Sign in

ToxSec

@toxsec.bsky.social
245 followers 87 following 1.5K posts

Security Engineer M.S. Cybersecurity, CISSP. AWS, NSA, USMC. www.toxsec.com

PostsRepliesMedia
ToxSec @toxsec.bsky.social · 07/09/2026
ATM Jackpot (DEF CON 18, 2010) – Barnaby Jack rolled a real ATM onstage and made it spew cash with a remote exploit. The demo coined the term “jackpotting” and forced ATM vendors to overhaul firmware security. #Defcon #Hackers
111
ToxSec @toxsec.bsky.social · 05/09/2026
Stay patient. Bug bounty is a long game, not a quick hack. #cybersecurity
010
ToxSec @toxsec.bsky.social · 02/09/2026
Discovering cloud environments is a profitable area for bug hunters. By mapping cloud assets, finding exposed IAM keys, exploiting SSRF to reach metadata, and taking advantage of permissive serverless roles, a full system breach is possible. Learn more: www.toxsec.com/p/a-bug-hunt... #BugBounty
toxsec.com
A Bug Hunter's Guide to Cloud Misconfigurations
ToxSec | A guide for bug bounty hunters on cloud misconfigurations.
010
ToxSec @toxsec.bsky.social · 27/08/2026
Rome Lab Breach (1994) – Two teenage hackers from the UK penetrated U.S. Air Force research networks for weeks, bouncing through dozens of international relays and nearly triggering a military alert. #Hackers
020
ToxSec @toxsec.bsky.social · 22/08/2026
bug hunting is gardening. plant payloads, water with patience, wait for errors to bloom. #bugbounty
020
ToxSec @toxsec.bsky.social · 20/08/2026
T-Mobile Sidekick Data Heist (2004) – A 21-year-old exploited a poorly secured proxy to steal Paris Hilton’s celebrity contacts and photos, exposing the weakness of early carrier web portals. #Hackers
010
ToxSec @toxsec.bsky.social · 19/08/2026
Every long night pays off. sometimes in cash, sometimes in skill. both count. #bughunting
010
ToxSec @toxsec.bsky.social · 18/08/2026
Always test like a pessimist and write like an optimist. #BugBounty
010
ToxSec @toxsec.bsky.social · 15/08/2026
Captain Crunch’s Jailhouse Phone (1972) – John Draper continued teaching phreaking techniques from prison, sneaking manuals to visitors and inspiring the next wave of modem hackers. #Hackers
000
ToxSec @toxsec.bsky.social · 14/08/2026
Automated reconnaissance can link tools to uncover secrets quicker than humans. Monitor your logs for pattern detection and secure directory access. #CyberSecurity #AI
000
ToxSec @toxsec.bsky.social · 12/08/2026
Morris Worm (1988) The first major internet worm was released by a Cornell grad student “just to measure the size of the internet.” It crashed 10% of the entire internet and earned the first conviction under the U.S. Computer Fraud and Abuse Act. #hackers
011
ToxSec @toxsec.bsky.social · 12/08/2026
The Badge Firmware Easter Egg (2019) – Reverse-engineers uncovered a hidden game inside the badge’s microcontroller that revealed secret party invites when beaten. #defcon
000
ToxSec @toxsec.bsky.social · 09/08/2026
WEP in a Weekend (DEF CON 8, 2000) – A small team proved the brand-new Wi-Fi encryption standard could be cracked with a few hours of packet capture—years before vendors fixed it. #defcon
010
ToxSec @toxsec.bsky.social · 06/08/2026
Project Raven Box (1970s) – Underground builders sold custom “black boxes” that simulated coin tones, letting phreakers make free pay-phone calls worldwide until Bell finally changed its signaling. #Hackers
010
ToxSec @toxsec.bsky.social · 05/08/2026
Every “no” is just getting you closer to the “yes.” #bugbounty #grind
010
ToxSec @toxsec.bsky.social · 02/08/2026
burp crashed again. i think it deserves a bounty. #bugbounty
000
ToxSec @toxsec.bsky.social · 02/08/2026
What’s your pre-report ritual before hitting “Submit”? #BugBounty
000
ToxSec @toxsec.bsky.social · 01/08/2026
How often do you revisit old programs after a scope expansion? #BugBounty
000
ToxSec @toxsec.bsky.social · 31/07/2026
The 414s (1983) – A group of Milwaukee teens dialed into dozens of government and corporate systems—including Los Alamos National Lab—sparking the first U.S. Senate hearing on computer crime. #Hackers
000
ToxSec @toxsec.bsky.social · 29/07/2026
funny how the broken things always hide behind the prettiest UIs. #bugbounty
000
ToxSec @toxsec.bsky.social · 26/07/2026
ever find a vuln that makes you say “no way this is real” out loud? #bugbounty
000
ToxSec @toxsec.bsky.social · 26/07/2026
The Max Headroom Broadcast Intrusion (1987) – Chicago TV viewers watched a hacker in a Max Headroom mask hijack two prime-time broadcasts using a rogue microwave link. The culprit was never caught. #hackers
000
ToxSec @toxsec.bsky.social · 25/07/2026
LLM hallucinations feel like chatting with a confident liar. #AIsecurity
110
ToxSec @toxsec.bsky.social · 23/07/2026
Probe every parameter. Don’t just test id=. Try integer fuzzing, negative numbers, encoded payloads, and nested JSON keys. Even “read-only” params can hide IDOR or injection bugs. #BugBounty
010
ToxSec @toxsec.bsky.social · 21/07/2026
funny how “deprecated” endpoints are usually the most alive. #bugbounty
010
ToxSec @toxsec.bsky.social · 19/07/2026
tracebit ran the context bomb through 100+ simulated attack runs in a fake aws environment. the whole idea is one content change to bait you already run. no new tooling, no new system. just a string that makes the attacker’s own model refuse itself. www.toxsec.com/p/context-bo...
toxsec.com
Context Bombs: Defensive Prompt Injection Traps
A decoy secret loaded with text built to trip an AI attacker’s own safety training, so the model refuses itself.
000
ToxSec @toxsec.bsky.social · 19/07/2026
How many Burp tabs is “too many” before you lose track? #BugBounty
020
ToxSec @toxsec.bsky.social · 17/07/2026
sometimes the grind feels endless, but persistence is the real exploit. #bugbounty #motivation
020
ToxSec @toxsec.bsky.social · 17/07/2026
The biggest risk in “serverless” is believing it means “securityless.” #Cybersecurity
020
ToxSec @toxsec.bsky.social · 16/07/2026
your #AI injection defense has a blind spot: it can't tell you when it fails. a #classifier that misses an attack doesn't raise its hand. you find out from a support ticket.
010
ToxSec @toxsec.bsky.social · 14/07/2026
model stealing sounds fancy until you realize it’s just downloading weights like a pirate. #machinelearning
020
ToxSec @toxsec.bsky.social · 12/07/2026
Lockpick Village – Physical security meets hacking: attendees learn to pick real locks, often opening “secure” high-end cylinders in under a minute. A DEF CON tradition that’s outlived several encryption algorithms. #defcon
000
ToxSec @toxsec.bsky.social · 11/07/2026
it’s always the endpoints with “test” in the name that give the best surprises. #bugbounty
001
ToxSec @toxsec.bsky.social · 08/07/2026
Car Hacking Village (DEF CON 23, 2015) – Researchers remotely killed a Jeep Cherokee’s engine on the highway, forcing Chrysler to recall 1.4 million vehicles. Live demo, worldwide headlines. #defcon
000
ToxSec @toxsec.bsky.social · 05/07/2026
blue teamers don’t get enough credit for the whack-a-mole game they play daily. #cybersecurity
040
ToxSec @toxsec.bsky.social · 04/07/2026
half the battle is convincing yourself to hit “send” on the report. #bugbounty
000
ToxSec @toxsec.bsky.social · 04/07/2026
spent 3 hours chasing a bug, turned out to be a load balancer just messing with me. #bugbounty
010
ToxSec @toxsec.bsky.social · 01/07/2026
when you feel like quitting, remember someone else will find it if you don’t. #hackerlife
011
ToxSec @toxsec.bsky.social · 28/06/2026
don’t give up today. tomorrow might be the report you’ve been chasing. #motivation #cybersecurity
010
ToxSec @toxsec.bsky.social · 28/06/2026
openai's plan ships three tiers off the same model. default refuses on shape. TAC drops friction for vetted defenders. cyber tier runs live-target validation. same weights, three walls, gated entirely on who you proved you are. #OpenAI #TrustedAccess #AISecurity
000
ToxSec @toxsec.bsky.social · 27/06/2026
every bounty program should include free aspirin in the reward. #bugbounty
000
ToxSec @toxsec.bsky.social · 26/06/2026
the u.s. government just forced #openai to hold back gpt-5.6, using the exact same playbook they used to crush #anthropic’s fable and #mythos models earlier this month.
110
Reposted by ToxSec
Scott Mc @scottdudeman69.bsky.social · 25/06/2026
AI is changing cybersecurity on both sides of the fight. PromptFlux shows how LLM-aware malware could adapt, generate commands, and challenge traditional detection methods. Security teams should prepare. aitransformer.online/promptflux-a... #CyberSecurity #AI #LLM #Malware
PromptFlux and LLMs
111
Reposted by ToxSec
blindthoughts.bsky.social @blindthoughts.bsky.social · 25/06/2026
Anthropic Accuses Alibaba of Stealing Claude as Cisco SD-WAN Root Exploit Detailed blindthoughts.com/anthropic-alibaba… #security #ai #geopolitics #silicon #cybercrime
121
Reposted by ToxSec
minhaz @sminhaz.bsky.social · 25/06/2026
people still confuse pentesting and red teaming. pentest = find all the holes you can. be loud. it's a vulnerability scan with a pulse. red team = can you get in, stay in, and achieve your goal without them ever knowing? it’s about testing the defenders, not just the tech.
121
ToxSec @toxsec.bsky.social · 25/06/2026
MFA exhaustion is a real issue. Notifications on your phone aren't foolproof. Think about using FIDO keys for essential accounts. #Security #Authentication
010
Reposted by ToxSec
Hacker News 100 @hn100.atproto.rocks · 24/06/2026
OpenAI unveils its first custom chip, built by Broadcom techcrunch.com/2026/06/24/openai-un… news.ycombinator.com/item?id=486633…
techcrunch.com
OpenAI unveils its first custom chip, built by Broadcom | TechCrunch
Named Jalapeño, the new processor was designed specifically for the unique needs of OpenAI's inference systems.
121
ToxSec @toxsec.bsky.social · 24/06/2026
dify, the platform behind a million ai apps, had a cross-tenant chat wiretap bug zafran’s difytap research found four flaws. the headliner lets an attacker enable tracing on a victim’s app and capture every prompt and response as a persistent exfil channel. patched in 1.14.2, one fix still pending.
020
Reposted by ToxSec
InfoSec @infosec.skyfleet.blue · 23/06/2026
Five-Eye Agencies Call for “Whole-of-Organization and Whole-of-Society Response” to Stop Cyber Threats
cybersecuritynews.com
Five-Eye Agencies Call for “Whole-of-Organization and Whole-of-Society Response” to Stop Cyber Threats
The Five Eyes cyber security agencies have issued a joint warning urging governments, businesses, and critical infrastructure operators to adopt a “whole-of-organization and whole-of-society response” to address rapidly evolving cyber threats driven by artificial intelligence (AI) . In a statement released on June 22, 2026, senior leaders from the United States, United Kingdom, Canada, Australia, and New Zealand emphasized that AI is fundamentally reshaping the cyber threat landscape. The agencies cautioned that the speed, scale, and sophistication of attacks are increasing significantly, with the timeline for emerging risks shrinking from years to months. The joint advisory highlights that frontier AI models are expected to surpass current industry expectations, enabling both defenders and adversaries with powerful new capabilities. However, threat actors are already leveraging AI to automate attacks, discover vulnerabilities faster, and scale operations with minimal effort. This shift is reducing the time between vulnerability discovery and exploitation, leaving organizations with narrower windows to respond. Five Eyes Agencies Warn on Cyber Threats The agencies stressed that cyber risk cannot be treated solely as a technical issue handled by IT teams. Instead, it must be recognized as a core business risk requiring active involvement from executive leadership and boards. Organizations are being urged to reassess their cyber resilience strategies and ensure that defensive controls are not only implemented but also capable of performing effectively under real-world attack conditions. A key theme of the statement is the importance of foundational security practices. The agencies noted that while AI introduces new capabilities, many breaches still occur due to basic security failures such as unpatched systems, weak access controls, and outdated infrastructure. They warned that legacy and unsupported systems are increasingly becoming strategic liabilities, particularly as attackers use AI to identify and exploit such weaknesses more efficiently. The advisory also reinforces the importance of adopting secure-by-design and secure-by-default principles across software and systems development. As AI systems continue to evolve, the risk of previously unknown vulnerabilities, including zero-day flaws , is expected to increase. Organizations are therefore encouraged to implement layered security approaches and prepare for inevitable breaches by strengthening incident response and recovery capabilities. In addition to defensive measures, the agencies emphasized the need for organizations to integrate AI into their security operations actively. AI-driven tools can help detect anomalies, improve vulnerability management, and accelerate incident response. However, the Cybersecurity and Infrastructure Security Agency (CISA) emphasized that success will not come from deploying more tools alone, but from effectively integrating security into core business strategy. The Five Eyes alliance underscored that collaboration and information sharing remain critical to collective defense. By working together across public and private sectors, organizations can better anticipate threats and respond more effectively. The agencies concluded with a clear warning that cyber resilience is now central to operational continuity and market trust. Organizations that act quickly will be better positioned to reduce risk and maintain confidence. At the same time, those that delay may face escalating operational, financial, and reputational consequences. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates. The post Five-Eye Agencies Call for “Whole-of-Organization and Whole-of-Society Response” to Stop Cyber Threats appeared first on Cyber Security News .
111
Reposted by ToxSec
Whitney Merrill @wbm312.bsky.social · 24/06/2026
Trend prediction: getting your CISSP to *actually* understand data center physical security and its weaknesses
181