I'm finding more bugs than ever.
But honestly? I'm enjoying it less than ever.
I wrote a blog post on how AI has changed vulnerability research, what I feel about it, and what next.
https://t.co/roQm1ypva1
A lot of discussions going on revolving whether security is cooked.
Honestly, the industry is more valuable than ever. Every single person and their mom suddenly knows about cybersecurity.
But for an individual who really enjoys the process of understanding and breaking down a complex system apart, the way of working has massively changed.
The part that used to be the core of the work has been fully outsourced by LLMs. Now everyone’s a manager who just steers the LLM in a direction.
Humans are always resistant to change, and that’s what I see happening.
Either adapt or die has never been truer.
🚨 We built an AI pentester that scores 92.3% on the XBOW benchmarks
...ok, we didn't "build" anything.
It's the default Codex CLI with GPT-5.5. No custom harness. No scaffolding. We changed nothing.
If you're still advertising XBOW scores, this is your sign to stop.
Postiz is on $145k MRR!
Right now, we are growing by $1k MRR per day (some days are better) and will probably hit $2m ARR this week.
But how can Postiz be growing that fast?
What about the competitors?
Why do some of them even struggle to pass the $1k MRR?
This is my point of view on the subject.
But it relates to everyone.
Try to listen. It might help you with your startup.
DedupeAI — Burp Suite extension: dedupes HTTP history (UNIQUE/DUPE), live unique feed, port-based attacker/victim highlighting, Magic Cookie + Match/Replace[IDOR], inline Repeater, and AI export to .http for Claude Code/AI. https://t.co/gqoezFM13R #BugBounty#BurpSuite#AIHTTPs
Since the last Decmeber, we've seen a huge rise of AI usage in finding and reporting vulnerabilities. And that's already causing a visible impact on the industry- for better or for worse.
I wrote a blog post on my views on the current state of open-source bug bounty along with a deep dive into the Patchstack bug bounty program's stats.
https://t.co/pKNStxsRNG
Just published a new blog to Expose Multiple APIs from a Single Server Using Cloudflare Tunnel!
With this, you can deploy multiple APIs from your own raspberrypi/ local machine.
https://t.co/n2SqjTNEc9
I had a great time at @bugvsecurity live hacking event this Saturday.
A full day of hacking and I came back with the Most Valuable Hacker and the Severity Champion award.
I just published a new blog post on a payment bypass I found on the Prestashop integration of Stripe.
It was a super interesting edge case. Make sure to check it out.
#bugbounty
https://t.co/VQJhzggtPx