Numbo
1.2K posts

Numbo retweetledi

Thank you to everyone who came to my shrek-themed hacking alongside AI talk today at Hacking APIs Con @hAPI_hacker

English

Replaced @Burp_Suite splash screen with a custom design.
Found the PNG inside the binary using a hex editor, generated new artwork with @ChatGPTapp, patched it in.
Guide and prompt:
bugbounty.zip/Share/burp-spl…
#AIArt #DigitalArt
English

I dropped 5x RCEs in a single report, it got triaged, then after 16 days the customer patched everything and rewarded it as P3?
So a potential $10k–15k critical report suddenly became a $500 payout in one comment - this severity decision genuinely makes no sense .
These kinds of decisions genuinely discourage researchers from hunting on platforms/programs.
Spending days finding impactful vulnerabilities, writing detailed reports, and helping secure production systems only to see the severity heavily downgraded afterward is extremely demotivating.
In this case, the issues were valid, triaged, and even patched by the customer, which clearly proves the impact was real. Yet the final outcome made it feel like all the effort put into the research had little value.
Researchers invest huge amounts of time and energy into finding critical vulnerabilities responsibly, and inconsistent severity decisions like this make people lose trust in the process.
Honestly, one comment was enough to completely kill the motivation and energy I had for #bugbounty
English

That's my chain — a full chain w/ logic bugs only! No memory corruption, no AI, and of course no collisions at all 😉
TrendAI Zero Day Initiative@thezdi
Confirmed! Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) chained 4 logic bugs to achieve a sandbox escape on Microsoft Edge, earning $175,000 and 17.5 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
English

ChatGPT has been allegedly sending your query topics to Meta and Google in real time.
Not just "you used ChatGPT"
The actual topic. Converted to page metadata.
Sent with your Facebook cookie, Google cookie, user ID, and hashed email.
"Who won the Super Bowl in 2005?" becomes "Super Bowl 2005 Winner" in the tracking payload.
Now imagine the query is about your health.
Your divorce. Your company's finances. Your breakdown at 1 AM.
A class action was just filed.
OpenAI allegedly violated privacy laws by disclosing private communications to third parties without consent.
We turned therapy, legal advice, and diary entries into one text box. And apparently it had tracking pixels watching.
English



























