Offensive security, shown end to end
Break it first. Then guard it.
AI, mobile, web, web3, IoT, cloud and APIs. Real lab targets and real bug bounty programs: the request, the response, the proof, then the fix.
- scope --authorised
- disclose --coordinated
- patch --ship
Latest video
Fresh out of the lab
The first episode is in the edit.
Subscribe on YouTube to see it the day it goes out. It will land here too, with chapters and links.
Subscribe on YouTubeSeven attack surfaces
Everything that ships, gets tested.
Every video belongs to one of them. Pick the stack you build on and start there.
AI & LLM security
Prompt injection, data exfiltration through agents and tools, jailbreaks, poisoned RAG. Then the guardrails that actually hold.
WatchMobile
Android and iOS apps under Frida: SSL pinning, root detection, local storage, deep links, and the API behind the app.
WatchWeb 2.0
IDOR, SSRF, broken access control, XSS, auth flows. The classics, found on real targets, reported properly.
WatchWeb3 & smart contracts
Solidity audits, reentrancy, oracle manipulation, access control on-chain. Reproduced on a fork, never on mainnet funds.
WatchIoT & hardware
Firmware extraction, UART and JTAG, exposed MQTT, default credentials. On devices we own, on the bench.
WatchCloud
Open buckets, over-broad IAM, instance metadata, leaked keys in CI. AWS, GCP and Azure, in labs built to be broken.
WatchAPI
BOLA, mass assignment, GraphQL introspection, rate limits that are not. The OWASP API Top 10, one request at a time.
WatchYour stack is missing?
Suggest a technology or an open-source project you want to see tested. Lab only, in public.
SuggestWrite-ups
The report behind the video.
Severity, CVSS, CWE, and what the program did with it: accepted, fixed, informative or duplicate. Duplicates get published too.
The first write-ups are waiting for their fix and for the program's go-ahead. Nothing is published before both.
Rules of engagement
To guard something is to answer for it.
The channel teaches attacks so that more people can defend. That only holds if the rules are the same in every video.
Ethics and responsible disclosure-
01
Authorised targets only
Labs, CTFs, our own systems, or bug bounty programs within their scope. Never a live target without written permission.
-
02
Fixed before it is shown
A real finding is published only once it is fixed and the program allows disclosure.
-
03
Every attack ends with the defence
The last part of each video is the fix: the line of code, the header, the policy that closes the hole.