What do you do when you find a vulnerability in a banking app and when you report it to them they say it's out of scope? I can't publish it without consent due to their terms and conditions. This vuln could be exploited to harm customers and they don't seem to care 🤷
I've recently been enjoying experimenting with AI Agents for penetration testing and bug bounty work. Feel free to read my blog post about it: https://t.co/3PXjsALnXF
🔍 My ultimate workflow for simple and easy JavaScript Analysis
⚡️ Comprehensive JavaScript analysis in offensive security, appsec testing, and red teaming wins.
Often you can find juicy hidden endpoints, parameters, & domains buried JS!
A thread 🧵 1/x
👇
Hackers are the unsung heroes that keep the Internet free, safe, and fun. When people think of hackers they usually think of cyber criminals. Nothing could be further from the truth: hackers' number one goal is to make the world a better place for all users.
#cybersecuritytips
@0xGradius Build relationships with everyone, ask questions, read internal docs, learn the workflows others use to get things done, find those gaps where you can help most. You're a friendly guy, I know you'll do great 👍
@IanColdwater If we as security professionals become the "department of no", those we are trying to protect will work around us. Instead we need to build relationships with them to understand their needs and help them do things as secure as possible
I just completed the @tryhackme Throwback room! I learned a lot while going through this and definitely recommend checking it out: https://t.co/qaBY9hgASp
@sogonsec @zeropointsecltd I can personally recommend the AD course from @SecurityTube with @nikhil_mitt https://t.co/55vRGkOhp4
I'm just finishing the CRTP course and it goes very deep into attacking and defending AD