

Ophion Security
54 posts

@OphionSecurity
Your offensive security partner. Unleash an automated hacker against your attack surface with Orion.





New Episode is live covering the craziness with Zendesk and the nuances of how "informative" report disclosure should be handled. Also, some badass write-ups from @OphionSecurity and a new song drop from @realytcracker! youtube.com/watch?v=yHQZUT…







Flight from Vegas after Defcon got delayed…hacked for 2 hours during the delay…reported a P2 on Square…got paid. I love hacking. #bugbounty #hacking



Catch me at BlackHat and Defcon next week for some stickers! #defcon #blackhat

Currently monitoring almost 1million+ records and assets through automation in one of our test deployments. Might have automated too hard.

🛡️ Vulnerability of the Week: Going from High to Critical in 5 Minutes to get millions of customers' PII When testing a company, I found a vuln where authenticated users could pass enumerable account tokens to access another user's PII: DoB, Address, Phone, Transaction history, account balances and more. #attacksurfacemanagement #bugbounty 🧵







