bsysop Profile Banner
bsysop Profile
bsysop

@bsysop

Followers
6K
Following
7K
Media
371
Statuses
5K

TOP12 @bugcrowd, TOP7 P1 Warrior 🚀 H1 AWC Champions 2024 and 2025 https://t.co/4PRRx7QQaH 🤟🏻 https://t.co/eehzMtCJO4

Miami, FL
Joined May 2011
Don't wanna be here? Send us removal request.
@bsysop
bsysop
9 months
Super happy to see our research ranking #3 in @PortSwigger Top Web Hacking Techniques of 2024! 🚀 This one was a wild ride! Huge thanks to @_medusa_1_ & @sw33tLie for the amazing teamwork and to @Bugcrowd, who supported us! ❤️ What next? Keep tuned 👀🥷🏻 #BugBounty #Hacking
@PortSwiggerRes
PortSwigger Research
9 months
The results are in! We're proud to announce the Top ten web hacking techniques of 2024!
10
9
96
@rez0__
Joseph Thacker
16 days
I interviewed the dynamic duo of @busf4ctor and @monkehack who just received the Top AI Hackers award from the last Google live hacking evnet 😊
3
16
82
@bsysop
bsysop
26 days
Diegoooo! 🔥 What a beast! Congratulations, man! One of the best mindsets out there, achieving one of the best results. Super well deserved! 💪👏
@_godiego__
godiego
28 days
Very happy to have received my @Hacker0x01 H1 Elite! Thank you to all my friends and collaborators over the years 🫶🏻 Also congrats to @alicanact60 on receiving his too! 🇹🇷🤝🇪🇸
1
0
16
@nunezspace
What I know
17 hours
I yearned for the truth to confirm my identity as a genuinely honest man—someone reliable in both speech and action. Yet the truth remained elusive. It wasn’t present in my family, nor in the religion I had known; not in school, nor in the workplace. Where could it be found? I
0
0
6
@bsysop
bsysop
26 days
What a legend!!! 🎉 Congratulations, Mr. Ali — you super well deserve it. Your talent and consistency keep setting the bar higher every single time. 🔥💪
@alicanact60
Ali Tütüncü
28 days
I’m officially a HackerOne Elite!!! Huge thanks to the @Hacker0x01 team for making this possible, and to all my friends for their amazing support. This is truly a big milestone in my journey, and I couldn’t be more excited! Congrats to @_godiego__ on receiving his too! 🇪🇸🤝🇹🇷
1
0
31
@j_zere
zere
26 days
During my bachelor's thesis, I reviewed several web apps of my university and ended up finding a large number of vulnerabilities. Here are a few that stood out, technically simple, yet highly critical. https://t.co/KBNC1KjBqf
Tweet card summary image
zere.es
During my final degree project, I audited several web applications from my university, the Universidad Politécnica de Madrid, and identified hundreds of vulnerabilities, many of which had a critical...
5
19
131
@pentestlyio
Pentestly.io
2 months
We recently carried out a series of Supabase audits for clients - and we kept running into the same pitfalls. Our latest write-up covers the most common misconfigurations and strange defaults we see in Supabase - along with how teams can avoid them. 👇 https://t.co/IeRowx4X1d
Tweet card summary image
pentestly.io
Harden Supabase with the following cheat-sheet with clear steps for RLS, schemas, Edge Functions, Storage, CORS and tokens. Built from real audits.
0
3
7
@bsysop
bsysop
2 months
Are you in São Paulo on Dec 13–14? Join us at the Bug Bounty Village @ H2HC! Call for Papers is open
@BugBountyBr
Bug Bounty Village Brazil
2 months
🚨 CALL 4 PAPERS — Bug Bounty Village @ H2HC 2025 🚨 Caçou um bug insano? Tem case real ou técnica nova? Esse é seu palco! Envie sua proposta pelo form: https://t.co/vtbDfTBXiR #H2HC #BugBountyVillage #Call4Papers #HackerCulture
1
0
5
@infosec_au
shubs
2 months
My favourite finding from @SLCyberSec's Security Research team in 2025 so far is a secondary context path traversal in Omnissa Workspace One UEM (CVE-2025-25231). Really interesting bug, and fun kill chain to RCE.
Tweet card summary image
slcyber.io
Secondary Context Path Traversal vulnerability in Omnissa Workspace One UEM (CVE-2025-25231) that leads to pre-auth API access as a super admin.
4
48
200
@bsysop
bsysop
2 months
This is 🔥
@infinitelogins
Harley Kimball
2 months
This week, Disclosed. #BugBounty Spotlight on CodeRabbit Exploit, NahamSec’s DEF CON vlog, Swiss Post’s €230K challenge, new tools for hunters, and more. Full issue → https://t.co/Affe2Yws7J Highlights below 👇 @KudelskiSec details how vulnerabilities in CodeRabbit’s AI
0
3
24
@WebSecAcademy
Web Security Academy
3 months
Moving to upstream HTTP/2 slams the door on desync attacks. Binary framing eliminates the ambiguity HTTP/1.1 suffers from, reducing exploitability. In this blog, @albinowax, Director of Research at PortSwigger, outlines a clear case for replacing HTTP/1.1 with HTTP/2 to prevent
0
19
98
@NEARProtocol
NEAR Protocol
4 days
NEAR 🤝 Sovereign AI Want to learn more about @svrn_ai? Join them live at 9am EST Oct 29th to hear how they will be supporting NEAR Protocol in powering the agentic future. Featuring: Sal, David, NEAR Legion
15
66
444
@0xacb
André Baptista
3 months
Just released a new recollapse version thanks to @ryancbarnett and @4ng3lhacker after their talk in @BlackHatEvents today. What’s new? 💥Mode 6: Fuzz case folding/upper/lower 💥 Mode 7: Fuzz byte truncations 💥 Recollapse is now available to use as a python library and
5
76
382
@sw33tLie
sw33tLie
3 months
Super glad to have collaborated on @albinowax’s research this year with @bsysop and @_medusa_1_. Funny enough, it all started with a random Slack DM that revealed a potential research collision with James, and things took off from there.
@albinowax
James Kettle
3 months
The whitepaper is live! Learn how to win the HTTP desync endgame... and why HTTP/1.1 needs to die:
8
6
113
@bsysop
bsysop
3 months
Thanks for the transparency and support during the research @ryancbarnett @akamai_research
@ryancbarnett
Ryan Barnett (B0N3)
3 months
Outstanding research by @albinowax, @bsysop and team. Here is @akamai_research coordinated response information - https://t.co/zVc4XgEsio
0
0
10
@bsysop
bsysop
3 months
It was great to see you all 🤟🏻
@ryancbarnett
Ryan Barnett (B0N3)
3 months
Thanks to @Hacker0x01 for the Vulnerability Vibes Event! I was awesome to finally meet many bug hunters in person. @rez0__ @0xacb @monkehack @bsysop @sw33tLie @Brumens2 @BadAt_Computers we didn’t get a pick!
1
0
10
@WebSecAcademy
Web Security Academy
3 months
🕵️‍♂️ 🎩 The desync endgame has just begun. New expert lab has just dropped. Straight from @albinowax’s #BHUSA talk: Understand the latest request smuggling techniques, sharpen your skills, unlock new bounties, and solidify your organization’s defenses with the new expert lab ⬇️
1
34
240
@albinowax
James Kettle
3 months
At #BlackHat? Catch "HTTP/1.1 Must Die! The Desync Endgame" today at 3:20 in Oceanside A, Level 2. Hope to see you there!
2
9
99
@Bugcrowd
bugcrowd
3 months
Let’s hear it for Bugcrowd’s Top P1 Hacker of 2025… priyanshuxo! 👑👏 This title is so much more than a badge. It celebrates the quiet grind behind every critical find. Long nights, dead ends, and countless hours dissecting complex systems… all fueled by curiosity and the
4
10
123
@bsysop
bsysop
3 months
At the moment, it is only compatible with @Bugcrowd, others are in the backlog. Any AI interaction is powered by @OpenAI and linked to your own ChatGPT account. Pull Requests and/or Issues are welcome in the repository 🙏🏻 CrowdAssist Link: https://t.co/QLy9Rb96Va #BugBounty
Tweet card summary image
github.com
Contribute to bsysop/CrowdAssist development by creating an account on GitHub.
1
0
24
@bsysop
bsysop
3 months
CrowdAssist can help you to: - Let AI ✨ help review and polish your reports and comments - Write reports with AI ✨ (Experimental) - Respond faster and more efficiently to triagers and Programs - Export report in Markdown - Add your IP in One-click - and more 🧵👇 #BugBounty
1
0
9
@bsysop
bsysop
3 months
CrowdAssist is a Chrome Extension built to simplify your workflow and help you interact with Bug Bounty platforms (Bugcrowd by now), adding some key features to improve the quality of your reports and reply more effectively when required. 🧵👇 #BugBounty #BugBountyTIps
1
0
11
@bsysop
bsysop
3 months
TOOL RELEASE🔥🚀 Clear reports and good communication with the teams can make the difference in the outcome of your report, including the final bounty/bonus. To assist you in the reporting and communication, here is CrowdAssist ✨. @Bugcrowd compatible. 🧵👇 #BugBounty #AI
7
38
201