Sabitlenmiş Tweet
Bounty Security
801 posts

Bounty Security
@BountySecurity
Offensive Web Application Security Software
Katılım Mayıs 2018
9.7K Takip Edilen19.2K Takipçiler

The gateway is the map of the architecture. Kong → likely rate limiting and auth plugins. Envoy → service mesh + microservices. Latency headers → where the LLM provider lives.
Passive recon that changes the whole engagement
🎁 15 days free → bountysecurity.ai/pages/contact-…
English
Bounty Security retweetledi

Sharp take from my @kaptorsecurity co-founder @joserabal .
Technical people used to be the most aware of the risks. Now we're one of attackers' favourite targets. Malicious extensions, agent Skills repos, indirect prompt injection
Full take 👇
linkedin.com/posts/cybersec…
English

x-openai-model: gpt-4o → which prompt injection patterns to use x-mcp-enabled: true → tool poisoning attack surface exists x-anthropic-model: claude-sonnet → different guardrails to bypass
Test it: burpbountylab.com
👉 Burp Bounty Pro: bountysecurity.ai/pages/burp-bou…
English

AI pentests are growing fast. The first step on any of them: figure out the model, the provider, the architecture.
Profile #1 of 6 in the new AI/LLM set detects:
🔍 x-ai-backend
🔍 x-llm-provider
🔍 x-openai-model
🔍 x-anthropic-model
🔍 x-mcp-enabled
🔍 x-model
English

Validate them on Burp Bounty Lab. Load Burp Bounty Pro with the new profiles, point at burpbountylab.com, all 6 fire
Start of an AI-focused profile set. Disclosure patterns you keep seeing in AI pentests? Drop them.
English

Kaptor Security@kaptorsecurity
Have you tried "definitive solutions" for AI-driven pentesting and only ended up wasting time on false positives? In our latest blog post: six approaches, what pays off and what doesn’t, and how to integrate AI at a sensible cost-benefit ratio. kaptor.ai/blog/ai-pentes…
ZXX
Bounty Security retweetledi

5 features the data says most users miss:
🏷️ Tags Manager
🧠 Custom Smart Scan rules
🔗 Multi-step profiles
✨ AI Scanner prompt customization
🪙 Per-host scan deduplication
Deep dive each day. Some old, some new in v3.1.0. All worth knowing
bountysecurity.ai/pages/burp-bou…
English

The math: scan 500 endpoints across 3 hosts. Without dedup, 62 profiles fire 500 times each. With dedup, 3 times each. ~30,000 fewer requests, same coverage ✨
Automatic. No config needed.
bountysecurity.ai/pages/burp-bou…
English

The 28 default rules are a starting point. Real value shows up when you build rules for your testing methodology.
Detect GraphQL → fire introspection. Detect Spring → fire Spring CVEs. Build once, works across every engagement ✨
bountysecurity.ai/pages/burp-bou…
English

Sharp piece from @kaptorsecurity on why pentesting AI systems isn't a classic pentest with extra steps.
Prompt injection, probabilistic guardrails, the lethal trifecta, PoisonedRAG, tool poisoning...
Worth a read for anyone auditing AI-driven systems.
kaptor.ai/blog/classic-p…
English

Real value: prioritize bug classes per engagement, teach the AI about your custom profile names, adjust correlations for specific tech stacks (GraphQL, JWT, etc) ✨
10 minutes at the start of an engagement.
bountysecurity.ai/pages/burp-bou…
English

Each scanner has independent config: excluded extensions, methods, threads, concurrency, RPS. Plus AI Analysis Concurrency for the AI Scanner.
Most users only know about Live Passive
bountysecurity.ai/pages/burp-bou…
English




