweeted
Nothing to see here... ๐Ÿซฃ Here are the pieces of content coming to the #HackTheBox platforms this week! ๐Ÿ”ต JustSomePages, a Sherlock created by iamr007 ๐Ÿ”ด Interpreter, an HTB Season 10 Machine, created by ReziT ๐Ÿ”ด PyDome, a Challenge created by pakcyberbot Find them on #HTB Labs and Enterprise Platform: okt.to/Of6urF #Cybersecurity #InformationSecurity #NewRelease #Hacking #CyberSkills
9
74
3,732
My new challenge, "PyDome", has been released on Hack The Box ( @hackthebox_eu ). Give it a try and let me know your thoughts! app.hackthebox.com/challengeโ€ฆ Feedback or constructive criticism is greatly appreciated. #hackthebox #challenge #pydome #pakcyberbot
1
1
52
Pak Cyberbot retweeted
Humanoid robot with open-source hardware and software github.com/Roboparty/roboto_โ€ฆ
16
234
1,495
63,454
Pak Cyberbot retweeted
Want to see what elite security research looks like? ๐ŸŒŸ @omer_asfu, one of Google Cloud VRP's best, dropped a cross-tenant finding: CVE-2025-13292 (nvd.nist.gov/vuln/detail/CVEโ€ฆ)

๐Ÿ‘ผGatewayToHeaven (CVE-2025-13292). I discovered a cross-tenant vulnerability in @GoogleCloud's #Apigee, allowing me to access other organizations' data (and sometimes even plaintext JWTs of end users). Below is the full breakdown of the exploit chainโ›“๏ธ
2
41
274
24,159
That's called dedication
This is who youโ€™re competing against, Chinese fruit seller and chip designer. Yea, youโ€™re cooked:
2
55
Pak Cyberbot retweeted
๐Ÿšจ We turned Google Gemini into a double agent. By sending a single, "silent" calendar invite, we hijacked Geminiโ€™s calendar capabilities to exfiltrate private dataโ€”with zero lines of code in the exploitation. The AI didn't just leak info; it actively worked for us. ๐Ÿงต๐Ÿ‘‡
1
3
13
1,840
๐Ÿš€ ๐—™๐—ถ๐—ฟ๐˜€๐˜ ๐—–๐—ฉ๐—˜ ๐—จ๐—ป๐—ฑ๐—ฒ๐—ฟ ๐— ๐˜† ๐—ก๐—ฎ๐—บ๐—ฒ โ€” ๐—–๐—ฉ๐—˜-๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ-๐Ÿฎ๐Ÿญ๐Ÿฒ๐Ÿฐ๐Ÿฌ @ReviveAdserver ๐Ÿ”— nvd.nist.gov/vuln/detail/CVEโ€ฆ ๐Ÿ”— revive-adserver.com/ #CVE #vulnerability #nist #nvd #hacking #cybersecurity
2
130
Pak Cyberbot retweeted
Day TWO of FIVE days of celebrating our 2 year ARCANUM-VERSARY! @arcanuminfosec 3rd Giveaway = FOUR seats to our new course by @the_IDORminator "Zero to [BAC] Hero" ! ๐Ÿ‘ 1 Like = 1 Entry! โ™ป๏ธ 1 Share = 2 Entries! Winners announced 1/21! Syllabus link below ๐Ÿ‘‡
112
404
764
40,002
Pak Cyberbot retweeted
Revive Adserver disclosed a bug submitted by @pakcyberbot: hackerone.com/reports/344533โ€ฆ #hackerone #bugbounty
2
1
1,296
Pak Cyberbot retweeted
Become an absolute Web3 Security beast in 2026!! Resources: 1. Owen Thurm - Web3 Security 101 playlist (Youtube) 2. Past audit reports - solodit.xyz 3. DeFi bible - github.com/OffcierCia/ultimaโ€ฆ 4. Books & Blog - rareskills.io/blog 5. Use AI to your advantage
32
71
489
21,133
Pak Cyberbot retweeted
Everything you need annas-archive.se

8
21
2,267