SecGus Profile Banner
chivato Profile
chivato

@SecGus

Followers
5K
Following
3K
Media
242
Statuses
3K

full-time bug bounty hunter

Lisbon, Portugal
Joined April 2015
Don't wanna be here? Send us removal request.
@SecGus
chivato
7 months
Yay, I was awarded a $18,000 bounty on @Hacker0x01! Don’t normally post these, but proud of this one ☝️ #TogetherWeHitHarder
14
6
330
@deobfuscately
Benjamin
16 hours
0
2
9
@chesscom
Chess.com
4 days
241
830
15K
@vasumanmoza
vas
27 days
Vibe coding is crazy man. Met a 12yr old making $600k a month with his vibe-coded SaaS he started 4 months ago. I asked how he built so fast. He said he just made a design-doc in GPT and fed it to Cursor with Sonnet-4 and it worked first try. His goal is to get to $2M a month
671
680
17K
@hipotermia
hipotermia
2 months
Madrid: el jueves 11 de septiembre por la tarde organizamos un "Speed Show & Tell", abierto a quien quiera presentar. Plazas limitadas, toda la info y registro aquí 👉
0
8
32
@Restore_NJ
Restore New Jersey
20 days
MODERATOR: Are you willing to commit to NOT raise the sales tax? MIKIE SHERRILL: I'm not going to commit to anything right now. On Nov. 4, vote NO on Mikie Sherrill. ❌
43
113
397
@_godiego__
godiego
2 months
Spanish team, champions of the @Hacker0x01 AWC cup 2024 🇪🇸🇪🇸
12
14
196
@Hacker0x01
HackerOne
4 months
The security research community in Europe and the Middle East just got even stronger. Say hello to these new HackerOne Brand Ambassadors: 🇦🇿 @AzeriumD34132 (Azerbaijan—new club!) 🇧🇪 @dropn0w & @hgreal1 (Belgium—new club!) 🇩🇰 @mthirup (Denmark—new club!) 🇮🇹 @Al7eX91 &
8
12
81
@hipotermia
hipotermia
4 months
3
9
222
@SecGus
chivato
5 months
That's a wrap for H1-6102, it was a pleasure meeting all the new faces (@bsysop @monkehack etc). Thanks to @salesforce & @Hacker0x01 for an amazing event out it Sydney!
3
2
71
@alexbindrei
Alexandrio
5 months
We won the H1 Ambassadors World Cup again! 🇪🇸 🧵A thread about our journey during the finals, the experience in Dubai, and a quick trip to Oman ⬇️
14
16
256
@Kahlissee
Khalissee
6 months
THE FULL DOCUMENTARY: Louis Theroux’s “The Settlers” (2025) Essential Viewing! Modern Israel’s foundation exposed - Settlers from around the globe seizing land, pushing an expansionist agenda that still drives unrest today.
150
5K
12K
@SecGus
chivato
6 months
the og bb scam
@How2use_AI
How 2 AI
6 months
In 2015, Google accidentally listed its domain for sale. A former employee noticed and snatched it up for just $12. Google had no choice but to meet his demands. What did he ask for? Not $100,000. Not $100 million. Here’s what he actually requested:
0
0
4
@SecGus
chivato
7 months
marketing team needs a raise
@Burp_Suite
Burp Suite
7 months
☘️ Ever tried to 'Split the B'? Neither had we—until now! Happy St. Patrick's Day from the PortSwigger team! Watch as some of the team tries to master this techy twist on a well-loved tradition. Sláinte! 🍻 (Non-alcoholic beer was used in the making of this video.)
0
0
3
@SecGus
chivato
8 months
Just had a really good experience with a triager on BugCrowd chasing a customer to payout the correct bounty. We need more technical triagers willing to put in the time to chase leads like this and fight for the hackers. Kudos to TheArtisan on @Bugcrowd !
1
0
37
@_godiego__
godiego
8 months
Guess who this was? I was talking about my great friend chivato aka @SecGus 😁
@Bugcrowd
bugcrowd
8 months
Hacking or Socializing? The LHE dilemma (with @insiderPhD and @_godiego__)
4
2
41
@KhanAbbas201
Abbas Khan
8 months
After observing the 1.5 Billion ByBit hack yesterday. Myself and @sammyaudits decided to dive deeper into all the bug bounties on top 10 centralized exchanges. What I've found is SHOCKING and Scary. Let's go through each one in the thread and callout the terrible and good
26
85
523
@SecGus
chivato
9 months
If anyone has a bypass requests with CSRF tokens on https://t.co/F8NgglY3bM I have an XSS going, 50/50 split
0
0
5
@SecGus
chivato
11 months
Insane work from Xbow pioneering AI offensive security
@Xbow
XBOW
11 months
AI vs AI: How XBOW found a path traversal vulnerability (CVE-2024-53844) in LabsAI's EDDI, an open source conversational AI middleware.
0
2
7
@SecGus
chivato
11 months
fans
@GxlDeFekir
Golde
11 months
“13. SHIBATTO” https://t.co/tmqf5ZNfAa
1
0
4
@SecGus
chivato
1 year
"We take the security of our customers’ data very seriously." "At this stage we do not provide monetary benefit for bugs that are reported." 🤡
0
0
10