Leandro Barragan
649 posts

Leandro Barragan
@lean0x2f
A.K.A. none_of_the_above | Offensive Sec Researcher | https://t.co/zhzGBvhEUz | https://t.co/XyZBK7P9wo | Building the best autonomous pentester @ https://t.co/mF7RKaHmHw




I just noticed CVE-2025-25257 and had a giggle. Not because it's yet another Fortinet remote bug. But because it's a SQLi, in a WAF product. The irony...









A new chapter for @Xbow. We're concluding our primary mission on Hacker1, so it will no longer be competing on the leaderboard. The platform was a critical step in our journey: an invaluable, large scale, live-fire range for developing and improving XBOW. xbow.com/blog/xbow-on-h…

-=[ PHRACK PROPHILE ON Gera ]=- #article" target="_blank" rel="nofollow noopener">phrack.org/issues/72/2#ar…
That’s the whole tweet…




A new chapter for @Xbow. We're concluding our primary mission on Hacker1, so it will no longer be competing on the leaderboard. The platform was a critical step in our journey: an invaluable, large scale, live-fire range for developing and improving XBOW. xbow.com/blog/xbow-on-h…





If I used my automation on all HackerOne programs, my score would have been double that of the AI Hackbots…

1/ XBOW Unleashes GPT-5’s Hidden Hacking Power. @OpenAI's initial assessment of GPT-5 showed modest cyber capabilities. But when integrated into the XBOW platform, we saw a completely different story: performance more than doubled. More on what we found: 🧵


