Claude Code went hunting blind – no hints 🧐
It mapped the app, tested multiple attack paths and found an impressive request smuggling bug 🔍
But proving impact? Still on the hunter 👀
Our guide to Claude Code for bug hunting 👇
https://t.co/kw5mrzikkL
If you run Claude Code, Cursor or Codex for security work, antigravity-awesome-skills is worth a look 👀
A whole library of installable SKILL.md playbooks, including a security pack: SQLi testing, broken auth review, SAST config & more.
👉 https://t.co/pA2k5Iq4YJ
#BugBountyTips #YesWeRHackers
What if the vulnerability is hiding inside the cache key? 🔑☠️
Catch @Brumens2 at the @BugBountyDEFCON for “Cache Key Injection: Smuggling Poison Through the Door.”
📅 Friday, August 7
⏰ 3:00 PM PDT
Expect collisions, cache poisoning, CPDoS, deception and stored XSS.
One village. Three reasons to stop by! 🎯
From 6–9 August, @yeswehack will be back in Las Vegas for @defcon 34, once again sponsoring @BugBountyDEFCON.
Here’s what we have planned 👇
🪙 ‘Payload Plz Reloaded’
Pick up a @yeswehack challenge coin at the village and create one polyglot payload capable of exploiting as many vulnerabilities as possible. The top three submissions will win exclusive prizes.
What happens in Vegas… gets discussed at @BSidesLV 🎰🐛
Want to talk Bug Bounty, swap hacking stories or simply say hello? Keep an eye out for @Brumens2 and @pwnwithlove!
And on August 4, join us at the BSides Las Vegas Happy Hour, proudly sponsored by YesWeHack 🍻
Want to get better at finding bugs in open source code?
Our practical guide walks through how to choose a target, analyse data flows and turn suspicious code into a validated vulnerability 🐞
Time to hack some code! 👇
https://t.co/hAQv3dO4t6
Finding a vulnerability is only part of a bug hunter’s job. Explaining it clearly can be just as challenging. 📝
@yassine_eal shares his Bug Bounty journey, the finding he’s most proud of and how he chooses programs to hunt 👇
https://t.co/3vokDJFbX2
“I could’ve rickrolled The World Cup” – a great title for some great research from BobDaHacker📺
Our latest hunter roundup also covers:
🔎 AI unleased across Google, by @brutecat
⚡ Zero-click sXSS in Next.js, by @zhero___
🍫 Poisoned PoCs, from us!
Read it 👇
https://t.co/HJ5uybCPQY
New #CTF challenge live on Dojo 🚩
The Hacker Club is accepting new members, but getting an invite is not so simple. Only approved email domains are allowed...
Can you bypass the restriction and join the club?
Go hack it 👉 https://t.co/ag8EtvTp7m
Ever wondered how to find WebSocket vulnerabilities while bug hunting? 👀
@amrelsagaei breaks it all down in a full video, from spotting potential issues to testing and exploiting them!
Watch it here 👉 https://t.co/I3Q7rHAlEG