1600+ regex patterns for detecting secrets, API keys, tokens, and passwords. 💀🔥
This open-source database can directly improve your secret scanning pipelines (TruffleHog, Gitleaks, etc.).
If you're doing AppSec seriously, this is worth integrating.
https://t.co/PeNzr9iD79
#AppSec #CyberSecurity #Infosec
I built FoxHound, a Firefox extension that gives any AI agent full control over your browser.
I needed this while hunting. There are bugs the egent can not properly exploit without using the browser. Clicking things, reading the DOM, replaying requests, checking cookies across containers, running JS on the page. So i built it.
The agent can navigate tabs, click elements, fill and submit forms, upload files, take screenshots, capture all HTTP traffic with full request and response bodies, replay and modify requests, read and write cookies and storage, intercept live requests, hook into postMessage traffic, WebSocket connections, route changes, console output, service workers, and more.
It also uses PwnFox containers so the agent knows which container each request came from. If you are doing multi account testing, everything stays separated.
Setup takes 2 minutes:
1. Install the extension: https://t.co/zp0L5sonlL
2. Run: npm install -g foxhound-mcp
3. Copy the config from the extension options page into your MCP client. Done.
It is free. Give it a try and if you find any issues or want to add anything, open an issue on the GitHub: https://t.co/XtmZfbZzcU
Autonomous bug-bounty framework for Claude Code — 40 specialist agents, exploit-chain builder, writeup search, and live HackerOne/Bugcrowd integration. https://t.co/RgAFn1JL3a
Celebrating 1 year with the client. Bugcrowd is doing good but client wants to celebrate 1 year relationship with the researcher. :). This is called long term relationship. hehe
Drop subdomains in
Get Gemini-enabled API keys out.
Automates HTML + JS crawling & AI access testing.
Bug hunters — this one’s for you 🔥
https://t.co/VhkJALEMnZ
Thanks to @trufflesecurity#BugBounty#bugbountytips
Automation of
https://t.co/JP65fk7JA7
0xJS is an AI-powered JS security tool;
- it can identify API keys, and other medium to critical severity secrets with high accuracy.
- also scans for potential security issues in JS i.e DOM-XSS, postMessage, URL redirect. e..t..c
- e..t..c; 0xJS v4.0 ( https://t.co/dfK8dxXdXL )
I just published a video demonstrating how a token scope misconfiguration can silently lead to privilege escalation, where a normal user login becomes an admin-capable session due to improper scope validation.
https://t.co/Ir93EIx71E