ToxSec @toxsec.bsky.social · 07/09/2026ATM Jackpot (DEF CON 18, 2010) – Barnaby Jack rolled a real ATM onstage and made it spew cash with a remote exploit. The demo coined the term “jackpotting” and forced ATM vendors to overhaul firmware security. #Defcon #Hackers 111
ToxSec @toxsec.bsky.social · 05/09/2026Stay patient. Bug bounty is a long game, not a quick hack. #cybersecurity 010
ToxSec @toxsec.bsky.social · 02/09/2026Discovering cloud environments is a profitable area for bug hunters. By mapping cloud assets, finding exposed IAM keys, exploiting SSRF to reach metadata, and taking advantage of permissive serverless roles, a full system breach is possible. Learn more: www.toxsec.com/p/a-bug-hunt... #BugBountytoxsec.comA Bug Hunter's Guide to Cloud MisconfigurationsToxSec | A guide for bug bounty hunters on cloud misconfigurations. 010
ToxSec @toxsec.bsky.social · 27/08/2026Rome Lab Breach (1994) – Two teenage hackers from the UK penetrated U.S. Air Force research networks for weeks, bouncing through dozens of international relays and nearly triggering a military alert. #Hackers 020
ToxSec @toxsec.bsky.social · 22/08/2026bug hunting is gardening. plant payloads, water with patience, wait for errors to bloom. #bugbounty 020
ToxSec @toxsec.bsky.social · 20/08/2026T-Mobile Sidekick Data Heist (2004) – A 21-year-old exploited a poorly secured proxy to steal Paris Hilton’s celebrity contacts and photos, exposing the weakness of early carrier web portals. #Hackers 010
ToxSec @toxsec.bsky.social · 19/08/2026Every long night pays off. sometimes in cash, sometimes in skill. both count. #bughunting 010
ToxSec @toxsec.bsky.social · 18/08/2026Always test like a pessimist and write like an optimist. #BugBounty 010
ToxSec @toxsec.bsky.social · 15/08/2026Captain Crunch’s Jailhouse Phone (1972) – John Draper continued teaching phreaking techniques from prison, sneaking manuals to visitors and inspiring the next wave of modem hackers. #Hackers 000
ToxSec @toxsec.bsky.social · 14/08/2026Automated reconnaissance can link tools to uncover secrets quicker than humans. Monitor your logs for pattern detection and secure directory access. #CyberSecurity #AI 000
ToxSec @toxsec.bsky.social · 12/08/2026Morris Worm (1988) The first major internet worm was released by a Cornell grad student “just to measure the size of the internet.” It crashed 10% of the entire internet and earned the first conviction under the U.S. Computer Fraud and Abuse Act. #hackers 011
ToxSec @toxsec.bsky.social · 12/08/2026The Badge Firmware Easter Egg (2019) – Reverse-engineers uncovered a hidden game inside the badge’s microcontroller that revealed secret party invites when beaten. #defcon 000
ToxSec @toxsec.bsky.social · 09/08/2026WEP in a Weekend (DEF CON 8, 2000) – A small team proved the brand-new Wi-Fi encryption standard could be cracked with a few hours of packet capture—years before vendors fixed it. #defcon 010
ToxSec @toxsec.bsky.social · 06/08/2026Project Raven Box (1970s) – Underground builders sold custom “black boxes” that simulated coin tones, letting phreakers make free pay-phone calls worldwide until Bell finally changed its signaling. #Hackers 010
ToxSec @toxsec.bsky.social · 05/08/2026Every “no” is just getting you closer to the “yes.” #bugbounty #grind 010
ToxSec @toxsec.bsky.social · 02/08/2026burp crashed again. i think it deserves a bounty. #bugbounty 000
ToxSec @toxsec.bsky.social · 02/08/2026What’s your pre-report ritual before hitting “Submit”? #BugBounty 000
ToxSec @toxsec.bsky.social · 01/08/2026How often do you revisit old programs after a scope expansion? #BugBounty 000
ToxSec @toxsec.bsky.social · 31/07/2026The 414s (1983) – A group of Milwaukee teens dialed into dozens of government and corporate systems—including Los Alamos National Lab—sparking the first U.S. Senate hearing on computer crime. #Hackers 000
ToxSec @toxsec.bsky.social · 29/07/2026funny how the broken things always hide behind the prettiest UIs. #bugbounty 000
ToxSec @toxsec.bsky.social · 26/07/2026ever find a vuln that makes you say “no way this is real” out loud? #bugbounty 000
ToxSec @toxsec.bsky.social · 26/07/2026The Max Headroom Broadcast Intrusion (1987) – Chicago TV viewers watched a hacker in a Max Headroom mask hijack two prime-time broadcasts using a rogue microwave link. The culprit was never caught. #hackers 000
ToxSec @toxsec.bsky.social · 25/07/2026LLM hallucinations feel like chatting with a confident liar. #AIsecurity 110
ToxSec @toxsec.bsky.social · 23/07/2026Probe every parameter. Don’t just test id=. Try integer fuzzing, negative numbers, encoded payloads, and nested JSON keys. Even “read-only” params can hide IDOR or injection bugs. #BugBounty 010
ToxSec @toxsec.bsky.social · 21/07/2026funny how “deprecated” endpoints are usually the most alive. #bugbounty 010
ToxSec @toxsec.bsky.social · 19/07/2026tracebit ran the context bomb through 100+ simulated attack runs in a fake aws environment. the whole idea is one content change to bait you already run. no new tooling, no new system. just a string that makes the attacker’s own model refuse itself. www.toxsec.com/p/context-bo...toxsec.comContext Bombs: Defensive Prompt Injection TrapsA decoy secret loaded with text built to trip an AI attacker’s own safety training, so the model refuses itself. 000
ToxSec @toxsec.bsky.social · 19/07/2026How many Burp tabs is “too many” before you lose track? #BugBounty 020
ToxSec @toxsec.bsky.social · 17/07/2026sometimes the grind feels endless, but persistence is the real exploit. #bugbounty #motivation 020
ToxSec @toxsec.bsky.social · 17/07/2026The biggest risk in “serverless” is believing it means “securityless.” #Cybersecurity 020
ToxSec @toxsec.bsky.social · 16/07/2026your #AI injection defense has a blind spot: it can't tell you when it fails. a #classifier that misses an attack doesn't raise its hand. you find out from a support ticket. 010
ToxSec @toxsec.bsky.social · 14/07/2026model stealing sounds fancy until you realize it’s just downloading weights like a pirate. #machinelearning 020
ToxSec @toxsec.bsky.social · 12/07/2026Lockpick Village – Physical security meets hacking: attendees learn to pick real locks, often opening “secure” high-end cylinders in under a minute. A DEF CON tradition that’s outlived several encryption algorithms. #defcon 000
ToxSec @toxsec.bsky.social · 11/07/2026it’s always the endpoints with “test” in the name that give the best surprises. #bugbounty 001
ToxSec @toxsec.bsky.social · 08/07/2026Car Hacking Village (DEF CON 23, 2015) – Researchers remotely killed a Jeep Cherokee’s engine on the highway, forcing Chrysler to recall 1.4 million vehicles. Live demo, worldwide headlines. #defcon 000
ToxSec @toxsec.bsky.social · 05/07/2026blue teamers don’t get enough credit for the whack-a-mole game they play daily. #cybersecurity 040
ToxSec @toxsec.bsky.social · 04/07/2026half the battle is convincing yourself to hit “send” on the report. #bugbounty 000
ToxSec @toxsec.bsky.social · 04/07/2026spent 3 hours chasing a bug, turned out to be a load balancer just messing with me. #bugbounty 010
ToxSec @toxsec.bsky.social · 01/07/2026when you feel like quitting, remember someone else will find it if you don’t. #hackerlife 011
ToxSec @toxsec.bsky.social · 28/06/2026don’t give up today. tomorrow might be the report you’ve been chasing. #motivation #cybersecurity 010
ToxSec @toxsec.bsky.social · 28/06/2026openai's plan ships three tiers off the same model. default refuses on shape. TAC drops friction for vetted defenders. cyber tier runs live-target validation. same weights, three walls, gated entirely on who you proved you are. #OpenAI #TrustedAccess #AISecurity 000
ToxSec @toxsec.bsky.social · 27/06/2026every bounty program should include free aspirin in the reward. #bugbounty 000
ToxSec @toxsec.bsky.social · 26/06/2026instead of a public launch, altman confirmed to staff that gpt-5.6 will be a restricted preview. the white house and commerce dept are forcing them to vet enterprise access customer-by-customer. why? 010
ToxSec @toxsec.bsky.social · 26/06/2026the u.s. government just forced #openai to hold back gpt-5.6, using the exact same playbook they used to crush #anthropic’s fable and #mythos models earlier this month. 110
Reposted by ToxSecScott Mc @scottdudeman69.bsky.social · 25/06/2026AI is changing cybersecurity on both sides of the fight. PromptFlux shows how LLM-aware malware could adapt, generate commands, and challenge traditional detection methods. Security teams should prepare. aitransformer.online/promptflux-a... #CyberSecurity #AI #LLM #Malware 111
Reposted by ToxSecblindthoughts.bsky.social @blindthoughts.bsky.social · 25/06/2026Anthropic Accuses Alibaba of Stealing Claude as Cisco SD-WAN Root Exploit Detailed blindthoughts.com/anthropic-alibaba… #security #ai #geopolitics #silicon #cybercrime 121