@_jenseci
iAccount based inIndia
About this account
- Account based in
- India
- Connected via
- India App Store
Account-level information from X, not a live location or the device used for a specific post.
Blending AI with Offensive Security Research and Bug Bounty. Creator of https://nitter.cf/t.co/0N9TViC20w
Joined July 2017
- Tweets2.2K
- Following620
- Followers25.1K
- Likes8.7K
Pinned Tweet
Close to $149k reward from 15 findings from 6 programs at HackerOne this month with @Paaastha.
We have been building a offensive security research product for a few months now and we have put it to test this month at HackerOne across programs. 50 high criticals pending.
We are building autonomous browser on top of proxy and data processing engines connected to agentic memory store for fully autonomous flow. long way too go yet before a commercial product.
[Benchmarks and detailed statistics soon]
Bug-bounty reward are getting inconsistent. In same day one RCE chain got 15k, another report with same chain and no preconditions got 4.5k
Open AI models are fighting for the compute.
In my today's testing it looks like @OpenAI Nerfed the GPT 6 SOL to make it refuse offensive security research request. Including any authorised security research
Hot take: CVSS is outdated and doesn't account for real world impact. Either it points to higher or lower scoring of a finding.
Open AI fixed this now. You will not be forced to ReKYC. Just connect keys and enable ACS. Thanks to whoever worked on this.
According to latest email from Open AI, Existing Daybreak users are being forced to do Re-KYC? and no matter what we do its being failed with Persona hence unable to setup Daybreak
Can anyone from @OpenAI help?
Jenish Sojitra retweeted
Trusted access and cyber verification for AI favour companies over individuals. Maybe that’s better for verification purposes. But the best vuln-finding tools go to whoever has the corporate paperwork. We're watching the slow death of the independent bug bounty researcher.
GPT 6 SOL feels significant downgrade from GPT 5.6 SOL for security research. Anyone else feeling same?
Opus 5.5 is basically useless for cybersecurity what a shame @AnthropicAI even with CVP verified.
Loving AI, bug bounty and infosec space lately on X, so many things happening, different opinions, incredible research and payouts, models going vague. everyone trying to bring their A game; interesting times we live in.
Jenish Sojitra retweeted
I was rewarded a total of $20K from HackerOne, including these two bounties.
Brilliant work by Mohan, Harsh and Team, this goes to show how underpaid bug bounty hunters are.
Though kudos to OpenAI for allowing to publish findings, I wish more companies do it. Research like this deserves to be recognised rather than get buried under program queue