@foo125973i
iAccount based inKazakhstan
About this account
- Account based in
- Kazakhstan
- Connected via
- Kazakhstan Android App
Account-level information from X, not a live location or the device used for a specific post.
Joined August 2025
- Tweets190
- Following82
- Followers4
- Likes6K
"3 random dudes”
1. hacked apple, again and again.
httpvoid.com/Apple-RCE.md
httpvoid.com/Hello-Lucee!-Le…
httpvoid.com/Hacking-Apple-w…
2. your github enterprise is our github enterprise.
httpvoid.com/GitHub-Enterpri…
3. get a discord message from me, get pwned.
hacktron.ai/blog/discord-rce
youtube.com/watch?v=R3SE4VKj…
4. oh yeah, at one point we basically had shells across the electron ecosystem. check the DEF CON research.
media.defcon.org/DEF%20CON%2…
5. your supabase database is my database.
hacktron.ai/blog/supapwn
6. we got the posthog prod database.
hacktron.ai/blog/posthog-rce
7. react2shell? vercel paid us $170k for helping secure their waf.
hacktron.ai/blog/react2shell…
8. your palo alto vpn is my vpn.
hacktron.ai/blog/cve-2026-02…
9. ai ides? we got shells for you, antigravity
hacktron.ai/blog/hacking-goo…
10. windsurf rce.
youtube.com/watch?v=23Mz7qcR…
11. turning cluely into malware.
hacktron.ai/blog/hacking-clu…
12. ai browsers? sure, uxss: your perplexity browser is my browser.
hacktron.ai/blog/perplexity-…
13. openai atlas too. kinda uxss
hacktron.ai/blog/hacking-ope…
14. hey, it’s not even our first time hacking discourse.
projectdiscovery.io/blog/dis…
15. adobe coldfusion: pre-auth rce. because apparently we needed another one.
projectdiscovery.io/blog/ado…
there’s a lot more. go dig.
anyway, yes: “3 random dudes.”
and @HacktronAI is full of more random dudes like these.
“Security researchers are doomed because of AI.”
I kept hearing versions of this, so I went back through 500 years of people saying the same thing every time a machine learned a human skill.
Some were idiots.
Some were right.
Here’s where I landed.
foo retweeted
Everyone except me ? We are in fact still in court over this.
Over the past several days, we have been listening to the conversation around coordinated disclosure and the relationship between security researchers and vendors. We recognize that this relationship is both critical and, at times, fragile. We deeply value the security community, and will continue to take your feedback seriously.
To be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research. When an individual breaks the law and engages in malicious activity causing real harm to our customers, we will work with law enforcement as appropriate.
We recognize the work that goes into researching and submitting a vulnerability. We are committed to approaching every interaction with transparency, clear communication, and professionalism. We continue to believe strongly in Coordinated Vulnerability Disclosure as the foundation for protecting customers and improving our products. Each year we process a high volume of vulnerability reports. That volume continues to grow and will continue with the rise of AI-enabled research. We acknowledge that some interactions have fallen short and are working to learn from them.
Many of us have experience on both sides of this work, as researchers reporting vulnerabilities and as responders triaging and assessing them. That perspective informs how we approach this feedback and the importance we place on getting it right, particularly as the volume and complexity of research continues to grow.
The security community plays a vital role in helping us protect customers. We are committed to maintaining a constructive and respectful relationship and growing together. We know that, given the nature of this work, there will at times be misunderstandings. We remain committed to engaging in good faith and to providing a respectful and professional experience for all researchers, regardless of past interactions.
Readers added context they thought people might want to know
This claim, however comes after they threatened to take legal action against Nightmare Eclipse a security researcher, over Zero Day exploits. The security researcher was also banned on Github for their research and a consequent ban from Gitlab as well.
theverge.com/tech/940416/mi…
tomshardware.com/tech-industry/…
foo retweeted
Happy Birthday Ijichi Nijika!!! 💛💙
#BocchiTheRock #ぼっち・ざ・ろっく
foo retweeted
Exciting news: we have teamed up with @intigriti
Bug hunters can now earn a FREE 6-month Burp Suite Professional license by hitting 400 reputation points on Intigriti.
More power. Deeper testing. Bigger impact.
Happy hunting 🐝
#BugBounty #Intigriti #BurpSuite
I wrote about how LLMs broke CTF competitions over on Mastodon.
vt.social/deck/@lina/1161989…
this is one of the most sophisticated exploits I have ever seen. She makes "I have reverse engineered the firmware" sound so simple. making this exploit chain in just 7 days is insane, I can understand why @CyanNyan6 was intimidated, now I'm intimidated too. bless your wedding
I hacked macOS and got credited on apple.com
And then I did a collab about it with my VTuber inspiration @CyanNyan6 and we accidentally fell in love with each other 🩵
youtube.com/shorts/ToulgVAof…
youtube.com/shorts/lRcvh3tVV…
People forget how dangerous internet can be, even if there is no physical danger. This is even more relevant today, isn't it?