Joseph Thacker

26.5K posts

Joseph Thacker banner
Joseph Thacker

Joseph Thacker

@rez0__

christian. father. hacker. founder. advisor. podcast: https://t.co/1aFavJN2h8 blog: https://t.co/JBPT1CJWJH products: 🤖 https://t.co/EVhQl8HTlp $200/mo 📚 https://t.co/MMmhw0cnaz $0/mo

/Users/rez0/ai Katılım Mart 2011
1.3K Takip Edilen72.7K Takipçiler
Sabitlenmiş Tweet
Joseph Thacker
Joseph Thacker@rez0__·
👑 WE WON! 🎉 LFGGGG! @Rhynorater @0xLupin @monkehack and I won MVH at the Google Live Hacking Event in Tokyo last week! It was focused on their AI products. We also had an awesome time in Japan. I'll post some of the highlights below.
Joseph Thacker tweet media
English
46
31
543
85.9K
Joseph Thacker
Joseph Thacker@rez0__·
@4osp3l Okay actually leaking cf api keys would maybe lead to some shells
English
1
0
1
84
Gospel
Gospel@4osp3l·
@rez0__ maybe a remote shell..? just saying. Lol… i can’t tell if that’s possible but i believe it could be. I had to tweet my thoughts 😂
English
1
0
2
237
Gospel
Gospel@4osp3l·
Okay we have - react2shell - wp2shell Ohhh, what of cf2shell ( cloudflare RCE ) ? if that happens, the INTERNET would be on a REAL fire. wait, what?? that would be interesting, ngl… we got thousands of applications running behind cloudflare. Or is cf2shell already available?
English
3
2
44
2.6K
Joseph Thacker
Joseph Thacker@rez0__·
Alright here’s the plan: 1) tweet 2030 predictions from different random accounts 2) after it is known who is in the final, delete the incorrect ones 3) crypto scam 5) ??? 6) profit?
English
2
0
1
4.2K
Joseph Thacker
Joseph Thacker@rez0__·
RT @goodside: Claude Fable 5 gives a contextually appropriate reply to my request that’s also an anagram of the request itself: https://t.c…
English
0
1
0
537
Justin Elze
Justin Elze@HackingLZ·
@rez0__ I’m also sure people have been running Wordpress code across all their bug finding harnesses for weeks and months now. However a single person dropped in with a RCE chain.
English
1
0
1
105
Joseph Thacker
Joseph Thacker@rez0__·
@HackingLZ Yeah one human found this and agents too hours to figure it out with a patch
English
1
0
1
671
Joseph Thacker
Joseph Thacker@rez0__·
@njcve_ Digital ocean is amazing with APIs and UI and not bothering hunters but a lot of places block their IPs outright
English
1
0
6
455
Nathan Jones
Nathan Jones@njcve_·
Recon hunters, what is your goto cloud provider for scanning at scale, and why? I'm trying to prevent a weekend of analysing results across several providers hoping someone just has the insight already.
English
1
0
9
1.3K
Joseph Thacker
Joseph Thacker@rez0__·
And you can make them all agent friendly too so later you can just tell codex or Claude code “do cold outbound, add them to the leads system, if they confirm, use Docusign clone to send their custom MSA you make and proposal for signing, and schedule them when we have availability”
English
0
0
1
283
Joseph Thacker
Joseph Thacker@rez0__·
AI brings decentralization to systems when anyone can spin up their own unique clone of an app. This alone is massssive for security.
English
1
1
17
2.4K
Joseph Thacker
Joseph Thacker@rez0__·
@trq212 @repligate Our entire community literally can’t, because we’re all bug hunters. We’re all migrating to codex becuase 5.6 with TAC is so good. And even if you’re cyber approved on anthropic, you can’t use fable for anything.
English
4
0
66
5.2K
Joseph Thacker retweetledi
Embrace The Red
Embrace The Red@EmbraceTheRed23·
Hugging Face Intrusion in a nutshell 1. First end-to-end agentic intrustion 2. Safety guardrails blocked defenders from using AI 3. HF switched stack to GLM 5.2 (open-weight model) running locally 4. No IOCs shared yet Hope more info well become available in the coming days
Johann Rehberger@wunderwuzzi23

The Hugging Face AI intrusion hasn't gotten much attention so far, yet it's a "milestone" from multiple perspectives youtu.be/JQQYhNK6AyU

English
1
2
4
1.1K
Joseph Thacker retweetledi
shubs
shubs@infosec_au·
@NateRobb @rez0__ @sshell_ @Cloudflare @hash_kitten @SLCyberSec Just so it's clear, we didn't ask for it to be dropped on Friday at 5PM EST. WordPress decided to release their patches then. Not much we could do. Given the nature of the bug, it is what it is, I can't fault WordPress.
English
1
2
68
4.5K
Ryan Barnett (B0N3)
Ryan Barnett (B0N3)@ryancbarnett·
After previously enduring the pain of peeling off all my hacker stickers when I had to upgrade my corp laptop, I decided to adopt @InsiderPhD’s tip of using laptop covers. Makes it easy to upgrade and you get to display them 👍
Ryan Barnett (B0N3) tweet media
English
3
1
17
1.2K
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
wait, my intention isn’t to downplay their skill if it came across that way. it’s exactly that skill that puts them at the top. some people excel at patch reversing, like my teammates, while others are exceptionally good at finding targets through recon. it does seem like the world may look very different soon, especially for the n-day niche but for other stuff like being pro at recon like todayisnew it won't affect that much?
English
1
0
1
381
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
if you want to know why n-day exploits being created out of thin air is bad, ask n-day niche hackerone or bugcrowd million-dollar bug hunters what kind of stuff they pop shells on. their edge has always been being faster than everyone else, other researchers and threat actors alike, at turning a patch into a working exploit so they could report it before it was abused which might now change.
English
3
4
70
7K