@_CryptoCati
iAccount based inUnited Kingdom
About this account
- Account based in
- United Kingdom
- Connected via
- United Kingdom Android App
Account-level information from X, not a live location or the device used for a specific post.
Security Researcher @rapid7 😈 Hacking Content @ https://nitter.cf/t.co/U7jVhNr9sC 💜
Not Here
Joined May 2016
- Tweets8.2K
- Following239
- Followers9K
- Likes88.9K
Pinned Tweet
Want to become an ethical hacker? 🥷 Here's a list of my favourite [mostly practical] resources 📚
They are all free (or have a free option) and there's more high quality material here than anybody realistically has the time to complete ⏳
Never seen a con upload talks as fast as @brucon 🔥 I was super nervous for this ngl. Planning to record a better run at some stage, but for now if you wanna check out the live one - here it is! 💌
youtu.be/NkM4UT2z0wc
5 min from the airport and @KLM cancel my direct flight to Amsterdam, exchange it for a non-direct flight 24 hours later.. So, I lose my accommodation and miss my train to Belgium tomorrow. I hate airlines so much 👎
To read private chat rooms in Better Messages, just tell it you're the AI bot. Identity was an IP-prefix check, and the IP came from a request header 🤖
cryptocat.me/blog/research/a…
Found an SQL injection in WCFM Marketplace, the WooCommerce multivendor plugin. A guest's checkout coordinates flow straight into a store-distance query, enough to read WordPress password hashes. CVE-2026-18442, fixed in 3.8.2, $134 bounty.
cryptocat.me/blog/research/a…
On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
I can't believe it's not XSS! 😱
cryptocat.me/blog/research/a…
Got something different for y'all today!
j/k, it's more XSS 😅
cryptocat.me/blog/research/a…
Got my first bounties today on @hackrate 🥳 Shout-out to the team, they've been awesome! 💜
Another day, another XSS. Got $5 for this one! 🤑
cryptocat.me/blog/research/a…
An unauth stored XSS I found was disclosed yesterday.
TLDR: X-Forwarded-For header gets logged as your IP without ever being checked, then runs in the admin's browser when they open the error log 😈
cryptocat.me/blog/research/a…
CryptoCat retweeted
> ShinyHunters attacker also claimed to have collected legitimate HackerOne payouts of $2k and $5k from 2 of the companies they infiltrated and extorted, treating BugBounty programs and intrusion as additional revenue streams against the same targets they were compromising.
💀
We're publishing our most detailed threat intelligence report to date.
It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them.
We disrupted every operation in the report, and used the lessons from them to strengthen our safeguards. Where appropriate, we also shared what we found with authorities and other AI companies.
These cases are not typical: we’re highlighting some of the most sophisticated misuse we’ve seen. But they’re especially important to discuss, because they show us where AI misuse is headed, where our safeguards work, and where they need to improve.
We’re publishing this report so others can spot the same activity on their own platforms, and so we can give the public a clearer view of how emerging threats develop.
Read the report: anthropic.com/threat-intelli…