You cannot reproduce an exploit AFTER patching it. Patching confirms the vulnerability — it doesn’t invalidate the original report.
RCE is universally critical. Dismissing it post-fix shows a broken triage process and complete disregard for researcher effort.
Responsible Disclosure? Apparently optional for some companies.
I reported a RCE to @alloyapp, demonstrated with a valid PoC by executing the id command and sharing the server-side output — clear proof of remote code execution.
#BugBounty#Infosec#ResponsibleDisclosure#RCE
Instead of acknowledging the severity, the company silently patched the issue by upgrading the vulnerable component and now asks me to “provide evidence again” to prove the vulnerability exists and is critical.
That’s not how security validation works.
Finally jumped on this Ai Red Team train and I am blown away by the results used and MCP Server to communicate to a simple C2 channel and asked for enumeration tasks, view file content and open an application all via the C2 what amazing results!
#redteam
HTTP is supposed to be stateless, but sometimes... it isn't! Some servers create invisible vulnerabilities by only validating the first request on each TCP/TLS connection. I've just published a Custom Action to help you detect & exploit this - here's a narrated demo:
Hi @GoWinstonAI,
I reported a few security vulnerabilities to your domain on September 28, 2025, but haven’t received any response yet. Could you please check the status of my submissions and provide an update?
A long time ago, i was using (Frogy Recon Tool) and the results were more than amazing
now its back as 2.0 and now i like it so much
https://t.co/RywgDZLrIg
by the amazing @iamthefrogy
Just want to share here if someone wants to check it
#bugbountytips#bugbountytip
@xss0r After changing card I got this error
Status code 59: Your payment could not be processed due to an authorization error. Please contactTeachable Support.
Reported a leak to @Zomato exposing 4000+ emails & 2000+ phone numbers of their users.
Zomato triager closed it as Informative, stating:
“Not an immediate threat”
“Wayback Machine invoice leaks are out of scope”
But…
Credentials ≠ Invoices.
Real data, real users, real impact
Credentials leaks can lead to account takeovers, phishing, SIM swap frauds & more.
Brushing it off as "archived invoice data" is a dangerous precedent.
Security isn’t just about scope docs — it’s about protecting users.
#bugbounty#infosec#responsibledisclosure
⚠️ Giveaway time! ⚠️ 👇
📢 Our new course "Attacking AI" will be Feb 27-28!
This two-day course equips security professionals with the tools and methodologies to identify vulnerabilities in AI systems. It's gonna be a BANGER.
Syllabus: https://t.co/cY9vcI7Z5y
We are giving away two seats this week!
⁉️How to enter the giveaway:
♻️ Repost this post = 2 Entries
🗣️ Reply = 1 Entry
❤️ Like = 1 Entry