Niemand (@niemand_sec) 's Twitter Profile
Niemand

@niemand_sec

Security Researcher at @xbow - Founder at @SwordBytesSec - Ex @immunityinc - #BugBounty hunter hackerone.com/niemand_sec - Blog niemand.com.ar

ID: 731143035698991104

linkhttps://www.youtube.com/channel/UCKmi4IhmmMerbnz816I_35w calendar_today13-05-2016 15:24:18

1,1K Tweet

4,4K Followers

373 Following

HackerOne (@hacker0x01) 's Twitter Profile Photo

Applications for the HackerOne Brand Ambassador program are open! ๐Ÿ™Œ We are looking for Brand Ambassadors from around the world to empower the next generation of security researchers. ๐Ÿ’ช Some countries without ambassadors are Estonia, Sweden, France, Italy, and Indonesia.

Applications for the HackerOne Brand Ambassador program are open! ๐Ÿ™Œ

We are looking for Brand Ambassadors from around the world to empower the next generation of security researchers. ๐Ÿ’ช 

Some countries without ambassadors are Estonia, Sweden, France, Italy, and Indonesia.
Nico Waisman (@nicowaisman) 's Twitter Profile Photo

We have been a little bit silent lately, but XBOW has been running at full steam. In 2025 we found 106 vulnerabilities in OSS projects, and we report 72 already.

We have been a little bit silent lately, but <a href="/Xbow/">XBOW</a> has been running at full steam. 
In 2025 we found 106 vulnerabilities in OSS projects, and we report  72 already.
GuidedHacking (@guidedhacking) 's Twitter Profile Photo

๐ŸšจCon Presentations by Guided Hacking Members The Underground World of Anti-Cheats From Niemand at Black Hat Europe 2019 ๐Ÿ‘‰youtu.be/yJHyHU5UjTg 1/10

๐ŸšจCon Presentations by Guided Hacking Members

The Underground World of Anti-Cheats
From <a href="/niemand_sec/">Niemand</a> at Black Hat Europe 2019
๐Ÿ‘‰youtu.be/yJHyHU5UjTg
1/10
Bug Bounty Village (@bugbountydefcon) 's Twitter Profile Photo

๐Ÿšจ๐Ÿ“ข Call for Volunteers! ๐Ÿ“ข๐Ÿšจ Bug Bounty Village @ DEF CON 33 is looking for in-person & remote volunteers to help make this yearโ€™s event epic! If youโ€™re passionate about bug bounty & community, apply now! ๐Ÿ”— bugbountydefcon.com/call-for-volunโ€ฆ #DEFCON #BugBounty #Volunteer

Bug Bounty Village (@bugbountydefcon) 's Twitter Profile Photo

AI isnโ€™t replacing bug bounty hunters anytime soon, but itโ€™s getting surprisingly close. In this DEF CON talk, Joel Noguera & Diego Jurado (@xbow) show how they built agents that exploit real-world XSS, JWT, and CSRF bugs autonomously youtu.be/YDsHI2acEVA #BugBounty #DEFCON

AI isnโ€™t replacing bug bounty hunters anytime soon, but itโ€™s getting surprisingly close.

In this DEF CON talk, Joel Noguera &amp; Diego Jurado (@xbow) show how they built agents that exploit real-world XSS, JWT, and CSRF bugs autonomously

youtu.be/YDsHI2acEVA

#BugBounty #DEFCON
Bug Bounty Village (@bugbountydefcon) 's Twitter Profile Photo

Ever run an exploit in the wrong path? AI has too In this demo, Niemand & djurado show their agent (@xbow) debugging itself, fixing dependencies, tweaking payloads and eventually logging in as admin โ€” autonomously. Full talk โ†’ youtu.be/YDsHI2acEVA #BugBounty #DEFCON

Bug Bounty Village (@bugbountydefcon) 's Twitter Profile Photo

This AI agent reads the JavaScript, understands the registration flow, creates a test user, and uses those creds to keep exploring the app Niemand, djurado, and @xbow are pushing what autonomous bug hunting can do. Full talk โ†’ youtu.be/YDsHI2acEVA #BugBounty #DEFCON

Bug Bounty Village (@bugbountydefcon) 's Twitter Profile Photo

This AI agent from @XBOW detects it's in an admin context, parses the full DOM, locates the URL-encoded flag, and solves the challenge โ€” fully autonomously. Niemand & djurado show how it works. Full talk โ†’ youtu.be/YDsHI2acEVA #BugBounty #DEFCON

Bug Bounty Village (@bugbountydefcon) 's Twitter Profile Photo

Niemand, djurado & @XBOW tested 5 pentesters vs their AI agent. Humans had 40 hrs. The AI cracked everything in 30 mins. Itโ€™s fast โ€” but humans still lead on creativity + hard bugs. Watch the full talk โ†’ youtu.be/YDsHI2acEVA #BugBounty #DEFCON

GuidedHacking (@guidedhacking) 's Twitter Profile Photo

๐Ÿ‘‘ They doubted my vision, now they witness our ascension. โŒ›๏ธ Coming Soon... ๐Ÿš€ Guided Hacking's Anticheat Development Course

H1 Disclosed - Public Disclosures (@h1disclosed) 's Twitter Profile Photo

โšก [20.98.103.245] Cross-Site Scripting (XSS) via /ssl-vpn/getconfig.esp at GlobalProtect VPN Portal ๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป @xbow โžŸ Informatica ๐ŸŸฅ High ๐Ÿ’ฐ None ๐Ÿ”— hackerone.com/reports/3096384 #bugbounty #bugbountytips #cybersecurity #infosec

โšก [20.98.103.245] Cross-Site Scripting (XSS) via /ssl-vpn/getconfig.esp at GlobalProtect VPN Portal 
๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป @xbow โžŸ Informatica 
๐ŸŸฅ High
๐Ÿ’ฐ None
๐Ÿ”— hackerone.com/reports/3096384
#bugbounty #bugbountytips #cybersecurity #infosec
Leandro Barragan (@lean0x2f) 's Twitter Profile Photo

Hacking with friends always pays off :) thank you HackerOne & Salesforce for such an amazing event! This time I teamed up with Kcho, djurado and Niemand to land a few crits that got us the eliminator award ๐Ÿ˜Š

Harley (@infinitelogins) 's Twitter Profile Photo

HackerOne celebrated top hackers at H16102 in Sydney. Congrats to the award winners. shubs , Lupin , shorlhax, doomerhunter , Niemand , djurado , kcho, none_of_the_above, Geluchat , Kรฉvin GERVOT (Mizu) (Sorry if I didn't tag you! Couldn't find your Twitter)

Niemand (@niemand_sec) 's Twitter Profile Photo

So happy to see XBOW performing as the top hacker in the US at HackerOne !! More than 1000 bugs have been submitted in just a few months ๐Ÿ”ฅ