Google is supposed to be impossible to hack.
@rhynorator found a $20K IDOR on the front page.
The kind of bug every hacker checks for.
This 1-node Caido workflow made their RPC traffic readable,
turning a crowded program into a private hunting ground.
@akita_zen@m359ah@PortSwigger Hahaha nice man π
Glad to hear u r doing well,AI stuff is getting crazy lately, so which service r u attacking nowadays?
Introducing nginx-poolslip, a fresh RCE for the the latest nginx release 1.31.0.
nginx-rift has been patched, but our security agent Vega has found a new 0 day.
We will release the full technical writeup with ASLR bypass 30 days after the patch on https://t.co/LAhOC5UHrp.
$14,337 Google Bug Bounty π€
Hacking Google Support: Leaking millions of customer records by Michael Dalton π€―π₯
π¨βπ» Michael Dalton (https://t.co/fmpfi56Mdf)
π https://t.co/zwLEQPXQV5
I pointed claude opus at chrome and told it to build a full v8 exploit for discord.
A week of back-and-forth pulling it out of dead ends. 2.3B tokens. $2,283 in API costs, and it popped a shell.
https://t.co/vwj9d33Bvq
Want to build AI Vulnerable environment in seconds?
π Introducing PromptMe-Lite - an enhanced fork of PromptMe with key improvements:
β¨ What's Different:
β’ Adds OpenAI API support alongside Ollama
β’ Redesigns some challenges to be fully exploitable without code/behavior modifications (e.g: LLM08)
β’ Removes heavyweight ML dependencies for faster deployment
π― Perfect for:
Security teams running CTF events or training programs needing flexible LLM deployment options
10 OWASP LLM Top 10 challenges. Production-ready. Open source. In seconds.
Get started π
https://t.co/yNWiyCAvZw
#AIRedTeam #LLMSecurity #OWASP #CTF
π¨ Live Hacking Event | Egypt @Hacker0x01 Club π¨
Weβre launching Desert Storm: Bug Bounty Challenge a two-phase live hacking event in collaboration with a private Hackerone program.
π₯οΈ Phase 1: Virtual hacking (2β16 February)
π Top 10 hackers qualify for the onsite finale
π Open to all skill levels
π― Real-world targets & exclusive rewards
Spots are limited. Registration closes 30 January.
π Register here: https://t.co/2vbXWOHqzX
#BugBounty #Hackerone #CyberSecurity #EgyptHackers #LiveHacking #Community #TogetherWeHitHarder
Many are asking if they can move their Next.js projects from Vercel to Replit?
Yes!
- Go to Import then GitHub
- enter repo URL
- Agent will take care of the rest
It will set up the dev and deployment environments!
For companies moving lots of work, happy to help + discount.
π The stage is set for the #AmbassadorWorldCup championship Finals! π
πͺπΈ Spain vs πͺπ¬ Egypt β Who will take the crown in DUBAI this May?
π¬π· Greece and π³π± Netherlands battle it out for 3rd place!
The world is watching. Who will rise as the HackerOne Ambassador World Cup Champions?