Erik

81 posts

Erik banner
Erik

Erik

@Eriik451

💻

Katılım Ekim 2016
377 Takip Edilen232 Takipçiler
N0xi0us
N0xi0us@_N0xi0us_·
This was a great bug bounty year submitting a bunch of bugs and achieving 17th place in leaderboard and 2nd place in country leaderboard (1st removing expats 👀)
N0xi0us tweet mediaN0xi0us tweet media
English
16
0
131
6.2K
𝕵𝖔𝖙𝖆 | jotita3
Recently I don't tweet much, but today has been a beautiful day that made me feel better after some other disappointments: 9th in Spain 🇪🇸 and a great impact! A year or so ago this was unthinkable for me 📈 Thanks #BugBounty
𝕵𝖔𝖙𝖆 | jotita3 tweet media𝕵𝖔𝖙𝖆 | jotita3 tweet media
English
10
1
95
4.2K
Erik retweetledi
hipotermia
hipotermia@hipotermia·
Thanks to everyone who joined us at the @Hacker0x01 Brand Ambassadors Speed Show&Tell in Madrid, and special thanks to all who presented! 💕
hipotermia tweet mediahipotermia tweet mediahipotermia tweet mediahipotermia tweet media
English
6
11
126
13.2K
Erik retweetledi
James Kettle
James Kettle@albinowax·
It's easy to bash vulnerabilities with logos but... I couldn't resist, say hello to http1mustdie.com :)
English
15
88
480
50.4K
Erik retweetledi
zhero;
zhero;@zhero___·
new discovery: cache poisoning on next.js - CVE-2025-49826 indefinite caching of a 204 response, rendering the affected pages inaccessible affected versions: >15.0.4 and <15.2.0 there will be no research paper for this one
inzo@inzo____

back to work with @zhero___ and a new vulnerability on @nextjs that led to CVE-2025-49826 both routers are impacted: app router: framework's cache is directly impacted on ISR pages, regardless of the presence of a CDN pages router: SSR pages only + requires a misconfigured CDN

English
14
84
477
38.8K
Erik retweetledi
TrendAI Zero Day Initiative
Confirmed! Former Master of Pwn winner Manfred Paul used an integer overflow to exploit #Mozilla Firefox (renderer only). His excellent work earns him $50,000 and 5 Master of Pwn points. #Pwn2Own #P2OBerlin
TrendAI Zero Day Initiative tweet mediaTrendAI Zero Day Initiative tweet media
English
3
20
205
35.9K
James Kettle
James Kettle@albinowax·
Anyone got suggestions for what podcasts you'd like to see me interviewed about research or @Burp_Suite on, or any more specific topics you'd like to hear about?
English
26
2
110
14K
Erik retweetledi
James Kettle
James Kettle@albinowax·
Are you a Burp Repeater power user? The latest release introduces a new feature called 'Custom actions'. With these you can quickly build your own repeater features. Here's a few samples I made for you:
James Kettle tweet media
English
18
86
543
41.3K
Erik retweetledi
Tarlogic
Tarlogic@Tarlogic·
First it was BleSpammer. Now it's VSC Enumerator. The @Tarlogic Innovation team has just released a new PoC that allows to discover hidden commands in Bluetooth adapters. In this GitHub link you have all the info 👇 github.com/TarlogicSecuri…
Tarlogic tweet media
English
0
3
7
801
Erik retweetledi
zhero;
zhero;@zhero___·
the research paper is out: Next.js and the corrupt middleware: the authorizing artifact result of a collaboration with @inzo____ that led to CVE-2025-29927 (9.1-critical) zhero-web-sec.github.io/research-and-t… enjoy the read!
zhero; tweet media
English
69
438
1.6K
174.5K
hackplayers
hackplayers@hackplayers·
📢¡Atención! Gracias a @therealdreg sorteamos una entrada presencial sin material para el bootcamp de Hardware Hacking del 17-20 de Abril: hardwarehacking.es 👉Lo único que tienes que hacer responder a este tweet mencionando a otro colega 📆Sorteo: 23 de Marzo
hackplayers tweet media
Español
8
5
10
6.5K
Erik retweetledi
Victor Fresk0
Victor Fresk0@hacefresko·
Good news! I've uploaded a new post about the most complex and beautiful vulnerability I've ever found, involving patching and uploading deprecated .jar libraries to get RCE on a big target. It's a very technical post, but I hope you like it ! :) hacefresko.com/posts/rce-on-s…
English
6
107
411
24.6K
Erik retweetledi
zhero;
zhero;@zhero___·
very pleased to announce the release of my new article based on my research that led to CVE-2024-46982 titled: Next.js, cache, and chains: the stale elixir zhero-web-sec.github.io/research-and-t… note: does not cover the latest findings shared in my recent posts enjoy reading;
zhero; tweet media
English
44
238
992
215.7K
Erik retweetledi
Tarlogic
Tarlogic@Tarlogic·
🚨 #BlueSpy is now available on our GitHub. This proof-of-concept allows you to listen in on conversations from Bluetooth headsets without your users' knowledge. We have already alerted manufacturers whose devices have some vulnerabilities. github.com/TarlogicSecuri…
English
3
101
243
27.4K