quick reminder for anyone hunting blind bugs: https://t.co/QzZGLOjipz HTTP/DNS for SSRF and log4j → XSS payload for admin panel injection → SMTP for password reset enumeration all four in one place, free, no signup: #BugBounty#AppSec#Recon#CyberSecurity #EthicalHacking #SSRF #OWASP
Super excited to release our latest Broken Access Control (BAC) Masterclass on @hackinghub_io with 2 hours of content and almost 20 labs. I'm giving away 3 free seats to anyone who comments, reposts, and replies to this post. Drop a 🔥 below!
More info 👉🏼 https://t.co/g8gwo5vYGN
Triage Assist is designed to support faster, more consistent, and higher-quality vulnerability triage while keeping expert human judgment exactly where it belongs: at the center of the process.
In our latest blog, our Product Manager, Stijn Bogaerts, covers everything from…
🤔 What Triage Assist is
🚀 How it supports our triage team
👀 What it means for security teams, triagers, and researchers
🗣️ Why “human-in-the-loop” is more than a buzzword
And why shipping AI inside a production security platform is harder than it looks. As well as what’s coming next.
Read the full blog to learn what Triage Assist means for the future. 👇️
https://t.co/7KrzKESonu
I created a challenge based on one of my Google bugs worth $12,000. It is an OAuth misconf. I will drop a writeup for it soon, before that, give it a try & practice, it doesn't matter if u r capable of solving it or not, just click and start poking 🙂
https://t.co/lAW53dVyk5
Found a 1-click account takeover via postMessage. No phishing, no fake login page, just one click and a full-access token.
Wrote up the full breakdown and also gave the whole site a little revamp while I was at it.
https://t.co/piH3rZg9LN
Our first official Burp Suite extension is live! 🤠
Intigriti Quick Scope (IQS) fetches all your public & private programs directly from the Researcher API and auto-configures your Burp scope, and mandatory request headers with a single click! 😎
Get it now in the BApp Store! 👇
https://t.co/JBpmei2boq
i'm taking a pause from hacking to resume building https://t.co/H7tDJivomZ. i regret closing it down and I shouldn't of done it. everything will be back online EXACTLY as it was very soon and i've got some big plans for the future. and yes, that includes zseano methodology v2 ;)
We've just released a high fidelity scanner for CVE-2026-41940 (cPanel/WHM authentication bypass). All public PoCs so far lead to false negatives, and are not reliable. @SLCyberSec's research team's notes on this here: https://t.co/7gik0IY4Cl & tool here: https://t.co/RKoB6WaSQk
"I'm still not an automation guy...it's not my style." - @ozgur_bbh
Ozgur Alp joins WE'RE IN to share his views on AI and how he became a full-time independent security researcher: https://t.co/todSbWxK3V
One thing I’ve observed while doing bug bounty:
It’s not always about learning more tools or techniques. Often, the difference comes from how deeply you analyze a feature. The same endpoint, tested with different perspectives, can lead to completely different findings.
#bugbounty
We've launched a new @WebSecAcademy topic on exploiting AI-powered security scanners! Learn how to use indirect prompt injection to steal data, cause damage & trigger exploit chains!