Got invited by @msftsecresponse to an exclusive, invite-only researcher experience at Black Hat USA 2026 in Las Vegas.
Honored to be part of the security research community and excited to connect with top researchers and the MSRC team.
#CyberSecurity#BugBounty#MSRC#BlackHat
Huge thanks to @msftsecresponse for the bounty
Had found a reeeeeaaalllllyyy coool bug in Microsoft. The chain on this one was wild.
Canโt wait for the responsible disclosure to clear so I can drop the writeup. Get ready for the deep dive.
#msrc#BugBounty#infosec#Microsoft
ุงูุญู ุฏููู ุญู ุฏุง ูุซูุฑุง
ู ู ุง ุชููููู ุงูุง ุจุงููู ุนููู ุชูููุช ู ุงููู ุงููุจ
Just got $$$$ from @EpicGames via @Hacker0x01. ๐ต๐๐
their team handled it fast and clean.
#bugbounty#HackerOne#EpicGames
A Broken Access Control scenario no one has talked about before.
Not a recycled bug. Not a misconfiguration.
A new access control logic pattern with real exploitation impact. ๐ฅ
Watch: https://t.co/Qola76vOdr
#bugbountytips#bugbountytip#bugbounty
Cross-Site ETag Length Leak
https://t.co/RYofmHVh6T
I just posted the author writeup for impossible-leak in SECCON CTF 14 Quals. As far as I know, this is a new XS-Leak technique! The ETag header can become a side channel :)