SysTrack

30 posts

SysTrack

SysTrack

@SysTrack40

Hackerone Systrack

Beigetreten Mayıs 2025
93 Folgt1 Follower
Critical Thinking - Bug Bounty Podcast
One of our most highly anticipated episodes, enjoy it! ...Let's learn how to train our Claudes :p ty @rez0__ Building Claude Skills as a Bug Bounty Hunter, part 1
English
3
13
98
7.1K
SysTrack
SysTrack@SysTrack40·
@RezyDev Painful. Sorry for your loss
GIF
English
1
0
0
235
SysTrack
SysTrack@SysTrack40·
@Michael1026H1 That's a lot of bugs in a small space of time. Are YOU AI? Lol
English
0
0
0
41
Michael Blake
Michael Blake@Michael1026H1·
Seeing a lot of fear mongering about 'required' use of AI in bug bounty. My approach hasn't really changed in the last couple of years, yet I'm sitting with 17 high / critical bugs from the last 10 days. Currently the only thing I use AI for in bug bounty is programming.
English
12
6
156
8.7K
dawgyg - WoH
dawgyg - WoH@thedawgyg·
Got Chrome to redirect to abort() with my code execution poc testing... just about there for the real RCE payload 🤞🤞🤞
English
1
0
89
5.5K
SysTrack
SysTrack@SysTrack40·
@Behi_Sec Listen to Synth Wave to make it not boring
English
0
0
0
277
Behi
Behi@Behi_Sec·
Recon is boring. Reading the API docs is boring. Testing every single edge-case you know is boring. If you want to find bugs, do boring.
English
10
31
268
8.5K
SysTrack
SysTrack@SysTrack40·
@h4x0r_dz Congratulations on completing step one. We are looking for AI experts to help us move our agency forward with AI implementation in investigations and protection. If you have the skills to get this far, you have the skills to go further.
English
0
0
0
365
Behi
Behi@Behi_Sec·
Which platform is the best currently? H1, Bugcrowd or Intigriti?
English
21
0
65
10.7K
SysTrack
SysTrack@SysTrack40·
@HackingLZ I only figured out HOW to work because of LLMs.
English
0
0
0
12
Justin Elze
Justin Elze@HackingLZ·
Still waiting to meet the person who's actually working less because of LLMs. Everyone I know is just doing more. Faster PoCs, better R&D, RE goes quicker, all of it. nobody's clocking out early.
English
51
10
259
13.6K
SysTrack
SysTrack@SysTrack40·
@k_firsov 100% agreed. Even still, with advancements in Claude, it may reduce the attack surface, but it doesn't mean there will be no attack surface or no requirement for human logic in guiding Claude. These industries are going through changes, but we can adapt to the changes
English
0
0
1
83
Kirill Firsov
Kirill Firsov@k_firsov·
So much drama today, people losing their minds over this "new" feature from Anthropic, calling it the death of pentesting and bug bounties. Even stocks tanked for companies that have nothing to do with it. Why? Because most investors in this space don't know shit about security or what Claude AI actually dropped. We have been running vulnerability scans with various AI models, including Opus 4.6 for months already. This release is basically just a handy button to run what used to be a chain of prompts doing the exact same thing. Investors: Buy back in. Bug hunters and pentesters: relax and level up with it. Anthropic’s social media team: Bravo! This clickbait worked out!
Claude@claudeai

Introducing Claude Code Security, now in limited research preview. It scans codebases for vulnerabilities and suggests targeted software patches for human review, allowing teams to find and fix issues that traditional tools often miss. Learn more: anthropic.com/news/claude-co…

English
41
50
372
41.5K
SysTrack
SysTrack@SysTrack40·
@Random_Robbie I tried reporting stuff like that but it usually gets pushed back if you cant prove impact. Even theoretical impact gets pushed back in my experience.
English
0
0
0
148
Random Robbie
Random Robbie@Random_Robbie·
Are people really reporting stupid shit like file paths and rate limit and no csrf and getting paid??? I only try to report impactful stuff myself. Lowest I go is xss and last night I reported some banking creds but don't really want to cause it didn't feel impactful
English
5
1
31
3K
SysTrack
SysTrack@SysTrack40·
@my_stewpid @PeterSRWeb3 Appreciate that. None are disclosed yet and I haven't started writing things up publically yet. But maybe I'll start doing that.
English
0
0
0
30
PeterSR
PeterSR@PeterSRWeb3·
So many people jumping into bug bounties right now... I'm genuinely curious—what's the actual success rate? Like, what % of hunters actually land their first payout? Or consistently make money? Feels like 95%+ quit early with zero $$$ 😅 Thoughts? Stats? Your experience? 👇
English
21
1
105
10.9K
SysTrack
SysTrack@SysTrack40·
@ctbbpodcast @Hacker0x01 Fair play for doing this lads. Great interview, and for me, even though I'm new, this clears up a lot. Hopefully puts an end to the drama.
English
0
0
1
142
Critical Thinking - Bug Bounty Podcast
We said we'd sit down with @Hacker0x01 to ask all the hard questions, and we did! In the episode below you'll find everything you wanted to know about whether or not your reports are being used to train LLMs, ToS changes, plans for the future and more! youtu.be/Pa4wWv_ONjM
YouTube video
YouTube
English
2
8
65
19.9K
SysTrack
SysTrack@SysTrack40·
@0xTib3rius Lol. Can I buy this demo video with resell rights on the video?
English
0
0
0
103
Tib3rius
Tib3rius@0xTib3rius·
I am about to COMPLETELY disrupt the cybersecurity industry...💀💀💀 Presenting the Continuous Reasoning AI Pentester! Multiple AI agents running every security tool under the sun against your environment, at record speeds. Full pentests achieved in less than AN HOUR. Zero human input. One hundred percent success.
English
200
292
2.7K
246.9K
H4x0r.DZ 🇰🇵
H4x0r.DZ 🇰🇵@h4x0r_dz·
Looks like HackerOne’s (the scam bug bounty platform) security budget got hacked first. Critical bounties went from $25,000 to $15,000. Guess critical bugs aren’t that critical anymore. lol
H4x0r.DZ 🇰🇵 tweet media
English
18
7
267
27.9K
spaceraccoon | Eugene Lim
spaceraccoon | Eugene Lim@spaceraccoon·
ICYMI: I created an LLM-powered tool to detect CVEs before they're even published - and it's now powering vulnerabilityspoileralert.com. This is a simple GitHub page statically generated using vulnerability-spoiler-alert-action. Check out the backtest findings at github.com/spaceraccoon/v… and let me know what you think the hit rate is! I'm running this open-source vulnerability intelligence project using a personal API token, but maybe @AnthropicAI... or @OpenAI might want to support this? 👀
English
12
37
242
20.7K