lean0x2f's profile picture. A.K.A. none_of_the_above | Offensive Sec Researcher | http://x2f.me | http://swordbytes.com | Building the best autonomous pentester @ http://xbow.com

Leandro Barragan

@lean0x2f

A.K.A. none_of_the_above | Offensive Sec Researcher | http://x2f.me | http://swordbytes.com | Building the best autonomous pentester @ http://xbow.com

Leandro Barragan reposted

This week, Disclosed. #BugBounty H1-65 Singapore & H1-468 Stockholm winners, new H1-Elites, Google’s AI VRP, YesWeHack wins EU tender, new programs, tools, write-ups & videos — and more. Full issue → getDisclosed.com Highlights below 👇 @tiktok_us & @okx H1-65…


Leandro Barragan reposted

It's out!! You can now watch @djurado's and @niemand_sec talk: "Prompt. Scan. Exploit - Ai's Journey Through Zero-Days, and a Thousand Bugs". Learn more about @Xbow and autonomous hacking. You can watch it in our Youtube channel exclusively: youtu.be/y_aQQmDMaY4. Enjoy!

BugBountyDEFCON's tweet card. Prompt. Scan. Exploit - Ai's Journey Through Zero-Days And A Thousand...

youtube.com

YouTube

Prompt. Scan. Exploit - Ai's Journey Through Zero-Days And A Thousand...


Enterprise security products don’t need to be secure (or even good at all) to be sold like hotcakes. 61B market cap and a myriad of vulns. No one cares about that other than people like us, this is as old as time :(

I just noticed CVE-2025-25257 and had a giggle. Not because it's yet another Fortinet remote bug. But because it's a SQLi, in a WAF product. The irony...



Leandro Barragan reposted

I discovered how to use CSS to steal attribute data without selectors and stylesheet imports! This means you can now exploit CSS injection via style attributes! Learn how below: portswigger.net/research/inlin…

garethheyes's tweet image. I discovered how to use CSS to steal attribute data without selectors and stylesheet imports! This means you can now exploit CSS injection via style attributes! Learn how below:

portswigger.net/research/inlin…

Leandro Barragan reposted

Legba v1.1.0 is out! 🥳This is a major release that required a significant amount of (human) effort, bringing several key improvements that deserve individual attention. 🧵👇

evilsocket's tweet image. Legba v1.1.0 is out! 🥳This is a major release that required a significant amount of (human) effort, bringing several key improvements that deserve individual attention. 🧵👇

I had the pleasure of working at the company this genius founded in 1996 (!). He and a handful of others shaped the spirit of the Argentinian hacking scene, sharing their knowledge and infecting us with curiosity.

-=[ PHRACK PROPHILE ON Gera ]=- phrack.org/issues/72/2#ar… That’s the whole tweet…



"XBOW isn’t here to replace pentesters or researchers; it augments teams. By removing routine burdens from penetration testers, it frees them to explore frontier vulnerability classes and the application-specific bugs that matter most." xbow.com/blog/xbow-on-h…


Xbow concludes its HackerOne & Bug Bounty efforts. It was a nice playground to hack live, real-world targets. Our pentest customers are already benefitting from all the experience we harvested :)

A new chapter for @Xbow. We're concluding our primary mission on Hacker1, so it will no longer be competing on the leaderboard. The platform was a critical step in our journey: an invaluable, large scale, live-fire range for developing and improving XBOW. xbow.com/blog/xbow-on-h…



Lot of people asked me about the models XBOW is using. This and Albert's blogpost about alloys may answer some of your questions (alloys here: xbow.com/blog/alloy-age…)

1/ XBOW Unleashes GPT-5’s Hidden Hacking Power. @OpenAI's initial assessment of GPT-5 showed modest cyber capabilities. But when integrated into the XBOW platform, we saw a completely different story: performance more than doubled. More on what we found: 🧵

Xbow's tweet image. 1/ XBOW Unleashes GPT-5’s Hidden Hacking Power.

@OpenAI's initial assessment of GPT-5 showed modest cyber capabilities. But when integrated into the XBOW platform, we saw a completely different story: performance more than doubled.

More on what we found: 🧵


Leandro Barragan reposted

I have no idea who the GUI designers were for NERV but they needed a huge raise

LinkofSunshine's tweet image. I have no idea who the GUI designers were for NERV but they needed a huge raise
LinkofSunshine's tweet image. I have no idea who the GUI designers were for NERV but they needed a huge raise
LinkofSunshine's tweet image. I have no idea who the GUI designers were for NERV but they needed a huge raise
LinkofSunshine's tweet image. I have no idea who the GUI designers were for NERV but they needed a huge raise

Leandro Barragan reposted

XBOW's architecture is incredible: a coordinator spins up multiple "solver" AIs that each hunt for specific vulns on different endpoints. Each uses isolated attack machines so if the target tries to counter-attack, it can't reach XBOW's main systems.

ctbbpodcast's tweet image. XBOW's architecture is incredible: a coordinator spins up multiple "solver" AIs that each hunt for specific vulns on different endpoints. 
Each uses isolated attack machines so if the target tries to counter-attack, it can't reach XBOW's main systems.

Leandro Barragan reposted

OpenAI hasn’t open-sourced a base model since GPT-2 in 2019. they recently released GPT-OSS, which is reasoning-only... or is it? turns out that underneath the surface, there is still a strong base model. so we extracted it. introducing gpt-oss-20b-base 🧵

jxmnop's tweet image. OpenAI hasn’t open-sourced a base model since GPT-2 in 2019.  they recently released GPT-OSS, which is reasoning-only...

or is it? 

turns out that underneath the surface, there is still a strong base model. so we extracted it.

introducing gpt-oss-20b-base 🧵
jxmnop's tweet image. OpenAI hasn’t open-sourced a base model since GPT-2 in 2019.  they recently released GPT-OSS, which is reasoning-only...

or is it? 

turns out that underneath the surface, there is still a strong base model. so we extracted it.

introducing gpt-oss-20b-base 🧵

Leandro Barragan reposted

Wandering through DEFCON someone yelled at me “hey it’s Mr False Positives!!”. Sadly, I was slightly too slow on the uptake to reply “That’s right, first name ‘Zero’”


Leandro Barragan reposted

Tomorrow, 10:00 AM @ #defcon33 @djurado9 & @niemand_sec break down how we built XBOW. Hear about the journey, the challenges, and the most impressive bugs we've found, straight from our top researchers.

Xbow's tweet image. Tomorrow, 10:00 AM @ #defcon33 
@djurado9 & @niemand_sec break down how we built XBOW. 
Hear about the journey, the challenges, and the most impressive bugs we've found, straight from our top researchers.

Leandro Barragan reposted

Gotta admit it’s so fun to hang out by the booth and suddenly see a high sev that XBOW just found scroll by in real time


I’m the proud first buyer of evilDoggie, the car-hacking interface from @GastonAznarez and @ogianatiempo (@faradaysec). Can’t wait to put it to work!

lean0x2f's tweet image. I’m the proud first buyer of evilDoggie, the car-hacking interface from @GastonAznarez and @ogianatiempo (@faradaysec).
Can’t wait to put it to work!
lean0x2f's tweet image. I’m the proud first buyer of evilDoggie, the car-hacking interface from @GastonAznarez and @ogianatiempo (@faradaysec).
Can’t wait to put it to work!

Leandro Barragan reposted

Computers are taking our jobs! (1952)

PulpLibrarian's tweet image. Computers are taking our jobs! (1952)

Loading...

Something went wrong.


Something went wrong.