Juan Pablo Perata @cxzero
OSCP | Pentester | Bug Hunter | CTF player | Developer | Community cxzero.github.io Joined September 2011-
Tweets431
-
Followers288
-
Following5K
-
Likes3K
Interesting- What LLM vuln research looks like claroty.com/team82/researc…
Success/Collision! David Tae & Louis Hur of Out Of Bounds targeted Ollama, hitting a one-vulnerability collision with a previous attempt and earning $28,000 and 3 Master of Pwn points. #Pwn2Own #P2OBerlin
Project Nightfall is live! Our globally renowned CTF starts today and runs for the next 5 days. Join the global leaderboard to test your skills in ICS, AI, and Web security. Check out the challenge teasers below for a look at the high-stakes scenarios you'll face. Sign up and start playing today > okt.to/1QBOar
Aaaand it's official! Orange Tsai (@orange_8361) of DEVCORE Research Team chained 3 bugs to achieve Remote Code Execution as SYSTEM on Microsoft Exchange, earning a whooping $200,000 and 20 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
There it is! Orange Tsai (@orange_8361) of DEVCORE Research Team was able to exploit Microsoft Exchange! If confirmed, they win a whooping $200,000 and 20 Master of Pwn points. Off to the disclosure room to explain how they did it and seal the deal. #Pwn2Own #P2OBerlin
Mind blown 🤯 Some smartphones sold in mainland China (like certain OPPO models) can read MIFARE Classic cards, crack the keys in seconds, store them, and then fully emulate the card directly on the phone. No extra hardware. Just the phone. Access control, transit cards, hotel keys… game over. Huge thanks to Ian for showing me this in person. Really eye-opening how far NFC capabilities have gone in some regions. Who else has seen this in the wild? #NFC #MIFARE #TechSecurity #oppo
Did you know Claude models have a "magic string" to test when a model refuses to respond? If that string enters prompt context, it can be abused to break LLM workflows until context is reset. It's the EICAR test string of the AI age. Details: hackingthe.cloud/ai-llm/exploit…
I read through the Claude Code leaked source, and I found that a big part of its “write secure code” story comes down to a single line in a prompt. No, really. This is the line: Be careful not to introduce security vulnerabilities such as command injection, XSS, SQL injection, and other OWASP top 10 vulnerabilities. If you notice that you wrote insecure code, immediately fix it. Prioritize writing safe, secure, and correct code. That is not a joke. Claude Code is supposed to automate a huge chunk of software engineering work. We are talking about a tool people increasingly treat like an autonomous developer, and the built-in security posture for the code it writes appears to be: please try not to write vulnerable code. Wow. I feel much safer already. What makes this more interesting is that Anthropic clearly did put real engineering effort into other parts of security. The leaked source shows concrete protections around what Claude Code itself is allowed to do: permissions, sandboxing, shell hardening, sensitive path protections, SSRF controls. So this is not a story of “they forgot security.” It is a story of where they implemented it. They seem to have put much more engineering into controlling the agent’s behavior than into verifying whether the software it produces is actually secure. And that is a huge distinction. Because a coding agent can be careful with your machine and still make terrible security decisions about auth, dependency trust, tenant isolation, migrations, or application logic. That is the part I think security people should pay attention to. When you look at AI coding tools, the question is not just: “does it have security features?” The real questions are: - what is enforced by code - what is optional - what is just a prompt That tells you where the actual security boundary is. And in Claude Code, at least from the leaked source, that boundary looks a lot closer to containing the agent than to ensuring secure output. Full write-up down.
After much trial and error, proud to show off tweak injection on iOS 18; possibly for the first time ever? DarkSword injection into SpringBoard on iPhone 15 Pro Max running 18.6.2 🎉
A new module just got merged into NetExec: get-scriptpath📜 This module queries all users for the scriptpath attribute. If you have privileges over one of these scripts (or they e.g. try to mount a network share) you can compromise this user on their next login. Made by @0xwyndo
🚨 CVE-2026-3055 (CVSS 9.3), a unauth memory overread vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances that could see active exploitation itw Vulnerability detection script available here: github.com/rxerium/rxeriu… Patches are available as per Citrix's advisory: support.citrix.com/support-home/k…
Collecting ADCS data with NetExec🔥 Thanks to the addition of CertiHound, developed and implemented by 0x0Trace, we can now collect ADCS data using the --bloodhound collector of NetExec. As before, the data is exported as JSON files that can be imported directly into BloodHound.
Netexec has some really nice NFS capabilities. I found a some weird behavior in one of them, which turned out to be a bug that just got patched. Let's walk through it. youtube.com/watch?v=WVWPgO…
One year ago I decided to automate my bug bounty workflows and let automation run 24/7 to discover targets and find security vulnerabilities. In the blog post I describe approach that I took, difficulties and earnings from this project 🤑 brzozowski.io/bug-bounty/202…
This is quality research on an under-appreciated request smuggling vector, check it out!
I’ve been digging into HTTP Trailers and found some new smuggling techniques: sebsrt.xyz/blog/trailing-…
🚨 New podcast episode! Very fun and educational chat with @watchtowrcyber's Ryan Dewhurst @ethicalhack3r! Great conversation about discovering the magic of computers, the constant acceleration of threats, and how to adapt and survive as a defender. youtu.be/5WznmQpJnj4?si…
Claude Code/Codex is powerful for one-off tools but it's scary how quickly you lose context when relying on vibe coding - definitely makes patching bugs/vulns more challenging in the long run.
This is streamingly exciting github.com/lachlan2k/Reac…
hacker bob @efnet_bob
483 Followers 1K Following admin https://t.co/RrCe94xVC7 2004-2005 / #efnet #phrack #el8 #phc
Fernando Benedictti @fbenedic
11 Followers 150 Following Linuxero. Entusiasta de la cyberseguridad. Café, café y mas café!!! b4rd0ck at protonmail dot com
Sumit Kumar @kalki_x0
56 Followers 149 Following Application Security Engineer Web / Api / Code Review
Good Guy Biker @goodguybikre
11K Followers 5K Following Canada's Good Guy Biker, WhiteHatHacker, Bitcoin Mining, Blockchain Expert, Crypto, Content Creator, Business Development, Optimist Trendsetter. #BTC #Vancouver
Abdul Mhanni @abdo_mhanni
244 Followers 848 Following Part Time Penetration tester, Full Time Script Kiddie
Codebender Cate™ ξ... @Codebender_Cate
1K Followers 3K Following Mother | INTP-T | Cyber-BASc | Gamer | @XboxAmbassadors | @WGUCyberClub | ΟΣΣ | Cyber competitor | Former @USArmy | CSIE in progress (1/4) | posts are mine
TheOuts1derX @TheOuts1derX
3K Followers 1K Following
Marcelo @MrW0l05zyn
327 Followers 423 Following
Nirav Patel @nirav4peace
345 Followers 985 Following Helping organizations in securing digital assets by providing professional penetration testing services | Director | Penetration Testing Consultant
Ilias @EliotGeo
332 Followers 522 Following Student in the world of Cybersecurity - Learning through hands-on labs and real-world scenarios
Jakub Brzozowski @redfr0g_
134 Followers 330 Following XSS and coffee enjoyer @ Nord Security https://t.co/jWOWe8bZ6q
Ryan Dewhurst @ethicalhack3r
21K Followers 811 Following • Vulnerability & Threat Intelligence at https://t.co/hpcaDY39hO • Founder of @_WPScan_ (acquired by Automattic) • Founder of DVWA • Ethical Hacking Graduate
DMoney @realdeemoney86
497 Followers 2K Following Security Architect|CISSP|CCSP|CISM Views are my own
witness🇫🇷🇦�... @Protizescript
1K Followers 7K Following Security engineer | Penetration Testing | Jesus #EverythingaboutCybersecurity #Jesus Messi | Mbappe
Fran Canteli @Franc_205
689 Followers 799 Following Hacking and Nerd Stuff | OSCP | BSCP | CEH | LU1DAC
bugbh @activedire90713
0 Followers 58 Following
Benjamin Adedini @adedinibenjamin
8 Followers 469 Following Am more of religious person trying get things right in my career, sport and social life
John Kanekunga @JKanekunga23492
3 Followers 36 Following
Akira @_Akira88
173 Followers 2K Following Akira The Cyber Hero #Hacktivist #Nightwalker #Human #ExposeTheTruth #RightToKnow Let's make the world a Safer and a Better place for living. #KingRezaPahlavi
Crauho @Crauho2609
109 Followers 3K Following
Mr Owl @ziko29504803
848 Followers 1K Following Bug Bounty Hunter - BBH Top 10 OWASP vulnerabilities Cyber Security It's better to lose yourself when you hacking You want experts. They want ego
David 👨💻🇺... @DavidRiveroUY
133 Followers 1K Following Uruguayan Frontend Developer, based in Portugal 🇵🇹 Public account: @DavidRiveroME
Wunon @Wunon5117440
97 Followers 3K Following
McSotee @McSotee73556
72 Followers 1K Following
rv @rvikrant09
446 Followers 5K Following An Avid Explorer. 😺 Photographer, 19 Photography Exhibitions
Geyndurn @GeyndurnGaKTY
6 Followers 86 Following
Melina N. Lentini @melinalentini
98 Followers 667 Following CyberSecurity Enthusiast | HackTheBox Ambassador
Esteban @ESandoval_uy
43 Followers 184 Following
jav0 @javobernardo
1K Followers 2K Following Hacker | Cybersecurity Researcher | Bug Bounty Hunter | Head of Hacking @ Strike | @BugBountyArg | Hincha de Racing
Joaco Mateauda @JoacoMateauda
3K Followers 4K Following Maestro y defensor de la Escuela Pública. Fulbrighter 2025- @ualbany @UAlbanyGradSch PhD in Educational Policy and Leadership
mrmacete @bezjaje
1K Followers 2K Following crack software, not balls. i am responsible for my ideas and their consequences. he/him. (mastodon: @[email protected])
Deasmees @DeasmeesbOQDIg
97 Followers 2K Following
Official Rex @officalrex55
2 Followers 67 Following
Shautharet @Shautharetp6ge
85 Followers 3K Following
~synawk~ @synaw_k
126 Followers 341 Following
🧙♂️Dirk Lem... @MagickNET
2K Followers 2K Following 🇳🇱 Maintainer of @ImageMagick and its .NET Standard/Framework library called Magick․NET. @Microsoft #MVP. Member of @SixLabors. 💖🇹🇼
Juan Schällibaum @JuanSchallibaum
61 Followers 232 Following Application Security Engineer 👨🏻💻 Creador de https://t.co/8XTvVZZiMx ⛓️
OrangeCon @OrangeCon_nl
1K Followers 218 Following The Dutch Cybersecurity Conference! Experience the Hackers Community in Amsterdam, on June 4th 2026!
Paradigm Shift @prdgmshift
1K Followers 0 Following Premium European cybersecurity research provider, powered by a world-class team with a decade-long track record.
Densel @luckyhacker43
1K Followers 0 Following Sharing free resources, write-ups, recon tips, OSINT guides, and learning roadmaps for aspiring security researchers. https://t.co/jzSgL2ryhW
Peter Steinberger �... @steipete
555K Followers 2K Following Polyagentmorous ClawFather. Came back from retirement to mess with AI and help a lobster take over the world. @OpenClaw🦞 + @OpenAI
Sumit Kumar @kalki_x0
56 Followers 149 Following Application Security Engineer Web / Api / Code Review
sender @senderend
117 Followers 95 Following Pentester, Red Teamer @Specterops | OSCP https://t.co/NxqedjZKrn https://t.co/2Srd2LBpUo https://t.co/ocu6vX5cF5
Simone Margaritelli @evilsocket
48K Followers 2K Following Music, cybersecurity, open source and AI • Author of bettercap, pwnagotchi, opensnitch, bleah, legba and a few other things. Chief Architect @ 🥷
Sofía Romano @alcafecafe
18K Followers 1K Following Comunicadora, locutora y actriz. Conductora @ladiaria Radio • Panelista @uypolemica • Llenos de Mística @observadoruy
Jopraveen @jopraveen18
892 Followers 733 Following { 23 y/o | VR @zoho | CTFs with @Infobahn_ctf | https://t.co/OFX17OHmJX }
Gergely Kalman @gergely_kalman
3K Followers 460 Following bug bounty hunter I guess @[email protected]
Black Lantern Securit... @BlackLanternLLC
674 Followers 220 Following
Matcluck @doopsec
102 Followers 10 Following
l0ss @mikeloss
2K Followers 2K Following Feels like he shouldn't be on Twitter. He/Him. If you like my hackin tools throw me a few bucks at https://t.co/tjcn0pzayt
Charlie Eriksen @CharlieEriksen
3K Followers 411 Following Security Researcher @AikidoSecurity. Previously @SecCodeWarrior, co-founder at Adversaryio & Principal Security Engineer/Partner @thesyndis. Opinions all my own
Jonathan Leitschuh - ... @JLLeitschuh
4K Followers 612 Following Inaugural Dan Kaminsky Fellow | Security Researcher for the OSS Ecosystem | Speaker | Dropper of 0days (Responsibly) | @GitHub Star ⭐️ | Opinions=Mine | He/Him
Abdul Mhanni @abdo_mhanni
244 Followers 848 Following Part Time Penetration tester, Full Time Script Kiddie
atc1441 @atc1441
15K Followers 394 Following Hack the planet! my biggest passion is to run a custom firmware on as many devices as possible
siunam @siunam321
1K Followers 345 Following 23y/o 🇭🇰 | Bug bounty hunter | Web security researcher | Playing CTF with @ARESxCTF, @malta_ctf, @BlackB6a, and NuttyShell
Jaime Pillora @jpillora
266 Followers 314 Following Go, JavaScript, Cloud and Network automation, Open Source https://t.co/hhYWAIEOrn
TheOuts1derX @TheOuts1derX
3K Followers 1K Following
Aashif @Cyb3rX7u
93 Followers 102 Following Security Researcher @ Hackerone | Ethical Hacker | Bug Bounty Hunter
Codebender Cate™ ξ... @Codebender_Cate
1K Followers 3K Following Mother | INTP-T | Cyber-BASc | Gamer | @XboxAmbassadors | @WGUCyberClub | ΟΣΣ | Cyber competitor | Former @USArmy | CSIE in progress (1/4) | posts are mine
hacker bob @efnet_bob
483 Followers 1K Following admin https://t.co/RrCe94xVC7 2004-2005 / #efnet #phrack #el8 #phc
Julian Peña @rainbowdynamix
175 Followers 391 Following Security Engineer | Occasional security researcher | Opinions are my own.
ZoomEye @zoomeye_team
12K Followers 501 Following A cyberspace search engine built for security researcher Daily Tricks || Latest Vulnerability Updates Email: [email protected] https://t.co/AUq5jNpKkl
Aman @Amank1412
14K Followers 983 Following 20, engineer | prev @ roger (YC) | prev research @ worldquant | DM for work/collab
Adam @MarkLuck01
3 Followers 4 Following
AngeloLiso @AngeloLiso01
4 Followers 25 Following
johnny @zeroxjf
4K Followers 176 Following iOS & MacOS Researcher (AI-Assisted) @trycua https://t.co/4vu4rvK5b5
Chaofan Shou @Fried_rice
69K Followers 2K Following
Valhguard @Valhguard
20 Followers 0 Following
Adrián Díaz @s4dbrd
737 Followers 297 Following Red Team | Reversing & Exploiting | I publish failed research in my blog Co-Founder @valhguard
Wyndo @0xwyndo
7 Followers 7 Following
Pentest Laboratories @pentestlabltd
2K Followers 0 Following Provide #RedTeaming services by executing custom scenarios to test your cyber resilience.
Silky @S1lky_1337
1K Followers 456 Following German IT-Security Researcher | 𝐎𝐒𝐄𝐏 | 𝐎𝐒𝐂𝐏 | 𝐂𝐑𝐓𝐏 | Pentester | Freetime Malware Dev
Marcelo @MrW0l05zyn
327 Followers 423 Following







































