Calling all researchers 📢
@agoda's program is now public on the HackerOne platform.
Help protect Agoda's customers' travel experiences and earn bounties up to $6K!
https://t.co/EJDBZq8ynd
#Happyhacking
Burp Suite Professional costs 475 dollars a year per seat.
A senior software engineer in Amsterdam built the open source replacement as a side project. He put it on GitHub for free. It has 10,569 stars.
His name is David Stotijn. The software is Hetty.
Here is what Hetty is.
An HTTP toolkit for security research. A machine-in-the-middle proxy that sits between your browser and the target. Every request and every response flows through Hetty. You can read them, search them, intercept them, edit them, replay them, and send them again.
This is the core loop of every web application security test ever performed. Burp Suite charges 475 dollars a year for it. Hetty does the same job for zero.
Here is the feature set.
A machine-in-the-middle HTTP proxy with full logs and advanced search. An HTTP client for manually creating and editing requests, and replaying any request you already proxied. Request and response interception for manual review, with full edit, send, receive, and cancel control. Scope support to keep your work organized to a single target. A web-based admin interface that runs in your browser. Project-based database storage so multiple engagements stay separate. A GraphQL service for programmatic access.
The installer is a single Go binary. Works on macOS, Linux, and Windows. No Java runtime, no enterprise license server, no machine fingerprinting, no telemetry.
Here is the price ladder.
Burp Suite Professional: 475 dollars a year per seat.
Burp Suite Enterprise: thousands per year, contact sales for a quote.
Burp Suite Community Edition: free, but throttled, no scanner, no project save, no intruder rate.
OWASP ZAP: free and open source, now owned by Checkmarx after a 2024 acquisition.
Hetty: zero. Forever. One binary. No account.
A pentester working full time pays Burp 475 dollars a year. A team of 10 pentesters pays 4,750 dollars a year. A bug bounty hunter who finds one vulnerability has already paid for Burp twice over.
Or they download a 30 MB Go binary written by a freelancer in Amsterdam and keep every dollar they earn.
David has not pushed a new commit in 16 months. The last commit was January 13, 2025. That is normal for a tool that is feature-complete. HTTP has not changed. The proxy still proxies. The intercept still intercepts. MIT licensed code does not expire when the maintainer takes a break.
Buy a domain. Find a bug. Cash a bounty.
PortSwigger took a free industry tool and put it behind a 475 dollar paywall. A freelancer in Amsterdam gave it back. On every platform. For zero dollars.
Your proxy. Your binary. Your bounties.
(Link in the comments)
🚨 Hackers found a way into Palo Alto’s GlobalProtect VPN without a password.
The flaw, tracked as CVE-2026-0257, lets attackers bypass PAN-OS authentication and establish unauthorized VPN sessions.
Palo Alto says it’s already being used in real attacks.
If you run GlobalProtect, check this now.
Details ➝ https://t.co/OSarZ4i9jF
OSINT is the foundation of every serious operation. Our OSINT training walks you through the tools, tradecraft, and investigative methods used by intelligence professionals worldwide.
https://t.co/tni26o97H6
@three_cube@DI0256@IamSmouk@co11ateral
Tilt automates the entire dev loop from code change to running Kubernetes pod, so you can focus on coding instead of manual rebuilds and redeploys.
- Watches files, builds container images, and updates your environment automatically
- Replaces manual `docker build && kubectl apply` workflows
- Provides best practice guides for HTML, NodeJS, Python, Go, Java, and C#
- Integrates with Kubernetes Slack community for questions and support
Explore it here:
https://t.co/YfApdbWnYk
10 MORE GITHUB REPOS YOU'LL WISH YOU FOUND SOONER.
Each one quietly destroys a paid app you probably still use. Save this.
1. Maybe Finance
Open source Mint and Copilot Money. Tracks every account, investment, and net worth chart in one dashboard.
Self-hosted. Bank-grade encryption.
Replaces YNAB ($109/year) and Rocket Money ($72/year).
https://t.co/loX7AeAlmi
2. Wireguard
The fastest, simplest VPN ever built. Lives inside the Linux kernel.
4,000 lines of code. Faster than OpenVPN and IPsec combined.
Replaces NordVPN, ExpressVPN, Surfshark.
https://t.co/CT815yy5U4
3. Inkscape
Professional vector design used by Tesla's documentation team and Disney animators.
Opens AI and SVG files. Runs on every operating system.
Replaces Adobe Illustrator ($240/year).
https://t.co/xPV3c1XO06
4. Audacity
The audio editor every podcaster used before Descript started charging $288 a year.
Multi-track editing, noise removal, mastering, all free.
Replaces Adobe Audition ($240/year).
https://t.co/0Anq57mWU4
5. Joplin
Open source Evernote with end-to-end encryption and full markdown support.
Syncs across Dropbox, OneDrive, or your own server.
Replaces Evernote Personal ($130/year).
https://t.co/9PbWf605HK
6. Kanboard
A minimal self-hosted Kanban board. No bloat. No AI features you didn't ask for.
Loads in under 500ms on a $5 VPS.
Replaces Trello Premium ($120/year per user).
https://t.co/GqZUuzKnn0
7. Nextcloud
Your own private Google Drive, Google Docs, Google Calendar, and Google Photos in one install.
Used by the German government and the European Parliament.
Replaces Google Workspace ($72+/year per user).
https://t.co/y2jPhEmPrR
8. Rallly
Doodle for grown-ups. Send a poll, pick a time, no signups for anyone.
The fastest meeting scheduler I've ever used.
Replaces Doodle Pro ($83/year).
https://t.co/9yOw9yRtMz
9. Standard Notes
End-to-end encrypted notes that sync across every device.
Two-factor auth, version history, offline mode.
Replaces Bear ($30/year) and Apple Notes lock-in.
https://t.co/B1Y4YE5ucx
10. OBS Studio
The streaming software every Twitch streamer and YouTuber on earth uses for free.
Records, streams, switches scenes, mixes audio. Pro-grade.
Replaces Streamlabs Ultra ($149/year) and Restream Pro ($192/year).
https://t.co/qrpbcHCm3Y
The thing keeping every subscription alive is the gap between what people know exists and what actually does.
Close the gap.
A teenager made $300,000 from Starlink.
Not by using the internet.
By turning Starlink satellites into a GPS system.
$180 hardware.
Claude-generated code.
350 sales.
The result?
A device that still works when GPS goes dark.
16 years old. 🤯
🔍 Found a handy tool for bug bounty hunters: Hacker-Scoper.
When you're dealing with massive recon output, one of the most annoying tasks is figuring out what's actually in scope.
Hacker-Scoper helps filter domains, URLs, IPs, CIDRs, and wildcard assets against bug bounty scope definitions, so you can spend less time cleaning data and more time hunting.
✅ Wildcard scope matching
✅ CIDR range support
✅ URL filtering
✅ Regex-based scopes
✅ Automatic scope detection for supported programs
Repo:
https://t.co/bFEF71wANk
Definitely worth checking out if your recon pipeline regularly produces thousands of assets.
#BugBounty #CyberSecurity #InfoSec #Recon #EthicalHacking
WifiForge 🔬🛠️🛡️ | Laboratorios Wi-Fi virtuales seguros
¡Practica hacking Wi-Fi sin necesidad de hardware físico caro!
WifiForge crea entornos Wi-Fi virtuales completos usando Mininet-WiFi y Docker. Te permite ejecutar herramientas como Aircrack-ng, Bettercap, Hashcat, Wifiphisher y más, de forma totalmente aislada y segura.
Ideal para aprender y practicar ataques Wi-Fi (WEP, WPA, Evil Twin, WPS, etc.) sin riesgo de afectar redes reales.
Solo úsalo en tus propios entornos o laboratorios autorizados. Cualquier uso contra redes ajenas sin permiso es ilegal.
#wifihacking #wirelesssecurity #pentest #redteam #ethicalhacking #ciberseguridad #offensivesecurity #docker #kali #opensource #lab
📶 𝗪𝗶𝗳𝗶𝗙𝗼𝗿𝗴𝗲 — 𝗪𝗶𝗙𝗶 𝗛𝗮𝗰𝗸𝗶𝗻𝗴 𝗟𝗮𝗯
• Built on mininet-wifi
• Simulates WiFi networks for testing
• No real hardware required
• Pre-configured attack labs
• Safe environment for learning WiFi attacks
⚠️ Not stable, use in VM only
Access Here 👇⬇️
https://t.co/XzlpoUYZlt
📶 Wi-Fi Security Testing on NetHunter 👀
In this reel, I’m exploring wireless security concepts using Kali NetHunter in a controlled lab environment to better understand how router settings can impact overall Wi-Fi security.
Many people never check their router configuration — but small settings can sometimes make a bigger difference than expected.
🧠 Understanding wireless security helps improve awareness, strengthen configurations, and build better habits for safer networks. 🔐
⚠️ Educational & authorized lab environments only.
💬 Comment “NETHUNTER” and I’ll send more details.
#KaliNetHunter #WiFiSecurity #CyberSecurity #InfoSec #Android
📶 Wi-Fi Security Awareness with Stryker
How secure is your Wi-Fi network, really?
In this reel, I’m testing a router with WPS enabled in a controlled environment to demonstrate why certain wireless settings can introduce unnecessary security risks.
🔍 Understanding how wireless networks are assessed helps improve awareness, strengthen configurations, and reduce exposure to common security issues.
Small settings can make a big difference when it comes to protecting your network. 🔐
⚠️ Educational & authorized testing only.
💬 Comment “WIFI” and I’ll send more details.
#WiFiSecurity #CyberSecurity #RouterSecurity #InfoSec #Android