Part 2 of one of our craziest episodes so far, with an insane amount of tips you can start applying right now on every target you hack on, thanks @brutecat for sharing everything with the community!
Episode 178, part 2
#bugbounty isnt dead. Its actually just fallen victim to an unprescedented unrelenting denial of service attack. Classic resource exhaustion
I think everyone wants to fix it with neat logic tricks, code, and bots. Which can help. But maybe the effective thing is to actually increase the exhausted resource(s) 🤷🏼♂️
Tried Kimi 2.6 LLM Agent Swarm. Looked promising at first, but its another misleading marketing SCAM.
Advertised as "300 Agents Swarm", it does not have capability launching 300 parallel sub agents! It only reserves 300 slots for 4-6 parallel agents at the time...
Github knew for hours, they delayed telling you and they wont be honest in the future. what an amazing run, its been an honor to play around with the cats over the past few months. #teamPCP#github
Here’s the sauce:
- agent md file with lots of disclaimers about how it’s approved testing
- a bunch of hacking skills
- /goal find a crit on target . com
That’s literally 90% of the way there and enough to blow anyone’s mind who hasn’t been convinced yet.
Starting June 15, paid Claude plans can claim a dedicated monthly credit for programmatic usage.
The credit covers usage of:
- Claude Agent SDK
- claude -p
- Claude Code GitHub Actions
- Third-party apps built on the Agent SDK
I got a CVE for LFI in Adobe Magento!
Back in Jan, the team at @AutonomousCyber's let me give them targets for their hackbot FUZZ-E to look at. It also found 2x zero days in Angular, which I'll post on later.
With 1 run overnight, it found vulns in wildly hardened projects.