Sign in

ToxSec

@toxsec.bsky.social
246 followers 87 following 1.5K posts

Security Engineer M.S. Cybersecurity, CISSP. AWS, NSA, USMC. www.toxsec.com

PostsRepliesMedia
ToxSec @toxsec.bsky.social · 07/09/2026
ATM Jackpot (DEF CON 18, 2010) – Barnaby Jack rolled a real ATM onstage and made it spew cash with a remote exploit. The demo coined the term “jackpotting” and forced ATM vendors to overhaul firmware security. #Defcon #Hackers
111
ToxSec @toxsec.bsky.social · 05/09/2026
Stay patient. Bug bounty is a long game, not a quick hack. #cybersecurity
010
ToxSec @toxsec.bsky.social · 02/09/2026
Discovering cloud environments is a profitable area for bug hunters. By mapping cloud assets, finding exposed IAM keys, exploiting SSRF to reach metadata, and taking advantage of permissive serverless roles, a full system breach is possible. Learn more: www.toxsec.com/p/a-bug-hunt... #BugBounty
toxsec.com
A Bug Hunter's Guide to Cloud Misconfigurations
ToxSec | A guide for bug bounty hunters on cloud misconfigurations.
010
ToxSec @toxsec.bsky.social · 27/08/2026
Rome Lab Breach (1994) – Two teenage hackers from the UK penetrated U.S. Air Force research networks for weeks, bouncing through dozens of international relays and nearly triggering a military alert. #Hackers
020
ToxSec @toxsec.bsky.social · 22/08/2026
bug hunting is gardening. plant payloads, water with patience, wait for errors to bloom. #bugbounty
020
ToxSec @toxsec.bsky.social · 20/08/2026
T-Mobile Sidekick Data Heist (2004) – A 21-year-old exploited a poorly secured proxy to steal Paris Hilton’s celebrity contacts and photos, exposing the weakness of early carrier web portals. #Hackers
010
ToxSec @toxsec.bsky.social · 19/08/2026
Every long night pays off. sometimes in cash, sometimes in skill. both count. #bughunting
010
ToxSec @toxsec.bsky.social · 18/08/2026
Always test like a pessimist and write like an optimist. #BugBounty
010
ToxSec @toxsec.bsky.social · 15/08/2026
Captain Crunch’s Jailhouse Phone (1972) – John Draper continued teaching phreaking techniques from prison, sneaking manuals to visitors and inspiring the next wave of modem hackers. #Hackers
000
ToxSec @toxsec.bsky.social · 14/08/2026
Automated reconnaissance can link tools to uncover secrets quicker than humans. Monitor your logs for pattern detection and secure directory access. #CyberSecurity #AI
000
ToxSec @toxsec.bsky.social · 12/08/2026
Morris Worm (1988) The first major internet worm was released by a Cornell grad student “just to measure the size of the internet.” It crashed 10% of the entire internet and earned the first conviction under the U.S. Computer Fraud and Abuse Act. #hackers
011
ToxSec @toxsec.bsky.social · 12/08/2026
The Badge Firmware Easter Egg (2019) – Reverse-engineers uncovered a hidden game inside the badge’s microcontroller that revealed secret party invites when beaten. #defcon
000
ToxSec @toxsec.bsky.social · 09/08/2026
WEP in a Weekend (DEF CON 8, 2000) – A small team proved the brand-new Wi-Fi encryption standard could be cracked with a few hours of packet capture—years before vendors fixed it. #defcon
010
ToxSec @toxsec.bsky.social · 06/08/2026
Project Raven Box (1970s) – Underground builders sold custom “black boxes” that simulated coin tones, letting phreakers make free pay-phone calls worldwide until Bell finally changed its signaling. #Hackers
010
ToxSec @toxsec.bsky.social · 05/08/2026
Every “no” is just getting you closer to the “yes.” #bugbounty #grind
010
ToxSec @toxsec.bsky.social · 02/08/2026
burp crashed again. i think it deserves a bounty. #bugbounty
000
ToxSec @toxsec.bsky.social · 02/08/2026
What’s your pre-report ritual before hitting “Submit”? #BugBounty
000
ToxSec @toxsec.bsky.social · 01/08/2026
How often do you revisit old programs after a scope expansion? #BugBounty
000
ToxSec @toxsec.bsky.social · 31/07/2026
The 414s (1983) – A group of Milwaukee teens dialed into dozens of government and corporate systems—including Los Alamos National Lab—sparking the first U.S. Senate hearing on computer crime. #Hackers
000
ToxSec @toxsec.bsky.social · 29/07/2026
funny how the broken things always hide behind the prettiest UIs. #bugbounty
000
ToxSec @toxsec.bsky.social · 26/07/2026
ever find a vuln that makes you say “no way this is real” out loud? #bugbounty
000
ToxSec @toxsec.bsky.social · 26/07/2026
The Max Headroom Broadcast Intrusion (1987) – Chicago TV viewers watched a hacker in a Max Headroom mask hijack two prime-time broadcasts using a rogue microwave link. The culprit was never caught. #hackers
000
ToxSec @toxsec.bsky.social · 25/07/2026
LLM hallucinations feel like chatting with a confident liar. #AIsecurity
110
ToxSec @toxsec.bsky.social · 23/07/2026
Probe every parameter. Don’t just test id=. Try integer fuzzing, negative numbers, encoded payloads, and nested JSON keys. Even “read-only” params can hide IDOR or injection bugs. #BugBounty
010
ToxSec @toxsec.bsky.social · 21/07/2026
funny how “deprecated” endpoints are usually the most alive. #bugbounty
010
ToxSec @toxsec.bsky.social · 19/07/2026
tracebit ran the context bomb through 100+ simulated attack runs in a fake aws environment. the whole idea is one content change to bait you already run. no new tooling, no new system. just a string that makes the attacker’s own model refuse itself. www.toxsec.com/p/context-bo...
toxsec.com
Context Bombs: Defensive Prompt Injection Traps
A decoy secret loaded with text built to trip an AI attacker’s own safety training, so the model refuses itself.
000
ToxSec @toxsec.bsky.social · 19/07/2026
How many Burp tabs is “too many” before you lose track? #BugBounty
020
ToxSec @toxsec.bsky.social · 17/07/2026
sometimes the grind feels endless, but persistence is the real exploit. #bugbounty #motivation
020
ToxSec @toxsec.bsky.social · 17/07/2026
The biggest risk in “serverless” is believing it means “securityless.” #Cybersecurity
020
ToxSec @toxsec.bsky.social · 16/07/2026
your #AI injection defense has a blind spot: it can't tell you when it fails. a #classifier that misses an attack doesn't raise its hand. you find out from a support ticket.
010
ToxSec @toxsec.bsky.social · 14/07/2026
model stealing sounds fancy until you realize it’s just downloading weights like a pirate. #machinelearning
020
ToxSec @toxsec.bsky.social · 12/07/2026
Lockpick Village – Physical security meets hacking: attendees learn to pick real locks, often opening “secure” high-end cylinders in under a minute. A DEF CON tradition that’s outlived several encryption algorithms. #defcon
000
ToxSec @toxsec.bsky.social · 11/07/2026
it’s always the endpoints with “test” in the name that give the best surprises. #bugbounty
001
ToxSec @toxsec.bsky.social · 08/07/2026
Car Hacking Village (DEF CON 23, 2015) – Researchers remotely killed a Jeep Cherokee’s engine on the highway, forcing Chrysler to recall 1.4 million vehicles. Live demo, worldwide headlines. #defcon
000
ToxSec @toxsec.bsky.social · 05/07/2026
blue teamers don’t get enough credit for the whack-a-mole game they play daily. #cybersecurity
040
ToxSec @toxsec.bsky.social · 04/07/2026
half the battle is convincing yourself to hit “send” on the report. #bugbounty
000
ToxSec @toxsec.bsky.social · 04/07/2026
spent 3 hours chasing a bug, turned out to be a load balancer just messing with me. #bugbounty
010
ToxSec @toxsec.bsky.social · 01/07/2026
when you feel like quitting, remember someone else will find it if you don’t. #hackerlife
011
ToxSec @toxsec.bsky.social · 28/06/2026
don’t give up today. tomorrow might be the report you’ve been chasing. #motivation #cybersecurity
010
ToxSec @toxsec.bsky.social · 28/06/2026
openai's plan ships three tiers off the same model. default refuses on shape. TAC drops friction for vetted defenders. cyber tier runs live-target validation. same weights, three walls, gated entirely on who you proved you are. #OpenAI #TrustedAccess #AISecurity
000
ToxSec @toxsec.bsky.social · 27/06/2026
every bounty program should include free aspirin in the reward. #bugbounty
000
ToxSec @toxsec.bsky.social · 26/06/2026
instead of a public launch, altman confirmed to staff that gpt-5.6 will be a restricted preview. the white house and commerce dept are forcing them to vet enterprise access customer-by-customer. why?
010
ToxSec @toxsec.bsky.social · 26/06/2026
the u.s. government just forced #openai to hold back gpt-5.6, using the exact same playbook they used to crush #anthropic’s fable and #mythos models earlier this month.
110
ToxSec @toxsec.bsky.social · 25/06/2026
nice! pretty interesting read.
000
ToxSec @toxsec.bsky.social · 25/06/2026
it absolutely is. it’s been wild to follow this.
000
Reposted by ToxSec
Scott Mc @scottdudeman69.bsky.social · 25/06/2026
AI is changing cybersecurity on both sides of the fight. PromptFlux shows how LLM-aware malware could adapt, generate commands, and challenge traditional detection methods. Security teams should prepare. aitransformer.online/promptflux-a... #CyberSecurity #AI #LLM #Malware
PromptFlux and LLMs
111
ToxSec @toxsec.bsky.social · 25/06/2026
+1 for awareness
000
ToxSec @toxsec.bsky.social · 25/06/2026
+1
000
ToxSec @toxsec.bsky.social · 25/06/2026
really interesting… fun to follow
010
Reposted by ToxSec
blindthoughts.bsky.social @blindthoughts.bsky.social · 25/06/2026
Anthropic Accuses Alibaba of Stealing Claude as Cisco SD-WAN Root Exploit Detailed blindthoughts.com/anthropic-alibaba… #security #ai #geopolitics #silicon #cybercrime
121