Everyone is using Claude Code in their bug hunting.
Almost nobody is using it well.
10 habits that separate "I tried AI" from "AI found bugs I'd have missed."
Thread 🧵
Last night i used dnsgen which is a great tool for subdomain permutation, but the features was limited and it was really slow, so i thought i have to create a tool by myself for same purpose,
https://t.co/vwfbXUYtQ6
#bugbounty
this is really an interesting attack,should be kept in mind.
another attack similar to this is:
1.send the req to change UR email to emA,save the otpA
(race condition): again send a req to change ur email to emB , on another request past the otpA to verify emB
**can be scaled**
Around 7 years ago, I started in security with pure curiosity and a lot of trial & error.
Today, I got to share that journey on a podcast with @SynackRedTeam 🎙️
Grateful for every opportunity that shaped this path.
🎙️Listen on Spotify: https://t.co/GepUSHmGdz
Don’t waste time chasing expensive AI tools. If you can’t build it, you don’t really understand it.
That’s where most beginners go wrong.
Everyone wants to use AI in cybersecurity, but very few actually learn what’s happening behind the scenes. They rely on tools, copy payloads, and stay stuck.
So I tried something different.
I fine-tuned a local AI model from scratch and trained it to generate smarter XSS payloads using cross-referenced datasets.
No APIs. No cost. Just a simple setup that actually helps you think beyond basic payloads.
If you’re serious about learning the real side of bug bounty, this is where you should start.
Watch here: https://t.co/OQ5xmPUFTl
🚨 Registration Open – @Hacker0x01 Bug Hunt 2026 (Qualifiers Round) 🇧🇩
The wait is over! Registration for the HackerOne Bug Hunt 2026 – Qualifiers Round is now live and will remain open till 25th October.
🔗 Register here: https://t.co/TfXnHe5HYa
#HackerOne#BugHunt2026
Just found an interesting behavior in Firefox that can be used for XSS:
If a response lacks the Content-Type header, Firefox renders it as text/plain.
But if the URL ends with an extension like .html, Firefox treats it as that.
#bugbounty#bugbountytips
This @bishopfox tool is next level! 🚀
Eyeballer uses AI to analyze screenshots and sorts them into categories based on appearance, including:
👀 Old-looking pages,
👀 Login pages,
👀 404 responses
👀 Web apps
👀 Parked domains
Get your eyeballs around this👇
$2,500 Bounties in GraphQL Hacking!
Started learning GraphQL security in Feb and picked a HackerOne program—luckily, it was all GraphQL! Found multiple bugs, including two high-severity ones which I wrote about.
Read here: https://t.co/m7YOM8z4Wo
the research paper is out:
Next.js and the corrupt middleware: the authorizing artifact
result of a collaboration with @inzo____ that led to CVE-2025-29927 (9.1-critical)
https://t.co/GZkbnr6o9H
enjoy the read!
Want to improve your security skills?
One Bug Per Day by @GalloDaSballo helps you learn a new vulnerability every day. A must-have resource for security researchers and developers 👇
https://t.co/zppxDqYf5I