rahmetu (@sshbounty) 's Twitter Profile
rahmetu

@sshbounty

fixing printers and Learning how to code, hack :)

ID: 1563511523900764160

calendar_today27-08-2022 12:59:40

860 Tweet

356 Followers

323 Following

Truffle Security (@trufflesec) 's Twitter Profile Photo

🚨 Google told devs: API keys aren't secrets. Gemini changed that. 😱 We found ~3,000 public keys silently authenticating to Gemini - exposing private files, cached data & charging for LLM usage 💥Even Google's own keys were vulnerable. 🔗 trufflesecurity.com/blog/google-ap…

🚨 Google told devs: API keys aren't secrets. Gemini changed that.

😱 We found ~3,000 public keys silently authenticating to Gemini -  exposing private files, cached data &  charging for LLM usage

💥Even Google's own keys were vulnerable.

🔗 trufflesecurity.com/blog/google-ap…
Intigriti (@intigriti) 's Twitter Profile Photo

Are you still searching for your first valid vulnerability? Q2 is just around the corner! It's time to lock in! 🫡 Join us in #BugQuest! Starting today, we'll share bug bounty tips, techniques, and resources that anyone can use to find Broken Access Control (BAC)

Are you still searching for your first valid vulnerability? Q2 is just around the corner! It's time to lock in! 🫡 

Join us in #BugQuest! Starting today, we'll share bug bounty tips, techniques, and resources that anyone can use to find Broken Access Control (BAC)
Critical Thinking - Bug Bounty Podcast (@ctbbpodcast) 's Twitter Profile Photo

We finally had dawgyg - WoH on the pod to talk about his origin story, recent Chrome research and how he optimises his AI workflow, his famous 180K payout on Yahoo and a LOT more. This is an episode we know a lot of people have been looking forward to, check it out!

Web Security Academy (@websecacademy) 's Twitter Profile Photo

Here's how to deliver reflected XSS through a HTTP request smuggling vulnerability! 👇 Try this Practitioner lab now: portswigger.net/web-security/r…

Phillip Wylie (@phillipwylie) 's Twitter Profile Photo

Overcoming public speaking fears? Toastmasters is your secret weapon. Recording yourself on video revealed you *don't* look as nervous as you feel. Practice speaking, refine your delivery, and build unshakeable confidence. #PublicSpeaking #Toastmasters

Dave Kennedy (@hackingdave) 's Twitter Profile Photo

Alright, I've stayed away from the Mythos stuff for a little bit. Going to comment on that, but AI as a whole. First, this AI industry is absolutely insane. I feel like I'm back in the 90s/2000s with innovation, but it's not tempered or methodical - it's pure chaos. Everyday

Graham Helton (@grahamhelton3) 's Twitter Profile Photo

I've begun working on a long overdue follow up to the post I get the most questions about, specifically, how I use obsidian to manage my entire career. A lot has changed since 2023 and it's now more useful than ever. This will be a long one worth your time

I've begun working on a long overdue follow up to the post I get the most questions about, specifically, how I use obsidian to manage my entire career. A lot has changed since 2023 and it's now more useful than ever. 

This will be a long one worth your time
Shreyas Chavhan (@shreyas_chavhan) 's Twitter Profile Photo

Happy to share that my first CVE is now public: CVE-2026-5189 This allowed an attacker to gain unauthorized read/write access to the internal database and execute arbitrary OS commands. 🔗 Public Advisory: support.sonatype.com/hc/en-us/artic… #bugbounty

Happy to share that my first CVE is now public: CVE-2026-5189

This allowed an attacker to gain unauthorized read/write access to the internal database and execute arbitrary OS commands.

🔗 Public Advisory:  support.sonatype.com/hc/en-us/artic…

#bugbounty
Yanir Tsarimi (@yanir_) 's Twitter Profile Photo

I've discovered CVE-2026-32173 by steering a single agent The vuln: you could listen to anyone's AI chat stream on Azure SRE agent. Including LLM thinking, commands, tools. The auth check was there, but at the wrong place. Patched. Critical, Information Disclosure. $20k bounty

David Bombal (@davidbombal) 's Twitter Profile Photo

The distance between your dreams and reality is called action. #DailyMotivation #inspiration #motivation #bestadvice #lifelessons #changeyourmindset

The distance between your dreams and reality is called action.

#DailyMotivation #inspiration #motivation #bestadvice #lifelessons #changeyourmindset
D Day (@archangeldday) 's Twitter Profile Photo

The best career move I ever made was abandoning traditional employment and doing my own thing! The "safe" path is not that safe in the long run!

PortSwigger (@portswigger) 's Twitter Profile Photo

Meet the Burp Ambassadors: Rana Khalil 🇵🇸 🌍 Rana Khalil is a security educator and founder of Rana Khalil’s Academy. Her mission: make web app testing accessible to more people. #BurpAmbassador #BurpSuite

Meet the Burp Ambassadors: <a href="/rana__khalil/">Rana Khalil 🇵🇸</a> 🌍

Rana Khalil is a security educator and founder of Rana Khalil’s Academy.

Her mission: make web app testing accessible to more people.

#BurpAmbassador #BurpSuite
zseano (@zseano) 's Twitter Profile Photo

i'm taking a pause from hacking to resume building bugbountyhunter.com. i regret closing it down and I shouldn't of done it. everything will be back online EXACTLY as it was very soon and i've got some big plans for the future. and yes, that includes zseano methodology v2 ;)

NetworkChuck (@networkchuck) 's Twitter Profile Photo

Ever wondered how to hide your most sensitive data in plain sight? 🕵️‍♂️ One file, two different volumes, two different passwords!  Learn how to create a hidden VeraCrypt volume, a "secret room" inside an encrypted container that only appears if you use a specific password! 🔐