Fyi I started blogging about windows secure channel a while back, you could probably get a couple of bug bounties out of certificate chain building related code, its a big attack surface: https://t.co/pIIxMwyDna
Exploiting llama.cpp’s RPC Server - From Null Buffer to RCE Against PIE + Full RELRO + NX | CVE-2026-34159:
The vulnerability is a one-line logic bug in the RPC server’s tensor deserialization pipeline.
Youtube: https://t.co/7gcPGHd27g
Blog: https://t.co/POwWG9aZZ9
Every JWT writeup online covers 2–3 attacks and stops.
I got tired of jumping between 40 blog posts, so I wrote the whole thing. All in one place.
https://t.co/iCSzQ4GjcS
#infosec#appsec#bugbounty#websec#jwt
Cloud hacking tools for bug bounty hunters:
CloudFox
https://t.co/htfw49SLGM
Pacu
https://t.co/CXdO5YRnIG
S3Scanner
https://t.co/cIb5YdxfI8
Extra tools, not purely cloud but used a lot in this workflow:
Nuclei
https://t.co/UiXI7zZFT1
TruffleHog
https://t.co/lEqC1BzIyj
#BugBounty #CloudSecurity #Pentesting #InfoSec #EthicalHacking #CyberSecurity
If you're into bug bounty, this repo is gold.
A massive collection of real-world writeups categorized by vulnerability type, XSS, IDOR, SSRF, RCE & more.
Stop guessing. Study how real hackers actually find bugs 👇
https://t.co/qebk8UGu9T
#BugBounty #InfoSec #Hacking #Pentesting #CyberSecurity
Every pentester should have these in their toolkit 👇🔥
From Shodan to https://t.co/jroBP3BGxS, this list covers servers, OSINT, attack surface, code search & threat intel
Did I miss anything? Drop your favorite tools in the comments 👇
#BugBounty #CyberSecurity #Infosec #Hacking #Recon
All my write-ups are available soon and I'm gonna drop a breakdown on a presentation, which is still relevant in 2026. Check my GitHub https://t.co/VIGQ4r76WK for old write-ups and I will try to also post the bugs which I found most are state machine and business logic, not generic but high-value, high-impact.
Pwning TRUfusion Enterprise again: chaining a pre-auth SSRF (CVE-2025-32355), a default password, and a path traversal (CVE-2025-59793) to gain RCE.
#security
https://t.co/0VmQ6SaQZc
Static JS analysis just got smarter.
jsluice is a Go-based tool that parses JavaScript using ASTs to extract endpoints, secrets, and interesting artifacts — no noisy regex scraping.
🔗source: https://t.co/7eyaQjt337
Perfect for bug bounty hunters who actually read JS instead of just grepping it. 🔎⚡
If you’re serious about client-side recon, this deserves a spot in your toolkit.
#BugBounty #AppSec #JavaScript #Recon
I analyze thousands of bug bounty content items every month. Less than 5% makes it to the newsletter.
I distilled those curated selections down to the top 25 resources for 2026 and put them in this PDF. It includes the top platforms, tools, and people that consistently deliver high signal content.
Comment RESOURCES and I'll DM you the PDF for free. (Make sure your DMs are open)
#BugBounty
🍽 Resources: Beginners Guide to Learning about Dependency Confusion.
Guide: https://t.co/kQCkwYz85w
Blog 1: https://t.co/aG9hNeq5C5
Blog 2: https://t.co/RB2IKEzEdh
#infosec