Sabitlenmiş Tweet
positive status
136 posts


@GodfatherOrwa @ai we don't need AI ads.
we need wise men who spit the truth
English

@apihog @Hacker0x01 Which type of vulnerability do you find more?
English
positive status retweetledi

@Damtap12 You know in an Easter Egg hunt, if you stop to ponder how the hunt may go instead of just picking up the eggs while they are still there, you may come to realize all the other kids got all the Easter Eggs before you were done pondering :) That was deep
English
positive status retweetledi
positive status retweetledi

AI-Powered Agents for Bub-Bounty Pentesting and Red-Teaming purposes github.com/matty69v/Bug-B…
English

DeepSeek V4 is actually better than Opus 4.7.
HealthRanger@HealthRanger
I just had DeepSeek V4 find and fix 8 memory leaks that were causing crashes in code written by Claude Opus 4.7. DeepSeek found them all and fixed them in minutes, at a total cost of maybe three pennies. DeepSeek is amazingly good at coding and bug fixing. And it costs almost nothing to use, even the Pro version. Best harness? OpenCode.
English
positive status retweetledi

@philopentest @intigriti This is amazing getting this far in such a short time. How did you pull it off?
English

This week, in April 2026, I reached the top 29 on Intigriti's all-time/global leaderboard. @intigriti is a bug bounty platform with 125,000+ ethical hackers. My first submitted bug was accepted on November 18, 2024.
Snapshot:
archive.is/CB8O1
#CyberSecurity #bugbounty

English
positive status retweetledi

I've been doing bug bounty for years.
I just published a long piece on what it actually feels like in 2026, and why something fundamental has shifted.
aituglo.com/state-of-bug-b…
Would love to get your feedback on it here on X or directly on the blog
English
positive status retweetledi

What paid tools/services do other vulnerability researchers use?
Mine are:
- Burp Suite Pro.
- Claude Code Max.
- cvefeed.io enterprise tier. Their chrome plugin just give me all context of any CVE code on the web. Among all the other features.
English

افتكر زمان تقريبا 2020 او قبلها ب حاجة بسيطة
كان جايلي انفيتيشن ل onlyfans علي HackerOne وكان جايلي بردو لبروجرام اسمة whatnot بتاع لايفات بردو تقريبا انا اونلي فانز كنت فاكرة موقع لايفات عادي والله زي لايفات الفيسبوك مثلا وكدة وبلغتلهم واحدة critical ومعرفتش انهم كدة غير بعد م بعتها واتقبلت 😂
ما علينا ربنا يجعلو في الدرك الاسفل من النار ويجحمة ان شاء الله 🤲🏻
RT@RT_com
⚡️ OnlyFans founder Leonid Radvinsky dies of cancer at the age of 43
العربية
positive status retweetledi
positive status retweetledi

Web-Fuzzing-Box - A curated collection of fuzzing dictionaries & payloads for web security testing. Brute force, directory enumeration, vulnerability exploitation — all in one place.
Passwords, usernames, paths, API endpoints, XSS/SQLi payloads, file upload bypasses, 403 bypasses, and more.
Many dictionaries are battle-tested — extracted from real-world engagements via the CaA project (Collector and Analyzer), not randomly generated wordlists.
Ready for Burp Intruder, ffuf, dirsearch, or any tool you throw at it.
Free. Open source.
github.com/gh0stkey/Web-F…
#bugbounty #infosec #pentesting #fuzzing #wordlists

English
positive status retweetledi

Hot take 🌶️:
Everyone in bug bounty is using AI incorrectly, judging from what I see on X. Those who’ve figured it out surely don’t want to share. I just learned this myself by completing Anthropic's Claude 101 course.
The reason I don’t want to share is that it would only increase AI slop and make bug bounty harder for everyone.
Here’s a hint: use AI as your co-pilot don’t fall into completely autonomous mode.
English
















