DC3 VDP (@dc3vdp) 's Twitter Profile
DC3 VDP

@dc3vdp

Official Twitter account of the U.S. DoD Vulnerability Disclosure Program (VDP).

ID: 1081215337603960833

linkhttps://www.dc3.mil/Missions/Vulnerability-Disclosure/Vulnerability-Disclosure-Program-VDP/ calendar_today04-01-2019 15:46:39

409 Tweet

4,4K Followers

114 Following

DC3 VDP (@dc3vdp) 's Twitter Profile Photo

NOV 2024 Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ Vulnerability Disclosure Program (#VDP) #Hacker0x01 DoD VDP received a critical severity submission detailing the presence of AWS instances and SMTP server credentials within public configuration files. Read all about it in the #Knowledgebyte.

NOV 2024 <a href="/DeptofDefense/">Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ</a> Vulnerability Disclosure Program (#VDP) #Hacker0x01 DoD VDP received a critical severity submission detailing the presence of AWS instances and SMTP server credentials within public configuration files. Read all about it in the #Knowledgebyte.
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

A huge shoutout to Roy Solberg (Roy Solberg) for closing out the year with an incredible achievement! From RXSS and SSRF to database extractions, your detailed findings have significantly bolstered DoD cybersecurity. Thank you for your dedication and expertise! #InfoSec #DoDVDP

A huge shoutout to Roy Solberg (<a href="/roysolberg/">Roy Solberg</a>) for closing out the year with an incredible achievement! From RXSS and SSRF to database extractions, your detailed findings have significantly bolstered DoD cybersecurity. Thank you for your dedication and expertise! #InfoSec #DoDVDP
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

Big thanks to @Grammatic for uncovering critical SQL injection vulnerabilities. Your diligence helps us safeguard our systems and protect sensitive data. ย #DIBVDP #CyberSecurity #InfoSec #WebSecurity #EthicalHacking

Big thanks to @Grammatic for uncovering critical SQL injection vulnerabilities. Your diligence helps us safeguard our systems and protect sensitive data. ย #DIBVDP #CyberSecurity #InfoSec #WebSecurity #EthicalHacking
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

Dec 2024 Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ Defense Industrial Based Vulnerability Disclosure Program #DIBVDP #Hackers reported a vulnerability involving SQL Injection which could have led to dumping sensitive data. Read all about it in the #KnowledgeByte.

Dec 2024 <a href="/DeptofDefense/">Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ</a> Defense Industrial Based Vulnerability Disclosure Program #DIBVDP #Hackers reported a vulnerability involving SQL Injection which could have led to dumping sensitive data. Read all about it in the #KnowledgeByte.
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

DEC 2024 Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ Vulnerability Disclosure Program #VDP #Hacker0x01 DoD VDP received a critical severity submission detailing a vulnerability that allowed for the extraction of database contents from a Lotus Domino Server. Read all about it in the #Knowledgebyte.

DEC 2024 <a href="/DeptofDefense/">Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ</a> Vulnerability Disclosure Program #VDP #Hacker0x01 DoD VDP received a critical severity submission detailing a vulnerability that allowed for the extraction of database contents from a Lotus Domino Server. Read all about it in the #Knowledgebyte.
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

๐Ÿšจ Privacy Alert! ๐Ÿšจ Jared Hrabak (H1 user badlifeguard) uncovered a serious vulnerability in an internal system exposing military members sensitive information. His vigilance is protecting our service members. Thank you for your dedication! #CyberSecurity #DoDSecurity #InfoSec

๐Ÿšจ Privacy Alert! ๐Ÿšจ Jared Hrabak (H1 user badlifeguard) uncovered a serious vulnerability in an internal system exposing military members sensitive information. His vigilance is protecting our service members. Thank you for your dedication! #CyberSecurity #DoDSecurity #InfoSec
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

Huge thanks to ใ‹ใฟใกใ‚ƒใ‚“ for uncovering the critical JWT info disclosure vulnerability! Your dedication to improving web security helps protect us all. This finding highlights the risks that could impact security frameworks. Stay vigilant! ๐Ÿ” #DIBVDP #CyberSecurity #EthicalHacking

Huge thanks to <a href="/dox69/">ใ‹ใฟใกใ‚ƒใ‚“</a> for uncovering the critical JWT info disclosure vulnerability! Your dedication to improving web security helps protect us all. This finding highlights the risks that could impact security frameworks. Stay vigilant! ๐Ÿ” #DIBVDP #CyberSecurity  #EthicalHacking
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

JAN 2025 Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ Vulnerability Disclosure Program (#VDP) #Hacker0x01 #Hackers reported a critical severity in GraphQL API misconfigurations that could allow for unauthorized data modification. Read all about it in the #Knowledgebyte.

JAN 2025 <a href="/DeptofDefense/">Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ</a> Vulnerability Disclosure Program (#VDP) #Hacker0x01 #Hackers reported a critical severity in GraphQL API misconfigurations that could allow for unauthorized data modification. Read all about it in the #Knowledgebyte.
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

JAN 2025 Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ Defense Industrial Based Vulnerability Disclosure Program #DIBVDP #Hackers reported a vulnerability involving JWT vulnerability which could have led to exposing sensitive data. Read all about it in the #KnowledgeByte.

JAN 2025 <a href="/DeptofDefense/">Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ</a> Defense Industrial Based Vulnerability Disclosure Program #DIBVDP  #Hackers reported a vulnerability involving JWT vulnerability which could have led to exposing sensitive data. Read all about it in the #KnowledgeByte.
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

Congratulations to Mohamed Aziz Hassine (Aziz) for his outstanding achievement as Researcher of the Year! ๐Ÿ† His research on the dangers of chaining IDOR + Stored XSS is crucial for enhancing online security. Keep up the amazing work! #DIBVDP #CyberSecurity #EthicalHacking

Congratulations to Mohamed Aziz Hassine (<a href="/aziz0x48/">Aziz</a>) for his outstanding achievement as Researcher of the Year! ๐Ÿ† His research on the dangers of chaining IDOR + Stored XSS is crucial for enhancing online security. Keep up the amazing work! #DIBVDP #CyberSecurity #EthicalHacking
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

2024 Finale: Celebrating Valeriyโ€”our Researcher of the Year! His tireless work uncovering multiple PII leaks has raised the bar in cybersecurity. Your vigilance inspires and strengthens our defenses. Hats off! #ResearcherOfTheYear #CyberSecurity #DoDSecurity

2024 Finale: Celebrating <a href="/Krevetk0Valeriy/">Valeriy</a>โ€”our Researcher of the Year! His tireless work uncovering multiple PII leaks has raised the bar in cybersecurity. Your vigilance inspires and strengthens our defenses. Hats off! #ResearcherOfTheYear #CyberSecurity #DoDSecurity
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

A big shoutout to hussain, our February 2025 Researcher of the Month, for uncovering a misconfigured API endpoint leaking PII. Their efforts play a key role in safeguarding sensitive information and reinforcing DoD cybersecurity. Well deserved! #InfoSec #DoDSecurity

A big shoutout to <a href="/hussain_saadi0/">hussain</a>, our February 2025 Researcher of the Month, for uncovering a misconfigured API endpoint leaking PII. Their efforts play a key role in safeguarding sensitive information and reinforcing DoD cybersecurity. Well deserved! #InfoSec #DoDSecurity
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

Thank you, @nzhg3i_nzm, for exposing the serious vulnerability of PII and CAC ID being accessible on an unauthenticated page. This kind of oversight opens the door to identity theft, unauthorized access, and privacy breaches. Your vigilance is critical! #DIBVDP #CyberSecurity

Thank you, @nzhg3i_nzm, for exposing the serious vulnerability of PII and CAC ID being accessible on an unauthenticated page. This kind of oversight opens the door to identity theft, unauthorized access, and privacy breaches. Your vigilance is critical! #DIBVDP #CyberSecurity
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

FEB 2025 Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ Defense Industrial Based Vulnerability Disclosure Program (#DIBVDP) #Hackers reported a vulnerability involving exposed PII which could have led to an advisory obtaining sensitive data. Read all about it in the #KnowledgeByte.

FEB 2025 <a href="/DeptofDefense/">Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ</a> Defense Industrial Based Vulnerability Disclosure Program (#DIBVDP)  #Hackers reported a vulnerability involving exposed PII which could have led to an advisory obtaining sensitive data. Read all about it in the #KnowledgeByte.
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

FEB 2025 Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ Vulnerability Disclosure Program (#VDP) #Hacker0x01 #Hackers reported a critical severity vulnerability identifying a security misconfiguration discovered in a DoD Salesforce deployment. Read all about it in the #Knowledgebyte.

FEB 2025 <a href="/DeptofDefense/">Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ</a> Vulnerability Disclosure Program (#VDP) #Hacker0x01 #Hackers reported a critical severity vulnerability identifying a security misconfiguration discovered in a DoD Salesforce deployment. Read all about it in the #Knowledgebyte.
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

Huge thanks to farinhando for uncovering critical vulnerabilities in Authentication Bypass via Response Manipulation! These findings highlight serious security risks that need urgent attention. Stay vigilant, update systems, and prioritize cybersecurity! ๐Ÿ”’ #DIBVDP #CyberSecurity

Huge thanks to <a href="/Kaenne/">farinhando</a> for uncovering critical vulnerabilities in Authentication Bypass via Response Manipulation! These findings highlight serious security risks that need urgent attention. Stay vigilant, update systems, and prioritize cybersecurity! ๐Ÿ”’ #DIBVDP #CyberSecurity
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

Huge thanks to Jonas Dias Rebelo for identifying an exposed debug file containing a full database dumpโ€”with plaintext passwords. A sharp catch that reinforces the importance of secure development practices. Your work is truly appreciated! #CyberSecurity #InfoSec #DoDSecurity

Huge thanks to <a href="/j0nasdias/">Jonas Dias Rebelo</a> for identifying an exposed debug file containing a full database dumpโ€”with plaintext passwords. A sharp catch that reinforces the importance of secure development practices. Your work is truly appreciated! #CyberSecurity #InfoSec #DoDSecurity
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

MAR 2025 Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ Defense Industrial Based Vulnerability Disclosure Program #DIBVDP #Hackers reported a vulnerability involving Improper Authentication that could lead to unauthorized access and system compromise. Read all about it in the #KnowledgeByte.

MAR 2025 <a href="/DeptofDefense/">Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ</a> Defense Industrial Based Vulnerability Disclosure Program #DIBVDP  #Hackers reported a vulnerability involving Improper Authentication that could lead to unauthorized access and system compromise. Read all about it in the #KnowledgeByte.
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

MAR 2025 Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ Vulnerability Disclosure Program #VDP HackerOne #Hackers reported a high severity submission identifying misconfigured access controls which could have led to disclosure of unauthorized information. Read all about it in the #Knowledgebyte.

MAR 2025 <a href="/DeptofDefense/">Department of Defense ๐Ÿ‡บ๐Ÿ‡ธ</a> Vulnerability Disclosure Program #VDP <a href="/Hacker0x01/">HackerOne</a> #Hackers reported a high severity submission identifying misconfigured access controls which could have led to disclosure of unauthorized information. Read all about it in the #Knowledgebyte.
DC3 VDP (@dc3vdp) 's Twitter Profile Photo

Kudos to Himanshu Nautiyal for the responsible disclosure of hardcoded public/private API keys in a JavaScript file โ€” a critical exposure of sensitive credentials. Your vigilance helps keep the web safer! #DIBVDP #CyberSecurity #InfoSec #WebSecurity #EthicalHacking

Kudos to Himanshu Nautiyal for the responsible disclosure of hardcoded public/private API keys in a JavaScript file โ€” a critical exposure of sensitive credentials. Your vigilance helps keep the web safer! #DIBVDP #CyberSecurity #InfoSec #WebSecurity #EthicalHacking