JD on Security

1.5K posts

JD on Security

JD on Security

@JDonSec

USA Katılım Mayıs 2009
484 Takip Edilen575 Takipçiler
Intigriti
Intigriti@intigriti·
what hacker movie are you watching this weekend? 😎
English
9
0
25
4.8K
zseano
zseano@zseano·
i'm taking a pause from hacking to resume building bugbountyhunter.com. i regret closing it down and I shouldn't of done it. everything will be back online EXACTLY as it was very soon and i've got some big plans for the future. and yes, that includes zseano methodology v2 ;)
English
43
53
639
24.2K
JD on Security retweetledi
Krigshaw
Krigshaw@krigshaw·
A lot of people probably do not have the guts or balls to say this but I will say it. I have noticed that a lot of known security researchers are almost "in bed" with Hacker platforms and forget where they came from or just don't care anymore because they've already made it. The only one that I haven't seen like this is @Jhaddix. Every single time I see someone stand up for themselves against the atrocious injustices and ACTUAL unethical practices of these Hacker platforms against security researchers, I see these big names white-knighting for the platform, as if the platform isn't already a multi-million or multi-billion dollar corporation with multiple white knights on their payroll already. And it's honestly very disappointing and frustrating. People like @rez0__ and @InsiderPhD are prime examples, and should be using their platform to fight for the bug hunters, not against them. It's honestly not only incredibly disrespectful but also a massive letdown. Like, we see these people as not only peers but pillars in the community. For me personally it pains me to write this this since I followed the Critical Thinking podcast in the past, the podcast "by Hackers for Hackers" by the way, unless apparently you post about a Hacker platform hosting a corrupt program that is ghosting you and not paying you for your find. And that my friends is an example of what's become the downfall of the entire bug bounty ecosystem: say one thing, do another. Hacker platforms say they'll pay you X bounty for Y finding, and when you do the report and follow their own "good-faith" principles, they'll downplay your find, ghost your requests, and scam you of your bounty. And the same people you thought were there to defend you when you try to take a stand are actually waiting to be outraged by your stance instead, because they've "met" and "are friends" and "partied at DEFCON" with employees from these platforms 🤡. STOP defending hacker platforms and START defending the hackers, THE PRODUCT. Without us hackers these platforms would be useless.
English
9
9
62
8K
JD on Security
JD on Security@JDonSec·
Hey @2K — closing a bug report as "N/A" then silently remediating the exact same host within 30 days isn't oversight. It's stiffing the researcher who told you it was broken. @Hacker0x01 #bugbounty
English
0
0
2
96
JD on Security
JD on Security@JDonSec·
Bug bounty programs are killing their own disclosure pipeline. Real vuln on something.org.com → CNAMEs to a vendor → program closes as N/A → bug stays open → breach happens anyway. Microsoft just reversed this. Most haven't. jdonsec.com/essays/its-you…
English
5
15
102
19.7K
JD on Security retweetledi
George Pu
George Pu@TheGeorgePu·
Anthropic just pulled Claude Code from the Pro plan. Pro users wanting it need Max now. $100/month minimum. 5x jump. I'm on Max 20x so I'm fine. Flagging for anyone on Pro who's about to find out. No announcement. Just a pricing page edit.
George Pu tweet media
English
1.1K
955
11K
6.6M
JD on Security retweetledi
Dave Kennedy
Dave Kennedy@HackingDave·
For the enterprises using Claude, if you are using it for heavy enterprise type stuff - be extremely careful. It's introducing massive bugs, security issues, and code quality is way worse than Opus 4.5, substantially worse on both 4.6 and 4.7. Our entire development team is shifting off of it. It's unusable at the moment aside from beautiful UI stuff, it's code quality is not something you can trust. Still no word from Claude on why they mangled their models and didn't tell anyone - which is particularly alarming on every front. I would recommend switching teams over to something like Cursor, Perplexity, or AWS Bedrock - as the frontier models continue to innovate (or regress) - having the ability for flexible model selection that doesn't disrupt development workflow will be insanely important for enterprise.
English
114
101
1.1K
183.6K
JD on Security retweetledi
Shubham Gupta 🇮🇳
Shubham Gupta 🇮🇳@hackerspider1·
Hey @Hacker0x01 super disappointed. Reported a critical bug on a private program: full access to 73 storage containers, (RCE) entire company's candidate PII downloadable. Triaged valid. Fixed by the team (confirmed). Then 2 months later closed as N/A "third-party SDK issue." If the key is served from your domain, leaking your users' PII, and your team fixes it how is that N/A? Filed mediation but 6–7 months is a long wait. Can someone from the team take a look? Bug is genuinely worth your time.
English
13
12
171
29K
JD on Security
JD on Security@JDonSec·
@elonmusk They need to be investigated for pedophilia, just imagine what must be happening at that organization.
English
0
0
0
6
JD on Security retweetledi
non aesthetic things
non aesthetic things@PicturesFoIder·
A poker bot farm where multiple bots sit at the same table and share their cards to collude against humans
English
236
528
8.5K
1.4M
JD on Security retweetledi
Deputy Secretary Jim O'Neill
We have frozen all child care payments to the state of Minnesota. You have probably read the serious allegations that the state of Minnesota has funneled millions of taxpayer dollars to fraudulent daycares across Minnesota over the past decade. Today we have taken three actions against the blatant fraud that appears to be rampant in Minnesota and across the country: 1. I have activated our defend the spend system for all ACF payments. Starting today, all ACF payments across America will require a justification and a receipt or photo evidence before we send money to a state. 2. Alex Adams and I have identified the individuals in @nickshirleyy's excellent work. I have demanded from @GovTimWalz a comprehensive audit of these centers. This includes attendance records, licenses, complaints, investigations, and inspections. 3. We have launched a dedicated fraud-reporting hotline and email address at childcare.gov Whether you are a parent, provider, or member of the general public, we want to hear from you. We have turned off the money spigot and we are finding the fraud. @ACFHHS @HHSGov
English
11.9K
26.1K
147.7K
13.9M
Only In Boston
Only In Boston@OnlyInBOS·
Need your help: where do you go for Portuguese food in Massachusetts?
English
125
7
67
50K
JD on Security
JD on Security@JDonSec·
@NahamSec Is it a self hosted AI? Also do you happen to have YT videos on bug bounty with AI?
English
0
0
0
82
Ben Sadeghipour
Ben Sadeghipour@NahamSec·
I just used AI to reverse engineer an N-day in a Wordpress plugin in like 50 minutes 🫠
English
13
4
292
25.4K
JD on Security retweetledi
Michelle #AmericaOnly🇺🇲
Michelle #AmericaOnly🇺🇲@MichelleRM68·
🚨JUST IN!: According to the NY Post, Nancy Pelosi's return on her stock OUTPERFORMED THE DOW by 17,000% for raking in 133 million from 1987-2025!! ARE YOU KIDDING ME RIGHT NOW?? She OUTPERFORMED the damn DOW? This is EXACTLY why Americans hate D.C. & nothing will be done!!👇
English
2.9K
22.1K
94.5K
5.5M
JD on Security retweetledi
David Wade
David Wade@davidwade·
The new salary transparency law begins next week in Mass. Employers have to post salary range for openings AND if you want to know what colleagues with your job title are making - your boss needs to give you the high and low. So… will you be asking for that info?
English
31
69
669
42.3K
𝐌𝐚𝐭𝐭 𝐏𝐢𝐧𝐧𝐞𝐫
Be honest because I’m trying to prove a point Would you back your child or grandchild's decision to attend trade school rather than college?
English
27.1K
2.9K
88.6K
2.7M