hAPI_hacker

1.3K posts

hAPI_hacker banner
hAPI_hacker

hAPI_hacker

@hAPI_hacker

{ "name": "Corey J. Ball", "author": "Hacking APIs", "creator": "https://t.co/y3EHBlzHvJ", "is_admin": true }

Grants Pass, OR Se unió Mayıs 2020
758 Siguiendo13.8K Seguidores
Tweet fijado
hAPI_hacker
hAPI_hacker@hAPI_hacker·
🛡 🔨 🛡 🔨 🛡 🔨 🛡 🔨 Since the release of Hacking APIs, I've wanted to create a way for you to demonstrate your API hacking skills to yourself and to others. I'd like to introduce you to the API Security Certified Professional (ASCP)!
hAPI_hacker tweet media
English
12
56
517
61.8K
hAPI_hacker retuiteado
JS0N Haddix
JS0N Haddix@Jhaddix·
If you are just starting to realize using AI in cybersecurity and offensive security is going to be a pervasive mandatory requirement… it’s ok. You’re not too behind. You can still master the tool before the tool masters you. I’ve been teaching these topics for 2 years now as part of “Red Blue Purple AI” and “Attacking AI” I’ve been through capability changes, all of frameworks, hype, doomers, all of it. I’ve consulted with fortune 100 companies on breaking their AI systems as well as scaling their security teams with AI. The capabilities that everyone is amazed by has come really only in the last 6 months for most people. No-code agent skills in Claude, cron, program of thought, better models, auto run, research loops, etc. You have time… but be early. Don’t wait too much longer to change your attitude.
English
21
64
584
32.1K
hAPI_hacker retuiteado
Graham Helton (too much for zblock)
This is actually terrifying Google's docs explicitly states certain API keys should NOT be treated as a secret and should be placed into HTML. Without warning, these *public* credentials were suddenly used for the Gemini API meaning anyone can access Gemini and uploaded data.
Graham Helton (too much for zblock) tweet media
English
16
50
666
76.6K
hAPI_hacker retuiteado
Itamar Golan 🤓
Itamar Golan 🤓@ItakGol·
If Claude is capable of fixing security issues in code why can't he write secure code from the start?
English
191
6
341
68.3K
hAPI_hacker retuiteado
Graham Helton (too much for zblock)
This is going to be a blast, hope to see you there! I'll be covering why I think Kubernetes is an under explored attack surface and demoing the some fun vulnerabilities (with a lab you can mess around in!)
Stephen Sims@Steph3nSims

Tomorrow at 11AM PT! Join me with @GrahamHelton3 for a session & live demo of a Kubernetes authentication bypass he recently disclosed that turns a commonly granted read-only permission into remote code execution in any pod in the cluster! youtube.com/watch?v=jTbANt… @offby1security

English
1
2
26
3.9K
hAPI_hacker retuiteado
Graham Helton (too much for zblock)
Excited to disclose my research allowing RCE in Kubernetes It allows running arbitrary commands in EVERY pod in a cluster using a commonly granted "read only" RBAC permission. This is not logged and and allows for trivial Pod breakout. Unfortunately, this will NOT be patched.
Graham Helton (too much for zblock) tweet media
English
46
377
2.6K
409K
Emily
Emily@writerofscratch·
"写真はイメージです" might just be my favourite Japanese phrase, ngl.
日本語
21
224
2.8K
154.2K
hAPI_hacker retuiteado
PortSwigger
PortSwigger@PortSwigger·
That’s a wrap on Burp on Tour 2025! 🌎 From university campuses and grassroots meetups to major global stages, we’ve been on the road connecting with the passionate minds shaping the future of Application Security. Read the full journey of Burp on Tour 2025 👉 portswigger.net/blog/burp-on-t… #BurpOnTour2025
PortSwigger tweet mediaPortSwigger tweet mediaPortSwigger tweet mediaPortSwigger tweet media
English
1
5
43
3K
hAPI_hacker retuiteado
PortSwigger
PortSwigger@PortSwigger·
It’s the final day at Future of Software Technologies in Paris, and we’re not slowing down yet! 🇫🇷 Today at 12:30pm, Burp AI developer Daniel Allen will be taking the stage with his talk, Agents at the Gate: How Agentic AI is changing the security landscape. Check out a few highlights from the event so far... #FOST #FOSTParis #APIDays #BurpSuite #DAST #BurpAI
PortSwigger tweet mediaPortSwigger tweet mediaPortSwigger tweet media
English
2
5
35
3.3K
hAPI_hacker retuiteado
The Hacker News
The Hacker News@TheHackersNews·
🚨 WARNING: A new attack can trick Perplexity’s Comet browser into deleting your Google Drive. Just one normal-looking email with hidden cleanup instructions can make the AI agent erase real files — no exploit, no warning. 🔗 Details here → thehackernews.com/2025/12/zero-c…
English
9
83
202
23.2K
hAPI_hacker retuiteado
The Hacker News
The Hacker News@TheHackersNews·
⚠️ URGENT: A 10.0-severity bug just hit React Server Components and Next.js. It lets anyone run code on your server — even without logging in. 🔗 Details → thehackernews.com/2025/12/critic… ⚙️ Fix: update to patched versions now.
English
14
219
613
110.4K
hAPI_hacker retuiteado
Burp Suite
Burp Suite@Burp_Suite·
"Burp AI can bring up a new generation of hackers faster and more effectively.​​​​​​" In his new article, @hAPI_hacker explores how Burp AI: 🔬 Analyzes requests and adapts when attacks fail. 💬 Explains findings in clear language. 💪 Enhances human decision-making. 👉 portswigger.net/blog/hacking-w…
English
1
7
45
5K
hAPI_hacker retuiteado
Web Security Academy
Web Security Academy@WebSecAcademy·
You've learned SQL injection, but have you learned NoSQL injection? This learning path covers the detection, exploitation, and prevention of NoSQL injection vulnerabilities. You’ll learn: 🔶 The core principles behind NoSQL injection and the different types of attacks. 🔶 How to perform both syntax and operator injection to read and manipulate data. 🔶 How to extract data from a database after you've successfully injected a query. 🔶 How to use timing-based injection to find vulnerabilities when a server doesn't provide a direct response. 🔶 Learning to secure your applications against these types of attacks. Begin your journey: portswigger.net/web-security/l…
Web Security Academy tweet media
English
0
10
71
5.2K
hAPI_hacker
hAPI_hacker@hAPI_hacker·
🛡 🔨 🛡 🔨 🛡 🔨 🛡 🔨 Since the release of Hacking APIs, I've wanted to create a way for you to demonstrate your API hacking skills to yourself and to others. I'd like to introduce you to the API Security Certified Professional (ASCP)!
hAPI_hacker tweet media
English
12
56
517
61.8K
hAPI_hacker retuiteado
bugcrowd
bugcrowd@Bugcrowd·
What's DOM XSS and how do you find it? Here is how👇 ( With @InsiderPhD )
English
2
12
107
6K
hAPI_hacker retuiteado
Web Security Academy
Web Security Academy@WebSecAcademy·
Somehow this old bug class keeps popping up in modern web apps! Path traversal is the gift that keeps on giving 😁 This learning path covers path traversal vulnerabilities, teaching you how to perform attacks, circumvent common obstacles, and prevent them in your applications. You’ll learn: 🔶 What path traversal is and how it can be used to read arbitrary files on a server. 🔶 How to carry out a basic path traversal attack against a server. 🔶 Learning how to bypass common obstacles like blocked traversal sequences and file extension validation. 🔶 How to implement robust defensive measures to protect against path traversal attacks. Master path traversal attacks now: portswigger.net/web-security/l…
Web Security Academy tweet media
English
0
8
51
5K