Skip to content

Offensive security, shown end to end

Break it first. Then guard it.

AI, mobile, web, web3, IoT, cloud and APIs. Real lab targets and real bug bounty programs: the request, the response, the proof, then the fix.

  • scope --authorised
  • disclose --coordinated
  • patch --ship

Latest video

Fresh out of the lab

All videos

The first episode is in the edit.

Subscribe on YouTube to see it the day it goes out. It will land here too, with chapters and links.

Subscribe on YouTube

Write-ups

The report behind the video.

Severity, CVSS, CWE, and what the program did with it: accepted, fixed, informative or duplicate. Duplicates get published too.

All write-ups

The first write-ups are waiting for their fix and for the program's go-ahead. Nothing is published before both.

Rules of engagement

To guard something is to answer for it.

The channel teaches attacks so that more people can defend. That only holds if the rules are the same in every video.

Ethics and responsible disclosure
  1. 01

    Authorised targets only

    Labs, CTFs, our own systems, or bug bounty programs within their scope. Never a live target without written permission.

  2. 02

    Fixed before it is shown

    A real finding is published only once it is fixed and the program allows disclosure.

  3. 03

    Every attack ends with the defence

    The last part of each video is the fix: the line of code, the header, the policy that closes the hole.

Newsletter

Get the fix before the exploit goes viral.

One email when there is something to show: a new video, a write-up cleared for disclosure, or an advisory that hits a stack we cover. No weekly recap, no fear-selling.

An address is enough. One-click unsubscribe.