nahuelrm

43 posts

nahuelrm

nahuelrm

@nahuelrm_

23. Bug Bounty grinder 🇦🇷

Katılım Kasım 2022
498 Takip Edilen2.3K Takipçiler
Sabitlenmiş Tweet
nahuelrm
nahuelrm@nahuelrm_·
I won MVH at H1-361 Live Hacking Event!! Also got Erradicator award. It was an incredible event! Loved meeting so many amazing people, spending time with friends, and learning a lot. Definitely something I will never forget! Huge Thanks to @Hacker0x01 for making it possible!
nahuelrm tweet medianahuelrm tweet medianahuelrm tweet media
English
39
14
415
15.9K
nahuelrm retweetledi
Harley Kimball
Harley Kimball@infinitelogins·
Vercel hacked via compromised AI customer, @nahuelrm_ takes MVH plus Erradicator at H1-361, @valent1nee takes the MVH from Google, @BRuteLogic audits autonomous AI vuln discovery claims, and @S1r1u5_ reports a Claude-assisted V8 exploit against Discord that hit a shell after 2.3B tokens, and more. This week, Disclosed. #BugBounty Full issue → getdisclosed.com Highlights below 👇 @rauchg reports a Vercel incident where an attacker pivoted from a compromised AI-platform customer into employee access, then enumerated environment variables. @nahuelrm_ wins MVH and the Erradicator award at HackerOne’s H1-361 Live Hacking Event. @valent1nee posts an MVH win from Google LHE Seoul 2026. @BRuteLogic publishes “Zero Days, Zero Truth,” a point-by-point audit of autonomous AI vulnerability discovery claims. @claudeai announces Claude Opus 4.7, then @elder_plinius drops a massive Opus 4.7 system prompt leak. @yeswehack ships a Caido integration for in-workspace program browsing and scope review, plus a Q1 Bucket List recap with remaining targets. @S1r1u5_ shares cost and workflow notes on an AI-assisted V8 exploit against Discord, roughly 2.3B tokens, about $2,283, ending in a remote shell. @H4cktus publishes a chain to RCE on Tomcat behind Cloudflare, with a thread, a blog, and a tool. @whoareme33 writes up a $15k CSPT that escalated to full account takeover, then a 2FA bypass via a prototype chain. @kartikeyagg turns one access control bug into 22 paid issues by mining client-side JavaScript for repeatable patterns. @Intigriti highlights a GraphQL vulnerability mapping workflow focused on enumeration and common authorization failures. @Jhaddix boosts an “authority framing” prompt-injection technique aimed at system prompt exfil. @ctbbpodcast threads on multi-agent token delegation confused-deputy risk, plus a HackerNotes TL;DR on AI exfiltration primitives and OAuth scope pitfalls. @NahamSec talks through how LLMs and agents are affecting hunter workflows and program triage volume. That's not all. Full links, writeups & more → getdisclosed.com The bug bounty world, curated.
English
3
4
24
2.9K
nahuelrm
nahuelrm@nahuelrm_·
I won MVH at H1-361 Live Hacking Event!! Also got Erradicator award. It was an incredible event! Loved meeting so many amazing people, spending time with friends, and learning a lot. Definitely something I will never forget! Huge Thanks to @Hacker0x01 for making it possible!
nahuelrm tweet medianahuelrm tweet medianahuelrm tweet media
English
39
14
415
15.9K
nahuelrm
nahuelrm@nahuelrm_·
@alexbindrei @Hacker0x01 Gracias Alex! Fue un gusto poder concerte, y hablar con vos :) Espero vernos pronto! 🫡
Español
0
0
0
171
Alexandrio
Alexandrio@alexbindrei·
@nahuelrm_ @Hacker0x01 The GOAT🎉 Fue un placer conocerte :) Muy merecido y muy contento por tu victoria. Disfrútalo.
Español
1
0
1
283
nahuelrm
nahuelrm@nahuelrm_·
@_godiego__ @H4cktus @Hacker0x01 Gracias Diego! Fue un gusto conocerte junto con todos los demas chicos de España! La pase increible con ustedes, espero verlos en algun proximo evento 👀🫡
Español
0
0
1
407
llorenzo
llorenzo@lucianolor44·
@nahuelrm_ @Hacker0x01 Felicitaciones amigo, merecidisimo!! orgulloso de lo lejos que llegaste loco 🥹🥹
Español
1
0
2
422