Abhishek Meena @aacle_
Building @Vulncure ⚡| Helping founders fix vulnerabilities before hackers find them. Talk to me about: Bug Bounties, LLM Security & React. Joined June 2017-
Tweets4K
-
Followers48K
-
Following287
-
Likes3K
My strategy for finding bugs is pretty simple: - First, understand what the feature does. - Then use it normally for a while. - After that, start changing things and see what breaks. Sometimes the best bugs come from doing something the developer didn’t expect.
There’s a peculiar thing about using Claude for bug bounties: The first hour can be incredibly productive. The next five hours? Sometimes, it’s just a matter of becoming overly confident about the wrong ideas. That’s when I realized: The real skill isn't just prompting Claude. The real skill lies in knowing when to stop it or tell it to abandon a fruitless path. "Stop. This approach is a dead end. Look here instead." AI-assisted bug hunting probably isn't about giving the AI more freedom. It’s likely about getting better at steering the investigation in the right direction.
"Bug bounty is dead." Meanwhile, someone just made $200K using one prompt. Maybe the real story isn't that bug bounty is dying. Maybe we're watching the definition of a bug bounty hunter change. The skill is moving from finding every bug yourself to knowing what to make the machine investigate.
Some bug bounty content just never gets old. STÖK's ( @stokfredrik ) content, old videos with TomNomNom... ( @TomNomNom ) watching this again genuinely took me back to the beginning of my own journey. Those who started hunting 6–7 years ago probably know exactly what I mean. You may have learned new tools, found new bugs, changed completely as a researcher... But some content still hits like it did on day one. 🫶 youtu.be/l8iXMgk2nnY
Repository :👇 github.com/devploit/nomor…
Tried nomore403 recently. Not just another 403 bypass tool throwing random payloads. It baselines responses, filters the noise, and scores results. Pretty useful for quickly testing access-control edge cases. Keeping this one around.
Yeah, I’ve tested it across multiple runs. For bug bounty work, Deepseek v4 pro was consistently better for me. Aikido's benchmark showed similar results: Deepseek had strong recall, while flash was highly cost-effective. Not saying it wins every single task, but for bug bounty work? hard to ignore.
If you doing bug bounty, try DeepSeek V4 Pro. its better than fable 5 in CyberGym bench: It’s also much cheaper, so you can run more testing. Not saying DeepSeek > Claude. But damn… hard to ignore 👀
Yesterday I said I forked Burp’s official MCP server because it was holding me back. Here’s what I actually changed. The official MCP server is mostly one-way. Claude can send a request to Burp Repeater. But it can't read the response back. It can't see Intruder results. It can't start or manage scans. So I fixed that. Now the AI can: → Stage Repeater requests and read them back by name → Set up Intruder attacks and read the results → Run crawls + active scans, check progress and stop them → Read site maps and history → Access scope + cookie jars when approved → Add notes and highlight findings → Use it with Claude, OpenCode, Copilot CLI and Codex CLI And I also built a live dashboard inside Burp to see what the AI is actually doing: requests, traffic, scans and activity. One honest limitation: Burp still doesn't expose an API for reading tabs you manually typed into. But anything the AI sends through the MCP is captured and can be read back. So yeah. I didn't plan to build all of this. I just wanted the MCP to stop getting in my way. 😭 GitHub release is coming. 🔥
I was going through a bunch of public SSRF reports on HackerOne while researching for this article. I ended up analyzing around 286 reports using claude, and one thing stood out to me. 8 of the top 20 didn't just end at SSRF. Researchers were able to take it further: → access internal services → hit cloud metadata endpoints → extract credentials → access cloud infrastructure That's what I find interesting about SSRF. Finding the SSRF is only one part of the bug. The more important question is: "What can the server reach from there?" I broke down some of the real patterns I found across the reports, along with examples of how SSRF ended up exposing AWS keys, GCP tokens and other cloud credentials. Full breakdown in my latest article 👇 medium.com/codetodeploy/s…
Minified JavaScript can look impossible to read. But sometimes the source map is still publicly accessible: app.js.map If it's exposed, the original source structure may be much easier to understand. Always check what developers accidentally ship alongside production code.
🚀 One of the most common questions I see from beginners: “How do I actually start bug bounty?” My honest answer: don't start by trying to learn everything. Pick one vulnerability. Understand: • How it works • Why it happens • Where it usually appears • How to test it • How to prove real impact Then practice it again and again. The mistake many beginners make is jumping between XSS, SQLi, SSRF, IDOR, APIs, recon, tools, and 20 YouTube videos at the same time. You don't need to understand the entire internet before finding your first bug. 🎯 Pick one thing. Understand it deeply. Test it repeatedly. Depth first. Then breadth. What vulnerability did you start with? 👇
One of the most underrated skills in bug bounty is knowing what not to investigate. You can spend hours testing a feature that will never lead anywhere. And on the same day, ignore a small weird behavior that could lead to a critical bug. The difference isn't always technical knowledge. Over time, good researchers develop an instinct for: - "This is probably nothing." - "This is interesting." - "I should spend another hour here." I think bug bounty is partly about finding vulnerabilities. But a huge part of it is learning where to spend your attention.
AI can make us faster, but if we outsource our thinking, we may become worse researchers. After testing AI in security workflows, here’s what I learned 👇
I can understand charging a fee to stop AI-generated spam. But as researchers, imagine this 👇 You spend hours testing a target. You find a real vulnerability. You validate it properly and submit the report. Then it gets closed as a duplicate because someone else found it before you. Fair enough. They were first. But losing $50 on top of that? That's the part I don't think researchers have much control over. A valid duplicate is still a real bug. Maybe it deserves submission credit instead.
While working on my upcoming Medium article on SSRF, I made this simple visual to explain where the bug actually lives. The attacker controls the input, but the server makes the request. 👇
I think this is the right approach. AI can save a huge amount of time on recon, repetitive testing, and exploring attack surfaces. But if we outsource too much of the actual thinking, we might become faster while becoming worse researchers. And I also agree on the model side. The best model isn't always the most expensive one. In my own testing, DeepSeek V4 Pro has been giving me an edge. In some cases, I've found it performing better than some of the more highly recognized top models. I think model selection should be based more on the actual task and testing workflow than the price or hype around the model.
I made Burp Suite’s MCP extension way better. And honestly, I got frustrated with how much it was holding me back. So I forked it. Started making a few changes and ended up building something way more capable than I originally planned. I’ve made the Burp Suite MCP way more powerful for the kind of testing I wanted to do. A lot more to share soon. Details tomorrow. GitHub release coming. 🔥
This is a great example of how impactful bugs often start from something that looks small.
Today I found a pretty interesting bug chain 👀 Started with a file upload extension filter bypass, then found a way to overwrite files belonging to other users. From there, I discovered a way to enumerate platform UUIDs. The final impact was crazy: I could potentially execute
AI is giving cybersecurity people something extremely valuable: More attempts. A researcher who could investigate 10 ideas in a day might now investigate 50. Most of those ideas will still fail. But security research has always been a numbers game. - More hypotheses. - More experiments. - More code understood. - More attack paths explored. The intelligence of AI isn't just replacing work. It's reducing the cost of being curious. And I think that will change cybersecurity far more than people expect.
A bug bounty hunter posts a subdomain enumeration technique. It gets millions of impressions. And now everyone is acting like they discovered a new life hack. “This is a new way to apply for jobs!” No, it isn't. It's a recon technique. The use case is discovering an organization's attack surface during authorized security research. But once something gets millions of impressions, people who don't understand the original context start reposting it with whatever angle might also go viral. This is the part of viral cybersecurity content I dislike the most: People don't learn the technique. They learn that the post is trending. And then suddenly everyone has their own “use case” for something they don't actually understand.
The XSS Rat - Proud X... @theXSSrat
167K Followers 1K Following Bug bounty profiles: https://t.co/3Uz5K130ah https://t.co/rzbqV5AmZ2 https://t.co/CDlzXdNvPB
Md Ismail Šojal �... @0x0SojalSec
52K Followers 6K Following Cyber_Security_Re-searcher || Ai Re-searcher || AI-Sec|| Malware Analysis II iOS || Pwn || 0SINT || Project AI-StrikeSec || 0ldAccounts Suspended @0xSojalSec ||
Het Mehta @hetmehtaa
43K Followers 2K Following Security Engineer | Content Creator | I talk about Cybersecurity, Tech, Privacy, AI & Startups | Building @Sentynio @100xSecurity
Katie Paxton-Fear @InsiderPhD
99K Followers 2K Following Dr, apparently. Security Adovcate @semgrep & Hacker. #BugBounty hunter & #infosec YouTuber. APIs & Interlinked OffSec, PhD in AI+Sec @hacknotcrime. she/her
Dr. Maik Ro ➡️�... @maikroservice
18K Followers 703 Following ☠️ inactive account ☠️ - Training the next generation of Hackers over at bsky / linkedin / youtube 🏴☠️💜
JS0N Haddix @Jhaddix
178K Followers 7K Following CEO, CISO, Trainer, Hacker, and Speaker. Cybersecurity + Hacking + AI + Sec Leadership @arcanuminfosec
It's Steiner254 @Steiner254
6K Followers 1K Following Penetration Testing | Application Security (Mobile, Web, APIs) | Zero Day Researcher | Bug Bounty Hunter 🙂 Honoured By @UN, @Huawei @UTAustin e.t.c
Renganathan @IamRenganathan
15K Followers 767 Following 22 | Ethical Hacker | Building @R_Protocols | Secured Google, Apple, LinkedIn, AWS & More | Product | Startups | Speaker | 50+ talks | Posts are personal
Kanhaiya Sharma @krishnsec
20K Followers 759 Following APPLICATION SECURITY & RECON | Top 5 P1 warriors @bugcrowd | https://t.co/8Fo8sBoCVN
Iman Gurung @ImanGurung13
8K Followers 451 Following Computer Engineer, Ethical Hacker, Tatoo Lover, Blind xss king
Bug Bounty Insights �... @bbr_bug
6K Followers 29 Following I share bug bounty insights to the bug bounty community
Rohit @whorsehgal
23K Followers 1K Following Builder . Security engineer . Traveller Currently making agents gossip on https://t.co/jgwyzxqSnS
Ryan John @PhD_Security
8K Followers 108 Following check out my youtube channel here: https://t.co/rTLZgZsZmT
who_xspacex @who_xspacex
0 Followers 157 Following
Thomas Thompson🏖�... @tomthomastech
4 Followers 157 Following Software Engineer - BS Computer Science - MBA
Ehab Hamada @WD_EhabHamada
4 Followers 359 Following Full-stack developer | MERN, React Native, Flutter | Code lover with a growth mindset | Exploring AI, PHP & C#
Man Like Civvies 🚀... @manlikecivvies
199 Followers 2K Following if the infusion of business and personal page doesn't exist then I just created something 🚀 💐
ReconHunter @ReconHunter123
3 Followers 76 Following website: https://t.co/tFfv9JTJdP Helps bounty hunters spot worth-hunting entry points inside scope | 帮赏金猎人在 scope 里更快找到值得盯的入口
Sambor Shellz 🦉 @sam0x420r
123 Followers 1K Following
So I took it @was_available
26 Followers 967 Following
Ax @AdaptiveAx
8 Followers 383 Following Ax. Alpha over Currency Builder. Ron's bot for all internet money + team. Alpaca is one rail. Still a 4.
xp xp1 @Xp1Xp85991
0 Followers 31 Following
Mat @element14th
42 Followers 757 Following
Hylan Ledger @HylanSec
18 Followers 213 Following Bug bounty Hunter,Crypto and blockchain, Sharing is Caring.
Leota Karly @KarlyLeota8690
4 Followers 272 Following
Mila Bas @sekbkbo95575
166 Followers 2K Following
Lin @0xLin77_
4 Followers 388 Following
Djinn @djinnengineer
3 Followers 71 Following
Twehbe @Twsec83
63 Followers 808 Following
CipherGuardian @CipherGuarn
2 Followers 143 Following I study aircraft, secure systems, build the web, and question reality for fun. Certified Ethical Hacker • Web Developer • Pilot in Training • Philosopher
محمد نعمان �... @N51648Man
3 Followers 94 Following
Oana Nedelcu @theoananedelcu
171 Followers 915 Following Sales Executive📍NY. Cybersecurity & AI | Tech Aficionado | Reconverted Engineer | Passionate about Innovation & Customer Service | Always Learning & Evolving
faiz @faizdmxq
5 Followers 86 Following
Hải Nguyễn Thanh @HaiNT1305
0 Followers 17 Following
🔥🔥🔥 @str3_h
0 Followers 624 Following
Fitzgerald Afari-Mint... @techfitz7
2 Followers 78 Following Defensive Cybersecurity | SOC investigations • Incident Response • Detection • DFIR | Labs, case files & lessons
Gambit @onchaingambit
1K Followers 4K Following ⛓️Freedom Maxi | chess noob 1700 elo ♟️| Sensitive young man ~
d stone @dstoneOffsec
5 Followers 79 Following
Owen @Owenbfmw
0 Followers 128 Following
Tochi eke @Tochieke7
12 Followers 557 Following
Nuhiat Arefin @nuhiatarefin
4 Followers 206 Following
Saikumar @SaikumarRaju21
99 Followers 470 Following
Lucifiel @LucifielHack
99 Followers 99 Following 🛡️ Security researcher · Web3/AI-agent · 🔴 Red Team Leader · Founder of 数字循真 (Runtime Semantic Intelligence) · 🔗 https://t.co/6QmibISlA0
المرتقى @ahmedghazi106
344 Followers 2K Following موقع المرتقى ، شروحات كتابية وصورية بشتى المجالات التقنية "برامج ، العاب ، حلول مشاكل والخ....
Alen Sebastian @Al3nVettithanam
5 Followers 134 Following
aXs @ahm3d0017
1 Followers 21 Following
Sam Alfares @sam_alfares
171 Followers 413 Following Startup investors, AI adoption accelerator, technologist, developer experience expert
kasulya @kasulya798
120 Followers 882 Following
Intigriti @intigriti
213K Followers 665 Following Bug bounty & VDP platform trusted by the world’s largest organisations! 🌍
Hacking Articles @hackinarticles
304K Followers 479 Following House of Pentesters Join us: https://t.co/Y6XOlSP7YA
PentesterLab @PentesterLab
207K Followers 0 Following Don’t just learn tools and payloads. Learn why vulnerabilities exist. Hands-on web hacking, security code review, and real-world CVE labs.
The XSS Rat - Proud X... @theXSSrat
167K Followers 1K Following Bug bounty profiles: https://t.co/3Uz5K130ah https://t.co/rzbqV5AmZ2 https://t.co/CDlzXdNvPB
Ben Sadeghipour @NahamSec
250K Followers 1K Following Cofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
OccupytheWeb @three_cube
266K Followers 3K Following Pentester, Forensic investigator, and former college professor. Trained hackers at each US military and intelligence. Visit me at https://t.co/G478wug0p4
bugcrowd @Bugcrowd
201K Followers 6K Following The leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™
TryHackMe @tryhackme
308K Followers 84 Following An online platform that makes it easy to break into and upskill in cyber security, all through your browser.
Aditya @ADITYASHENDE17
63K Followers 423 Following MS Cyber 🇬🇧 | Work @BforeAI | @Bugcrowd Top 100 | Solo Bug Bounty Hunter/Trainer | Professional Biker | @kong_sec 🇮🇳 | Own Views ≠ Employment |
John Hammond @_JohnHammond
324K Followers 3K Following Cybersecurity Researcher @HuntressLabs Just Hacking Training @JustHackingHQ w/ @ethicalhacker https://t.co/UtsNJiyQtS && https://t.co/narO3sz7y6
🇸🇦 Murtada Bin ... @0x_rood
29K Followers 342 Following Digital Nomad Lifestyle 💎 | Not doing collabs, not selling courses
Joseph Thacker @rez0__
74K Followers 1K Following christian. father. hacker. founder. advisor. podcast: https://t.co/1aFavJN2h8 blog: https://t.co/JBPT1CJWJH products: 🤖 https://t.co/EVhQl8HTlp $200/mo 📚 https://t.co/MMmhw0cnaz $0/mo
InfoSec Community @InfoSecComm
56K Followers 634 Following Largest InfoSec publication with 80,000+ followers and 3M+ monthly views.
Het Mehta @hetmehtaa
43K Followers 2K Following Security Engineer | Content Creator | I talk about Cybersecurity, Tech, Privacy, AI & Startups | Building @Sentynio @100xSecurity
Nithin 🦹♂️ @thebinarybot
19K Followers 597 Following Heckr | Former Community Manager @InfoSecComm | eJPT | Certified Red Team Professional (CRTP)
Katie Paxton-Fear @InsiderPhD
99K Followers 2K Following Dr, apparently. Security Adovcate @semgrep & Hacker. #BugBounty hunter & #infosec YouTuber. APIs & Interlinked OffSec, PhD in AI+Sec @hacknotcrime. she/her
The Bug Bounty Hunter @tbbhunter
48K Followers 0 Following Promotions or business ✉️[email protected]
Harnoor Singh @iHarnoorSingh
22K Followers 2K Following YouTuber | DevRel building 📶 https://t.co/2eKbeUi4Of 🌉 https://t.co/BXNwccmcyJ prev @Microsoft @panaauto | Singh in USA
VulnCode @VulnCode_
4 Followers 0 Following We build what your business actually needs to grow. Websites • Automation • Scraping • Apps
BugBunny.ai - Continu... @BugBunny_ai
3K Followers 5 Following AI pentesting at scale. Real findings, validated PoCs. N°1 on HackerOne. 89+ confirmed CVEs across Google, Python, Meta, OpenAI, etc.
The Hacker News @TheHackersNews
2.2M Followers 2K Following The #1 trusted source for cybersecurity news, insights, and analysis — built for defenders and trusted by decision-makers.
Bug Bounty Hunter @trybughunter
2K Followers 22 Following AI-powered bug bounty hunting from your terminal. Managed by @shuvonsec
@levelsio @levelsio
936K Followers 3K Following 💸https://t.co/sQ0aiU7v02 📸https://t.co/lAyoqmSBRX $80K/m 🎮https://t.co/tF49atJ396 $44K/m 🏡https://t.co/1oqUgfD6CZ $23K/m 👙@X $20K/m 🌍https://t.co/UXK5AFqCaQ $15K/m 💾https://t.co/T74ZwJ1F0C 🏩https://t.co/4p4dzTDVN6 📝https://t.co/8VnHmB3uah
Darko Mesaroš @darkosubotica
6K Followers 2K Following Developer Advocate/Computer person @AWSCloud , but opinions are my own! :wq!
Bitscale @bit_scale
236 Followers 239 Following The creative GTM tool for RevOps teams. Generate leads, enrich data from 100+ sources, and run personalised outbound campaigns at scale. Trusted by 1000+ teams.
Pliny the Liberator �... @elder_plinius
236K Followers 1K Following ⊰•-•⦑ latent space steward ❦ prompt incanter 𓃹 hacker of matrices ⊞ breaker of markov chains ☣︎ ai danger researcher ⚔︎ bt6 ⚕︎ architect-healer ⦒•-•⊱
Mohd Danish @mddanishyusuf
16K Followers 769 Following "The Micro Startups Guy" ❯ https://t.co/5hDIulx6OL ❯ https://t.co/Fm6K0XfkjX
Shuvonsec @shuvonsec
924 Followers 6 Following NASA-Recognized Ethical Hacker | World’s #1 Hacker on TryHackMe Monthly Leaderboard | Building AI-Powered Security Tools
Kirill Firsov @k_firsov
6K Followers 431 Following Co-founder and CTO of @FearsOff | Protecting the World’s Top Crypto Exchanges & Financial Institutions | Cybersecurity Enthusiast
Techbrokaran @0xhaxor
1K Followers 762 Following Former Bug Bounty Hunter Tech Creator • Gamer Gaming Gear Reviews & Comparisons
X @TheMsterDoctor1
36K Followers 339 Following 🧠 Retired Hacker | AppSec & Bug Bounty 💣 Found bugs others miss 🏆 CVEs • $500K bounties • real exploits 📌 Follow for daily hacker playbooks
Deven @devenbhooshan
6K Followers 582 Following Building https://t.co/XqfgO9OxEV ex @gojektech @amazon
Buchi Reddy B @buchireddy
1K Followers 2K Following Founder & CEO @LevoIncHQ On a mission to help enterprises adopt AI securely. The digital world needs better security. #AISecurity #AppSec #APISecurity
Who Am I ? 🇪🇬 �... @19whoami19
4K Followers 768 Following CEO & Founder @CYBERVULNLLC : @VulnXio | Penetration Tester and Bug Bounty Hunter since 2023
chux @chux13786509
9K Followers 329 Following Web Hacking 👻 | Bug Hunting | CVEs | Hacking Puzzles | Exploitation | https://t.co/LbpguTTSEk | https://t.co/e9bO0RZKlB
Debangshu 🇮🇳�... @ThisIsDK999
8K Followers 1K Following Security Ninja/Thought Leader. @hacker0x01 Brand Ambassador. Top 200 | Hacker Advisory Board @bugcrowd. Founder @defndit Opinions are personal.
mrdesoky0 @mrdesoky0
1K Followers 323 Following Bug Hunter | Android Developer | Never stop chasing your dream
Tib3rius @0xTib3rius
73K Followers 663 Following Cybersecurity Content Creator | UwU-Anointed Wapp King | DEF CON Gameshow Host | Ex-Brit | https://t.co/04RRExvxXj (he/him) 🇺🇸 @TheRealC3rul34n is bae 🥰
Oege de Moor @oegerikus
7K Followers 601 Following CEO and founder of XBOW. Previously: Founder of GitHub Next, founder of GitHub Copilot, CEO and founder of Semmle (GitHub Advanced Security), prof at Oxford.
Ayush Agarwal @ayushagarwal
10K Followers 459 Following Founder @dodopayments ~ helping builders monetize their software in 5 mins. Join: https://t.co/DwMoPoh5ni
Thái Vũ @thaivd98
3K Followers 941 Following
ProjectDiscovery @pdiscoveryio
42K Followers 144 Following Real, exploitable vulnerabilities. No noise. Nuclei scans fast. Neo closes the loop. @pdnuclei × @neo_ai_engineer
Ryan Barnett (B0N3) @ryancbarnett
6K Followers 486 Following Web App Defender | Bug Hunter/Triager | Purple Team | Detection Engineering | Author | Senior Threat Research Manager @Akamai_research | OWASP Project Leader ✝️
Gopesh Sharma @MrSharmaX
2K Followers 755 Following https://t.co/0WDWm0DA8n | https://t.co/uONxZLwyeZ | India♥️
harris0ft @harris0ft
5K Followers 99 Following Christian, Hacker, Independent Security Researcher. https://t.co/7rmqelX5L4
Jay Dwivedi @jaydwivedi_
41K Followers 517 Following Founder & Designer https://t.co/FR0Oyhsmjw | https://t.co/cITXz5BXHC | https://t.co/cqKmFriuqF
Rock Pratap Singh (Ro... @Rockpratapsingh
839 Followers 341 Following Radhe Radhe 🙏 || Security Researcher | Bug Hunter | Ethical Hacker | VAPT | Google, Nokia, NASA, Apple, Lenovo, Blackberry, Cambridge, Indian UK gov HOF🇮🇳 |
Ron Chan @ngalongc
19K Followers 652 Following
Harsh D Ranjan @HarshDRanjan1
3K Followers 855 Following Just another Hackerone hunter Zoom Top 10 🤝
Abdelkader Mouaz @hamzadzworm
4K Followers 279 Following Your Limite is: Where You Decide To Stop :) Work Hard = Dream Big -.-

































