Found a cool bug at Meta.
From misconfigured Grafana instance to R/W access on 507 private Meta repositories.
Wrote up the full chain here:
https://t.co/LYQ0prc68d
$157k bounty awarded by @metabugbounty
New write up: "I Came for the XSS, Stayed for the Police-Only Data"
Its technically nothing super fancy but I often think about what I saw there. Most bug bounty hunters wont learn a lot here but its somehow interesting whats out there.
https://t.co/OBSebA8DUd
Heyy @ELFiProtocol
There's a critical security vulnerability affecting your assets.
Please reach out ASAP or provide a channel for disclosure. Thanks :)
Excited to share my talk onsite at @BSidesDehradun on 11 January 2026 โ diving into how recon evolves from simple text files to production-grade systems.
๐ Introducing BYTEZ โ a Fireside Chat Series
BSides Indore ร India West HackerOne Club ๐ค
๐ Speaker: Sudip Shah (@kn1ght_yagami)
Security researcher, Facebook Bug Bounty contributor
๐ง Hosts: @ThisIsDK999 & @_venom26
๐ Dec 20
Join Discord ๐
https://t.co/gpHNC7GRd1
#Bytez
As part of our efforts at @Hacker0x01 India West Club, weโre launching Bytez โ a fireside chat series on security & real-world impact.
Inaugural guest: @kn1ght_yagami , known for deep Facebook Bug Bounty research across complex business logic, and high-impact disclosures.
Join the Discord for updates ๐
https://t.co/OpivyPTgHJ