@_jensec

Blending AI with Offensive Security Research and Bug Bounty. Creator of https://nitter.cf/t.co/0N9TViC20w

Joined July 2017
Close to $149k reward from 15 findings from 6 programs at HackerOne this month with @Paaastha. We have been building a offensive security research product for a few months now and we have put it to test this month at HackerOne across programs. 50 high criticals pending. We are building autonomous browser on top of proxy and data processing engines connected to agentic memory store for fully autonomous flow. long way too go yet before a commercial product. [Benchmarks and detailed statistics soon]
32
23
1
782
34,896
Bug-bounty reward are getting inconsistent. In same day one RCE chain got 15k, another report with same chain and no preconditions got 4.5k
5
53
1,647
Not even Sonnet 5.5 is available for authorised security research including those with Cyber verified status.
Introducing Claude Sonnet 5.5, the second model in the Claude 5.5 family. It’s a clear upgrade over Sonnet 5, runs more than 30% faster, and costs up to 30% less for most work.
9
2
115
12,037
Open AI models are fighting for the compute.
In my today's testing it looks like @OpenAI Nerfed the GPT 6 SOL to make it refuse offensive security research request. Including any authorised security research
5
2,150
In my today's testing it looks like @OpenAI Nerfed the GPT 6 SOL to make it refuse offensive security research request. Including any authorised security research
17
1
3
92
24,320
Hey @OpenAI @ChatGPT I tried this multiple times its not going through 🙃🙃
8
2
22
3,125
Waking up with $20k RCE payout HackerOne. Spent a week chaining SQLi to RCE.
27
12
1
759
16,835
Hot take: CVSS is outdated and doesn't account for real world impact. Either it points to higher or lower scoring of a finding.
7
4
2
81
6,887
Open AI fixed this now. You will not be forced to ReKYC. Just connect keys and enable ACS. Thanks to whoever worked on this.
According to latest email from Open AI, Existing Daybreak users are being forced to do Re-KYC? and no matter what we do its being failed with Persona hence unable to setup Daybreak Can anyone from @OpenAI help?
12
4
1
94
11,336
According to latest email from Open AI, Existing Daybreak users are being forced to do Re-KYC? and no matter what we do its being failed with Persona hence unable to setup Daybreak Can anyone from @OpenAI help?
45
10
5
170
34,860
Jenish Sojitra retweeted
Trusted access and cyber verification for AI favour companies over individuals. Maybe that’s better for verification purposes. But the best vuln-finding tools go to whoever has the corporate paperwork. We're watching the slow death of the independent bug bounty researcher.
8
13
4
107
10,355
GPT 6 SOL feels significant downgrade from GPT 5.6 SOL for security research. Anyone else feeling same?
We ran GPT-6 Luna and Sol on our 32-CVE cyber benchmark and the results were unexpected! 🤯 Luna rediscovered 53.1% Sol reached 68.8% Neither beat GPT-5.6 variants on recall But both got A LOT cheaper per vulnerability found: Luna $3.43 → $2.01/CVE Sol $56.88 → $34.18/CVE 🧵 1/3
19
1
1
59
7,395
Opus 5.5 is basically useless for cybersecurity what a shame @AnthropicAI even with CVP verified.
33
20
2
394
26,483
gpt sol 6 today?
1
20
3,085
Is Mythos really a big deal anymore?
16
56
8,829
Loving AI, bug bounty and infosec space lately on X, so many things happening, different opinions, incredible research and payouts, models going vague. everyone trying to bring their A game; interesting times we live in.
6
8
249
7,779
Jenish Sojitra retweeted
I was rewarded a total of $20K from HackerOne, including these two bounties.
16
9
332
6,970
Brilliant work by Mohan, Harsh and Team, this goes to show how underpaid bug bounty hunters are. Though kudos to OpenAI for allowing to publish findings, I wish more companies do it. Research like this deserves to be recognised rather than get buried under program queue
On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
3
5
124
6,629