TommyBoy

@tommyboyhacking.bsky.social

Hack/Planets https://tommyboyhacking.github.io/tommylinkin/

Forcing researchers to pay to submit individual submissions is a ridiculous idea still. It effectively turns into gambling. Is platform triage going to randomly mark my bug OOS? (they already did this before AI-slop) Is the company simply not being fair in their decisions?

Random recent positive news: a top bug hunter informed one of my hacker friends that he nominated both my friend and I to be +1 for a upcoming Live Hacking Event. I doubt I'll make the final cut, but that was genuinely one of the coolest things that's happened to me here and I'm forever grateful.

I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! 🔥 The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇 gmsgadget.com 1/4

Bild

Just decided to make this at 4am last night due to some frustrations. Will try to improve on this in the future. SENOAE (Search Engine No AI Emulator) Simple, but effective. It just appends Google's -noai flag to the end of every search. PoC:

It's funny to think how easily it can all be taken away. My life's work is effectively numbers on a profile showing i found bugs on X, Y or Z. Never had a company agree to disclosure. Just realizing now that if I ever got banned I literally have nothing to show for my work in this space.

New by me - although Citrix say there is no evidence of exploitation of CitrixBleed 2 vulnerability, they are wrong - it has been under active exploitation since mid June by an IP associated to a ransomware group, with multiple IP addresses now involved. doublepulsar.com/citrixbleed-...

CitrixBleed 2 exploitation started mid-June — how to spot it

CitrixBleed 2 — CVE-2025–5777 — has been under active exploitation to hijack Netscaler sessions, bypassing MFA, globally for a month.

doublepulsar.com