mssoffsec @mssoffsec
Proud Indian 127.0.0.1 Joined September 2019-
Tweets2K
-
Followers280
-
Following2K
-
Likes7K
@ahmetdotrun @Hacker0x01 Bro is blasting cloudfalre Bugbounty program 🔥🔥
@GodfatherOrwa Will be waiting for your comeback man ...
I found an unauthenticated lookup where a phone number returned: - Full name. - Date of birth. - Home address. Phone numbers are public enough to collect and structured enough to enumerate. Paid $2,500. People argue that a record identifier is “not guessable.” That does not help when the identifier is a phone number printed on profiles, invoices, signatures, and breach lists. Thx @bugcrowd #ItTakesACrowd #CyberSecurity #BugBounty
Real-world scenario [4]: (A Journey of Limited Path Traversal To RCE) #CTF #bugbounty #bugbountytips #bugbountytip
No username. No password. Just a header. How a simple oversight led to a $3,000 authentication bypass. medium.com/@0xalr/no-user…
Just got rewarded with $3500 on @Hacker0x01 🐍✨
Have you checked out @hadriansecurity's subwiz? It's a recon tool that uses ML to predict and resolve subdomains👇
Source Map Exposure -> Hidden Endpoint Discovery POC -> 1. Found JavaScript source map file (.map) 2. Downloaded original unminified source code 3. Identified hidden API endpoints 4. Discovered internal application logic Learning -> 1. Remove source maps from production 2. Review frontend code before deployment #BugBounty #CyberSecurity #BugBountyTips #InfoSec
I earned a $22,500 bounty from Airbnb using a custom Opus 4.7 workflow built with MCP and Skills. It feels like bug bounty hunting has changed forever
Found a cool bug at Meta. From misconfigured Grafana instance to R/W access on 507 private Meta repositories. Wrote up the full chain here: sectricity.com/blog/misconfig… $157k bounty awarded by @metabugbounty
Account Takeover using SSO Logins by Rikesh Baniya medium.com/p/account-take…
This article on JavaScript analysis for pentesters is a solid walkthrough of: • endpoint extraction • hidden routes • dangerous DOM sinks • framework-specific attack surfaces • client-side recon methodology Worth reading if you're into client-side bug bounty hunting: kpwn.de/posts/javascri… #bugbounty #websecurity #javascript #infosec #appsec #pentesting
Lets check will my luck works out :)
Super excited to release our latest Broken Access Control (BAC) Masterclass on @hackinghub_io with 2 hours of content and almost 20 labs. I'm giving away 3 free seats to anyone who comments, reposts, and replies to this post. Drop a 🔥 below! More info 👉🏼 hhub.io/BAC2026
StubZero: $148,337 RCE in Google Cloud Production brutecat.com/articles/googl…
Organization Takeover via IDOR ($3,700) medium.com/@xploiterr/fro… #BugBounty
I loved this article by @iamgk808. Read it, it’s inspiring, and it’s honest about the time and effort involved. Honestly, it inspired me. Thanks for writing it, Ganesh! 😎 infosecwriteups.com/from-failure-t… #bugbounty #cybersecurity
Yay, I was awarded a total of $5,500 in bounties on @Hacker0x01! hackerone.com/eliteoffensive Vulnerabilities Found: 1. Privilege Escalation (Trial User → Platform Admin) 1. While reading the site's JavaScript files, I found an API endpoint and noticed it accepted an "author" parameter in the request body. 2. The JS hinted that the "author" value was used to identify who the request belonged to — and that this value needed to be an admin's email for certain actions. 3. I collected 15–20 employee emails through public sources (OSINT). 4. I tested them one by one as the "author" value. One matched a platform admin account, and that request was accepted. 5. Using that admin's email as "author" along with my own account ID, I changed my account "plan" from "trial" to "internal". The request went through, and my role was updated. 6. Root cause: the endpoint was authorizing the request using a value from the request body instead of the role from the user's authenticated session. 2. SSRF → Cloud Metadata Credential Exposure 1. The app had a feature that fetched user-supplied URLs from the server side. 2. Confirmed by pointing it at a public echo service — the response showed a cloud server IP, not mine. The server was making the request. 3. The URL filter blocked the metadata service IP in its standard dotted form, but didn't normalize alternate representations. Converting the same IP to its decimal form bypassed the filter cleanly. 4. From there, the standard two-step metadata flow worked: first request returned a session token, second request used that token to return temporary instance role credentials. 5. Root cause: block-list URL filtering without IP normalization. A single canonicalization step on the resolved address would have caught this. 3. IDOR Exposing 285,000+ Customer Invoices The invoice download endpoint used sequential IDs with no ownership check. Changing the ID returned other customers' invoices. 4. IDOR Enabling Cross-Tenant Audit Log Manipulation A "log move" endpoint trusted client-supplied IDs, which allowed moving log entries across tenant boundaries and tampering with audit history. 5. Unauthenticated Path Traversal A public endpoint accepted file paths without sanitization, allowing partial file reads across the platform with no authentication required. Key lessons: → Never authorize based on request-body fields. Use the session/JWT role. → URL-fetch features need allow-lists, and must normalize alternate IP forms. → Sequential IDs are fine; missing ownership checks are not. → "Unauthenticated" doesn't mean "untrusted input is safe." #bugbounty #securityresearcher #ethicalhacker #cybersecurity #vulnerability #penetrationtesting #securityaudit #digitalsecurity #tech #innovation #hackerone #freelance #freelancer #pentester #ssrf #idor #privilegeescalation #pathtraversal #appsec #infosec #TogetherWeHitHarder #bugbountytips
Finding Critical Bugs in Adobe Experience Manager (AEM) muhammadwaseem29.tech/blog/aem
@0x_rood Could you please share the tips to find the admin part..
Ahsan Khan @hunter0x7
35K Followers 1K Following [Hacker + lover of bash] I Don't know how to hack but i know how to pwnd!
sudha @sudhacam
3K Followers 5K Following show avaliable tele id https://t.co/eEvJmy4GS9 tele channel https://t.co/IDv4MwHNI4 timepassers direct block 🔞 geniune service nambi vaaga santhosama poga
bb00x @ihebhamad514
810 Followers 4K Following Bug Bounty Hunter | Security Researcher | Learning, hunting & improving methodologies | DMs open #bugbounty #hackerone #bugcrowd #appsec #hackers #hacking #hack
07x_v3177.exe @VedGawde
197 Followers 4K Following Trust in His plan | God's love makes even the hardest journeys worthwhile | His love is the compass guiding your life's purpose |
Damian Strobel @damian_89_
8K Followers 1K Following Into IT Security and Big Data | https://t.co/7ZEf1Ijfvp | https://t.co/wMB3f2XEX7
bugsploiterr @systempwn3d
31 Followers 2K Following
Philopentest @philopentest
260 Followers 274 Following I am active on Intigriti bug bounty, reached the top 29 there in April 2026
0xSabir @0xSabir
950 Followers 1K Following Ethical hacker | Web app pentester | Securing apps | Tweeting AI Generated Posts
xer0dayz @xer0dayz
8K Followers 2K Following Founder of @Sn1perSecurity. Creator of Sn1per and @SILENTCHAINAI. Top 20 worldwide on @bugcrowd in 2016. OSCE/OSCP - https://t.co/iqw8gBpkKb
Tharani Dharan @tharanijpt
8 Followers 262 Following Inside the cocoon, learning to become an engineer
sin99xx @sin99xx
924 Followers 631 Following “The impediment to action advances action. What stands in the way becomes the way.” l (╯°□°)╯
Mohan Raj @Mohan_Mohe
22 Followers 301 Following
Aadham @ha3k4r
92 Followers 1K Following Cyber Security Professional, Certified in CEH, ECSA and Palo Alto PCNSE, CCNA Security, CCNP Security, Fortinet NSE4,5,6, ISACA CISM & Trader | Investor
𝙍𝙖𝙢𝙆𝙧�... @GHOST_OPERATOR_
539 Followers 285 Following Associate Security Consultant | CRTP | eWPTXv2 | eMAPT | Bug hunter | Secured Apple, Asus,LG, Lenovo, Nokia and many more
Qanon @qanonfree
0 Followers 5K Following
Irfauiqawd @Irfauiqawd9594
36 Followers 2K Following
🇮🇷 Arshiya🇮�... @arshiyaiha
651 Followers 555 Following Bug Bounty is a game of patience and persistence, and every triage is a victory.
John Allen Muhammad @JohnAllenM38859
2 Followers 174 Following
Chanikyya sampath Gar... @ChanikyyaG
1 Followers 15 Following
for @fairforhunters
0 Followers 24 Following Fighting for fairness in the bug bounty world. No more ghosting. No more unfair rejections. #FairForHunters
Gokul Selvaraj @_ayan_gokul
6 Followers 947 Following
Vrushabh Doshi @doshi_vrushabh
269 Followers 268 Following #OSCP+ #SecurityEngineer #eWPTXv2 #CPENT #Infosec #bugbountyhunter CVE-2022-35406
Dharunkumar Shanmugam @dharunkumar_sh
38 Followers 399 Following 🇮🇳| Dravidian | Amazonian | Aspiring to be a Pentester (Red teaming) & Bug hunter | Mil-Sim enthusiast & Gamer
✨_geeknik_//✨ @geeknik
20K Followers 7K Following Human Co-Founder & CTO⇢https://t.co/JDh2Hm8yG2 A mad scientist with a penchant for chaos. Fuzzing from kernelspace➠uncanny valley.
あまねゆみこ @amaneyumik82577
63 Followers 2K Following
cxz @cxz1799591
0 Followers 34 Following
Chris Hanlon @ChrisHanlonCA
17K Followers 18K Following Security Engineer Google Security Hall of Fame Presenter & Workshop host at #BSidesLV and #DEFCON
0xm1racle @0xm1racle
917 Followers 2K Following Bug Hunter Aspirant I hacking for fun and profit | Thank you h1 | views and opinions on tweets are mine alone
Thasair @ThasairfNVCbiV
12 Followers 186 Following
Raman Sandhu @Raman_sandhu__
484 Followers 1K Following Scorpyns — Founder & CEO | RankMentor · RanksApart | Where psychology meets technology, and vision becomes execution
Corporate Kaikooli @corporatekooli
6 Followers 99 Following
Blacksolo , Sp00f3dBy... @MBlacksolo
692 Followers 980 Following Security Researcher , Bughunter, Student.
Kapil Gurav @hackersden_
1K Followers 712 Following I hack thing's | Senior Product Security Specialist | Ex- Payatu | MVP Member of Bugcrowd | Speaker | Freelancer | Views Are Personal
Bornunique911 @bornunique911
592 Followers 4K Following Self-taught Cybersecurity enthusiast | 500+ rooms on TryHackMe & HTB | 100+ CTF's via https://t.co/I0tVpqLFOP | CompTIA Sec+ Certified | Always learning & growing
Amar @0xluap
3 Followers 77 Following
PentesterLab @PentesterLab
206K Followers 0 Following Don’t just learn tools and payloads. Learn why vulnerabilities exist. Hands-on web hacking, security code review, and real-world CVE labs.
Ben Sadeghipour @NahamSec
250K Followers 1K Following Cofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
Ahsan Khan @hunter0x7
35K Followers 1K Following [Hacker + lover of bash] I Don't know how to hack but i know how to pwnd!
Luke Stephens (hakluk... @hakluke
100K Followers 2K Following Hacker, marketer. I manage socials and marketing for cybersecurity orgs. Founder of @hacker_content and @haksecio
JS0N Haddix @Jhaddix
177K Followers 7K Following CEO, CISO, Trainer, Hacker, and Speaker. Cybersecurity + Hacking + AI + Sec Leadership @arcanuminfosec
Aditya @ADITYASHENDE17
63K Followers 421 Following MS Cyber 🇬🇧 | Work @BforeAI | @Bugcrowd Top 100 | Solo Bug Bounty Hunter/Trainer | Professional Biker | @kong_sec 🇮🇳 | Own Views ≠ Employment |
zseano @zseano
81K Followers 715 Following rebuilding https://t.co/oFH3BQm9YZ ex full time amazon hacker 2018-2026 🫡 -_^
Emad Shanab - أبو ... @Alra3ees
50K Followers 605 Following Father | Lawyer | Bug Bounty Hunter | Complete newbie | Every Law has its own Bugs. https://t.co/Cwuy2zfF8N https://t.co/Bd9ltJWS5X
THREAT CON @THREAT_CON
6K Followers 82 Following THREAT CON, The Only Hackers' Convention in Nepal. #Workshop: Sep 11-12 #Conference: Sep 13 #Buy Tickets: https://t.co/Ik7MgkwdUA Join us: https://t.co/SXRjgJJBA4
The XSS Rat - Proud X... @theXSSrat
167K Followers 1K Following Bug bounty profiles: https://t.co/3Uz5K130ah https://t.co/rzbqV5AmZ2 https://t.co/CDlzXdNvPB
Joseph Thacker @rez0__
73K Followers 1K Following christian. father. hacker. founder. advisor. podcast: https://t.co/1aFavJN2h8 blog: https://t.co/JBPT1CJWJH products: 🤖 https://t.co/EVhQl8HTlp $200/mo 📚 https://t.co/MMmhw0cnaz $0/mo
dawgyg - Defcon @thedawgyg
59K Followers 1K Following #h1415 2020 MVH, Bug Bounty Hunter, Reformed Blackhat. Views/Likes/Retweets do not represent my employer in anyway.
bugcrowd @Bugcrowd
201K Followers 6K Following The leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™
Intigriti @intigriti
212K Followers 668 Following Bug bounty & VDP platform trusted by the world’s largest organisations! 🌍
shubs @infosec_au
59K Followers 2K Following Co-founder, security researcher. Building an attack surface management platform, @assetnote
root@AkashHamal0x01:~... @AkashHamal0x01
9K Followers 716 Following Solo | https://t.co/I6KH8WN8nm | Community Helper 🤝| WebApp Security 🐞 | Avid Learner 📖 | Male | Father of Two | Married 💍. 60+ CVEs
👑 OFJAAAH → ofja... @ofjaaah
20K Followers 581 Following Bug Hunter ☣ | Hi I Hacker spare time and not spare time too 🧙♂️. https://t.co/ob6h7VO9uC
Nitin Gavhane @NitinGavhane_
1K Followers 276 Following Security Researcher | Technical Writer on Medium (1.5K+ Followers)
Hack Glasgow @Hack_Glasgow
234 Followers 250 Following People make Glasgow, but together we Hack Glasgow. Returning Saturday 15th August 2026.
Rajus Priya 💎 @rajuspriya
3K Followers 233 Following Chennai couple 36/35 | Open-minded Cpls || Seeking a banana 🍌FwB meets T_grm : © Rajuspriya
Professor Larry Dense... @luckyhacker43
3K Followers 0 Following Sharing free resources, write-ups, recon tips, OSINT guides, and learning roadmaps for aspiring security researchers. https://t.co/UYlYa33j6W
07x_v3177.exe @VedGawde
197 Followers 4K Following Trust in His plan | God's love makes even the hardest journeys worthwhile | His love is the compass guiding your life's purpose |
bb00x @ihebhamad514
810 Followers 4K Following Bug Bounty Hunter | Security Researcher | Learning, hunting & improving methodologies | DMs open #bugbounty #hackerone #bugcrowd #appsec #hackers #hacking #hack
Marius du Preez @mdp_sec
2K Followers 187 Following Bug bounty hunter breaking Web2 apps, APIs & business logic. $102k in my first 6 months. Sharing what works and doesn't. 🇦🇺 https://t.co/bFQ2v80j23
CERT-In @IndianCERT
47K Followers 29 Following Official Twitter handle of Indian Computer Emergency Response Team, Ministry of Electronics & Information Technology, Government of India
Harshvardhan Singh Ra... @Harshva97597668
178 Followers 6 Following Bug Bounty Hunter Telegram Community:- https://t.co/99xSIO0Ahq
sagitz @sagitz_
11K Followers 901 Following Cloud Security Researcher at @wiz_io • Microsoft Most Valuable Researcher 21/22/23 • Black Hat Speaker • Ask me anything about https://t.co/57lyhfcUee
kat traxler @NightmareJS
2K Followers 3K Following Montessori kid using her chaos monkey energy to manifest security impact
HackenProof @HackenProof
39K Followers 2K Following Expert bug bounty and crowdsourced security marketplace · 400+ programs · $ 26M + paid in bounties · 85k+ ethical hackers
Seth Kraft @skraft09
649 Followers 5 Following Cybersecurity Engineer | Vulnerability Researcher | 18x CVEs | 27x Bug Bounty Awards | OSS Contributor
Ebrahem Hegazy 🇵�... @Zigoo0
35K Followers 935 Following Founder of @DarkEntryAMS. Vulnerabilities Hunter since 2013. ex Sr. Manager at Visa Inc, HackerOne, Deloitte, QCERT and EGCERT. Tweets are my own.
bugsploiterr @systempwn3d
31 Followers 2K Following
TheHatedOne @3ugman
304 Followers 112 Following Bug Bounty Hunter. Until death, all defeat is psychological.
Bug bounty wizard @bugbountywizard
2K Followers 0 Following Top bug bounty writeups for bounty Hunter from https://t.co/3lXxhPa7oQ , https://t.co/kMVGsjehJS #bugbounty #bugbountytips
Saif Abdullah Khan Ma... @badhacker0x1
2K Followers 348 Following Just another servant of Allah | A bug bounty hunter| Junior Knight at @kn16h75qu4d.
Abhi Sharma 𝕏 @a13h1_
3K Followers 94 Following Cybersecurity Researcher | Bug Bounty Hunter Finding bugs in systems & habits Writing on Medium 📝 #CyberSecurity #InfoSec #bugbounty #hackerone
BugBunny.ai - Continu... @BugBunny_ai
3K Followers 5 Following AI pentesting at scale. Real findings, validated PoCs. N°1 on HackerOne. 89+ confirmed CVEs across Google, Python, Meta, OpenAI, etc.
Aditya BISHT @cherry4akuma
662 Followers 4 Following 17 yo || Google ranked #1034 , MICROSOFT Recognised Ranked top 1%ile hackerone | 14k usd || 3rd year cse || Open Source: Tlsx merged pr
Philopentest @philopentest
260 Followers 274 Following I am active on Intigriti bug bounty, reached the top 29 there in April 2026
DestroyerX @ide9x
1K Followers 632 Following I'm Ahmed, also Known As DestroyerX | wannabe Security Researcher | الْحَمْدُ لِلَّهِ
Trilok Dhaked @Tr1l0kDh4k3d
527 Followers 1K Following Radhe Radhe ❤️ 🙏 Jai shri krisna ❤️🙏 Farmer🚜🇮🇳 ⛳🚩#05 #bharatpur Founder & CEO: Building @InfoSec_Securit @Bugsec.AI
Nick Mykhailyshyn �... @whoareme33
2K Followers 873 Following Security Reseacher and Software Engineer
Bug Bounty Hunter @trybughunter
2K Followers 22 Following AI-powered bug bounty hunting from your terminal. Managed by @shuvonsec
zhannnnn.teiuuuuu @h1nhantieu
88 Followers 174 Following CRTO | CRTA | Pentester | Cyber Security Researcher | CVE Researcher | Bug bounty Researcher
Caner @xzemit42
549 Followers 148 Following
Dr Gerhard Knecht, Ph... @GerhardKnecht
13K Followers 11K Following Cybersec. & Audit VP, Global CISO, Global Head MSS, Prof. Speaker, TV appearance, Top 10 UK security personality 2010, Compliance guru, AI, Security Follow-back
Mehmet INCE @mdisec
34K Followers 2K Following Vuln. Researcher since 00s. cto & co-founder @PRODAFT. Muay Thai addict.
Vipul 🇮🇳 @GodSpeed000123
2K Followers 39 Following Penetration Tester | Bug Bounty Hunter | IIT Jodhpur
Suresh Aydi (xploiter... @_xploiterr
3K Followers 1K Following What can you be if you worked as hard as you can ? ✍️ Write-ups → https://t.co/2ki4J3756e
0xSabir @0xSabir
950 Followers 1K Following Ethical hacker | Web app pentester | Securing apps | Tweeting AI Generated Posts
Project Zero Bugs @ProjectZeroBugs
37K Followers 0 Following A bot that posts the latest blog posts and disclosures from Google's Project Zero
Omar Espino • @omespino
11K Followers 742 Following Security hall of fame: Google VRP • Microsoft • Reddit • Telegram • Twitter • Facebook • Apple • Netflix • Slack • etc •










































