I do the hacks. He/him. Building and hacking stuff at @OphionSecurity

Joined August 2016
334 Photos and videos
Every critical I find in major corp has been through the most obscure feature that is annoying as hell to setup. It never ceases to give.
The harder the configuration, the more the bugs. I used to give up when something was very annoying to setup, but it attracts me more now. Apparently, almost everyone avoids those, which leads to really simple yet impactful findings :P
1
4
38
3,033
Hacking with AI recently has been fun. Here is couple of things I did recently: - Parsed multiple JS files within seconds after identifying a target domain. Used the parsing data to find a critical vulnerability. - For a different program, used mixture of redress, radare2 and GPT-4o to reverse engineer a pretty large golang based server. The more I prompt, the more I am convinced automating hacking with AI is the future. #aihacking #hackbot #LLM
2
9
1,364
getting ready to hack and send criticals
1
1
801
We are doing #VibeSecurityForAI If you are an AI startup (pre-seed or seed ) we will test your application for free. We are doing this only for next two weeks. We are hackers who have hacked major companies like Zoom, AWS, Amazon, Google, banks and more. DM me or contact us @OphionSecurity. #AISecurity #vibecoding #pentest #securityassessment #vibesecurity
2
1
1,030
Presenting on some fun stuff with @OphionSecurity this year at @_kernelcon_ and @bsidesseattle. Come for the talk, stay for the vulnerabilities. #vulnerabilities #bugbounty #attacksurfacemanagement
2
1
1,077
Been trying out Cursor for the last few days with prompts generated through deep research via ChatGPT and Grok, it is definitely a game changer. I have deployed apps that I have wanted personally within hours. ◦ AI aided development is future. ◦ Security is still under-development. Just #vibecoding and deploying will cost in long term. ◦ SaaS mills that deploy what users want within 24 hours is going to be a future combined with #ai agents for sales. (imagine @levelsio on steroid pushing apps out every hour)
4
804
Uranium238 retweeted
9 Mar 2025
🚨 New blog alert! I recently "compromised" a threat actors Telegram based C2 channel, that was used for exfiltration of stolen data from the Nova infostealer. The threat actor stupidly tested their infostealing malware on their OWN production "hacking" box.... (1/3)
5
40
243
43,957
taptastic.app/?score=10&patt… I reached level 10 in Taptastic! 🎮 Final speed: Super Fast Tiles: 9 The pattern that defeated me: 🟥 🟨 🟨 🟥 🟦 🟦 🟦 🟥 🟨 🟩 🟨 Can you beat my score? #Taptastic
1
529
Vibe coded a security script to open source for a future talk. I love AI. #security #GenAI #LLMs
1
2
572
Vibe coded so much: I did not even write a single piece of code. It did all the heavy lifting.
421
Uranium238 retweeted
1 Mar 2025
update! @cursor_ai is donating me $50,000 USD for my efforts with the todesktop vulnerability
28 Feb 2025
how to gain code execution on millions of people and hundreds of popular apps and of course, firebase was (partially) the cause kibty.town/blog/todesktop/
147
53
2,892
315,069
Uranium238 retweeted
North Korea stole $1.4billion by injecting JavaScript through an AWS S3 bucket to spoof the UI interface during a transaction? It's almost like the entire infosec industry is focusing on hyperbolic amplified APT threats that are "cool" rather the stark realities confronting us.
91
876
9,333
675,157
Announcing: Ask Us Anything Security - A free security advisory for startups Security often gets pushed to the back burner at startups until something breaks or a big deal requires it. But what if you could get expert security guidance without the overhead? At Ophion Security, we have worked with startups and large enterprises to secure their products, cloud environments, and compliance posture without slowing down growth. As part of that mission, we’re offering free security advisory ask us anything, and we’ll personally reply with actionable advice. ✅ Worried about SOC 2, ISO 27001, or customer security questionnaires? ✅ Unsure if you’re protecting customer data correctly? ✅ Need guidance on securing your cloud infra, SaaS stack, or engineering workflows? ✅ Question about getting the right pentest done and what should be in scope? Drop your security questions here, and we’ll respond within 24 hrs, no strings attached: forms.gle/UtFbbD3m7Lbs78SY6 #startupsecurity #growth #founders #security #TechStartups #CloudSecurity

1
556

ALT Ah Shit Here We Go Again GIF

349
I will be attending @CactusCon this weekend! I will have some stickers, and swags dropping around the con area. #cactuscon13
1
386
Complete your security reviews faster while building your product. Contact us today to learn more.
Endless security reviews, questionnaires, and compliance can be a nightmare when selling to enterprises. 🛡️ What if you could handle it all in one platform? Pentests, Questionnaires, & more. Check it out: ophionsecurity.com/use-case/… #Cybersecurity #SaaS #SecurityCompliance
2
831
At the rate “AI code editors” have popped, I wanna see these code editors writing code for new code editors startups.
3
977