alex @insertScript
@[email protected] # https://t.co/liE6hop4OX Array(10).join('a'-1)+ Batman! #Cure53 Joined June 2012-
Tweets2K
-
Followers7K
-
Following217
-
Likes13K
@zhero___ zeroday.cloud/2026-competiti… has Next.js as a target ;-)
On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
@rebane2001 uh cool idea. Kinda curious why nobody got weird for the first result - at least in the screenshots I have seen.
We are going to be at DEF CON! If you want to learn fault injection hands-on, make sure to bring your laptop.
@J0R1AN this is perfect - I needed that for a test case I always wanted to try^^
This new HTML feature just shipped in Chrome 150, it's gonna be veeeeery interesting 👀 github.com/WICG/declarati…
If a website uploads your pictures to S3 as public objects and serves them through a reverse proxy, you have XSS even if the website's implementation is safe! I wrote about this in full in this post: blog.voorivex.team/content-type-o…
Can you spot the XSS vulnerability? 👀 Test it out live at: pwnbox.io/challenges/mim…
@garethheyes oh it is definitely up there - but for me the IE's valueOf location assignment stays my favourite^^ +{"length":1,"0":"javascript:alert(1)","toString":[].join,"valueOf":location}
I co-authored an educational article on cache poisoning vulnerabilities with @intigriti. If you're looking to understand the fundamentals and pick up a few practical tips along the way, give it a read!
Most hunters skip web cache poisoning because it looks intimidating... 😓 But a single misconfigured cache layer can regularly turn into critical findings, even on heavily tested targets! 🤠 In our latest article, we walk you through identifying cache layers, spotting unkeyed
DOMPurifyバイパスの歴史をまとめたページ。HTMLサニタイザーバイパスのノウハウがぎっしり詰まってる。 特に今年に入ってから発見された<selectedcontent>のバイパスは驚いた github.com/cure53/DOMPuri…
New short article on a real-world exploitation case rather than pure research, demonstrating how a specific mistake in Next.js can lead to a systematic zero-click SXSS on its latest versions (w/@inzo____): Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js zhero-web-sec.github.io/research-and-t…
Damn, what a read
StubZero: $148,337 RCE in Google Cloud Production brutecat.com/articles/googl…
@magicmac2000 I had to double check that this is actually a new post from you. Nice to see back giving browsers a hard time :-D
FFFF the axios thing is bad, almost all node.js project use it, we use it. didn't want to install some tool with a bunch of deps just to check if our gcloud/docker images are affected, trivy literally got supply chained two weeks ago lmao built me a small tool. stdlib only, just shells out to docker/gcloud cli. if those are compromised we're all cooked anyway. CHECK YOUR IMAGES. github.com/hacktronai/cull
@AmirMSafari Well I learned a lot trying to solve this challenge. But mainly I was reconfirmed that @kinugawamasato is basically living in browsers. Took him 1 hour 11minutes to solve it (assuming he read my message sharing this challenge frame perfect)
@shhnjk Hm does that work with img and alt text as well 🤔Would be funny especially when you have full control of the remote image
Again just a quick JS PoC (nothing new, just some PoC to try it): JS Array length of 4294967295, and push vs [][length]=value behavior. Push fails, assignment works but length value isn't increased anymore. Don't really see how this can be abused. insert-script.com/examples/javas…
Your chance to be part of a historic event for cryptography education in the Levant is still open! The CFP for Cedarcrypt, the most ambitious and exciting cryptography event in the Levant region in recent memory, has a deadline of April 10 and we still have room in the program. If you've been meaning to submit a talk, workshop, or research presentation, now's the time. We want hands-on workshops, lectures on both foundational and real-world topics, and research talks including work in progress. Topics range from post-quantum crypto and ZK proofs to secure implementation and protocol verification. We're also still actively seeking sponsors. Sponsorship funds student stipends directly — it's how we make the event accessible to grad students and early-career researchers worldwide. If your organization is in this space, let's talk. Accepted speakers get travel support, free registration, and accommodation help. July 13–16, Paphos, Cyprus. Join us in making a real difference in how real-world cryptography is taught in the Levant! Come meet and engage with excited new students! cedarcrypt.org
@rebane2001 The only solutions I can think of: Overwrite the prototypes - Number or Object use document.all as the one exception. Afaik no symbols are utilized sadly for this operator.
We take a closer look at the 2nd exploit, and sit down with @_manfp to learn about his research process. youtube.com/watch?v=NT1VCm…
Gareth Heyes \u2028 @garethheyes
40K Followers 1K Following Web security researcher at PortSwigger. Author of JS for Hackers and Hackvertor. https://t.co/akVN6ZR4C8
Ben Sadeghipour @NahamSec
253K Followers 1K Following Cofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
LiveOverflow 🔴 hex... @LiveOverflow
164K Followers 1K Following wannabe hacker... he/him 🌱 grow your hacking skills @hextreeio
shubs @infosec_au
60K Followers 2K Following Co-founder, security researcher. Building an attack surface management platform, @assetnote
@[email protected]... @SecurityMB
11K Followers 284 Following Improving the world’s security at Google. Opinions are mine.
James Kettle @albinowax
85K Followers 106 Following Director of Research at @PortSwigger aka @Burp_Suite. Find my research, tools & contact details at https://t.co/vP6UbGmvl3
STÖK ✌️ @stokfredrik
139K Followers 1K Following Hi.. im that hacker / creative that your friends told you about.,
Youssef Sammouda (sam... @samm0uda
41K Followers 597 Following Security Researcher/Hacker 1st in Meta bug bounty program for 6 years Opinions are my own and not my employer's.
Tuan Anh Nguyen⚡️... @haxor31337
16K Followers 2K Following 30 y/o Bug Bounty Hunter and Red Team Lead at Viettel Cyber Security. Brand Ambassador @Hacker0x01 - Researcher Spotlight @Bugcrowd
Harsh Jaiswal @rootxharsh
28K Followers 1K Following Co-founder and research @hacktronai | auditing at @cure53berlin | prev @zomato @vimeo @pdiscoveryio @httpvoid0x2f
Frans Rosén @fransrosen
44K Followers 911 Following Co-founder of @centrahq/@detectify/@poweredbyingrid. I do not advertise doing hacking services, do not trust the ones telling you I do.
Nicolas Grégoire @Agarri_FR
28K Followers 628 Following Web hacker and Burp Suite Pro trainer Refer to https://t.co/D5tRH7U2hg for trainings Follow @MasteringBurp for free tips and tricks
Justin Gardner @Rhynorater
39K Followers 2K Following Christian | Full-time Bug Bounty Hunter | Host of @ctbbpodcast | Advisor @CaidoIO | 4x LHE MVH | 🗣️ English, 日本語 | ♥️ @mariahchan_ ♥️
Soroush Dalili @irsdl
20K Followers 949 Following Hacker (ethical), web appsec specialist, trainer, tools builder & apps breaker 🕸️https://t.co/YipuTcYnWc🥷 🍏A dad-joke maker🍐
ϻг_ϻε @steventseeley
23K Followers 564 Following Artist disguised as a logician. Pwn2Own Winner. Spiritual Alchemy. An adept in the making.
InfoSec Community @InfoSecComm
57K Followers 634 Following Largest InfoSec publication with 80,000+ followers and 3M+ monthly views.
spaceraccoon | Eugene... @spaceraccoonsec
26K Followers 314 Following Author of "From Day Zero to Zero Day" - No Starch Press. Every day is 0day! Personal profile - all opinions expressed are my own.
lcamtuf @lcamtuf
41K Followers 499 Following Blog: https://t.co/j7rfeVwqXc Homepage: https://t.co/iFAXZxCgg9
adi @kxrma_74
2 Followers 46 Following
Venkata Satish Guttul... @snakeyesV1
3K Followers 4K Following Ex-CISO https://t.co/E3wzyAP4qW | vCISO | Cybersecurity Advisor, Auditor, Academic Board Member
Freddy @Freddycrur
36 Followers 2K Following
Hiranmaya Panda @Hiranmaya_007
23 Followers 2K Following
Nick Aliferopoulos @naliferopoulos
154 Followers 416 Following Opinions are my own. Uncool hax are my own. Cool hax are other peoples' hax.
khizar Abbas @khizarAbbaz7vr
7 Followers 80 Following
Eric @Ericddo_
3 Followers 816 Following
Shivasai_challa @mr_cyborgboy
384 Followers 1K Following Interested in Software Security | Life Long Learner | Love to learn, how things work under the hood | Always Philosophically intrigued.
Abdulrazzaq Alsamawi @Abderzaq_samawi
20 Followers 2K Following Cybersecurity Engineer | Penetration Tester | Security Analyst | DFIR | DevSecOps
Mogtaba @MOGTABA_X
23 Followers 874 Following
Abdelkrim @ASn4k3y3
26 Followers 1K Following
Gajji @gajji_bhatti
9 Followers 423 Following
Chandra sri shekhar P @_Obsidium
3 Followers 76 Following CSE student curious how things work under the hood. Building backend w/ Spring Boot. New to cybersecurity & CTFs, learning fundamentals first.
streaak @streaak
7K Followers 785 Following BBAC kidnapped me | I hack things, play video games and occasionally take photographs
Marvin Amador @kyl4nprax
67 Followers 1K Following Investigador de Seguridad (CEH | CTIA | CompTIA Network+) | Pasatiempo: Análisis de Malware y Cacería de Amenazas… Happy Hunting!!! #SISAP #MakeITsecure
Florence @Florenceui8w
299 Followers 7K Following
yagyu @YagyuKagura
8 Followers 493 Following
MHG 🇵🇸 @NeverGiveUP8333
141 Followers 752 Following Nothing Interesting here, it's just me grinding to find bugs
spoderx555 @spoderx555
33 Followers 220 Following
CyberHelper @cyberhelpmllm
1 Followers 34 Following
jack @NobodySpac51299
0 Followers 119 Following
zinox @zinox1631808
2 Followers 83 Following Cybersecurity Hacker | Bug Bounty Hunter🪲 Loves learning, experimenting, and discovering bugs.
Alex_ @Alex_ctf_
172 Followers 807 Following 🇫🇷 Bug bounty hunter CTF player (Web/RE) @idekCTF & ECSC Team France 2023
Ishfaq Fariq @ishfaq_fariq
169 Followers 2K Following Cybersecurity Engineer| Frontend Developer | Application Security Engineer | Red Teamer | Software Engineer |
lam @AcrapX
19 Followers 1K Following
sof @sofilipp_
2 Followers 55 Following
vladimir metnew @v_metnew
4K Followers 416 Following perpetually playing weird gambling games with computational machines
Mahmoud Sherif @Mahmoudp90
340 Followers 2K Following Penetration Tester💻 | Don’t tell people your plans. Show them your results.
Binanio @b1n4n1o
0 Followers 227 Following
xD @xD140011
21 Followers 443 Following
qu1zo @472quizo
8 Followers 869 Following
Bornunique911 @bornunique911
593 Followers 4K Following Self-taught Cybersecurity enthusiast | 500+ rooms on TryHackMe & HTB | 100+ CTF's via https://t.co/I0tVpqLFOP | CompTIA Sec+ Certified | Always learning & growing
oxqat3any @HZayeid
18 Followers 555 Following
Rebane @rebane2001
16K Followers 2K Following 🇪🇪🏳️⚧️ | Archivist | 13 CVEs in Chrome | CSS sophomore | MapartCraft | Puppy | Horse | rebane2001#3716 | Lyra (she/it) 🦊 @[email protected]
zerobatman @zerob4tman
4 Followers 126 Following
Houssam Miliani @N0rmalizer_
82 Followers 826 Following
Intigriti @intigriti
216K Followers 671 Following Bug bounty & VDP platform trusted by the world’s largest organisations! 🌍
Gareth Heyes \u2028 @garethheyes
40K Followers 1K Following Web security researcher at PortSwigger. Author of JS for Hackers and Hackvertor. https://t.co/akVN6ZR4C8
Ben Sadeghipour @NahamSec
253K Followers 1K Following Cofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
LiveOverflow 🔴 hex... @LiveOverflow
164K Followers 1K Following wannabe hacker... he/him 🌱 grow your hacking skills @hextreeio
PentesterLab @PentesterLab
209K Followers 0 Following Don’t just learn tools and payloads. Learn why vulnerabilities exist. Hands-on web hacking, security code review, and real-world CVE labs.
@[email protected]... @SecurityMB
11K Followers 284 Following Improving the world’s security at Google. Opinions are mine.
Nicolas Krassas @Dinosn
162K Followers 792 Following Head of Threat & Vulnerability Mgmt @ Henkel AG & Co. KGaA https://t.co/NC1orlKZLB Posting content that I find interesting.
PortSwigger Research @PortSwiggerRes
124K Followers 7 Following Web security research from the team at @PortSwigger
chompie @chompie1337
90K Followers 1K Following hacker, exploit developer/weird machine mechanic head of X-Force Offensive Research (XOR) @IBM
James Kettle @albinowax
85K Followers 106 Following Director of Research at @PortSwigger aka @Burp_Suite. Find my research, tools & contact details at https://t.co/vP6UbGmvl3
STÖK ✌️ @stokfredrik
139K Followers 1K Following Hi.. im that hacker / creative that your friends told you about.,
Binni Shah @binitamshah
140K Followers 159 Following Linux Evangelist, Malwares, Security enthusiast ,Investor,World Economy, Finance,Contrarian , Philanthropist , Reformist , Sigma female [email protected]
Frans Rosén @fransrosen
44K Followers 911 Following Co-founder of @centrahq/@detectify/@poweredbyingrid. I do not advertise doing hacking services, do not trust the ones telling you I do.
Nicolas Grégoire @Agarri_FR
28K Followers 628 Following Web hacker and Burp Suite Pro trainer Refer to https://t.co/D5tRH7U2hg for trainings Follow @MasteringBurp for free tips and tricks
Justin Gardner @Rhynorater
39K Followers 2K Following Christian | Full-time Bug Bounty Hunter | Host of @ctbbpodcast | Advisor @CaidoIO | 4x LHE MVH | 🗣️ English, 日本語 | ♥️ @mariahchan_ ♥️
Soroush Dalili @irsdl
20K Followers 949 Following Hacker (ethical), web appsec specialist, trainer, tools builder & apps breaker 🕸️https://t.co/YipuTcYnWc🥷 🍏A dad-joke maker🍐
ϻг_ϻε @steventseeley
23K Followers 564 Following Artist disguised as a logician. Pwn2Own Winner. Spiritual Alchemy. An adept in the making.
ippsec @ippsec
125K Followers 373 Following
lcamtuf @lcamtuf
41K Followers 499 Following Blog: https://t.co/j7rfeVwqXc Homepage: https://t.co/iFAXZxCgg9
skull @brutecat
9K Followers 410 Following security @google. 21. i run a blog @ https://t.co/cBW6gzSS5u
AmirMohammad Safari @AmirMSafari
8K Followers 418 Following Part-time bug hunter, full-time thinker of thoughts nobody asked for
Nowasky @nowaskyjr
2K Followers 100 Following Ademar Nowasky Junior | Sponsor my research: https://t.co/USVXKJdest
Sonar Research @Sonar_Research
11K Followers 5 Following Cutting-edge security research by @SonarSource to educate the world about code security across all software. We're also at @[email protected] 🦣
Rebane @rebane2001
16K Followers 2K Following 🇪🇪🏳️⚧️ | Archivist | 13 CVEs in Chrome | CSS sophomore | MapartCraft | Puppy | Horse | rebane2001#3716 | Lyra (she/it) 🦊 @[email protected]
Martin Doyhenard @tincho_508
3K Followers 228 Following Security Researcher. Speaker at BlackHat, DEF CON, RSA, Hack In The Box, Troopers, EkoParty
Jorian @J0R1AN
3K Followers 453 Following Normalize being weird. (also here: https://t.co/cr9Y0kDEBi)
Hacktron AI @HacktronAI
10K Followers 12 Following Hacktron is an autonomous vulnerability hunter for ambitious engineering teams. Built by world-class security researchers. Powered by one principle: PoC || GTFO
slonser @slonser_
5K Followers 222 Following Co-Founder @neploxaudit. CTF team @C4TBuTS4D Security Researcher.
Valentino Massaro @valent1nee
1K Followers 143 Following
PraSec @PraSec_conf
139 Followers 0 Following PraSec (Prague Security) is an IT security (hacking if you prefer) event which brings together similarly minded people from our beloved industry.
splitline 👁️🐈... @_splitline_
3K Followers 638 Following 友民党 / CTF with ${cYsTiCk} / script kiddie at @d3vc0r3 / Tâi-gí, zh-TW, en-US, es-PY / 🐈⬛
Chris Evans @scarybeasts
25K Followers 199 Following CISO and Chief Hacking Officer at HackerOne. Past: Founded {vsftpd, Chrome security, Google Project Zero}; Tesla; Dropbox. Hacker / Researcher. beebjit.
GMO Flatt Security In... @flatt_sec_en
930 Followers 1 Following Building AI that finds & fixes web security bugs — autonomously. SOTA in white-box bug hunting. Try Takumi: https://t.co/zruO7dgEcc
RyotaK @ryotkak
12K Followers 656 Following Security researcher? | Icon: @MelvilleTw | Private: @RyotaK_Private | Misskey: https://t.co/63E5Rpv2pk | Blog: https://t.co/c7NFQXhV90
Simone Margaritelli @evilsocket
48K Followers 2K Following Co-founder & CTO @ @usemilgram • Author of bettercap, pwnagotchi, opensnitch, bleah, legba and a few other things.
Erik Donker @kire_devs_hacks
634 Followers 469 Following I develop stuff and I hack things. #6 Microsoft MSRC 2024 Most Valuable Researcher. Two times consecutive #1 Dynamics 365/Power Platform security researcher.
Gal Weizman @WeizmanGal
2K Followers 574 Following Security & Vulnerability Research of Browsers & AI
Kévin GERVOT (Mizu) @kevin_mizu
7K Followers 798 Following Vulnerabilty researcher at @assetnote 🐛 | DOMLogger++ developer 👨🏻💻 | CTF with @FlatNetworkOrg, @rhackgondins 🦦 | @ECSC_TeamFrance 2023 🇫🇷
David Buchanan does n... @David3141593
17K Followers 752 Following add my blog to your RSS reader or something. also @[email protected], at://retr0.id
h43z @h43z
5K Followers 406 Following Interested in the unexpected - js, web, security, linux, mind, religion, drugs, history, psychology, culture, freedom and trailrunning
Chromium Disclosed Se... @BugsChromium
7K Followers 0 Following Tweets publicly disclosed bugs in Chromium. Not an official Google product. Run by @SecurityMB. Mastodon: @[email protected]
C:\hristian Mehlmauer @firefart
3K Followers 3K Following I hacked the planet - opinions are my own - Mastodon: https://t.co/FTAelGh7DO
BrunoZero @BrunoModificato
2K Followers 439 Following CTFer for: @Water_Paddler / Security auditor @osec_io my writeups: https://t.co/XurIhbWdj7 24y
Arseniy Sharoglazov @_mohemiv
4K Followers 253 Following Penetration Tester at Positive Technologies, likes to share what I learn with others | @ptswarm
Jakob Inf @JakobInf
7 Followers 8 Following
Renwa @RenwaX23
10K Followers 64 Following
SentinelOne @SentinelOne
58K Followers 1K Following ONE autonomous platform to prevent, detect, respond, and hunt. Do more, save time, secure your enterprise: https://t.co/N75g1HAnCs 🐱💻
ΡΛSCΛLSΞC @PascalSec
4K Followers 498 Following 👨💻 Team Lead Sol. Engineering @Intigriti 📺 Hacking Content Creator at @Hacksplained (paused) Views are my own and don't reflect the views of my employer.
Reconless @0xReconless
6K Followers 3 Following Security research, blogs, and videos by @filedescriptor, @ngalongc & @EdOverflow YouTube: https://t.co/IGj1aW40ro
SecuriTEA & Crumpets @SecuriTnC
193 Followers 60 Following Talking all things security with professionals, hosted by @LewisArdern Upcoming Guest: Gareth Heyes - PortSwigger Join the community! https://t.co/6m1KmgQENr






























