@_CryptoCat

Security Researcher @rapid7 😈 Hacking Content @ https://nitter.cf/t.co/U7jVhNr9sC 💜

Not Here
Joined May 2016
Want to become an ethical hacker? 🥷 Here's a list of my favourite [mostly practical] resources 📚 They are all free (or have a free option) and there's more high quality material here than anybody realistically has the time to complete ⏳
28
326
5
1,256
131,970
Never seen a con upload talks as fast as @brucon 🔥 I was super nervous for this ngl. Planning to record a better run at some stage, but for now if you wanna check out the live one - here it is! 💌 youtu.be/NkM4UT2z0wc
1
3
20
1,373
Presented my @rapid7 research at @brucon today! Thank you to everyone for listening, hope you enjoyed it 🙂 – at Mechelen, Belgium
2
45
1,000
Hacker hangout with @ahmed_vapt 💜 – at Mechelen, Belgium
3
1
38
2,672
Excited (and nervous) to announce that I'll be presenting some of my (@rapid7) 0day research @brucon on Thursday, 2:30pm 💌 "Signed, Sealed, Compromised: Weaponizing Enterprise Mail Infrastructure"
4
4
1
53
2,253
5 min from the airport and @KLM cancel my direct flight to Amsterdam, exchange it for a non-direct flight 24 hours later.. So, I lose my accommodation and miss my train to Belgium tomorrow. I hate airlines so much 👎
6
6
1,663
Back in the airport, let's try again! 🤞
1
1
169
Found an SQL injection in WCFM Marketplace, the WooCommerce multivendor plugin. A guest's checkout coordinates flow straight into a store-distance query, enough to read WordPress password hashes. CVE-2026-18442, fixed in 3.8.2, $134 bounty. cryptocat.me/blog/research/a…
3
4
31
1,580
CryptoCat retweeted
On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
354
1,397
544
11,854
2,799,360
> builds technology that could literally destroy the world > max bounty: $10k ($0 for model safety issues) we're cooked 💀💀💀
4
13
2
254
14,711
Got my first bounties today on @hackrate 🥳 Shout-out to the team, they've been awesome! 💜
4
21
1,432
CryptoCat retweeted
> ShinyHunters attacker also claimed to have collected legitimate HackerOne payouts of $2k and $5k from 2 of the companies they infiltrated and extorted, treating BugBounty programs and intrusion as additional revenue streams against the same targets they were compromising. 💀
We're publishing our most detailed threat intelligence report to date. It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them. We disrupted every operation in the report, and used the lessons from them to strengthen our safeguards. Where appropriate, we also shared what we found with authorities and other AI companies. These cases are not typical: we’re highlighting some of the most sophisticated misuse we’ve seen. But they’re especially important to discuss, because they show us where AI misuse is headed, where our safeguards work, and where they need to improve. We’re publishing this report so others can spot the same activity on their own platforms, and so we can give the public a clearer view of how emerging threats develop. Read the report: anthropic.com/threat-intelli…
3
14
3
281
35,270