Found a target using Firebase? Try out Insecure Firebase Exploit by @KHIZER_JAVED47, a simple Python-based tool to quickly test for missing access controls and validation checks! 😎
🔗 github.com/MuhammadKhizer…
The @xai Grok 2.5 model, which was our best model last year, is now open source.
Grok 3 will be made open source in about 6 months.
huggingface.co/xai-org/grok-2
If you're interested in learning Android Application Hacking, my recommendations are to check out Android App Hacking - Black Belt Edition on Udemy and the HTB Academy Android courses. They're really good resources, in my opinion! #EthicalHacking#Android#AppSec
🤖 HexStrike AI MCP Agents Automating Cybersecurity with AI ⚡
HexStrike AI MCP Agents is a powerful Model Context Protocol (MCP) server that links AI agents (Claude, GPT, Copilot, and more) with 150+ cybersecurity tools.
🚨 CORS Misconfigurations – The Silent Killer in Web Security 🚨
Most hunters skip over CORS because it looks “boring.”
But here’s the truth:
A single misconfigured CORS policy can lead to account takeover, data leaks, or complete app compromise.
This isn’t about chasing…
🚨Alert🚨 CVE-2025-54336 (CVSS 9.8): Critical Flaw in Plesk Obsidian Exposes Servers to Full Compromise
📊11.6M Services are found on the hunter.how yearly.
🔗Hunter Link:hunter.how/list?searchVal…
👇Query
HUNTER : product.name="Plesk Obsidian"…
BountyOS
New Linux distro for different #cybersecurity tasks:
- based on Debian 12
- 75+ tools
- simple installation (ISO file)
bountyos.github.io
Creator Sirat Sami (analyz3r) (5K+ reputation on HackerOne!)
One liner for finding files
subfinder -d domain.com -silent | \
while read host; do \
for path in /config.js /config.json /app/config.js /settings.json /database.json /firebase.json /.env /.env.production /api_keys.json /credentials.json /secrets.json…
I found a weird WAF bypass.
soloboy");alert(origin);// => 403
solo,boy");alert(origin);// => 200
When I add a comma to the name, WAF gets bypassed. Application behaviour always surprises me.
Hakoriginfinder by @hakluke is a simple tool to quickly identify the origin hosts of targets behind firewalls, CDNs, and other types of reverse proxies! 🤠
🔗 github.com/hakluke/hakori…
9 Followers 82 Following"Benim naçiz vücudum elbet bir gün toprak olacaktır, ancak Türkiye Cumhuriyeti ilelebet payidar kalacaktır" Mustafa Kemal Atatürk.
2 Followers 133 FollowingFront-End Freelancer & Pentester: 3+ سنوات في بناء واجهات React وتأمين التطبيقات عبر TryHackMe/HackTheBox. تواصل: +201127799760
37 Followers 337 FollowingHavacılık, uzay, siber güvenlik ve savunma politikaları ve teknolojileriyle ilgilileniyorum ve arastiriyorum... Türküm dogruyum caliskanim...
4K Followers 599 FollowingElastic Security Labs is democratizing security by sharing knowledge and capabilities necessary to prepare for threats. Spiritually serving humanity since 2019.
44K Followers 3 Followingالمنصة الأولى من نوعها بمنطقة الشرق الأوسط من @TuwaiqAcademy | لتوظيف مهارات الباحثين بالأمن السيبراني في اكتشاف الثغرات البرمجية .. لفضاء سيبراني آمن وموثوق
67K Followers 28 FollowingThe world's largest secure & private email provider. Swiss-based, end-to-end encrypted, and free. Brought to you by the scientists behind @ProtonPrivacy.
76 Followers 6 FollowingZafer Partisi Eskişehir Gençlik Kolları resmi X hesabıdır.
#TürkiyeOrtadoğuOlmasın diyorsan bağlantıya tıklayarak bize katıl 👇🏻
1K Followers 13 FollowingGirişimciler, solo geliştiriciler ve vibe coder’lar topluluğu. 💯
Canlı yayınlarda SaaS uygulamaları geliştiriyor ve üretmeyi teşvik ediyoruz. 🚀
1.1M Followers 0 FollowingNational Security Agency/Central Security Service official account, home to America's codemakers and codebreakers. Likes, retweets, and follows ≠ endorsement.
237K Followers 638 Following✨ the ol' reliable ✨ The privacy-first voice and chat platform. Decentralized. Secure. Yours to customize. Dev Updates: @teamspeakdev
4K Followers 599 FollowingElastic Security Labs is democratizing security by sharing knowledge and capabilities necessary to prepare for threats. Spiritually serving humanity since 2019.
43K Followers 897 FollowingCo-founder of @centrahq/@detectify/@poweredbyingrid. I do not advertise doing hacking services, do not trust the ones telling you I do.