We now have our monthly Dojo champions! 🏆
Massive congrats to d0x, Frozenk and twilightwounds for solving Deadbolt - you’ve earned a cool YesWeHack swag pack 🎁
Keep an eye on your mailbox 📬
⚔️ Haven't tried our challenges on Dojo yet? Join the fun: https://t.co/0yoDzOoCeV
Is @CaidoIO your favourite Bug Bounty tool?
Then good news: you can now access ALL your @yeswehack programs directly inside Caido!
Browse programs, view full details, and add assets/scopes instantly. Keep hunting without ever leaving your workspace.
👉 https://t.co/2m9pxpIPxo
If mastering open-source hacking is on your list, don’t miss this amazing content!
Our latest guide breaks down every technique clearly, from simple workflows to advanced #BugBounty methods 🙀
Start learning here 👇
https://t.co/q3DFX0Ikq8
Episode 2 of Becoming an AI Hacker is live. This time Ads (0xmoose) showed me how to actually steal data from AI chatbots: markdown exfil, zero click image rendering, even DNS exfil when markdown is blocked. I also have a challenge for you at the end 👀 https://t.co/6iheuXbO38
🇨🇺 En Cuba se llamó "Revolución Cubana"
🇻🇪 En Venezuela "Revolución Bolivariana"
🇳🇮 En Nicaragua “Revolución Sandinista”
🇨🇴 En Colombia “Pacto Histórico”
🇲🇽 En México "Cuarta Transformación"
Distintos nombres, pero el mismo resultado: dictadura, miseria y muerte ☠️.
Got my first duplicate on a private bug bounty program 🔁 Means someone else found it too — the bug was real. Back to hunting 🕵️♂️ #BugBounty#InfoSec#YesWeHack
🚀Visit the Bug Bounty Village: HackingHub x Caido x Bugcrowd at BSidesSF (March 21–22).
Workshops, high-value prizes, and a dedicated Web CTF🚩
#BSidesSF#BugBountyVillage
Hey, hunters! We just dropped a new deep dive on code analysis 💡 Our latest hunter guide covers advanced techniques such as taint analysis and CodeQL, demonstrated with real tools against a real target 👇
#BugBountyTips
https://t.co/q3DFX0Ikq8
CUBANOS GRITAN: «No queremos luz, queremos libertad»
Esto para cuando la prensa intenta lavar el rostro del régimen diciendo que la protesta es solo por falta de electricidad.
Estados Unidos empieza a liberar a los cubanos, mientras AMLO y Morena intentan mantenerlos oprimidos bajo la dictadura.
¡Que caiga el régimen tirano!
¡Viva la libertad para Cuba!
You’ve seen phpinfo.php in a pentest — but what if it’s not just a harmless info leak?
Most people dismiss it as a low-impact artifact. But I’ll show how chaining it with a specific misconfiguration can expose sensitive data, bypass protections, and create a path to escalation.
The video breaks down the exact steps to combine phpinfo.php with a common server-side flaw. You’ll see how this pairing can be weaponized in real-world scenarios — and why hunters often overlook it.
Check it out here: https://t.co/wZF0H9KSuB
Think you can spot the hidden flaw? 🤔
Remember, sometimes the most subtle inputs can lead to significant discoveries.
Write the solution in the thread below!
How to fix it?
1️⃣Strict Validation: Use .required() for every critical field in your schema.
2️⃣Explicit Logic: Don't assume absence is safety. Verify that the token exists AND is valid.
3️⃣Try/Catch: Always wrap sensitive functions like bcrypt.hash to prevent DoS.
🔐 Null Safety Nightmare: Did you know a simple unchecked null can let someone take over your account... or crash the entire server with ONE request?
No password. No token. Just a dumb mistake. 📷 😬Quick thread on a bug I dissected. #Cybersecurity#BugBounty 📷
All I needed was the victim's ID (usually easy to find in API responses or public profiles).
Request: POST /api/users/password/resetBody: { "id": "VICTIM_ID", "password": "hacked123" }
✅ Response:"Password updated successfully!" Full access