Nate
16.2K posts

Sabitlenmiş Tweet

Nate retweetledi

This is really cool. I can’t wait to see what these guys do. Lots of really creative people involved.
Sybil@runsybil
The way we hack is changing and we're building what comes next We've raised a total of $40M to create the AI-native platform for offensive security
English

Information warfare is deeply interesting to me, it’s becoming increasingly obvious that there is competition over control of the values, narratives, and the movement of the cultural zeitgeist. I believe the shift that we’ve seen to decentralised systems (namely social media and how information is disseminated) has made this not only more pervasive, but far more visible. It’s fascinating to see people I know building broad foundations of geopolitics based on what must be at least partially the product of soft power operations. I think it’s only been a lot more recently that the western axis is realising there’s a game being played here for a while that they weren’t fully appreciating not only in the pervasiveness, scope, reach, and influence of these operations but also the difficulty of responding to them in free and open societies.
English
Nate retweetledi
Nate retweetledi

Spent the last few weeks building an XSS hunting agent using Claude Agent SDK. Custom tools for param discovery, CSP analysis, context detection, and browser-based confirmation.
Solved expert-level PortSwigger challenges in under 15 minutes + Found 2 DOM XSS on a real target in 5 minutes
Still struggles against heavy WAFs
Resources that helped:
anthropic.com/engineering/bu…
platform.claude.com/cookbook/patte…
#BugBounty #AgenticAI #InfoSec


English
Nate retweetledi

We decided to revisit an old research problem with some new LLM powered tooling. Check out our latest blog post to see how we approached this research, and the new Java deserialization gadget chains it discovered in just two days! buff.ly/CeAQZ2B
English
Nate retweetledi

WontFix can be an RCE Goldmine
SOAPwn by @chudyPB
#5 in PortSwigger Web Hacking Techniques of 2025
Microsoft’s refusal to patch HttpWebClientProtocol invalid casting makes any .NET app using ServiceDescriptionImporter permanently vulnerable to arbitrary file write via malicious WSDLs.
Blog link 👇
labs.watchtowr.com/soapwn-pwning-…
English

@thedawgyg @busf4ctor Yeah neat I’ll send them a message tomorrow and ask.
English

@nnwakelam @busf4ctor They will even sometimes provide a lil extra info for the blog post and all. So deff worth letting them know and sharing a draft once its ready
English

@busf4ctor Thanks. I wanted to get proper permission from them before even writing it up. Cheers man. I’ll reach out to them
English

@nnwakelam You can just ask for that in the issue tracker. You have permission after 90 days, I think. Anyway, no reason not to tell them about it, they always accept it and even ask you to share it with them so they can help you
English

Neat
Intigriti@intigriti
Found an exposed Swagger/OpenAPI file on your target? 🧐 Sj by @BishopFox audits endpoints defined in Swagger docs automatically, tests all defined endpoints, generates curl/sqlmap commands, and even bruteforces for hidden definition files! 🤠 Check it out! 👇 🔗 github.com/BishopFox/sj
English

geohot.github.io//blog/jekyll/u…
This is a really good read. I like how this guy brings a lot of what he speaks on back to this idea of “creating more value than you consume”.
English

The peptide industry is going to continue moving incredibly quickly, and just like we’ve seen with GLP1 drug classes we will see both new novel chemicals and analogues of existing ones enter the marketplace rapidly. The next few years is going to be incredibly exciting. Many different types of addiction and health related issues can be treated in non-invasive ways already and we’ve barely scratched the surface.
English

@nnwakelam Hacked the FBI
Search the system
Find child porn
Get angry
Threaten to turn the FBI into the FBI
Get on web cam so they can show you badges
sounds like the plot to a bad hacker movie lol
English

reuters.com/world/us/forei…
The person familiar with the breach said the intrusion was carried out by a foreign hacker who did not appear to realize they had penetrated a law enforcement server. The hacker expressed disgust at the presence of child abuse images on the device and left a message threatening to turn its owner over to the FBI, the person said.
English





