todayisnew

618 posts

todayisnew banner
todayisnew

todayisnew

@codecancare

May you be well on your side of the screen.

Ontario, Canada Joined Mart 2014
331 Following23.6K Followers
todayisnew
todayisnew@codecancare·
@rez0__ So your saying vb6 and text files are not going to cut it ;) great work looks really amazing, I’ve folded in and training as well, it’s automation with intelligence. Templates / tools / scripts are no longer hard coded, they are clean adapting prompts that well are awesome :)
Niagara Falls, Ontario 🇨🇦 English
0
0
2
147
Joseph Thacker
Joseph Thacker@rez0__·
It is hard to communicate how much bug bounty has changed due to AI in the last 2 months: not gradually and over time in the "progress as usual" way, but specifically this last December. There are a number of asterisks but imo coding agents basically didn't work for security research before December and basically work since - the models have significantly higher quality, long-term coherence and tenacity and they can power through large and long hacking tasks, well past enough that it is extremely disruptive to the default bug bounty workflow. Just to give an example, over the weekend I pointed Claude Code at a new program's scope and wrote: "Here are the target domains. Enumerate subdomains, grab all the JavaScript bundles, run the full analysis pipeline (endpoints, secrets, source-sink tracing, postMessage handlers), fuzz the discovered paths, spider the authenticated surface, check for IDORs on user APIs, test any interesting GraphQL endpoints, and write up an HTML report of everything you find." The agent went off for ~30 minutes, ran into multiple issues (auth failures, WAF blocks, malformed responses), researched solutions, resolved them one by one, analyzed the JS, fuzzed endpoints, tested access controls, and came back with the report. Two confirmed vulnerabilities and a handful of interesting leads. I didn't touch anything. All of this could easily have been a full weekend of manual work just 3 months ago but today it's something you kick off and forget about for 30 minutes. As a result, bug bounty hunting is becoming unrecognizable. You're not manually clicking through Burp Suite and hand-testing parameters one by one like the way things were since this industry started, that era is over. You're spinning up AI agents, giving them targets *in English* and managing and reviewing their output in parallel. The biggest prize is in figuring out how you can keep ascending the layers of abstraction to set up long-running orchestrator agents with all the right skills, memory and instructions that productively manage multiple parallel hacking instances for you. The leverage achievable via top tier "agentic engineering" for security research feels very high right now. My friends and I have been building out custom skill libraries for Claude Code - things like JS static analysis pipelines, authenticated fuzzing, IDOR testing frameworks, GraphQL introspection - and sharing them with each other. Each person's agent gets better as the collective skill set grows. We're finding more bugs in a week than we used to find in a month. It's not perfect, it needs high-level direction, judgement, hacker intuition, oversight, iteration and hints and ideas. It works a lot better in some scenarios than others (e.g. especially for targets with thick JavaScript clients where you can verify findings with a curl command). The key is to build intuition to decompose the target just right to hand off the recon and testing parts that work and help out around the edges with the creative exploitation. But imo, this is nowhere near "business as usual" time in bug bounty.
Andrej Karpathy@karpathy

It is hard to communicate how much programming has changed due to AI in the last 2 months: not gradually and over time in the "progress as usual" way, but specifically this last December. There are a number of asterisks but imo coding agents basically didn’t work before December and basically work since - the models have significantly higher quality, long-term coherence and tenacity and they can power through large and long tasks, well past enough that it is extremely disruptive to the default programming workflow. Just to give an example, over the weekend I was building a local video analysis dashboard for the cameras of my home so I wrote: “Here is the local IP and username/password of my DGX Spark. Log in, set up ssh keys, set up vLLM, download and bench Qwen3-VL, set up a server endpoint to inference videos, a basic web ui dashboard, test everything, set it up with systemd, record memory notes for yourself and write up a markdown report for me”. The agent went off for ~30 minutes, ran into multiple issues, researched solutions online, resolved them one by one, wrote the code, tested it, debugged it, set up the services, and came back with the report and it was just done. I didn’t touch anything. All of this could easily have been a weekend project just 3 months ago but today it’s something you kick off and forget about for 30 minutes. As a result, programming is becoming unrecognizable. You’re not typing computer code into an editor like the way things were since computers were invented, that era is over. You're spinning up AI agents, giving them tasks *in English* and managing and reviewing their work in parallel. The biggest prize is in figuring out how you can keep ascending the layers of abstraction to set up long-running orchestrator Claws with all of the right tools, memory and instructions that productively manage multiple parallel Code instances for you. The leverage achievable via top tier "agentic engineering" feels very high right now. It’s not perfect, it needs high-level direction, judgement, taste, oversight, iteration and hints and ideas. It works a lot better in some scenarios than others (e.g. especially for tasks that are well-specified and where you can verify/test functionality). The key is to build intuition to decompose the task just right to hand off the parts that work and help out around the edges. But imo, this is nowhere near "business as usual" time in software.

English
27
56
564
84.2K
todayisnew
todayisnew@codecancare·
@Arl_rose Thanks for the kindness, support and shared moments over the years :) Hope your next adventure brings you more joy and opportunities :)
English
1
0
7
834
Ariel Garcia
Ariel Garcia@Arl_rose·
After almost seven years, my journey at HackerOne comes to an end today. This has been one of the most impactful experiences of my life, and I wanted to share a bit more about the ride. It all started in 2018. I had a dream of bringing a Live Hacking Event to Argentina after seeing the magic of the community in Las Vegas. I am forever grateful for the trust placed in me back then. Someone took a chance on a random guy from Argentina and made my hire happen, and I wouldn't be where I am today without that shot. In the years since, I have been lucky enough to build things from the ground up. I was tasked with building the pentest community from scratch when we launched the product, and seeing it grow into a home for hundreds of professional pentesters has been incredible. My biggest passion project was always focused on a worldwide hacking competition. My early pitches for a regional tournament eventually evolved into building a global network of hackers instead. We started that program with just seven people. Today, I leave a network of 90 ambassadors across 45 countries. That network finally allowed me to execute the Ambassador World Cup. Watching that tournament evolve into a global phenomenon that paid out 2.4 million dollars in its latest edition was a dream come true. From the finals in my hometown of Buenos Aires to the trophy presentation in Dubai, seeing hackers find their first bugs through this program has been the highlight of my career. After 20 Live Hacking Events as an employee, traveling the world and meeting the community in person kept my passion alive for years. None of this was a solo effort. I was only able to be creative because my team was the best in the business and I was given the room to run. Thank you to the global community of hackers and the rockstars on the community team for being such a massive part of my life. I am moving on to a new chapter to do some fun stuff. More to come on that soon. Thank you for everything and stay in touch!
English
26
1
195
9.4K
todayisnew
todayisnew@codecancare·
@the_IDORminator @rez0__ Thanks for the kind words, and prayers :) hope life goes well on your side as can be :)
Kitchener, Ontario 🇨🇦 English
1
0
9
1.4K
the_IDORminator
the_IDORminator@the_IDORminator·
@rez0__ @codecancare Oh sorry to hear that man, will keep in our prayers. Yea my bad, I used to go by zwink on the platform :)-
English
1
0
12
2.1K
the_IDORminator
the_IDORminator@the_IDORminator·
I find it fascinating that hackers are willingly uploading their payout emails which contain PII to that #bugbounty.forum site just to validate their payments. Imagine the server scrapes your name, email, and other data while it "verifies" it. Make good decisions 😜
English
7
2
91
20K
todayisnew
todayisnew@codecancare·
@the_IDORminator @rez0__ Oh Hello ;) getting back at it, some health challenges for some loved ones took priority to support them last year or so. You look like you’ve been doing some awesome things yourself :)
Kitchener, Ontario 🇨🇦 English
1
0
17
1.9K
the_IDORminator
the_IDORminator@the_IDORminator·
@codecancare @rez0__ Its the Bugcrowd leaderboard guy!! Hello @codecancare Ive seen your face everytime I load the leaderboard for 5 years 🤣 You still hacking these days?
English
2
0
14
2.4K
todayisnew
todayisnew@codecancare·
@Hack_All_Things Your kindness, fairness, and sense of humour still echos out in all your connections :) thanks for sharing some of those precious moments with me and my family :)
todayisnew tweet media
English
0
0
9
673
Roy Davis
Roy Davis@Hack_All_Things·
Peace out world. Best wishes to all. ALS has won this battle, but hopefully not the war!
Roy Davis tweet media
English
131
59
1.6K
146.7K
todayisnew
todayisnew@codecancare·
@mcipekci You did great :) bug hiding in plain site in a popular program great use of your skills with AI helping to do some of the work :)
Kitchener, Ontario 🇨🇦 English
2
0
18
1.9K
Mustafa Can İPEKÇİ
Mustafa Can İPEKÇİ@mcipekci·
Collaborations make bug bounties more fun. Recently, @codecancare found a potential SQL injection on a target and asked me to check it. The SQL injection was in the URI, as the backend used direct input, treating "+" as normal instead of a space. I manually exploited it with a simple case-when payload on string concatenation: (case when 1=1 then '5' else (select 1 union select 2) end) If false, it returns two rows in the subquery, causing a DBMS error. I exploited it using Burp's Intruder with a cluster bomb technique. On a Synack engagement, I’d provide the Intruder configuration for triage, but since it wasn’t, I tested SQLmap. It failed, even with tampers like between and equal2like. I created a Python script using Gemini Pro. After it rejected prompts for ethical reasons, like dumping data, I rephrased to "fetching," and it worked. The script mimics SQLmap’s functionality: gist.github.com/mcipekci/80fbe… This shows how to exploit similar cases and create PoC scripts using AI efficiently. Unlike SQLmap’s numerous requests, this script is leaner and more robust. #bugbounty #bugbountytips
English
9
28
242
19.3K
Roy Davis
Roy Davis@Hack_All_Things·
Friday @Zoom Bug Bounty researcher spotlight on @codecancare (todayisnew). A top tier hacker withover 240 valid reports submitted, including 8 critical findings! Thank you Eric for your great work and gracious professionalism!
Roy Davis tweet media
English
3
2
146
75.5K
todayisnew
todayisnew@codecancare·
@Lordnilrac I think I found your wallet if I can get it back to you
Waterloo, Ontario 🇨🇦 English
0
0
0
184
Jenish Sojitra
Jenish Sojitra@_jensec·
Last week, I achieved a total of $500k+ bounty reward from single @Hacker0x01 program. Statistics: Timeline: 2 Years. Total Reports: 359 Valid Reports with Bounty: 280 Duplicates: 22 Critical: 23 High: 88 Medium: 168 Low: 69 Max Reward: $7k Lowest Reward: $150 Improper Access Control/Authentication Issue - 32% Improper authorization/BAC/IDOR - 25% Information Disclosure - 13% Injections- 8% XSS(Stored) - 6% Others - 14% Web Portals - 70% Mobile Apps API - 16% Documented API - 6% CIDRs/IPs - 6% Code review analysis- 2% #BugBounty
Jenish Sojitra tweet media
English
68
64
1.2K
54.4K
Hussein Daher
Hussein Daher@HusseiN98D·
Starting off 2025 with some cool vulns. Gg everyone 🌙 Zero automation for me. Cc @Bugcrowd
Hussein Daher tweet media
English
15
2
258
12.3K
todayisnew
todayisnew@codecancare·
@Hack_All_Things Or x number of valid reports unlocks different scope, that way maybe more fragile scope only getting looked at by a smaller sub group :)
Kitchener, Ontario 🇨🇦 English
0
0
5
784
todayisnew
todayisnew@codecancare·
@Hack_All_Things Maybe open triage for the event a month earlier? If you get a x valid reports triaged comes with free travel / accommodations? No valid bugs get the lesser package to participate remotely maybe? That way only paying for travel for those who you know already bring value? :)
Kitchener, Ontario 🇨🇦 English
1
0
10
1.1K
Roy Davis
Roy Davis@Hack_All_Things·
If Zoom were to host an In-Person Live Hacking Event in Denver Colorado (USA) sometime over the Summer of 2025, during which over $500,000 in bounties were up for grabs, would you be willing to cover your own travel expenses?
English
27
12
104
19.8K
todayisnew
todayisnew@codecancare·
@ncookie_eth looking to get in touch with you if can send a dm, pretty urgent ncukxxx@xxx.com
Kitchener, Ontario 🇨🇦 English
0
0
0
238
todayisnew
todayisnew@codecancare·
Thank you, @Hacker0x01, for the opportunity and support, and to everyone who has kindly collaborated with me over the years. Wishing everyone peace and joy this holiday season on your side of the screen :)
Marco (@jmo740)@jmo740

Congratulations @codecancare The king of automation has reached over 200,000 reputation points on @Hacker0x01 🔥 Eric you are doing a great job 🪲

Kitchener, Ontario 🇨🇦 English
12
7
336
26.1K
todayisnew
todayisnew@codecancare·
@theSpaghettiSec @Hacker0x01 Thanks for the kind words :) and the collabs from you and all others to reach the milestone :) hope everyone can find some peace in there own way over this holiday season :)
English
4
2
99
4.7K
Marco (@jmo740)
Marco (@jmo740)@jmo740·
Congratulations @codecancare The king of automation has reached over 200,000 reputation points on @Hacker0x01 🔥 Eric you are doing a great job 🪲
Marco (@jmo740) tweet mediaMarco (@jmo740) tweet media
English
5
6
258
36.3K