bsysop
@bsysop
Followers
6K
Following
7K
Media
372
Statuses
5K
TOP10 @bugcrowd, TOP7 P1 Warrior 🚀 H1 AWC Champions 2024 and 2025 https://t.co/4PRRx7QQaH 🤟🏻 https://t.co/eehzMtCJO4
Miami, FL
Joined May 2011
Super happy to see our research ranking #3 in @PortSwigger Top Web Hacking Techniques of 2024! 🚀 This one was a wild ride! Huge thanks to @_medusa_1_ & @sw33tLie for the amazing teamwork and to @Bugcrowd, who supported us! ❤️ What next? Keep tuned 👀🥷🏻 #BugBounty #Hacking
10
9
96
Are you more of a night hacker or a daytime hunter? 🌃 If you're neither, sign up and start hacking today: https://t.co/a7nbuFrT6D
4
4
52
CrowdAssist Update. - Auto-Renew Session If you keep getting disconnected from BugCrowd every few hours, CrowdAssist can automatically renew your session for you (eventually, this feature may be removed later) - Firefox Compatibility Happy Hacking 🤟🏻 #CrowdAssist #BugBounty
TOOL RELEASE🔥🚀 Clear reports and good communication with the teams can make the difference in the outcome of your report, including the final bounty/bonus. To assist you in the reporting and communication, here is CrowdAssist ✨. @Bugcrowd compatible. 🧵👇 #BugBounty #AI
0
1
21
I interviewed the dynamic duo of @busf4ctor and @monkehack who just received the Top AI Hackers award from the last Google live hacking evnet 😊
3
16
83
Diegoooo! 🔥 What a beast! Congratulations, man! One of the best mindsets out there, achieving one of the best results. Super well deserved! 💪👏
Very happy to have received my @Hacker0x01 H1 Elite! Thank you to all my friends and collaborators over the years 🫶🏻 Also congrats to @alicanact60 on receiving his too! 🇹🇷🤝🇪🇸
1
0
16
What a legend!!! 🎉 Congratulations, Mr. Ali — you super well deserve it. Your talent and consistency keep setting the bar higher every single time. 🔥💪
I’m officially a HackerOne Elite!!! Huge thanks to the @Hacker0x01 team for making this possible, and to all my friends for their amazing support. This is truly a big milestone in my journey, and I couldn’t be more excited! Congrats to @_godiego__ on receiving his too! 🇪🇸🤝🇹🇷
1
0
31
During my bachelor's thesis, I reviewed several web apps of my university and ended up finding a large number of vulnerabilities. Here are a few that stood out, technically simple, yet highly critical. https://t.co/KBNC1KjBqf
zere.es
During my final degree project, I audited several web applications from my university, the Universidad Politécnica de Madrid, and identified hundreds of vulnerabilities, many of which had a critical...
5
20
133
We recently carried out a series of Supabase audits for clients - and we kept running into the same pitfalls. Our latest write-up covers the most common misconfigurations and strange defaults we see in Supabase - along with how teams can avoid them. 👇 https://t.co/IeRowx4X1d
pentestly.io
Harden Supabase with the following cheat-sheet with clear steps for RLS, schemas, Edge Functions, Storage, CORS and tokens. Built from real audits.
0
3
8
Are you in São Paulo on Dec 13–14? Join us at the Bug Bounty Village @ H2HC! Call for Papers is open
🚨 CALL 4 PAPERS — Bug Bounty Village @ H2HC 2025 🚨 Caçou um bug insano? Tem case real ou técnica nova? Esse é seu palco! Envie sua proposta pelo form: https://t.co/vtbDfTBXiR
#H2HC #BugBountyVillage #Call4Papers #HackerCulture
1
0
5
My favourite finding from @SLCyberSec's Security Research team in 2025 so far is a secondary context path traversal in Omnissa Workspace One UEM (CVE-2025-25231). Really interesting bug, and fun kill chain to RCE.
slcyber.io
Secondary Context Path Traversal vulnerability in Omnissa Workspace One UEM (CVE-2025-25231) that leads to pre-auth API access as a super admin.
4
49
200
This is 🔥
This week, Disclosed. #BugBounty Spotlight on CodeRabbit Exploit, NahamSec’s DEF CON vlog, Swiss Post’s €230K challenge, new tools for hunters, and more. Full issue → https://t.co/Affe2Yws7J Highlights below 👇 @KudelskiSec details how vulnerabilities in CodeRabbit’s AI
0
3
23
Moving to upstream HTTP/2 slams the door on desync attacks. Binary framing eliminates the ambiguity HTTP/1.1 suffers from, reducing exploitability. In this blog, @albinowax, Director of Research at PortSwigger, outlines a clear case for replacing HTTP/1.1 with HTTP/2 to prevent
0
19
98
Just released a new recollapse version thanks to @ryancbarnett and @4ng3lhacker after their talk in @BlackHatEvents today. What’s new? 💥Mode 6: Fuzz case folding/upper/lower 💥 Mode 7: Fuzz byte truncations 💥 Recollapse is now available to use as a python library and
5
78
381
Super glad to have collaborated on @albinowax’s research this year with @bsysop and @_medusa_1_. Funny enough, it all started with a random Slack DM that revealed a potential research collision with James, and things took off from there.
8
6
113
Thanks for the transparency and support during the research @ryancbarnett @akamai_research
Outstanding research by @albinowax, @bsysop and team. Here is @akamai_research coordinated response information - https://t.co/zVc4XgEsio
0
0
10
It was great to see you all 🤟🏻
Thanks to @Hacker0x01 for the Vulnerability Vibes Event! I was awesome to finally meet many bug hunters in person. @rez0__ @0xacb @monkehack @bsysop @sw33tLie @Brumens2
@BadAt_Computers we didn’t get a pick!
1
0
10
🕵️♂️ 🎩 The desync endgame has just begun. New expert lab has just dropped. Straight from @albinowax’s #BHUSA talk: Understand the latest request smuggling techniques, sharpen your skills, unlock new bounties, and solidify your organization’s defenses with the new expert lab ⬇️
1
33
240
At #BlackHat? Catch "HTTP/1.1 Must Die! The Desync Endgame" today at 3:20 in Oceanside A, Level 2. Hope to see you there!
2
9
99
Let’s hear it for Bugcrowd’s Top P1 Hacker of 2025… priyanshuxo! 👑👏 This title is so much more than a badge. It celebrates the quiet grind behind every critical find. Long nights, dead ends, and countless hours dissecting complex systems… all fueled by curiosity and the
4
10
121
At the moment, it is only compatible with @Bugcrowd, others are in the backlog. Any AI interaction is powered by @OpenAI and linked to your own ChatGPT account. Pull Requests and/or Issues are welcome in the repository 🙏🏻 CrowdAssist Link: https://t.co/QLy9Rb96Va
#BugBounty
github.com
Contribute to bsysop/CrowdAssist development by creating an account on GitHub.
1
1
26