Sam Curry (@samwcyo) 's Twitter Profile
Sam Curry

@samwcyo

Hacker, bug bounty hunter. Run a blog to better explain web application security.

ID: 825606932887134212

linkhttp://samcurry.net calendar_today29-01-2017 07:30:06

2,2K Tweet

94,94K Followers

988 Following

Parker Conrad (@parkerconrad) 's Twitter Profile Photo

Rippling sued @Deel today. Our lawsuit alleges Deel cultivated a spy at Rippling & orchestrated a long-running trade-secret theft. The spy searched ā€œdeelā€ in our systems 23 times per day on avg, letting him spy on Deel’s own customers who were considering a switch to Rippling.

Rippling sued @Deel today. Our lawsuit alleges Deel cultivated a spy at Rippling & orchestrated a long-running trade-secret theft. The spy searched ā€œdeelā€ in our systems 23 times per day on avg, letting him spy on Deel’s own customers who were considering a switch to Rippling.
Phrack Zine (@phrack) 's Twitter Profile Photo

We heard you needed some more time, so we wanted to let you cook. We decided to push the Phrack 72 CFP deadline back until June 15th. Stay tuned for upcoming Phrack events. Print this flyer out and give it to someone IRL!!

We heard you needed some more time, so we wanted to let you cook. 

We decided to push the Phrack 72 CFP deadline back until June 15th. 

Stay tuned for upcoming Phrack events. 

Print this flyer out and give it to someone IRL!!
Sam Curry (@samwcyo) 's Twitter Profile Photo

I’ve been getting a lot of weird messages from people like this asking to hack both Chinese and American companies. They have offered to send thousands of dollars in advance to prove they are legit. I haven’t really looked into it too much but none of it ever makes sense.

I’ve been getting a lot of weird messages from people like this asking to hack both Chinese and American companies. They have offered to send thousands of dollars in advance to prove they are legit. I haven’t really looked into it too much but none of it ever makes sense.
zhero; (@zhero___) 's Twitter Profile Photo

the research paper is out: Next.js and the corrupt middleware: the authorizing artifact result of a collaboration with inzo that led to CVE-2025-29927 (9.1-critical) zhero-web-sec.github.io/research-and-t… enjoy the read!

the research paper is out:

Next.js and the corrupt middleware: the authorizing artifact

result of a collaboration with <a href="/inzo____/">inzo</a> that led to CVE-2025-29927 (9.1-critical)

zhero-web-sec.github.io/research-and-t…

enjoy the read!
Assetnote (@assetnote) 's Twitter Profile Photo

Our security research team recently analyzed the authentication bypass vulnerability in Next.js (CVE-2025-29927). Our blog post details how to detect this vulnerability with more reliability. Read more here: slcyber.io/assetnote-secu…

Our security research team recently analyzed the authentication bypass vulnerability in Next.js (CVE-2025-29927). Our blog post details how to detect this vulnerability with more reliability. Read more here: slcyber.io/assetnote-secu…
Ian Carroll (@iangcarroll) 's Twitter Profile Photo

Pretty crazy to look back on this as we just hit $8M ARR + 500k MAU! Seats.aero is still fully bootstrapped, but I think we are going to have to hire soon. Have hit the limit on being "solo" where you start hampering your own progress. Even just support is quite difficult now

ic3qu33n (@nikaroxanne) 's Twitter Profile Photo

v happy to finally share my slides for my REcon 2024 talk ā€œGOP Complex: Image parsing bugs, EBC polymorphic engines and the Deus ex machina of UEFI exploit devā€ Really proud of this talk+v grateful to the amazing REcon team for another incredible conšŸ–¤ github.com/ic3qu33n/REcon…

Cooper Young (@thecooperyoung) 's Twitter Profile Photo

Just published my write-up on exacerbating XSS via an "Iframe Sandwich" Shoutout to Justin Gardner for helping me pop the bug! coopergyoung.com/exacerbating-c…

payloadartist (@payloadartist) 's Twitter Profile Photo

$64k in #bugbounty for finding basic secrets in predictable places because teams skipped Git 101 and proper .gitignore hygiene. Good on the reporter for cashing in on the perpetual lack of fundamental version control understanding. medium.com/@sharon.brizin…

$64k in #bugbounty for finding basic secrets in predictable places because teams skipped Git 101 and proper .gitignore hygiene. Good on the reporter for cashing in on the perpetual lack of fundamental version control understanding. 

medium.com/@sharon.brizin…
Sam Curry (@samwcyo) 's Twitter Profile Photo

Does anyone have any fun home automation projects? I'm looking for some inspiration while fixing some flood damage to my basement.

ZachXBT (@zachxbt) 's Twitter Profile Photo

1/ In late 2023 a former Yuga Labs security researcher was stopped at the airport after law enforcement mistakenly linked them to a $1.1M phishing theft from a Bored Ape owner. Here’s an investigation into where the stolen funds went and who’s actually responsible.

1/ In late 2023 a former Yuga Labs security researcher was stopped at the airport after law enforcement mistakenly linked them to a $1.1M phishing theft from a Bored Ape owner. 

Here’s an investigation into where the stolen funds went and who’s actually responsible.
EFF (@eff) 's Twitter Profile Photo

NEW: You’ve got to love the internet before you can hate on it, Molly White told EFF’s Cindy Cohn and Jay Sherman’s March on the latest episode of ā€œHow to Fix the Internet.ā€ eff.org/deeplinks/2025…

Youssef Sammouda (sam0) (@samm0uda) 's Twitter Profile Photo

I've made nearly 3 millions from bug bounty in the past ~5 years, reported hundreds of bugs but i still think this shit isn't for me. Is it me or this field is actually not worth spending your life for, am i actually making a difference or in a loop checking developers mistakes ?