Pluto retweetledi
Pluto
8.3K posts

Pluto
@Hoesenbug
Security Researcher / Bug Bounty Hunter
Pakistan Katılım Nisan 2020
1.1K Takip Edilen255 Takipçiler
Pluto retweetledi

she literally explained why some people never feel lazy and how to copy them (in 2 mins)
stressed@onlystresstoday
Lord, remove any laziness from my body and push me to my full potential the rest of this year.
English

@ghost__man01 read this, tried it ,found a phpinfo reported it in 5 minutes
English

New Write-up API Hunting to Employee PII Data #bugbounty #bugbountytips #bugbountytip #hacking #cybersecurity #hackers #cybersec #infosec
Free Article Link👇👇👇
🔗ghostman01.medium.com/api-hunting-to…
English
Pluto retweetledi
Pluto retweetledi
Pluto retweetledi

🚨 Someone just turned your WiFi router into a full-body surveillance system.
No cameras. No wearables. No video. Just radio waves.
It's called RuView. It uses the WiFi signals already in your room to detect human poses, track breathing, measure heart rate, and see through walls.
Not a concept. Not a research paper. Working code you can run right now.
Here's what this thing actually does:
→ Tracks full 17-point body pose using only WiFi signals
→ Detects breathing rate (6-30 BPM) without touching anyone
→ Measures heart rate (40-120 BPM) from across the room
→ Sees through walls, furniture, and debris up to 5 meters deep
→ Tracks multiple people simultaneously with zero identity swaps
→ Self-learns from raw WiFi data. No labeled datasets needed
Here's how it works:
WiFi signals pass through your room and hit the human body. The body scatters those signals differently based on position, breathing, even heartbeat. RuView reads that scattering pattern and reconstructs everything.
A mesh of 4 ESP32 nodes ($48 total) gives you 360-degree coverage with 12 measurement links, 20 Hz updates, and sub-30mm precision.
Here's the wildest part:
It has a disaster response mode called WiFi-Mat. It detects survivors trapped under rubble through concrete walls, classifies injury severity using START triage protocol, and estimates 3D position. The kind of tool that saves lives after earthquakes.
The Rust implementation processes 54,000 frames per second. That's 810x faster than the Python version. The entire Docker image is 132 MB.
The AI model fits in 55 KB of memory. Runs on an $8 ESP32 chip.
Train once, deploy in any room. No retraining. No recalibration.
1,100+ tests. SHA-256 verified capability audit.
22.4K GitHub stars. 2.7K forks. MIT License.
100% Open Source.

English
Pluto retweetledi
Pluto retweetledi

You can now dump all your #bugbounty @Hacker0x01 reports using bbscope thanks to @R3dTr4p's pull request!
bbscope reports h1 --output-dir h1-reports
More platforms coming soon!
github.com/sw33tLie/bbsco…

Corben Leo@hacker_
@AnthropicAI you killed it. wow.
English
Pluto retweetledi

😰Client-side mistake leads to full read/write access! This bug bounty writeup details how an exposed secret in JavaScript allowed an attacker to forge admin tokens and control an internal support system. A must-read for #CyberSecurity pros! #BugBounty #Hacking #HackProve
@NeM0x00/from-a-simple-client-side-mistake-to-full-read-write-access-of-an-internal-support-system-ebd40e4588ee" target="_blank" rel="nofollow noopener">medium.com/@NeM0x00/from-…
English
Pluto retweetledi

💡 Bug Bounty Recon for Everyone! Learn essential tools & methodologies like Subfinder, Alterx, DNSX, Naabu, HTTPX, and Katana to master reconnaissance and expand your attack surface. Don't miss these pro tips! #BugBounty #CyberSecurity #Hacking #HackProve
@batuhanaydinn/bug-bounty-recon-for-everyone-220ae026a42c" target="_blank" rel="nofollow noopener">medium.com/@batuhanaydinn…
English
Pluto retweetledi

New write-up: how a business logic flaw let a large pizza be purchased at a small price.
Real-world checkout manipulation + server-side validation gaps.
@raslanco/large-pizza-small-price-exploiting-a-critical-business-logic-flaw-in-checkout-55f7497e5ab6" target="_blank" rel="nofollow noopener">medium.com/@raslanco/larg…
#bugbountytips #bugbountytip #ethicalhacking #infosec
English
Pluto retweetledi

Time-Based SQL Injection Is Still Everywhere!🔥
You can fingerprint the backend DB version with
'; IF (SUBSTRING(@@VERSION,1,1) = 'M') WAITFOR DELAY '0:0:15' --
Delay = proof.
#RedTeam #BugBounty #SQLi #bugbountytips #hackerone

English
Pluto retweetledi

A Step-by-Step Guide to Uncovering Vulnerabilities in a Mobile App | by Ahmad A Abdulla | Feb, 2026 | Medium ahmadaabdulla.medium.com/a-step-by-step…
English
Pluto retweetledi
Pluto retweetledi
Pluto retweetledi

Tired of hitting 403 errors during your security testing?
NoMore403 by @devploit automates bypass techniques to get past those pesky restrictions.
Try it at 👇
github.com/devploit/nomor…
English
Pluto retweetledi

GIVEAWAY TIMEEEE
udemy.com/course/uncle-r…
Limited to 100x - Sorry rat pack, udemy made a change, can not give more coupons
English
Pluto retweetledi

We disclosed a critical unauthenticated RCE chain in mcp-atlassian (4M+ downloads).
CVE-2026-27826 - SSRF via Atlassian URL headers
CVE-2026-27825 - Arbitrary file write → RCE
Fixed in 0.17.0.
Full breakdown 👇
blog.pluto.security/p/mcpwnfluence…
English








