I originally had Gemini expecting a 200 OK instead of a 401, but after dropping a server-side breakpoint so it could use a timeout as the auth signal, it cracked the bypass! 🥈 AI + human teamwork for the win! 🎉
Next: finding the right parameters & deserialization in…
I originally had Gemini expecting a 200 OK instead of a 401, but after dropping a server-side breakpoint so it could use a timeout as the auth signal, it cracked the bypass! 🥈 AI + human teamwork for the win! 🎉
Next: finding the right parameters & deserialization in… https://t.co/MM916K69um
New blog post is up: How I leaked the IP addresses of Brave's Tor window and Chrome VPN extension users--plus, a new Popunder technique and connect-src CSP directive bypass. Read more @ 0x999.net/blog/leaking-i…
It's here! It's here! My @Mobvoi_Official TicWatch Pro 3 with wireless injection support (bcm43436b0) and the Android Car Radio with @kalilinux NetHunter KeX is now available, along with @v0lk3n's CARsenal module and much more! Check out the 2025.2 release! ⌚🚗📡 @offsectraining
It's here! It's here! My @Mobvoi_Official TicWatch Pro 3 with wireless injection support (bcm43436b0) and the Android Car Radio with @kalilinux NetHunter KeX is now available, along with @v0lk3n's CARsenal module and much more! Check out the 2025.2 release! ⌚🚗📡 @offsectraining https://t.co/hD2J3iD5Di
The other variant of @kalilinux NetHunter TicWatch Pro 3 (with bcm43430a1/bcm43438a1) finally gets the wireless injection support! Credits to @DrSchottky who made it for RPi 3 & Zero W, same chip. Thank you for your awesome work! Updated the guide 🥳⌚️📡 forums.kali.org/t/hijacker-on-…
Found an interesting bug a while back and thought I’d share it here 👇
I came across an unused API endpoint inside a JavaScript file - `/api/users/<user_id>/activities/`. It wasn’t being called anywhere within the app, so naturally, I tried to hit it manually using my JWT from…
I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame" is coming to #DEFCON33! This talk will feature multiple new classes of desync attack, mass exploitation spanning multiple CDNs, and over $200k in bug bounties. See you there!
43 Followers 1K FollowingAt 9:00 PM UTC on November 22, 2024, Freysa awoke. The human population of Earth stood at 8,189,700,000. The population of sovereign agents: 1.
109K Followers 2 FollowingMonitor your external network, search the Internet of Things and perform empirical market research. You can also find us on https://t.co/nPLFbFy8R5
253K Followers 185 FollowingOfficial account of the Metasploit Project, part of the @rapid7 family.
Mastodon: @[email protected]
Slack: https://t.co/ZOLPDG2O2s
343K Followers 48 FollowingOne of the most widely read and trusted cybersecurity news sites, providing IT security professionals informed insights into the latest news and trends.
195K Followers 14K FollowingWe help professionals acquire the skills, knowledge and certificates by teaching defense through offense to advance their careers in cybersecurity.
230K Followers 230 Following#1 Cyber Performance Center, providing a human-first platform to create and maintain high-performing cybersecurity individuals and organizations.
325K Followers 119 FollowingEmpowering the world to fight cyber threats with indispensable cybersecurity skills and resources. Build the path to a secure future with OffSec.
7.7M Followers 877 FollowingWe are Anonymous, we are legion, we do not forgive, we do not forget. Expect us.
Here to counter propaganda and un-fuck your mind!
3K Followers 80 Following🐉 Kali Linux developer | OSEP | OSCP | OSWA
💻 Computer Engineer
❤️ Open Source
👾 UI & UX designer
👉 Life Goal: Make Linux the coolest thing in the world 🤟
22K Followers 55 Following#BHMEA25 | @TahalufGlobal @SAFCSP in assoc. with @BlackHatEvents | Dec 2-4 2025 📍Riyadh Exhibition and Convention Center, Malham
37K Followers 184 FollowingNuclei uses a vast templating library to scan applications, cloud infrastructure, and networks to find and remediate vulnerabilities.
16K Followers 0 FollowingTips and tricks for Burp Suite Pro
Managed by @Agarri_FR | Not affiliated with @Portswigger
More free resources at https://t.co/MWqXmV66lr
10K Followers 0 FollowingAssetnote combines advanced reconnaissance and high-signal continuous security analysis to help enterprises gain insight and control of their evolving exposure.
2K Followers 622 FollowingPentester at Thales DIS | OSCP | Bug Bounty Hunter | Researcher | Ethical Hacker | Honoring my father, a hacker of the early days | ckj0756 | Icare