Deep dives into AI security, web application vulnerabilities, bug bounty hunting, and offensive security research. From CVEs to conference talks.
Bypassing "Invite Only" workspace restriction through the Slack integration's joinTeam callback. $1,200 bounty.
Bypassing Trello Premium's board deletion restrictions by moving the board to an attacker-controlled workspace. $1,200 bounty.
Any board member can trigger another user's private Butler automation via the powerup-run-command API. $300 bounty.
Prompt injection, agent exploitation, model supply chain attacks, guardrail bypass
SSRF, SQLi, XSS, IDOR, authentication bypass, API vulnerabilities
Detailed writeups from real programs — methodology, tooling, and full attack chains
Custom exploits, automation scripts, recon workflows, and open-source security tools
New writeup notifications, research drops, and security insights. No spam, just signal.