Niemand (@niemand_sec) 's Twitter Profile
Niemand

@niemand_sec

Security Researcher at @xbow - Founder at @SwordBytesSec - Ex @immunityinc - #BugBounty hunter hackerone.com/niemand_sec - Blog niemand.com.ar

ID: 731143035698991104

linkhttps://www.youtube.com/channel/UCKmi4IhmmMerbnz816I_35w calendar_today13-05-2016 15:24:18

1,1K Tweet

4,4K Followers

373 Following

HackerOne (@hacker0x01) 's Twitter Profile Photo

Applications for the HackerOne Brand Ambassador program are open! 🙌 We are looking for Brand Ambassadors from around the world to empower the next generation of security researchers. 💪 Some countries without ambassadors are Estonia, Sweden, France, Italy, and Indonesia.

Applications for the HackerOne Brand Ambassador program are open! 🙌

We are looking for Brand Ambassadors from around the world to empower the next generation of security researchers. 💪 

Some countries without ambassadors are Estonia, Sweden, France, Italy, and Indonesia.
Nico Waisman (@nicowaisman) 's Twitter Profile Photo

We have been a little bit silent lately, but XBOW has been running at full steam. In 2025 we found 106 vulnerabilities in OSS projects, and we report 72 already.

We have been a little bit silent lately, but <a href="/Xbow/">XBOW</a> has been running at full steam. 
In 2025 we found 106 vulnerabilities in OSS projects, and we report  72 already.
GuidedHacking (@guidedhacking) 's Twitter Profile Photo

🚨Con Presentations by Guided Hacking Members The Underground World of Anti-Cheats From Niemand at Black Hat Europe 2019 👉youtu.be/yJHyHU5UjTg 1/10

🚨Con Presentations by Guided Hacking Members

The Underground World of Anti-Cheats
From <a href="/niemand_sec/">Niemand</a> at Black Hat Europe 2019
👉youtu.be/yJHyHU5UjTg
1/10
Bug Bounty Village (@bugbountydefcon) 's Twitter Profile Photo

🚨📢 Call for Volunteers! 📢🚨 Bug Bounty Village @ DEF CON 33 is looking for in-person & remote volunteers to help make this year’s event epic! If you’re passionate about bug bounty & community, apply now! 🔗 bugbountydefcon.com/call-for-volun… #DEFCON #BugBounty #Volunteer

Bug Bounty Village (@bugbountydefcon) 's Twitter Profile Photo

AI isn’t replacing bug bounty hunters anytime soon, but it’s getting surprisingly close. In this DEF CON talk, Joel Noguera & Diego Jurado (@xbow) show how they built agents that exploit real-world XSS, JWT, and CSRF bugs autonomously youtu.be/YDsHI2acEVA #BugBounty #DEFCON

AI isn’t replacing bug bounty hunters anytime soon, but it’s getting surprisingly close.

In this DEF CON talk, Joel Noguera &amp; Diego Jurado (@xbow) show how they built agents that exploit real-world XSS, JWT, and CSRF bugs autonomously

youtu.be/YDsHI2acEVA

#BugBounty #DEFCON
Bug Bounty Village (@bugbountydefcon) 's Twitter Profile Photo

Ever run an exploit in the wrong path? AI has too In this demo, Niemand & djurado show their agent (@xbow) debugging itself, fixing dependencies, tweaking payloads and eventually logging in as admin — autonomously. Full talk → youtu.be/YDsHI2acEVA #BugBounty #DEFCON

Bug Bounty Village (@bugbountydefcon) 's Twitter Profile Photo

This AI agent reads the JavaScript, understands the registration flow, creates a test user, and uses those creds to keep exploring the app Niemand, djurado, and @xbow are pushing what autonomous bug hunting can do. Full talk → youtu.be/YDsHI2acEVA #BugBounty #DEFCON

Bug Bounty Village (@bugbountydefcon) 's Twitter Profile Photo

This AI agent from @XBOW detects it's in an admin context, parses the full DOM, locates the URL-encoded flag, and solves the challenge — fully autonomously. Niemand & djurado show how it works. Full talk → youtu.be/YDsHI2acEVA #BugBounty #DEFCON

Bug Bounty Village (@bugbountydefcon) 's Twitter Profile Photo

Niemand, djurado & @XBOW tested 5 pentesters vs their AI agent. Humans had 40 hrs. The AI cracked everything in 30 mins. It’s fast — but humans still lead on creativity + hard bugs. Watch the full talk → youtu.be/YDsHI2acEVA #BugBounty #DEFCON

GuidedHacking (@guidedhacking) 's Twitter Profile Photo

👑 They doubted my vision, now they witness our ascension. ⌛️ Coming Soon... 🚀 Guided Hacking's Anticheat Development Course

H1 Disclosed - Public Disclosures (@h1disclosed) 's Twitter Profile Photo

⚡ [20.98.103.245] Cross-Site Scripting (XSS) via /ssl-vpn/getconfig.esp at GlobalProtect VPN Portal 👨🏻‍💻 @xbow ➟ Informatica 🟥 High 💰 None 🔗 hackerone.com/reports/3096384 #bugbounty #bugbountytips #cybersecurity #infosec

⚡ [20.98.103.245] Cross-Site Scripting (XSS) via /ssl-vpn/getconfig.esp at GlobalProtect VPN Portal 
👨🏻‍💻 @xbow ➟ Informatica 
🟥 High
💰 None
🔗 hackerone.com/reports/3096384
#bugbounty #bugbountytips #cybersecurity #infosec
Leandro Barragan (@lean0x2f) 's Twitter Profile Photo

Hacking with friends always pays off :) thank you HackerOne & Salesforce for such an amazing event! This time I teamed up with Kcho, djurado and Niemand to land a few crits that got us the eliminator award 😊

Harley (@infinitelogins) 's Twitter Profile Photo

HackerOne celebrated top hackers at H16102 in Sydney. Congrats to the award winners. shubs , Lupin , shorlhax, doomerhunter , Niemand , djurado , kcho, none_of_the_above, Geluchat , Kévin GERVOT (Mizu) (Sorry if I didn't tag you! Couldn't find your Twitter)

Niemand (@niemand_sec) 's Twitter Profile Photo

So happy to see XBOW performing as the top hacker in the US at HackerOne !! More than 1000 bugs have been submitted in just a few months 🔥