Sign in

Alex Chapman

@ajxchapman.bsky.social
2.9K followers 466 following 219 posts

Full Time #BugBounty Vulnerability Researcher blog.ajxchapman.com

PostsRepliesMedia
Reposted by Alex Chapman
cje @cje.io · 01/09/2026
"What is a bug worth" has always been *the* question: The Vulnpocalypse Is Repricing the Bug Bounty Economy www.darkreading.com/vulnerabilit...
darkreading.com
The Vulnpocalypse Is Repricing the Bug Bounty Economy
The surge in AI-powered vulnerability reports is driving down bug bounty prices, and that could spell trouble for independent researchers.
0105
Alex Chapman @ajxchapman.bsky.social · 26/08/2026
Parton _and_ Curry 😔
001
Alex Chapman @ajxchapman.bsky.social · 24/08/2026
My first daughter would have been 8 today. Instead of joy and happiness on her birthday, my family live with a deep sadness on this day. Chloë was stillborn as a result of Edwards Syndrome. I miss her so much, a beautiful life that could have been but was never given the chance. I love you baby, Dad
010
Alex Chapman @ajxchapman.bsky.social · 12/08/2026
Anyone know how to find the focal point of a colander ☀️🌙🌕
010
Alex Chapman @ajxchapman.bsky.social · 15/05/2026
If you run a Bug Bounty program (or platform) now might be a good time for you to publish the average time to triage for various issue severities. There are a _lot_ of disgruntled hackers out there at the moment who are waiting weeks / months for a program to even perform a first look at a report!
3111
Alex Chapman @ajxchapman.bsky.social · 11/05/2026
Bug Bounty is remotely debugging last year's unreliable n-day using last week's reliable n-day... which I can't report because the vendor needs "time to patch." 🤦
040
Reposted by Alex Chapman
Ollie Whitehouse @ollieatnowhere.bsky.social · 10/05/2026
Heading to OffensiveCON this week? Thank you for coming to my talk... claude.ai/share/227b48...
0111
Alex Chapman @ajxchapman.bsky.social · 08/05/2026
Well this is depressing.
100
Reposted by Alex Chapman
Patrick Gray @patrick.risky.biz · 04/05/2026
If you would like to see a preview of @jameskettle.com's Blackhat talk "the HTTP terminator" then check out this interview my colleague @jameswilson.io recorded with him. Some pretty freaky stuff! VIDEO: www.youtube.com/watch?v=GdFG... AUDIO: risky.biz/RBNEWSSI126/
youtube.com
Sponsored: James Kettle built an AI hacker
YouTube video by Risky Business Media
2157
Alex Chapman @ajxchapman.bsky.social · 14/04/2026
2026 and Bug Bounty triage is broken. This has on the horizon for years, even without LLM pressure, but it still seems to have caught _every_ major platform and large private program by surprise.
0121
Reposted by Alex Chapman
James Kettle @jameskettle.com · 14/04/2026
I'm thrilled to announce "Can AI Do Novel Security Research? Meet the HTTP Terminator" will premiere at Black Hat USA! Check out the abstract: blackhat.com/us-26/briefi...
0135
Alex Chapman @ajxchapman.bsky.social · 10/04/2026
👏 @intigriti.com
Submission limits (open submissions)
Updated yesterday
To keep response times fair for everyone, Intigriti may limit how many submissions you can have open at the same time.

 

What is a submission limit?
 

A submission limit restricts how many submissions you can have open simultaneously. The limit is calulated based on your validity ration

 

If you reach the limit, you won’t be able to create a new submission until one of your open submissions is processed.
140
Alex Chapman @ajxchapman.bsky.social · 25/03/2026
The VSCode remote editor function has really gone to crap recently. Any form of linting is just spinning server CPU at 100% and OOM killing random processes. Going to have to go back to filesystem monitoring and rsync at this rate.
040
Reposted by Alex Chapman
renniepak @renniepak.nl · 19/03/2026
When reviewing pull requests with new additions for CSPBypass.com, I often find myself questioning how useful a given entry actually is. If no websites whitelist a specific host, there is little point in adding it.
155
Alex Chapman @ajxchapman.bsky.social · 10/03/2026
Every bug hunter / vulnerability researcher / pentester should have to write their own blind or timing based SQL injection tool. It's like a rite of passage, if you've taken the time to understand and produce your own you'll probably make it in this world, if not 😬 x.com/slonser_/sta...
152
Reposted by Alex Chapman
mkultra tournament edition @amenbreakpoint.com · 10/03/2026
Last BSidesNYC I sat behind a guy doing the CTF with ChatGPT. Ctrl-a paste page source and a screenshot, hit enter, repeat. User totally not reading the output. LLM got the flag (flappybird-style JS challenge) after maybe ten rounds of this. Last message dude sent in the session was "We did it!".
141
Alex Chapman @ajxchapman.bsky.social · 10/03/2026
This post on LLM use in CTFs sums up my feelings on the subject nicely. vt.social/@lina/116198... When simply directing LLMs for development / security research / CTFs it's quick, often accurate, often useful, but I don't inherently learn anything other than how to direct the LLM.
vt.social
Hoshino Lina (星乃リナ) 🩵 3D Yuri Wedding 2026!!! (@lina@vt.social)
There's a lot of discourse on Twitter about people using LLMs to solve CTF challenges. I used to write CTF challenges in a past life, so I threw a couple of my hardest ones at it. We're screwed. At ...
341
Alex Chapman @ajxchapman.bsky.social · 04/03/2026
What I'm waiting for: Email updates to 5 separate Bug Bounty reports What I get: Email notifications of 3 year old reports being closed 😭
230
Reposted by Alex Chapman
🇵🇹 snipe, lixo tóxico ⭑⭒⭒⭒⭒ @snipe.lol · 12/01/2026
Same.
redstopgringo
Follow
•••
Are Pinky and the Brain still trying to take over the world? Because at this point, I'm willing to hear the Brain's platform.
the-other-sandy 就@
••.
At this point, I'm willing to hear Pinky's platform.
56
22,966
25,029
611133
Alex Chapman @ajxchapman.bsky.social · 29/11/2025
If you are selling a mirror and your ad creative includes images of the product with impossible reflections, I'm going to have to go ahead and assume your product doesn't work very well!
110
Alex Chapman @ajxchapman.bsky.social · 05/11/2025
I'm sympathetic to corporate policy "patch gaps", but when it's framed as "acceptable exploitation window" it hits on a different level 🤔
280
Reposted by Alex Chapman
Rhianna Pratchett @rhi.bsky.social · 07/10/2025
Dad’s books are full of empathy, common sense, and a healthy suspicion of the powerful. But at its heart his work is also about how systems keep people poor while pretending it’s their own fault. So I hope Kemi’s taking notes as well as reading the jokes.
13877621966
Reposted by Alex Chapman
Alex Chapman @ajxchapman.bsky.social · 28/09/2025
An in depth summary of the consequence of Google VRP increasing bounties in 2024. "We observe statistically significant increases in the reporting of high-value bugs, especially in the highest impact tiers and high merit submissions." 🔥 arxiv.org/abs/2509.16655
arxiv.org
Incentives and Outcomes in Bug Bounties
Bug bounty programs have contributed significantly to security in technology firms in the last decade, but little is known about the role of reward incentives in producing useful outcomes. We analyze ...
083
Alex Chapman @ajxchapman.bsky.social · 28/09/2025
An in depth summary of the consequence of Google VRP increasing bounties in 2024. "We observe statistically significant increases in the reporting of high-value bugs, especially in the highest impact tiers and high merit submissions." 🔥 arxiv.org/abs/2509.16655
arxiv.org
Incentives and Outcomes in Bug Bounties
Bug bounty programs have contributed significantly to security in technology firms in the last decade, but little is known about the role of reward incentives in producing useful outcomes. We analyze ...
083
Alex Chapman @ajxchapman.bsky.social · 18/09/2025
The new favourite fidget toy on my desk is the Zippo lighter I've had since I was a teenager. There is something about the noise of the cap flipping open and flint sparking. This has replaced the ever popular poker chips. Needless to say, I am not a great example for my kids 😬
220
Alex Chapman @ajxchapman.bsky.social · 16/09/2025
Hackers tops the list of films that have influenced my life. Without seeing this film as a young teen I may not have misspent my youth in front of a computer trying to understand how it all worked. Which, despite what my parents suggested at the time, seems to have worked out well for me 😆
090
Alex Chapman @ajxchapman.bsky.social · 12/09/2025
That feeling when you finally read that blog post you've had open in a browser tab for 3 months, and it's complete garbage 😑
0312
Alex Chapman @ajxchapman.bsky.social · 24/08/2025
It's been another year since my wife and I lost our first daughter Chloë. She would have been 7 today. With each passing year I can't help but think about what her life would have been like, what our life would have been like, had she been given a chance. I love her so much, but don't even know her.
1220
Alex Chapman @ajxchapman.bsky.social · 15/08/2025
This jaw dropping write-up of an LLM solving a DEF CON CTF challenge(!) with minimal human interaction 🤯 It seems like "vibe-reversing" is becoming a viable option now...
wilgibbs.com
All You Need Is MCP - LLMs Solving a DEF CON CTF Finals Challenge
DEF CON CTF Every year world-class teams play difficult CTFs such as Plaid CTF and HITCON CTF in an attempt to qualify for DEF CON CTF by getting first place. There are usually only 3-4 CTFs a year de...
1113
Alex Chapman @ajxchapman.bsky.social · 08/08/2025
There is something quite depressing about many of the advertised agentic AI use cases being posting "viral" content to social media. It stinks of one person assuming their time is inherently worth more than everyone else.
Simpsons meme "Old Man Yells At Cloud"
030
Alex Chapman @ajxchapman.bsky.social · 08/08/2025
I've said it before and I'll say it again, Windows 11 is _such_ a hostile user experience, it's like they've actively tried to make it unpleasant to use 😑
181
Reposted by Alex Chapman
avi bagla @avibagla.com · 06/08/2025
Can Bluesky say every word in the dictionary? I dunno but I plan to find out! I made a website that tracks every single word said on bluesky (as of yesterday).
64610136
Reposted by Alex Chapman
James Kettle @jameskettle.com · 07/08/2025
The whitepaper is live! Learn how to win the HTTP desync endgame... and why HTTP/1.1 needs to die: http1mustdie.com
http1mustdie.com
HTTP/1.1 Must Die
Upstream HTTP/1.1 is inherently insecure, and routinely exposes millions of websites to hostile takeover. Join the mission to kill HTTP/1.1 now
04022
Reposted by Alex Chapman
Samuel Groß @saelo.bsky.social · 01/08/2025
We released our Fuzzilli-based V8 Sandbox fuzzer: github.com/googleprojec... It explores the heap to find interesting objects and corrupts them in a deterministic way using V8's memory corruption API. Happy fuzzing!
github.com
Add V8SandboxFuzzer · googleprojectzero/fuzzilli@675eccd
This is a basic fuzzer for the V8 Sandbox. It uses the memory corruption API to implement a random-but-deterministic (given a seed) traversal through the V8 heap object graph and corrupts some obje...
0257
Reposted by Alex Chapman
Alex Chapman @ajxchapman.bsky.social · 21/07/2025
I presented my magnum opus in 2014 and have been in steady decline ever since.
021
Reposted by Alex Chapman
Alex Chapman @ajxchapman.bsky.social · 21/07/2025
There are bad security takes, and then there is @daniel.haxx.se attempting to shame @jameskettle.com for not "responsibly disclosing" a vulnerability to the curl project that doesn't affect the curl project... and _then_ complaining the details are being kept "secret" :facepalm:
mastodon.social
daniel:// stenberg:// (@bagder@mastodon.social)
@albinowax@infosec.exchange @fuomag9@kiwi.fuo.fi @dan@infosec.exchange the website, the naming, the scare, the secrecy
282
Alex Chapman @ajxchapman.bsky.social · 21/07/2025
I presented my magnum opus in 2014 and have been in steady decline ever since.
021
Alex Chapman @ajxchapman.bsky.social · 21/07/2025
There are bad security takes, and then there is @daniel.haxx.se attempting to shame @jameskettle.com for not "responsibly disclosing" a vulnerability to the curl project that doesn't affect the curl project... and _then_ complaining the details are being kept "secret" :facepalm:
mastodon.social
daniel:// stenberg:// (@bagder@mastodon.social)
@albinowax@infosec.exchange @fuomag9@kiwi.fuo.fi @dan@infosec.exchange the website, the naming, the scare, the secrecy
282
Alex Chapman @ajxchapman.bsky.social · 16/07/2025
After the intense focus of Live Hacking Events, I often find myself at quite a deep emotional low point. The highs of the event fade, focus needs to completely shift to other, usually less valuable, targets. I find these events hugely rewarding, but need to remember to be kind to myself after them.
060
Reposted by Alex Chapman
Samuel Groß @saelo.bsky.social · 09/07/2025
If you have a machine with PKEY support and somewhat recent Linux kernel you can now play around with hardware support for the V8 sandbox. When active, JS + Wasm code has no write permissions outside the sandbox address space. To enable, simply set `v8_enable_sandbox_hardware_support = true`.
1184
Alex Chapman @ajxchapman.bsky.social · 09/07/2025
Famous last words: > This just leads to weird behavior, not a vulnerability
010
Reposted by Alex Chapman
Geluchat @gelu.chat · 04/07/2025
Today was my last day as a pentester at Bsecure. After a three-year journey of hunting on the side, I’m ready to go all-in as a full-time bug bounty hunter. You can read about my journey from pentester to full-time hunter here: gelu.chat/posts/from-p...
gelu.chat
Finding Freedom, One Bug at a Time: My Journey from Pentester to Full-Time Hunter
After seven years in pentesting, I transitioned full-time into bug bounty hunting, leveraging deep experience and continuous learning. This article shares key moments and insights from that journey.
3247
Alex Chapman @ajxchapman.bsky.social · 02/07/2025
Yesterday I discovered it's theoretically possible to create an ASCII Jar file, one where each byte of the file is a valid ASCII character. Today I'm trying to create one. Sometimes I regret my impulses.
050
Alex Chapman @ajxchapman.bsky.social · 01/07/2025
I often find when explaining complex exploits that it can appear like such an unlikely event that the exploitable steps exist. In reality it's just _this_ is the particular set of unlikely steps I found. I'm sure there are others, but I stopped looking after these steps were successful 🤔
170
Alex Chapman @ajxchapman.bsky.social · 30/06/2025
I love it when I answer my own questions
040
Alex Chapman @ajxchapman.bsky.social · 11/06/2025
I've recently reported a bug that was _caused_ by patching. If the old version of the library was left unpatched it wouldn't have been vulnerable 🫣 Remember folks, don't patch your dependencies... or do... or you are damned either way 🤷‍♂️
070
Alex Chapman @ajxchapman.bsky.social · 10/06/2025
At 33,500,000,000 hashes / second, it'll only take *checks calculator* 17.5 years and $115,000 for an exhaustive search... I might need to rethink this 🤔
240
Alex Chapman @ajxchapman.bsky.social · 09/06/2025
I'm currently at the "Is it worth it to rent some cloud GPUs in order to attempt to bruteforce a hash" stage of bug hunting 😬
2111
Alex Chapman @ajxchapman.bsky.social · 03/06/2025
CVE-2025-5419 ITW Chrome exploit mitigated in 1(!) day after report to all users without requiring a browser update 🤯 I hand't read up on the Finch Kill Switch before, such a powerful exploit mitigation feature from the Chrome team! developer.chrome.com/docs/web-pla...
developer.chrome.com
What is a Chrome Finch experiment?  |  Web Platform  |  Chrome for Developers
Learn about how Chrome safely ships new features.
031