Richard Johnson @richinseattle.bsky.social Fuzzing; Vulnerability Research;
Deep Learning; Reverse Engineering
Training & Publications @ http://fuzzing.io
Hacking the planet since 1995
Undercurrents.io BOFH
I'll stop the world and melt with you
Mike Shema @mutantzombie.bsky.social Mike listens to #synthwave, plays TTRPGs, and hosts @aswpodcast.com
Read more at https://dangerouserrors.com
jvoisin @dustri.org Blog feed for https://dustri.org/b
Also available at https://mastodon.social/@jvoisin
Pieter Hiele @honoki.net 💻 hacker / relapsed bug bounty hunter
💤 mostly tired of tech
✍️ occasional blogger
🎵 amateur jazz pianist
⁉️ chess enthusiast
🤿 daydreaming of scuba diving
🌐 https://honoki.net
@doomerhunter.bsky.social @doomerhunter.bsky.social
Black Hat Events @blackhatofficial.bsky.social The World's Premier Technical Cybersecurity Conference Series
blackhat.com
Join Us at Black Hat USA this August 2-7, 2025: blackhat.com/us-25/
Adam Baldwin @evilpacket.net Hacker / Farmer / Builder / Breaker
clickity, hackity, pwned.™
More info: https://evilpacket.net
Matthew Green @matthewdgreen.bsky.social I teach cryptography at Johns Hopkins. https://blog.cryptographyengineering.com
@handle.invalid @handle.invalid https://infosec.exchange/@swapgs
SensePost @sensepost.com Work like hell,
Share all you know,
Abide by your handshake,
Have fun. - Dan Geer
DEF CON @defcon.bsky.social The world’s premier hacker conference. Serving the global hacker community since 1993.
Defcon.org
Forum.defcon.org
Defcon.social
Michael Stepankin @artsploit.com Security Researcher at GitHub Security Lab, ex Portswigger.
https://artsploit.blogspot.com/
The Hacker's Choice (1995) @hackerschoice.bsky.social Security Research Group.
@cfreal.bsky.social @cfreal.bsky.social
Antoine Roly @aroly.bsky.social Hacker, Bug Bounty Hunter, Pentester,...
From Namur, BE.
Christian Folini @christian-folini.ch Web application security guy with a passion for OWASP's open source WAF projects and National Cyber Strategy.
Maintains "Swiss Cyber Security" starter pack and cherishes his small collection of medieval helmets.
0x999 @0x999.net
Mikhail Shcherbakov @yu5k3.bsky.social Doing security research. For fun and profit...
bubu @albertofdr.bsky.social about://inducebrowsercrashforrealz 🍕🖥️
https://albertofdr.github.io/
Lauritz @lauritz-holtmann.de IT-Security Researcher, Pentester and Bug Hunter. Passionate about 💻, 🤽♂️, ⚜️, 🎸 and ⚽ #meinVfL
#Kaeferjaeger + H1 Ambassador
🏠 https://security.lauritz-holtmann.de
alp1n3 🌲 @alp1n3.dev 🔮 AppSec & Go
Bruno Modificato @brunomodificato.bsky.social CTFer for: @Water_Paddler / Security auditor @osec_io
Sometimes bug bounty and research
Anne van Kesteren @annevk.nl Web Standards Engineer at U+F8FF.
Mike West @mikewe.st web browser stuff: security, privacy, safety, etc.
@fransrosen.bsky.social @fransrosen.bsky.social
Rebane @rebane2001.bsky.social 🇪🇪🏳️⚧️ | Archivist | 12 CVEs in Chrome | CSS sophomore | MapartCraft | Horse | rebane2001#3716 | Lyra 🦊
she/her
https://lyra.horse/
@rebane2001@infosec.exchange
Sam Curry @zlz.bsky.social
Freddy @freddyb.bsky.social manager/security things for Firefox. love my family, my bike and reading books.
You can also find me on Mastodon as @freddy@security.plumbing, which I consider my primary account.
Homepage: https://frederikbraun.de/
Masato Kinugawa @masatokinugawa.bsky.social '"><>ma<s>ato
@shhnjk.bsky.social @shhnjk.bsky.social This account posts hallucinations non-stop. More grounded and less noisy thought on x.com/shhnjk :)
Zeyu (Zayne) @zeyu2001.bsky.social • CS @ Cambridge
• CTFs with Water Paddler / Blue Water
• Security at Electrovolt / Cure53
• DEFCON 31-32 finalist
• Also on Twitter and infosec.exchange
stypr @harold.kim Touring sourcecodes. ARIN ISP Operator (AS400671). Retired CTF Player.
icchy @icchy.bsky.social https://twitter.com/icchyr からまだ移行できていません
kunte_ @kunte0.bsky.social CTF Player with FluxFingers | Ph.D. Student
theMiddle @meninthemiddle.bsky.social Rev3rse Security, SicuraNext
BitK @handle.invalid
Josip Franjković @josipfranjkovic.bsky.social I am an average Joe who enjoys breaking websites. My security blog: https://josipfranjkovic.com
ggisz @ggisz.bsky.social AppSec & Offensive Security
Orange Tsai @orange.tw This is 🍊
Jorian @jorianwoltjer.com Normalize being weird.
Alfin @alfinjose.bsky.social CVE-2023-52555 | Web Security Researcher | CTF player bi0s
Luke Jahnke @nastystereo.com Blogging at https://nastystereo.com
Justin Gardner @rhynorater.bsky.social Christian | Full-time Bug Bounty Hunter | Host @ctbbpodcast.bsky.social | Advisor @caido.io | 3x LHE MVH | 🗣️ English, 日本語
d4d @zakfedotkin.bsky.social Zak Fedotkin
All thought are mine and mine alone
ϻг_ϻε @steven.srcincite.io Hermetic Initiate. Exploring conscience and the nature of reality. I also hack things.
Assetnote @assetnote.io True Attack Surface Management - https://assetnote.io
John Hammond @johnhammond.bsky.social Hacker. Friend. Cybersecurity Researcher at Huntress.
Tom Stacey @t0xodile.com Security researcher at PortSwigger. You can find all of my write-ups and research at https://thomas.stacey.se.
shubs @shubs.io Co-founder, security researcher. Building an attack surface management platform, @assetnote.io
smaury @smaury.bsky.social Co-Founder @shielder.com
CTF Player jbz.team
Cliff Jumping Lover (23mt max so far)
Plenum @plenumlab.bsky.social Mostly crushing it, basically everyday
s1r1us | Mohan Sri Rama Krishna Pedhapati @mohansrk.bsky.social Founder @ElectrovoltSec Browser and Web Security @cure53berlin, Blockchain Security @osec_io, Rambling on http://mohansrkp.substack.com
Tom Anthony @tomanthony.bsky.social Web dev since 1998. Bug bounty & security enthusiast. PhD in AI. CTO at SearchPilot - data driven SEO.
https://www.tomanthony.co.uk
Michael Blake @michael1026.bsky.social Application security engineer / bug bounty
Mathias Karlsson @avlidienbrunn.se Web security fiddler. Bug bounty bastard. Sometimes I cut shapes.
/ XNL -н4cĸ3r @xnl-h4ck3r.bsky.social Aspiring Bug Bounty Hunter & dev of tools: GAP, xnLinkFinder & waymore, featured in "Bug Hunter’s Methodology: Application Analysis v1" by JHaddix 🤘
RTFM🧐
0xacb @0xacb.com Hacker grinding for L1gh7 and Fr33dφm, straight outta the cosmic realm.
Co-founder @ethiack.com
https://0xacb.com
Kévin Gervot (Mizu) @mizu.re About me?
| Website: https://mizu.re
| Tool: https://github.com/kevin-mizu/domloggerpp
| Teams: @rhackgondins, @FlatNetworkOrg, @ECSC_TeamFrance
| From: https://twitter.com/kevin_mizu
₦฿₭ @nbk.bsky.social Paw / Pwn / Purr
@nbk_2000
Eduardo Vela @sirdarckcat.bsky.social
Johan Carlsson @joaxcar.bsky.social Full time bug bounty hunter. Look for ”joaxcar” on other platforms
Rory McCune @mccune.org.uk Security geek, Containers, Kubernetes, Golang/Ruby, hillwalking
Home Page :- https://www.mccune.org.uk
Blog:- https://raesene.github.io
ZAP by Checkmarx @zaproxy.org The Worlds Most Popular Web App Scanner.
kingthorin_rm @kingthorin.bsky.social IT Sec guy, zaproxy co-lead, WSTG co-lead, VWAD co-lead, OWASP Ottawa volunteer, Hac≺3r, supporter of oxford commas, #INTJ. (Opinions == mine) 🍁
OWASP® Foundation @owasp.org We improve the security of apps with community-led open source projects, 260 local chapters, and tens of thousands of members worldwide. Famous for OWASP Top 10
OWASP Juice Shop @owasp-juice.shop Probably the most modern and sophisticated insecure web application. Only we offer a 100% @owasp.org Top Ten incompliance guarantee! Skeets by @bkimminich.bsky.social
OWASP London Chapter @owasplondon.bsky.social #OWASP London Chapter
Follow us on X/Facebook/Meetup/Eventbrite/LinkedIN/YouTube. Mastodon: https://infosec.exchange/@owasplondon
🌐 Webpage: https://owasp.org/london
👋 Meetup: https://meetup.com/OWASP-London
📺 YouTube: https://youtube.com/OWASPLondon
OWASP Ottawa @owaspottawa.bsky.social The OWASP Chapter for Canada's Capital region.
https://owasp.org/ottawa/
Join us for monthly meetups discussing a variety of security topics.
Robin @digi.ninja Hacker, coder, climber, runner, triathlete.
Always learning.
Co-flounder of SteelCon
David Paterson @djpaterson.dev Software Engineer at PortSwigger and Man City season ticket holder
Sam Stepanyan @securestep9.bsky.social OWASP London Chapter Leader. #OWASP Global Board Member. OWASP #Nettacker Project Leader. #AppSec Consultant, #CISSP. Follow me on Twitter/X and Mastodon https://twitter.com/securestep9 https://infosec.exchange/@securestep9
Tib3rius @tib3rius.bsky.social Web App (mostly) Hacker | Cybersecurity Educator | Content Creator | Ex-Brit | Links: http://linktr.ee/tib3rius (he/him) 🇺🇸 A mostly unserious person. @therealc3rul34n.bsky.social is bae 🥰
Josh Grossman (tghosth 👻) @joshcgrossman.com Friendly AppSec Ghost 👻
https://appsecg.host
Dominique Righetto @righettod.eu 👨💻 AppSec enthusiast | 🐶 Addicted to Shetland Sheepdogs | 🌏 Open Source/AppSec/OWASP junkie | 🐝 OWASP Secure Headers Project Leader.
🚩 Opinions mentioned are mine.
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social Secure Code Trainer - Best-selling author of Alice and Bob Learn Secure Coding & Alice and Bob Learn Application Security. #AppSec she/her
https://shehackspurple.ca 🌻
Björn Kimminich @bkimminich.bsky.social IT Product Group Lead at Kuehne+Nagel; @owasp-juice.shop Project Leader; @owasp-de.bsky.social Chapter Co-Leader; @owasp.org Project Committee Chair; @magic.wizards.com Amateur Player @mull2five.bsky.social
Erlend Oftedal @webtonull.bsky.social Security researcher at Crosspoint Labs. AppSec. Tweets are my own and do not express the opinion of my employer. OWASP. retire.js
Jeremy Long @ctxt.bsky.social Builder, infosec, SCA and SAST enthusiast, blue team.
Founder of OWASP dependency-check.
https://github.com/sponsors/jeremylong
Dan @basic-123.bsky.social
SeanWrightSec @seanwrightsec.com Principal Application Security Engineer focused on all things #AppSec. Occasionally dabble in my own research. Also keen gamer and aspiring photographer.
Soroush Dalili 🍏🍐 @irsdl.bsky.social Hacker (ethical), web appsec specialist, trainer, tools builder & apps breaker, X: @irsdl
https://secproject.com/
https://soroush.me/
https://burpsuite.ninja/
Lukas Weichselbaum @webappsec.dev Leading Google's web security team.
Passionate about web security and making secure-by-default web development the norm. Contributed to web platfom security features like CSP, Fetch Metadata, COOP and Trusted Types.
Adriana Porter Felt @apf.bsky.social I like writing silly skeets, but that doesn't pay so I also make Google Chrome. mamá, Eng Director, volunteer at Second Harvest. 🇺🇲🇨🇷
Twitter: @__apf__
Emily Stark @estark.bsky.social Encryption, HTTPS, certificates, web security, security UX, software engineering and management, TMI about parenting. Opinions are my own.
Philippe De Ryck @philippederyck.bsky.social I help developers protect companies through better web security
Web Security Academy @websecacademy.bsky.social Free web security training from PortSwigger.
Koto @kkotowicz.bsky.social Security ninja wannabe / board game geek / photon catcher
Michal Špaček @spazef0rze.bsky.social In your web, securing your app. Hacker, webdev, speaker, engineer. Security shoptet.cz, ex-report-uri.com, ex-teenager. HTTPS = How To Transfer Private Sh💩. Also https://infosec.exchange/@spazef0rze
Marco Squarcina @minimalblue.bsky.social Senior Scientist @TU Wien / Web & Mobile Security / #drumandbass DJ
🚩 with @mhackeroni.bsky.social We_0wn_Y0u kukhofhackerei Team Austria
🔗 https://minimalblue.com/
Michele Spagnuolo @miki.it 💼: Staff Information Security Engineer at Google. 🛠️: Rosetta Flash, BitIodine. 💛: web security, ⟠, ₿, finance. Data is the most dangerous form of opinion.
Ben Stock @benstock.bsky.social Tenured Faculty @c-i-s-p-a.bsky.social Helmholtz Center for Information Security
@arturjanc.bsky.social @arturjanc.bsky.social
Simon Bennetts @psiinon.bsky.social ZAP Project Lead
PortSwigger Research @portswiggerres.bsky.social Web security research from the team at PortSwigger.
lcamtuf @lcamtuf.coredump.cx Substack: http://lcamtuf.substack.com/archive
Homepage: http://lcamtuf.coredump.cx
@borshik.bsky.social @borshik.bsky.social
garethr @garethr.bsky.social VP Product @snyksec. @openpolicyagent Conftest maintainer. Developer, designer, product. Open source geek. Devops Weekly. @gdsteam alum. he/him.
d0nut @d0nut.dev 🦀 Rust + Security 🔑
Michael Skelton @codingo.com VP of Security Operations at Bugcrowd, Security Content @ http://youtube.com/codingo, tools @ http://github.com/codingo. SecTalks and BSides Gold Coast co-organizer - He/Him
Daniel Cuthbert @dcuthbert.bsky.social Ageing hacker, long time documentary photographer. Black Hat Review board. Now sitting on numerous government cyber security boards so I guess that means I’ve grown up right?