mattbwtf @mattbwtf
linux | infosec | stuff $HOME Joined April 2023-
Tweets136
-
Followers5
-
Following218
-
Likes4K
Hackers Breach Toptal GitHub, Publish 10 Malicious npm Packages With 5,000 Downloads dlvr.it/TMjmxZ #CyberSecurity #GitHub #Malware #npm #SoftwareSupplyChain
I discovered how to use CSS to steal attribute data without selectors and stylesheet imports! This means you can now exploit CSS injection via style attributes! Learn how below: portswigger.net/research/inlin…
ProjectDiscovery v1.3: New navigation, dashboard, and improvements — ProjectDiscovery Blog projectdiscovery.io/blog/projectdi… @pdiscoveryio #bugbounty
Over 600 Laravel Apps Exposed to Remote Code Execution Due to Leaked APP_KEYs on GitHub dlvr.it/TMQ4n8 #Cybersecurity #Laravel #AppSecurity #CodeExecution #DataBreach
Not every XSS leads to alert(1). Some almost work, but don’t. Instead of discarding them, save them. Here’s how weak XSS vectors can be powerful when chained creatively👇 1️⃣ HTML Injection Sometimes you can inject HTML but not script. Don’t dismiss it as low impact. This…
v1.103 of @code is here! Check out what's new: 🚀 GPT-5 rolling out to @code today 🛠️ Enable more than 128 MCP tools with virtual tools ✅ Chat checkpoints 🌳 Git worktree support …and much more: aka.ms/VSCodeRelease Here are some of the highlights 🧵
Attention @kalilinux users! In the coming day(s), apt update is going to fail for pretty much everyone. The reason? We had to roll a new signing key for the Kali repository. You need to download and install the new key manually: offs.ec/4lUEtak
New video alert! Just hopped on camera and yapped about how I do everything DNS for automation. Not saying it's perfect/right, but it is what I do :) Let me know what you think! youtu.be/otegh-41etk
🚨 Crypto devs & traders beware! Fake Python package ccxt-mexc-futures hijacked MEXC trades—1,065+ downloads, rerouted orders, stole tokens. Now, 1 in 5 AI-generated packages are fake. Slopsquatting is rising. 🔗 Full story: thehackernews.com/2025/04/malici…
I think many people are familiar with the topic of blind CSS exfiltration, especially after the post by @garethheyes However, an important update has occurred since then, which I wrote below ->
4chan just got hacked hard. The person who hacked them claimed they dumped the entire database.
Welp I was phished. Classic case. Bound to happen to me once every 10 years or so, I guess. Will go through it on WAN Show, but I 100% should have known better. They got me during a BBQ and sent me scrambling for a solution when the solution would have been to do nothing.
Reddit has agreed to sell user data to an undisclosed AI company. Can you guess which one it might be? news.itsfoss.com/reddit-selling…
TypeScript 5.2 is now here! 🎉 Now faster with - 'using' & explicit resource management - decorator metadata - easier tuple type notation - better object completions - the inline variable refactor - clickable inlay parameter hints and more! Try it today! devblogs.microsoft.com/typescript/ann…
🚨 Woah. An intentional backdoor discovered in encrypted radio comms used globally for over 25 years. Buckle up!
🚨 Security Alert: A new #malware family called Realst is targeting Apple #macOS systems, including macOS 14 Sonoma! Written in Rust #programming language, it empties #cryptocurrency wallets & steals passwords. Find details here: thehackernews.com/2023/07/rust-b… #cybersecurity

AmazingDudeWX @AmazingDude29
3K Followers 7K Following Severe weather enthusiast | Meteorologist in training | Giving out major weather alerts across the USA daily! 🌪️ = 0 #wxtwitter #BeHereForIt
RachelPope @71lRLw95SDTHl
45 Followers 4K Following No circumstances will force me to make investment decisions outside of my potential circle
Dark @LastS1ayer
1 Followers 53 Following
Cloudflare Radar @CloudflareRadar
22K Followers 8 Following Internet trends, as seen by the @Cloudflare global network.
Nicolas Grégoire @Agarri_FR
27K Followers 630 Following Web hacker and Burp Suite Pro trainer Refer to https://t.co/D5tRH7U2hg for trainings Follow @MasteringBurp for free tips and tricks
Julien | MrTuxracer �... @MrTuxracer
37K Followers 443 Following Freelancer | #BugBounty | @Hacker0x01 H1-Elite | $1,500,000 Overall Bounties | ❤️ Reversing | Mobile Hacker | https://t.co/pcWduPOt0n
Mukul Goyal @itz_mg_
3K Followers 506 Following 17 | Bug Bounty Hunter | Aspiring Security Researcher
Guilherme Rodrigues (... @guilhermesgi
183 Followers 386 Following 🇧🇷🧑🏾💻 InfoSec Analyst |🐞 ETH Hacker | Bug Hunter | 🏆 Microsoft MVR 2023 & 2025 | 👑 Microsoft Leaderboard: Q1/23 • Q4/24 • Q1/25 • Q2/25
Microsoft Security Re... @msftsecresponse
145K Followers 215 Following We are the Microsoft Security Response Center. To report security vulnerabilities or abuse in Microsoft products, visit https://t.co/kxEbdfMny1.
xploiterr @_xploiterr
2K Followers 905 Following Let everything happen to you, just keep going… like she said. ✍️ Write-ups → https://t.co/2ki4J3756e
payloadartist @payloadartist
42K Followers 286 Following Yapping about AI, AppSec, Hacking, & Cybersecurity • Helped secure organizations like Google • Opinions are my cat's • Part-time shitposter
DHH @dhh
554K Followers 131 Following Father of three, Creator of Ruby on Rails + Omarchy, Co-owner & CTO of 37signals, Shopify director, NYT best-selling author, and Le Mans 24h class-winner.
slonser @slonser_
4K Followers 163 Following Co-Founder @neploxaudit. CTF team @C4TBuTS4D Security Researcher at Solidlab.
Gareth Heyes \u2028 @garethheyes
37K Followers 1K Following JavaScript for hackers: Learn to think like a hacker. https://t.co/e0aNEbEDk5
Gunnar Andrews @G0LDEN_infosec
5K Followers 916 Following Hack Stuff | Code Stuff | Fitness | Kaizen OSCP | OSWA | OSWE https://t.co/4lgaVGZxd0 https://t.co/db6Gmb2ImT https://t.co/uY8NkPXaqA
André Baptista @0xacb
17K Followers 781 Following Hacker grinding for L1gh7 and Fr33dφm, straight outta the cosmic realm. Co-founder @ethiack
terminal @terminaldotshop
26K Followers 11 Following delicious coffee, ethically sourced, and roasted to perfection • order via your terminal • ssh https://t.co/62f84mRBoO • get help @ [email protected]
Ariel Garcia @Arl_rose
6K Followers 3K Following Community Builder. Pentester. Bug bounty Hunter. Bug bounty village @ DEFCON. https://t.co/PojmVAcqXQ Tweets are my own and not the views of my employer.
ThePrimeagen @ThePrimeagen
297K Followers 1K Following skill issues: 🟩⬛️⬛️⬛️⬛️⬛️(69/420) https://t.co/qWJnB6p4EP https://t.co/IwY3FTx1ZE https://t.co/TYJ6aSpwYs
James Kettle @albinowax
79K Followers 92 Following Director of Research at PortSwigger aka Burp Suite. Find my research, tools & contact details at https://t.co/vP6UbGmvl3
xAI @xai
1.8M Followers 38 Following
NetworkChuck @NetworkChuck
218K Followers 635 Following Believer. Beard. Coffee. Tech. Youtube. Check the link in my bio to see my latest video!
Faav @efaav
721 Followers 169 Following Developer @ https://t.co/qiMEJOTD1H (& NameMC Extras), Bad web developer, Bug hunter.
Angel Hacker @4ng3lhacker
515 Followers 25 Following George Mason Cyber Security Engineering Student | Databuoy Software Engineering Intern | Bug Hunter ✝️
Ryan Barnett (B0N3) @ryancbarnett
5K Followers 401 Following Web App Defender | Bug Hunter/Triager | Purple Team | Detection Engineering | Author | Senior Threat Research Manager @Akamai_research | OWASP Project Leader ✝️
OpenAI @OpenAI
4.3M Followers 3 Following OpenAI’s mission is to ensure that artificial general intelligence benefits all of humanity. We’re hiring: https://t.co/dJGr6Lg202
Fireship @fireship_dev
201K Followers 933 Following Build and ship your app faster with @JeffDelaney23 🔥📽️ https://t.co/oF4GTcT7UC
Harley Kimball @infinitelogins
7K Followers 1K Following Hacker Community Cultivator, Pentester, Bug Bounty Hunter | Co-Founder of @BugBountyDEFCON | Founder of Disclosed. (link in bio)
Signal @signalapp
595K Followers 23 Following Signal is an end-to-end encrypted messaging app. Privacy isn’t an optional mode, it’s just the way that Signal works. Every message, every call, every time.
MG @_MG_
50K Followers 717 Following Nightmare Reifier. I sell some of them too: https://t.co/5HhKqfxtda & https://t.co/9flQ1nSPZ2
NWS Tornado @NWStornado
385K Followers 0 Following Official Twitter account for the National Weather Service used to distribute experimental tornado warning impact graphics. Read more at: http://t.co/j1qyDV2Jw5
Tornado Talk @tornado_talk
10K Followers 704 Following We are dynamic, information packed website devoted to tornado history with 550+ event summaries! Join our community on Patreon: https://t.co/vajms3oTty
AmazingDudeWX @AmazingDude29
3K Followers 7K Following Severe weather enthusiast | Meteorologist in training | Giving out major weather alerts across the USA daily! 🌪️ = 0 #wxtwitter #BeHereForIt
Johann Rehberger @wunderwuzzi23
7K Followers 597 Following Hacking neural networks so that we don’t get stuck in the matrix. Builder and Breaker. Opinions are my own. https://t.co/ij8buvMaXg
PentestGPT @PentestGPT
22K Followers 0 Following AI-Powered Penetration Testing Assistant for offensive security testing, focused on web applications and network penetration testing.
spaceraccoon | Eugene... @spaceraccoonsec
25K Followers 302 Following Here to learn! Infosec@Open Government Products | White Hat && SecOps
Thach Nguyen Hoang �... @hi_im_d4rkn3ss
3K Followers 337 Following Security Researcher @starlabs_sg. Pwn2Own Mobile 2020, 2021, 2022, 2023. Pwn2Own Vancouver 2022, 2023, 2024, 2025.
WhiteHatMage @WhiteHatMage
3K Followers 317 Following Bug bounty wizard - All Stars @immunefi. I cast Exorcise on vulnerabilities and Heal on protocols. Prevented exploits worth over $150M.
Jenish Sojitra @_jensec
22K Followers 533 Following $2M in Bug Bounties. Creator of https://t.co/Sbnrie1LXH Security @Exodus
OffSec @offsectraining
325K Followers 119 Following Empowering the world to fight cyber threats with indispensable cybersecurity skills and resources. Build the path to a secure future with OffSec.
Polymarket @Polymarket
634K Followers 5K Following Trade politics, news, culture, sports & tech. Discord: https://t.co/tzKrbDf7dZ Tag @AskPolymarket to get live odds.
The Lunduke Journal @LundukeJournal
16K Followers 529 Following Tech Journalism with zero ads, & zero Big Tech influence. We cover the Big Tech stories that other publications are afraid to touch.
Ciarán Cotter @monkehack
4K Followers 543 Following • Irish/Japanese web hacker living in Scotland. • Researcher for @ctbbpodcast Lab. I run https://t.co/Ja1P3vco1X | Newsletter weekly at https://t.co/KA5b2kY8ih
Learn Prompting @learnprompting
16K Followers 895 Following Creators of the Internet's 1st Prompt Engineering Guide. Trusted by 3M Users. Compete for $100K in Largest AI Red Teaming Competition: https://t.co/AEiLMn2jzy
Donut Operator 🍩 @DonutOperator
845K Followers 2K Following YouTuber, skate shop owner, former police and SWAT officer, veteran, gamer, foodie, Kentucky colonel. Co-host of @unsubscribecast Co-owner @pepperboxtv
Evan You @youyuxi
292K Followers 2K Following Husband / Father of two / Founder @voidzerodev / Creator @vuejs & @vite_js. Chinese-only alt: @yuxiyou
Sam Curry @samwcyo
97K Followers 1K Following Hacker, bug bounty hunter. Run a blog to better explain web application security.
Kévin GERVOT (Mizu) @kevin_mizu
6K Followers 755 Following Researcher for @ctbbpodcast lab 🐛 | DOMLogger++ developer 👨🏻💻 | CTF with @FlatNetworkOrg, @rhackgondins 🦦 | @ECSC_TeamFrance 2023 🇫🇷
Nir Ohfeld @nirohfeld
4K Followers 841 Following Head of Vulnerability Research @wiz_io | @Microsoft MVR (2021-2025) | Pwn2Own 2025 | @Forbes 30 Under 30