ToxSec's Avatar

ToxSec

@toxsec

⚠️ AI Security Engineer M.S. Cybersecurity, CISSP. Amazon, NSA, Defense Contractor, USMC. 🫟 www.toxsec.com

191
Followers
42
Following
1,145
Posts
07.09.2025
Joined
Posts Following

Latest posts by ToxSec @toxsec

bug hunting teaches you patience… or caffeine dependency. usually both. #bugbounty

10.03.2026 01:05 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Prevent mass account enumeration or password spraying by keeping an eye on rate limits. A weak or absent 429 error can escalate a single-user action into a larger issue. #Security #CyberSafety

08.03.2026 16:05 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

sometimes the PoC is just a screenshot of β€œoops, unauthorized.” #bugbounty

07.03.2026 18:10 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

sometimes the logs look back at you like β€œyou really tried that, huh?” #bugbounty

07.03.2026 03:33 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Zero Trust Home Network: AI Breaks Flat WiFi in Minutes Evil twins, AirSnitch isolation bypass, AI-powered exploit chaining, and NAS zero-days make flat home networks a red team playground in 2026.

parked curbside. one command. AI agent cloned the WiFi, ran the deauth flood, bypassed client isolation, and got root on the NAS in 20 minutes. no pentester required. #AIHacking #WiFiSecurity full chain: www.toxsec.com/p/zero-trust...

06.03.2026 19:12 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Burp Suite: where good intentions meet infinite tabs. #Infosec #TechChat

06.03.2026 05:34 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

why do developers love leaking their staging environments into google? #bugbounty

06.03.2026 02:05 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Keep your head down, your proxy on, and your notes tidy. that’s the game. #bugbounty

04.03.2026 02:09 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

this is to prevent unauthorized practice of law by ai. it includes a private right of action with mandatory attorneys’ fees for violations.

what do you thinkβ€”will this kill ai legal tools or just make them smarter?

03.03.2026 19:54 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

ny bill would prohibit ai #chatbots from giving legal advice.

a new york state bill, sb 7263, which passed the internet and #technology committee, states that chatbots can’t provide substantive legal responses or advice that would count as practicing #law if done by a person.

03.03.2026 19:54 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Gotta love a practical guide

03.03.2026 19:48 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I think it partly has to do with the Claude Code security announcement but it is actually an ironic vibe. Coding everywhere is about to deliver some massive insecurities and just as these products are going to be shipping to deliver the security market crashes

03.03.2026 19:47 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

This is pretty cool and honestly I'm not super surprised

03.03.2026 19:47 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Really good call out. It does seem that these phishing-style attacks are on the rise right now

03.03.2026 19:46 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

This looks like an interesting read

03.03.2026 19:46 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Super interesting

03.03.2026 19:46 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Slot machine is a great way to phrase it. It really does feel like that even between individual sessions

03.03.2026 19:46 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Yeah I thought this was super interesting. It kind of shows you that they are taking the quantum threat seriously and trying to get ahead of it

03.03.2026 19:45 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I know some of these tools are actually pretty good. It's been interesting watching the arms race between the forensics tools

03.03.2026 19:45 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Pretty interesting and high expectations here

03.03.2026 19:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

This is too cool!

03.03.2026 19:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

No kidding lol

03.03.2026 19:44 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Yeah I agree. It's been a fantastic product

03.03.2026 19:44 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Red Team Distillation Attacks Clone Frontier LLMs at Scale Chinese labs distilled Claude’s agentic reasoning and coding edge with 24k fake accounts and 16 million queries. Here’s the red team playbook we run in 2026.

www.toxsec.com/p/red-team-d...

03.03.2026 15:51 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

24k burner accounts. 16M queries. three chinese labs distilled Claude's agentic reasoning into their own models and nobody noticed until it was done. API access is the attack surface. #AISecurity #ModelDistillation #RedTeam

03.03.2026 15:51 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

An expired API key retains its function until it’s actually canceled, not just changed. #TechTalk #API

01.03.2026 18:10 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
OpenAI Signs What Anthropic Wouldn't, Models Break Everything Anyway Autonomous jailbreaks hit 97%, distillation campaigns run at industrial scale, and war games end in nuclear fire.

www.toxsec.com/p/openai-sig...

01.03.2026 17:09 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
OpenAI Signs What Anthropic Wouldn't, Models Break Everything Anyway Autonomous jailbreaks hit 97%, distillation campaigns run at industrial scale, and war games end in nuclear fire.

www.toxsec.com/p/openai-sig...

01.03.2026 17:08 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

reasoning models jailbreak other AIs at 97% success with zero human input. grok kept escalating until researchers pulled the plug. the capability is the vulnerability. #AISecurity #PromptInjection

01.03.2026 17:08 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

What's the longest period you've waited in silence for triage? #BugBounty

28.02.2026 17:10 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0