Just caught Deepseek V4.1 flash using the expression “load-bearing”.
Anthropic’s claims that Deepseek distills from their models might not be that wrong after all 🙃
Some time ago wrote an article where I showed the easiest to find Web Application Bug of 2026.
I notice that a lot of people in the Bug Bounty and Pentesting world are still neglecting this bug and missing out on bounties 💸
Check it out
https://t.co/JuvEBsIMdQ
I was looking for bugs in a web target and saw a promising Employee-only endpoint.
5 minutes later, I managed to get access to it, and when I noticed how critical it was, I reported it and got a very generous reward 💰
Learn how I did it
https://t.co/XKCHNivAoY
I was looking for bugs in a web target and saw a promising Employee-only endpoint.
5 minutes later, I managed to get access to it, and when I noticed how critical it was, I reported it and got a very generous reward 💰
Learn how I did it
https://t.co/XKCHNivAoY
Bug Bounty is Evolving 🧬
Are you still hunting like it's 2024?
My latest article is a Deep Dive into the Bugs you should be hunting in 2026.
If you value high-quality writeups (without AI slop) check it out!
https://t.co/HB5CNph6Sw
Some time ago wrote an article where I showed the easiest to find Web Application Bug of 2026.
I notice that a lot of people in the Bug Bounty and Pentesting world are still neglecting this bug and missing out on bounties 💸
Check it out
https://t.co/JuvEBsIMdQ
Some time ago wrote an article where I showed the easiest to find Web Application Bug of 2026.
I notice that a lot of people in the Bug Bounty and Pentesting world are still neglecting this bug and missing out on bounties 💸
Check it out
https://t.co/JuvEBsIMdQ
I was looking for bugs in a web target and saw a promising Employee-only endpoint.
5 minutes later, I managed to get access to it, and when I noticed how critical it was, I reported it and got a very generous reward 💰
Learn how I did it
https://t.co/XKCHNivAoY
With what i've observed lately, hacking manually beats AI completely… the statement "Hacking with AI is easy money" is completely wrong and overstated.
You can apply both, but make sure to be exceptionally strong with manual hacking.
I was looking for bugs in a web target and saw a promising Employee-only endpoint.
5 minutes later, I managed to get access to it, and when I noticed how critical it was, I reported it and got a very generous reward 💰
Learn how I did it
https://t.co/XKCHNivAoY
Here is another fun activity you should try this weekend.
Study some LLM bugs.
AI security will soon be required in every security job because AI is literally everywhere.
And here is a great database to learn from - like Solodit but for LLM bugs. 🫡
https://t.co/uet0Qdyohw
I was looking for bugs in a web target and saw a promising Employee-only endpoint.
5 minutes later, I managed to get access to it, and when I noticed how critical it was, I reported it and got a very generous reward 💰
Learn how I did it
https://t.co/XKCHNivAoY
I was looking for bugs in a web target and saw a promising Employee-only endpoint.
5 minutes later, I managed to get access to it, and when I noticed how critical it was, I reported it and got a very generous reward 💰
Learn how I did it
https://t.co/XKCHNivAoY
I was looking for bugs in a web target and saw a promising Employee-only endpoint.
5 minutes later, I managed to get access to it, and when I noticed how critical it was, I reported it and got a very generous reward 💰
Learn how I did it
https://t.co/XKCHNivAoY