Borg
286 posts

Borg
@BorgHQ
Experts in Web2 & Web3 security for penetration testing, zeroday research, risk management. For inquiries, contact us at https://t.co/2mfEeQlbRO.
Null Byte Beigetreten Nisan 2022
97 Folgt3.3K Follower
Angehefteter Tweet

Another one!
We're slowly onboarding, let us know if you'd like to try it out!
alexander@a1exander
🏆Another win for Mjolnir: our autonomous agentic pentesting agent just earned $2,000 bounty from Yearn.fi! The bug: reflected XSS through the /api/vault/meta endpoint on the Yearn.fi frontend. Because wallets are often already connected on the webapp, the impact could have been severe; including potential loss of funds. Frontend security in crypto is not optional. Thanks to @yearnfi for a smooth dialogue and quick mitigation! Issue has been fixed, ref: github.com/yearn/yearn.fi…
English

We are slowly opening this up for early access.
Send us a DM if you're interested in hearing more!
alexander@a1exander
Our autonomous pentesting agent Mjolnir just got it's first finding confirmed and paid! @borghq
English

Very important reminder for everyone in the space.
Let us help you prevent this from happening to your company - borgsecurity.io
English
Borg retweetet

today @borghq's autonomous hacking AI discovered a **huge** vulnerability on defi protocol with $20B TVL.
the vulnerability could have lead to loss of funds, and was in fact related to web2 infrastructure rather than their smart contracts.
benchmarking is cool and all, but the real battletest for agentic pentesting is bug bounties and real world testing with humans in the loop.

English
Borg retweetet
Borg retweetet

the team just cracked the code for **actual** agentic pentesting.
we beat other agentic pentesting frameworks and mastered complex attack chaining in agents
@borghq @sjaluu @LORD_RIAN_

English

The annual audit is a expired methodology.
Actually securing a stack requires a live feed of continuous testing. If your testing doesn't match your deployment velocity, you’re just operating on a 364-day security lag.
Stop paying for compliance PDFs.
Your security should be as alive as your development
English










