Jake Miller @theBumbleSec
Web Security Researcher | h2c smuggling, JSON Interop vulns, Server-side Spreadsheet Injection | AppSec @OpenAI; formerly @BrexHQ, @BishopFox thebumble.io Joined October 2012-
Tweets437
-
Followers2K
-
Following400
-
Likes495
Amazing work @albinowax! I’m just blown away with your creativity in finding new desync variants. I’m looking forward to trying it out in the labs.
Browser-Powered Desync Attacks: A New Frontier in HTTP Request Smuggling by @albinowax portswigger.net/research/brows…
The results are in! We're proud to announce the Top 10 Web Hacking Techniques of 2021! portswigger.net/research/top-1…
It seems that there is a lot confusion about the log4j JNDI injection vulnerability (CVE 2021-44228). In our latest blog post we provide additional background fundamentals about JNDI and JNDI exploitation (and a lot of links): mogwailabs.de/en/blog/2021/1…
@projectzerodays Sure! I found a few of these over the course of that year on services that accepted XLS uploads. They were all instrumenting MS Excel on a backend server for document processing: labs.bishopfox.com/tech-blog/2018… and labs.bishopfox.com/hubfs/Blog%20P…
Check out our blog post on Context Aware Content Discovery blog.assetnote.io/2021/04/05/con… - we drop a tool (Kiterunner - github.com/assetnote/kite…) and some datasets. Hope you can find more endpoints through our work!
Found another jndi bypass like 🟠's groovy bypass using org.yaml.snakeyaml.Yaml. Heres a controller for rouge-jdni to add it to your arsenal gist.github.com/TheGrandPew/74….
Great research by @artsploit! Also, be sure to check out the labs and updates to content at portswigger.net/web-security/o…
New attacks on OAuth: SSRF by design and Session Poisoning by @artsploit portswigger.net/research/hidde…
Awesome to see @seanyeoh finding some epic examples of h2c smuggling! Great work @assetnote team!
My colleague @seanyeoh wrote up his security research on H2C smuggling and the various cloud providers he successfully exploited (Cloudflare, Azure). He also released a tool called h2csmuggler! Check it out at blog.assetnote.io/2021/03/18/h2c…
Excited to share that I have just started a new position on the AppSec team @BrexHQ! Looking forward to being a part of their awesome team :)
I used Radamsa to fuzz and find an inconsistency between 2 NodeJS URL parsers and bypass host whitelisting in Kibana webhooks. The impact was low here but the parser issue can probably cause some trouble in other Node code bases. Read more details 👇 blog.deesee.xyz/fuzzing/securi…
More great lessons on fuzzing from @Nosoynadiemas! I am always excited when I see a new post in this series. Thank you for sharing!
Learn how to take aim at HTTP attack surfaces in @Nosoynadiemas series on fuzzing the Apache Web Server github.co/2OdR2SK
Istio vulnerability with an 8.2 CVSS. They're calling it a 0day. Also a lesson in JWT validation mistakes. > If a JWT token is presented with an issuer that does not match the issuer field specified in JwtProvider, then the request is mistakenly accepted groups.google.com/g/envoy-securi…
@h3xstream @nst021 Thank you for letting me know! Love the depth of this piece. It also provides coverage for languages that I skipped like Swift, Perl, Obj-C, and Lua. Added a link and shout out in the Takeaways section :)
@nlohmann The trials included: 1) attempting to induce duplicate keys through truncation 2) fuzzing Unicode codepoints/raw/transforms 3) using unofficial JSON grammar 4) edge-case numbers 5) adding small quirks/errors: stray quotes or backslashes, odd whitespace. Hope that helps! (2/2)
@nlohmann Hey Niels! Nice to meet you :) During my tests, nlohmann/json had behavior consistent with JSON parsing "norms" and the spec. Notably, it made excellent use of exceptions! I'd be happy to provide more context on the test cases. (1/2)
@pry0cc Haha I was biting my tongue earlier this week, as my new research was just about to be published, but now I can share it. JSON Interoperability Vulnerabilities: labs.bishopfox.com/tech-blog/an-e…
JSON Interoperability vulnerabilities sound like they have some serious bug-bounty potential. Nice work once again by @theBumbleSec/@bishopfox labs.bishopfox.com/tech-blog/an-e…
@albinowax @irsdl @bishopfox Can't wait to see it! Feel free to DM me. I have some ideas :)
Accompanying labs and cheat sheet: github.com/BishopFox/json…
Just when you thought JSON was the one thing you could trust. My latest research on JSON interoperability vulnerabilities highlights the risks of inconsistent parser behavior (40+ parsers) and attacks to bypass business logic in microservice architectures. labs.bishopfox.com/tech-blog/an-e…
Sam Curry @samwcyo
101K Followers 1K Following
Julien | MrTuxracer �... @MrTuxracer
39K Followers 442 Following Founder of @rcesecurity | #BugBounty | @Hacker0x01 MVH && H1-Elite | $1,5+ Mio in Bounties | Mobile Hacker | @[email protected]
Nate @nnwakelam
43K Followers 1K Following
shubs @infosec_au
59K Followers 2K Following Co-founder, security researcher. Building an attack surface management platform, @assetnote
James Kettle @albinowax
84K Followers 103 Following Director of Research at @PortSwigger aka @Burp_Suite. Find my research, tools & contact details at https://t.co/vP6UbGmvl3
Luke Stephens (hakluk... @hakluke
100K Followers 2K Following Hacker, marketer. I manage socials and marketing for cybersecurity orgs. Founder of @hacker_content and @haksecio
STÖK ✌️ @stokfredrik
138K Followers 1K Following Hi.. im that hacker / creative that your friends told you about.,
chompie @chompie1337
89K Followers 1K Following hacker, exploit developer/weird machine mechanic head of X-Force Offensive Research (XOR) @IBM
Nicolas Grégoire @Agarri_FR
28K Followers 628 Following Web hacker and Burp Suite Pro trainer Refer to https://t.co/D5tRH7U2hg for trainings Follow @MasteringBurp for free tips and tricks
Tuan Anh Nguyen⚡️... @haxor31337
16K Followers 2K Following 30 y/o Bug Bounty Hunter and Red Team Lead at Viettel Cyber Security. Brand Ambassador @Hacker0x01 - Researcher Spotlight @Bugcrowd
Dave Kennedy @HackingDave
231K Followers 6K Following Founder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhdJh. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
Md Ismail Šojal �... @0x0SojalSec
48K Followers 5K Following Cyber_Security_Re-searcher || Ai Re-searcher || AI-Sec|| Malware Analysis II iOS || Pwn || 0SINT || Project AI-StrikeSec || 0ldAccounts Suspended @0xSojalSec ||
Harsh Jaiswal @rootxharsh
22K Followers 1K Following Building @hacktronai | researching at @httpvoid0x2f | auditing at @cure53berlin | prev @zomato @vimeo @pdiscoveryio
Houssam Miliani @N0rmalizer_
35 Followers 646 Following
onarph @onarph
0 Followers 37 Following
Marcelo Prado @mprado
3K Followers 1K Following Staff AI Engineer @brexhq. I like to build cool shit and ride bikes 🏍️ Leading our new AI Assistant to help customers automate their work
harsh raj @harsh38raj
0 Followers 77 Following
twis @Twis65640Twis
1 Followers 523 Following
sin99xx @sin99xx
922 Followers 598 Following “The impediment to action advances action. What stands in the way becomes the way.” l (╯°□°)╯
Evan Klein @EvanKlein338226
408 Followers 815 Following Security researcher | Pentester for Austin startups | Finding vulns before the bad guys | HS student @AlphaSchoolATX | DM for assessments
Sean @SeanSneakly
0 Followers 50 Following
Balú @RaulPastor7
108 Followers 428 Following
0xadt204 @0xadt204
3 Followers 483 Following
saifuddine @saifuddineX
145 Followers 587 Following Site Reliability Engineer "SRE" at a smart office furniture company | MIS Student | Bug Bounty Hunter | Tech Enthusiast | مصري | مسلم ـــــــ تحيا مصر 🇪🇬
Mogtaba @MOGTABA_X
23 Followers 834 Following
Johnny @Luckyrocky2028
251 Followers 7K Following Stay Hungry, Stay Foolish. Only those who are self-disciplined can attain true freedom.|No Politics.
Cyberkid0x1🇵🇸 @Cyberkid012
806 Followers 2K Following Cyber Security Enthusiasts, Bug hunter, Ethical Hacker, Certified Appsec Practitioner 😎👨💻👩💻👩💻💾.
𝕋ℍ𝔼 𝟘-𝔻... @the_0_day
0 Followers 2K Following Web Developer & Pentester | Let's Work Together To Secure The Web.
usama1912 @usama1912
0 Followers 190 Following
Vaisov Bek @vaisovbek
808 Followers 7K Following Security Researcher aka Bug Bounty Hunter | CTF Player
Mahmoud Ashraf @Mhmud_Ashraf
3 Followers 77 Following
Lorsom @lorsom10
1 Followers 46 Following
Akash P @akash_p1989
48 Followers 2K Following
Nekrom @Nekrom__
259 Followers 867 Following Bug Bounty & Red Teaming Tips and Tricks 💻 #Cybersecurity #BugBounty #BugBountyTips #RedTeam
Kevin Shakwa @sh4kw4
2 Followers 78 Following
Mohamed haddad @medhaddad0
1 Followers 162 Following
hik hok @hikhok998371
0 Followers 37 Following
sagitz @sagitz_
8K Followers 895 Following Cloud Security Researcher at @wiz_io • Microsoft Most Valuable Researcher 21/22/23 • Black Hat Speaker • Ask me anything about https://t.co/57lyhfcUee
EnidNicholas @44Kt9fqNi6Fp1g
35 Followers 2K Following
Intigriti @intigriti
211K Followers 668 Following Bug bounty & VDP platform trusted by the world’s largest organisations! 🌍
Sam Curry @samwcyo
101K Followers 1K Following
Ben Sadeghipour @NahamSec
249K Followers 1K Following Cofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
Gareth Heyes \u2028 @garethheyes
38K Followers 1K Following Web security researcher at PortSwigger. Author of JS for Hackers and Hackvertor. https://t.co/e0aNEbFb9D
Julien | MrTuxracer �... @MrTuxracer
39K Followers 442 Following Founder of @rcesecurity | #BugBounty | @Hacker0x01 MVH && H1-Elite | $1,5+ Mio in Bounties | Mobile Hacker | @[email protected]
Nate @nnwakelam
43K Followers 1K Following
shubs @infosec_au
59K Followers 2K Following Co-founder, security researcher. Building an attack surface management platform, @assetnote
James Kettle @albinowax
84K Followers 103 Following Director of Research at @PortSwigger aka @Burp_Suite. Find my research, tools & contact details at https://t.co/vP6UbGmvl3
Luke Stephens (hakluk... @hakluke
100K Followers 2K Following Hacker, marketer. I manage socials and marketing for cybersecurity orgs. Founder of @hacker_content and @haksecio
PortSwigger Research @PortSwiggerRes
122K Followers 7 Following Web security research from the team at @PortSwigger
STÖK ✌️ @stokfredrik
138K Followers 1K Following Hi.. im that hacker / creative that your friends told you about.,
Aditya @ADITYASHENDE17
63K Followers 421 Following MS Cyber 🇬🇧 | Work @BforeAI | @Bugcrowd Top 100 | Solo Bug Bounty Hunter/Trainer | Professional Biker | @kong_sec 🇮🇳 | Own Views ≠ Employment |
Yassine Aboukir 🐐 @Yassineaboukir
33K Followers 415 Following HackerOne Top 40, Elite, Pentest Lead, Ambassador, x2 MVH Title, $1 million bounties and ex- Hacker Advisory Board • Digital Nomad/Hybrid Athlete/Surfer
ϻг_ϻε @steventseeley
23K Followers 560 Following Artist disguised as a logician. Pwn2Own Winner. Spiritual Alchemy. An adept in the making.
chompie @chompie1337
89K Followers 1K Following hacker, exploit developer/weird machine mechanic head of X-Force Offensive Research (XOR) @IBM
Nicolas Grégoire @Agarri_FR
28K Followers 628 Following Web hacker and Burp Suite Pro trainer Refer to https://t.co/D5tRH7U2hg for trainings Follow @MasteringBurp for free tips and tricks
kylebot @ky1ebot
6K Followers 334 Following @OpenAI | CTF player @Shellphish | PhD @ASU | @angrdothorse dev | Author of how2heap, angrop | Vulnerability Research Hobbyist
rkvl @rkervell
566 Followers 781 Following
Mayank Bansal @MankyBansal
318 Followers 461 Following Building ChatGPT at @openai | EB-1A & O-1A recipient
Stephen Brandon @brandon_stephen
102 Followers 200 Following Engineering Manager. Corgi connoisseur. Database guy.
Rohan Varma @TheRohanVarma
24K Followers 358 Following codex @openai, prev: @cursor_ai @adoptclarity, @tryexplo, @czi, @palantirtech
Zain Shah @zan2434
20K Followers 3K Following teaching machines @southpkcommons previously: @samsung @opendoor @openai @ycombinator S13
Thinking Machines @thinkymachines
177K Followers 1 Following Thinking, beeping, and booping. @tinkerapi
Sholto Douglas @_sholtodouglas
48K Followers 2K Following Scaling RL @AnthropicAI, ex @DeepMind - working towards intelligence too cheap to meter
Noam Brown @polynoamial
152K Followers 939 Following Researching reasoning @OpenAI | Co-created Libratus/Pluribus superhuman poker AIs, CICERO Diplomacy AI, and OpenAI o-series 🍓 reasoning models
Pliny the Liberator �... @elder_plinius
227K Followers 1K Following ⊰•-•⦑ latent space steward ❦ prompt incanter 𓃹 hacker of matrices ⊞ breaker of markov chains ☣︎ ai danger researcher ⚔︎ bt6 ⚕︎ architect-healer ⦒•-•⊱
Qrious Secure @qriousec
3K Followers 4 Following Pwn2Owner since 2020 Debugger is main vehicle to satisfy our boundless Qriousity. A non-profit hackers' club driven by passion.
Nguyen The Duc @ducnt_
3K Followers 392 Following Just another web warrior ⚔️ Security Researcher ۞ Principal Security Engineer @Verichains ۞ Pwn2Own 2023 ۞@vnsec squad ۞ 💰https://t.co/wuyz6IfAbA ۞ nano 💻
Pham Khanh @rskvp93
2K Followers 373 Following Security Engineer at @calif_io. Winner of Pwn2own Vancouver 2021, Torento 2022, Vancouver 2023. MSRC top 100 2019, 2020, 2021.
Calif @calif_io
6K Followers 31 Following We're https://t.co/KTEDnC2VUV. Join us to make the Internet safer for your mum and everyone else: https://t.co/eUFMLkW9t2.
Marcelo Prado @mprado
3K Followers 1K Following Staff AI Engineer @brexhq. I like to build cool shit and ride bikes 🏍️ Leading our new AI Assistant to help customers automate their work
Mike Ruth @MF_Ruth
282 Followers 183 Following Senior Staff Security Engineer @Rippling | Brex, Cruise, VMware alum | M.C. & host @Defcon @cloudvillage_dc | Play Games. Heal Kids. @ExtraLife4Kids 🎮
MOGWAI LABS GmbH @mogwailabs
515 Followers 0 Following a infosec boutique with a strong emphasis on offensive security, based in Neu-Ulm (South Germany)
Angelboy @scwuaptx
6K Followers 997 Following Senior Security Researcher at @d3vc0r3 MSRC 2024/2025/2026 MVR Top 100
Alisa Esage Шевч�... @alisaesage
41K Followers 99 Following Independent hacker and researcher, owner of Zero Day Engineering @zerodayalpha • Newsletter: https://t.co/vKGn2Qbk5B
sean @seanyeoh
2K Followers 478 Following formerly @assetnote. appsec @ bytedance. tweets and thoughts are my own.
Inti De Ceukelaire @securinti
29K Followers 370 Following Hacker | @intidc (Dutch) | Chief Hacker Officer @intigriti
Hussein Nasser @hnasr
89K Followers 640 Following Backend and Database Courses https://t.co/Qonec4YftL YouTube https://t.co/FfDg8cnVCI Author of Root Cause https://t.co/x5hQ6JCIcw Engineer @esri
Joao Matos @joaomatosf
2K Followers 959 Following
Colin O'Brien @InsanityBit
2K Followers 488 Following Software Engineer @tines_hq Previously: SWE @Datadog CEO/ Founder of @graplsec SecEng @Dropbox SWE @Rapid7
Kev @kevin_backhouse
4K Followers 142 Following Security researcher @GHSecurityLab @GitHub. Opinions are my own. he/him
daniel:// stenberg:// @bagder
58K Followers 525 Following Typos and segfaults. I write curl. On team @wolfSSL. I don't know anything. @[email protected] My weekly email: https://t.co/9UYYYMLWaw
Tetrane @tetrane
1K Followers 1 Following Creator of REVEN - Timeless Debugging & Analysis Platform. Software Reverse-Engineering for Vulnerability & Malware Analysis Now part of eShard
𝚑𝚐𝟾 @_hg8_
3K Followers 470 Following Security Researcher & Privacy Activist. 🐘 DM are welcome for any questions.
Kuba Gretzky @mrgretzky
17K Followers 765 Following Creator of Evilginx - Reverse Proxy Phishing Framework for Red Teams: https://t.co/hPg644CTnM
ohjin @pwn_expoit
4K Followers 453 Following I'm still hungry. I will be world-class, @[email protected]
Philippe Arteau @h3xstream
3K Followers 215 Following Security Researcher, interested in web security, crypto, pentest, static analysis but most of all, samy is my hero.
Flashback Team @FlashbackPwn
4K Followers 3 Following Hacking team (@pedrib1337 + @RabbitPro), winners of Pwn2Own Tokyo 2020. We hack stuff and make videos: https://t.co/lqSIfETowB
Harsh Jaiswal @rootxharsh
22K Followers 1K Following Building @hacktronai | researching at @httpvoid0x2f | auditing at @cure53berlin | prev @zomato @vimeo @pdiscoveryio
Rahul Maini @iamnoooob
15K Followers 2K Following Research at @httpvoid0x2f @HacktronAI, before @pdiscoveryio
Atul @atul_hax
1K Followers 547 Following I attach a debugger and (cry|rant|yell|bang my head|you name it) until I have a exploitable bug. ?? #FIELD_OFFSET(nt!_EPROCESS, Token) long 0x4b8
h0mbre @h0mbre_
16K Followers 663 Following # Exploit Reliability Engineer # Developing a full-system snapshot fuzzer: https://t.co/mfVXhwoGYD # Avi: https://t.co/3fsQfVprCf













































