Someone found an RCE on my website yesterday.
CVE-2025-55182.
React2Shell.
I don't have a bug bounty program.
I never asked for a security assessment.
I woke up to a DM: "Hey I found a critical vulnerability in your site. I only ran the exploit to verify it worked. Here's my PayPal for the bounty."
Bounty?
I checked my logs.
Forty-seven requests to my RSC endpoint.
Something, something ... Prototype pollution payloads.
They used the GitHub script.
The one with 2,000 stars.
The one that runs id automatically "for verification purposes."
They spawned a shell on my production server.
uid=1001(nextjs) gid=65533(nogroup)
They took a screenshot.
They posted it on Twitter.
"Popped a Shell on a Live Website 🚀💀 #BugBounty #CVE-2025-55182 #YOLO"
They got 84781 likes.
My customers' data was on that server.
I asked them to delete the screenshots.
They said "I removed the domain name, you should be thanking me."
Thanking them.
For unauthorized access to my production infrastructure.
For running arbitrary commands on systems I own.
For posting proof of exploitation for clout.
They called it "responsible disclosure."
I called my lawyer.
They called me "ungrateful."
I called the FBI.
Now they're in my DMs explaining that "this is how the industry works" and I "don't understand pen testing."
A pen what?
I understand it perfectly.
I understand that running https://t.co/C6kmBequB5 against random websites isn't research.
I understand that "I removed the identifying info" doesn't undo the unauthorized access.
I understand that #BugBounty doesn't apply when there's no bounty program.
I understand that finding my site on Shodan doesn't constitute authorization.
Their followers are defending them now.
"Presumption of innocence."
"You don't know if it was authorized."
"The screenshots were redacted."
Three hundred people are calling me a bootlicker for reporting a crime.
Someone said I should be grateful they didn't deploy a cryptominer.
The bar is underground.
I just wanted to run a small Next.js app.
I didn't ask to be someone's proof-of-concept.
I didn't consent to being their "first"
I didn't sign up for an unscheduled penetration test from a stranger with a GitHub account.
There is no safe harbor for spraying public exploits at random websites.
There is no legal protection for "I was just verifying the vulnerability."
There is no ethical framework where unauthorized prototype pollution is a favor.
But sure.
Thank you for your service.
You found a CVE that was already public.
Using a tool someone else wrote.
Against a target that never authorized you.
And you posted about it on main.
For likes.
Hero.
thread of funny shit from browsing the 4chan source code. gonna tweet this live as i find stuff
okay admin.php i guess we are just raw dogging SQL in the big '25
Just Released an initial version of CutterMCP for @cutter_re , Inspired by @lauriewired's GhidraMCP.
Automate your reversing and malware analysis 😎
https://t.co/19rX87R1I1
Just back from an electrifying time at @nullcon Goa! 🌴 Met incredible minds, won cool prizes 🏆, and scored "First Blood" in a CTF challenge! Thanks to all who made this experience unforgettable. 🙌
#NullconGoa2023#infosec#Networking
433Screen-SignalHacker by luispl77
https://t.co/hUTJLoTuMQ
Full duplex 433 MHz Signal jammer, recorder, decoder and hacking multitool device based on ESP32 microcontroller and RFM69HW radios...
#SoftwareDefinedRadio#SDR#ESP32
The Indian coding youtube scene is so bad, all learning is directed towards cracking interviews.
No enthusiasm for computer science as a subject, all of them seem to be in the shorts, quantity over quality, clickbait bandwagon, like a typical content creator.
If you're interested in bluetooth low level hacking take a look at this cool project by Matheus Eduardo Garbelini (@MatheusGarbelin)
Active Bluetooth BR/EDR Sniffer/Injector: https://t.co/23zJgxEXvq
#bluetooth#esp32#espressif#hacking#infosec
YouTube has more than 38,000,000 channels.
Most are weird vlogs, TV show montages, music videos, and memes.
But if you’re interested in cybersecurity, these 8 channels will teach you more than a 4-year college degree:
Imagine getting your credentials phised by some ~$6 NFC antenna via a redirect ☠️ You can also HTML smuggle an .apk onto the device e.g. MDMCompanyUpdater.apk