Working on fast, accurate and auditable CVE enrichment at Volerion.

Joined February 2012
53 Photos and videos
Pinned Tweet
13 Oct 2023
The $15,000 secret of viewing posts from private Instagram accounts. 003random.com/posts/meta-bou… #bugbounty #bugbountytips #writeup

5
154
687
59,763
This bug was buried so deep. You had to use a mobile user agent to reach the code path. Then block the victim account. And then request one of their posts via the oEmbed endpoint. This would trigger a try catch condition where super user privileges were used to fetch the post.
Replying to @intigriti
1️⃣ How I Exposed Instagram's Private Posts by Blocking Users @rub003 won 3rd place at BountyCon 2022 by chaining Instagram oEmbed endpoint quirks with mobile user agent detection to access private posts (earning him $14,500 in bounties). 003random.com/posts/meta-bou…
3
8
116
12,547
003random retweeted
Jan 3
@VolerionSec's algorithm looks better, 0.6 impact seems more correct. volerion.com/vulnerabilities…
1
2
49
16,792
003random retweeted
Replying to @FFmpeg @grok
wrong pixel no bad but CVSS say medium bad
2
1
21
1,467
20 Aug 2025
😭
1
374
003random retweeted
13 Aug 2025
🦾💼 #DEFCON33 may feel like a “hacker holiday,” but the CVE conveyor belt never stops. Out of the 249 newly published CVEs, the highest EPSS in the set is 0.09475 — CVE-2025-47188 — with a CRITICAL CVSS score. Volerion gives it a contextual risk score of 3.6/10, factoring in real-world usage and internet exposure of the affected products. The ecosystem doesn’t take time off — and neither does Volerion’s AI-driven analysis, turning raw CVEs into actionable, prioritized risk. #DEFCON #CVE
1
2
368
31 Jul 2025
CVE-2025-54576 is quite cool. It's so easy to make your web app vulnerable to this. You would expect `skip_auth_routes` to match routes only, but meanwhile it was comparing against `GetRequestURI`. Fixed in v7.11.0 by comparing against `GetRequestPath`. 👉blog.volerion.com/posts/CVE-…
1
328
28 Jul 2025
😂The award for best NVD CVE description goes to...
1
3
411
28 Jul 2025
The largest description award goes to nvd.nist.gov/vuln/detail/CVE…, but nvd.nist.gov/vuln/detail/CVE… is quite funny too. Who actually reads these?

ALT Confused Eyes GIF by MOODMAN

2
2
359
28 Jul 2025
.@VolerionSec writes consistent length summaries. For example, the one from above: volerion.com/vulnerabilities… "in various models" is so much better than listing all 50 vulnerable versions in the description. We have a products tab for the actual affected products and versions.
1
1
199
23 Jul 2025
Can the person farming CVEs in sample software projects just stop please. This year already, 448 CVEs were reported on phpgurukul, which is just a sample project not meant to deploy😭. Why vuldb is allowing this, idk... The CVE ecosystem is getting ruined by sh*t submissions.
3
5
428
23 Jul 2025
🤡
136
23 Jul 2025
Personal opinion. However, at @volerionsec we're thinking the exact same 🤡. Most CVE submissions are just spam nowadays. Made possible by a couple specific CNAs.
132
4 Jul 2025
getJS will now ignore certificate errors, so that your bug bounty automation will less likely error on the hosts that are the most interesting (e.g. self-signed certificates). github.com/003random/getJS/
4
220
003random retweeted
3 Jul 2025
Our models identified the correct product (CPE), versions (semver) and gathered remediation options. This data is available through our API within minutes after a CVE is published.
1
2
216
003random retweeted
Pre-orders have started shipping and getting to readers around the world! Whether you’re new to vulnerability research or sharpening an existing skill set, this book will show you how to think (and work) like a bug hunter. This book will teach you how to: ✅ Identify promising targets across codebases, protocols, and file formats.    ✅ Trace code paths with taint analysis and map attack surfaces with precision. ✅ Reverse engineer binaries using Ghidra, Frida, and angr. ✅ Apply coverage-guided fuzzing, symbolic execution, and variant analysis. ✅ Build and validate proof-of-concept exploits to demonstrate real-world impact. More than a toolkit, this is a window into how top vulnerability researchers approach the work. You’ll gain not just techniques but also the mindset to go deeper, ask better questions, and find what others miss. Use promo code ZERODAYDEAL at checkout to get 30% off! Buy now: 📘 No Starch: nostarch.com/zero-day 📘 Amazon: amazon.com/Day-Zero/dp/17185… #FromTheDayZeroToZeroDay #Cybersecurity #BugBounty #Hacking #VulnerabilityResearch #InfoSec #BookLaunch
6
21
139
8,809
003random retweeted
24 Jun 2025
We just launched our blog! blog.volerion.com/

ALT Happy Winnie The Pooh GIF by Leon Denise

1
2
3
196
003random retweeted
11 Jun 2025
Launching today! Volerion transforms raw CVEs into structured and instant insights #CVE #CyberSecurity #infosec
2
17
40
14,732