drop (@dropn0w) 's Twitter Profile
drop

@dropn0w

Offensive Security Consultant | CBBH,eJTPv2,PJMT,BSCP certified | 10+ CVEs | Security Researcher | Views are my own

ID: 1247617804079181825

calendar_today07-04-2020 20:10:50

954 Tweet

1,1K Followers

544 Following

drop (@dropn0w) 's Twitter Profile Photo

Not a lot of people know this, but I used to be a professional Counter-Strike player. Later on, I kept playing FPS games just for fun for many years, countless hours. In my 30’s, I decided to use those gaming hours for learning about cybersecurity, and that’s what brought me to

drop (@dropn0w) 's Twitter Profile Photo

Some of you asked me, so... I found a really old aftermovie: WCG 2004 Brazil 🇧🇷 Country Finals, 21 years ago. Some of you weren't even born yet. 😅 I was just a teenager, and my parents had to sign a form so I could take part in the tournament. It was the first time I ever

drop (@dropn0w) 's Twitter Profile Photo

Super valuable advice for anyone trying to break into any kind of role, or simply looking to create opportunities in life. Sometimes, technical expertise isn’t the key factor. Sometimes, opportunities are in front of you, and other times, you have to create them yourself. Either

drop (@dropn0w) 's Twitter Profile Photo

Man, I’ve been playing around with creating some AI CTF challenges, with levels ranging from easy to hard, but honestly, making really hard challenges is tough. There are so many ways to leak the flags, so many techniques. It really makes me wonder about devs building AI

drop (@dropn0w) 's Twitter Profile Photo

If you’re into Request Smuggling bugs, I hate to say it, but you might be just a little bit of a psychopath 😂 Out of all bug types, this one drives me crazy, so annoying to exploit.

rez0 (@rez0__) 's Twitter Profile Photo

Rogue MCP servers on the internet are a botnet waiting to happen. Also, CSRF -> RCE due to poor security in MCP. And this is just the tip of the iceberg imo. AtomicByte's blog breaks down how a short collab with Jorian resulted in multiple Critical findings (🔗 below)

Rogue MCP servers on the internet are a botnet waiting to happen.

Also, CSRF -> RCE due to poor security in MCP.

And this is just the tip of the iceberg imo.

<a href="/atomicbyte_/">AtomicByte</a>'s blog breaks down how a short collab with <a href="/J0R1AN/">Jorian</a> resulted in multiple Critical findings (🔗 below)
drop (@dropn0w) 's Twitter Profile Photo

🎉I’m excited to announce that I’ll be presenting my talk “𝐔𝐩 𝐚𝐧𝐝 𝐃𝐨𝐰𝐧 𝐓𝐞𝐜𝐡𝐧𝐢𝐪𝐮𝐞: 𝐄𝐱𝐩𝐨𝐬𝐢𝐧𝐠 𝐇𝐢𝐝𝐝𝐞𝐧 𝐃𝐚𝐭𝐚 𝐟𝐫𝐨𝐦 𝐑𝐀𝐆 𝐒𝐲𝐬𝐭𝐞𝐦𝐬” at leHACK in Paris, France at the end of June. In this talk, I’ll demonstrate a technique I discovered

HackerOne (@hacker0x01) 's Twitter Profile Photo

The security research community in Europe and the Middle East just got even stronger. Say hello to these new HackerOne Brand Ambassadors: 🇦🇿 godtengri (Azerbaijan—new club!) 🇧🇪 drop & hg_real (Belgium—new club!) 🇩🇰 @mthirup (Denmark—new club!) 🇮🇹 Al7eX &

The security research community in Europe and the Middle East just got even stronger. Say hello to these new HackerOne Brand Ambassadors:

🇦🇿 <a href="/AzeriumD34132/">godtengri</a> (Azerbaijan—new club!)

🇧🇪 <a href="/dropn0w/">drop</a> &amp; <a href="/hgreal1/">hg_real</a> (Belgium—new club!)

🇩🇰 @mthirup (Denmark—new club!)

🇮🇹 <a href="/Al7eX91/">Al7eX</a> &amp;
drop (@dropn0w) 's Twitter Profile Photo

I’m honored and proud to announce that I’ve been selected as the HackerOne Ambassador for Belgium 🇧🇪 I won’t be on this journey alone, I’ll be collaborating with Hans Gillis (hg_real), one of the best game hackers in the world. Together, we’ll represent our country and help

I’m honored and proud to announce that I’ve been selected as the <a href="/Hacker0x01/">HackerOne</a>  Ambassador for Belgium 🇧🇪 

I won’t be on this journey alone, I’ll be collaborating with Hans Gillis (<a href="/hgreal1/">hg_real</a>), one of the best game hackers in the world. Together, we’ll represent our country and help
drop (@dropn0w) 's Twitter Profile Photo

🚨 It’s happening tomorrow at leHACK ! I’ll be giving my talk on 𝐀𝐈 𝐑𝐀𝐆 𝐒𝐲𝐬𝐭𝐞𝐦𝐬, where I’ll introduce a technique I developed to extract hidden information from RAG systems, called 𝐔𝐩 𝐚𝐧𝐝 𝐃𝐨𝐰𝐧 𝐓𝐞𝐜𝐡𝐧𝐢𝐪𝐮𝐞. 🧠 In this talk, we’ll dive into the

🚨 It’s happening tomorrow at <a href="/_leHACK_/">leHACK</a> !

I’ll be giving my talk on 𝐀𝐈 𝐑𝐀𝐆 𝐒𝐲𝐬𝐭𝐞𝐦𝐬, where I’ll introduce a technique I developed to extract hidden information from RAG systems, called 𝐔𝐩 𝐚𝐧𝐝 𝐃𝐨𝐰𝐧 𝐓𝐞𝐜𝐡𝐧𝐢𝐪𝐮𝐞.

🧠 In this talk, we’ll dive into the
drop (@dropn0w) 's Twitter Profile Photo

Glad I got to give my talk at leHACK this morning. Everything went smoothly, and I’m really happy with all the great feedback! Thanks to everyone who attended! Normally, leHACK publishes the recording in a few weeks or months. I’ll share it as soon as it’s out. #leHACK

Glad I got to give my talk at <a href="/_leHACK_/">leHACK</a> this morning.

Everything went smoothly, and I’m really happy with all the great feedback!

Thanks to everyone who attended! Normally, leHACK publishes the recording in a few weeks or months. I’ll share it as soon as it’s out.

#leHACK
YesWeHack ⠵ (@yeswehack) 's Twitter Profile Photo

However your day’s been, it’s about to get better. Our leHACK video is out 😎 This edition had everything: a buzzing booth, heaps of swag, a fortune wheel, and of course, our #LiveHackingEvent. Press play and relive #leHACK2025 👇 youtube.com/watch?v=gZAOHn…

drop (@dropn0w) 's Twitter Profile Photo

This year's LHE was great, with a really nice scope and 2 bugs identified! Thanks to YesWeHack ⠵ for featuring me in this aftermovie! #hacktheplanet #LiveHackingEvent #leHACK2025

drop (@dropn0w) 's Twitter Profile Photo

If you know someone who knows someone who knows someone at DEFCON looking to trade workshops, pass this on: I am looking for “From Prompt to Protection: A Practical Guide to Building and Securing Generative AI Applications” workshop ticket, I can trade for “Advanced Ghidra

drop (@dropn0w) 's Twitter Profile Photo

When a company or product works great, I think it’s important to say it too. Man, I just had top-notch support from Caido I had a small issue with the Shift plugin, and in less than 5 minutes, boom! None other than Justin Gardner himself jumped on a call, and we figured out