Amal PK @0xkratos.bsky.social Cyber Security Researcher | CTF Player | VAPT
FluxFingers @fluxfingers.net Participating in Capture the Flag security competitions representing @ruhr-uni-bochum.de since 2007. Also, organizers of annual Hack.lu CTF.
Web: https://FluxFingers.net
Also on Twitter and https://infosec.exchange/@fluxfingers
spq @spq42.bsky.social CTF player, Security engineer at Google, http://infosec.exchange/@spq ; @_spq__ on Twitter
@samm0uda.bsky.social @samm0uda.bsky.social
Alfin @alfinjose.bsky.social CVE-2023-52555 | Web Security Researcher | CTF player bi0s
totz_sec @totz-sec.bsky.social
Amin Nasiri @aminnasiri.com Fan of reading RFCs and interested in playing with different versions of HTTP and web-related protocols & also inductive reasoning; a Hitchhiker when I am AFK;
https://aminnasiri.com
https://github.com/nxenon
pspaul @pspaul95.bsky.social
Ciarán Cotter (monke) @monke.ie Irish web hacker. Founder @ Simian Security. Newsletter every week at https://monke.ie. Reach out at https://simiansecurity.com 🇮🇪/🇯🇵
Tom Anthony @tomanthony.bsky.social Web dev since 1998. Bug bounty & security enthusiast. PhD in AI. CTO at SearchPilot - data driven SEO.
https://www.tomanthony.co.uk
g̸͕̊i̴̜̽u̴̟̒ş̶͝ȇ̴̼p̸̻͐p̶̯̃e̸̯̾(ᵇᵒʸ-ᵈⁱᵛⁱˢⁱᵒⁿ) @giuseppesec.bsky.social dad software in femboy hardware | i can be trusted with web apps 🙂
kunte_ @kunte0.bsky.social CTF Player with FluxFingers | Ph.D. Student
BitK @handle.invalid
st98 @st98.bsky.social CTFs with zer0pts and BunkyoWesterns / Web Security / Posts random things mostly in Japanese
X: https://twitter.com/st98_
Mastodon: https://infosec.exchange/@st98
Website: https://st98.github.io/
alp1n3 🌲 @alp1n3.dev 🔮 AppSec & Go
Lauritz @lauritz-holtmann.de IT-Security Researcher, Pentester and Bug Hunter. Passionate about 💻, 🤽♂️, ⚜️, 🎸 and ⚽ #meinVfL
#Kaeferjaeger + H1 Ambassador
🏠 https://security.lauritz-holtmann.de
bubu @albertofdr.bsky.social about://inducebrowsercrashforrealz 🍕🖥️
https://albertofdr.github.io/
Mikhail Shcherbakov @yu5k3.bsky.social Doing security research. For fun and profit...
0x999 @0x999.net
Tom Stacey @t0xodile.com Security researcher at PortSwigger. You can find all of my write-ups and research at https://thomas.stacey.se.
smaury @smaury.bsky.social Co-Founder @shielder.com
CTF Player jbz.team
Cliff Jumping Lover (23mt max so far)
@hgarrereyn.bsky.social @hgarrereyn.bsky.social
Johan Carlsson @joaxcar.bsky.social Full time bug bounty hunter. Look for ”joaxcar” on other platforms
Orange Tsai @orange.tw This is 🍊
Luke Jahnke @nastystereo.com Blogging at https://nastystereo.com
Josip Franjković @josipfranjkovic.bsky.social I am an average Joe who enjoys breaking websites. My security blog: https://josipfranjkovic.com
Justin Gardner @rhynorater.bsky.social Christian | Full-time Bug Bounty Hunter | Host @ctbbpodcast.bsky.social | Advisor @caido.io | 3x LHE MVH | 🗣️ English, 日本語
@shhnjk.bsky.social @shhnjk.bsky.social This account posts hallucinations non-stop. More grounded and less noisy thought on x.com/shhnjk :)
Christian Folini @christian-folini.ch Web application security guy with a passion for OWASP's open source WAF projects and National Cyber Strategy.
Maintains "Swiss Cyber Security" starter pack and cherishes his small collection of medieval helmets.
theMiddle @meninthemiddle.bsky.social Rev3rse Security, SicuraNext
Anne van Kesteren @annevk.nl Web Standards Engineer at U+F8FF.
Arun Krishnan @winters0x64.bsky.social Web security researcher, team bi0s
CVE-2024-8143, CVE-2024-8550, CVE-2024-10649
Bug Bounty Reports Explained @gregxsunday.bsky.social
Matan Berson @matanber.com Hacker and bug bounty hunter mostly focusing on client-side security.
h1-702 Vigilante, h1-65 Eliminator, AWC23 Best New Hacker
Mathias Karlsson @avlidienbrunn.se Web security fiddler. Bug bounty bastard. Sometimes I cut shapes.
Kévin Gervot (Mizu) @mizu.re About me?
| Website: https://mizu.re
| Tool: https://github.com/kevin-mizu/domloggerpp
| Teams: @rhackgondins, @FlatNetworkOrg, @ECSC_TeamFrance
| From: https://twitter.com/kevin_mizu
Jason Haddix @jhaddix.bsky.social CEO, CISO, Trainer, Hacker, and Speaker.
AI + hacking + sec leadership.
ex:BuddoBot-Ubisoft-Bugcrowd-Fortify-HP-Redspin-Citrix.
@manuelvsousa.bsky.social @manuelvsousa.bsky.social
Bruno Modificato @brunomodificato.bsky.social CTFer for: @Water_Paddler / Security auditor @osec_io
Sometimes bug bounty and research
Eduardo Vela @sirdarckcat.bsky.social
Juan Manuel Fernández @xc3ll.bsky.social Just a biologist that loves to break cyber-stuff. Adepts of 0xCC founder.
Amy B @nyanbox.stackchk.fail aka itszn (itszen)
0xffff000041414141
Security researcher creating pwnable puzzles
https://infosec.exchange/@nyanbox
https://x.com/itszn13
LLM Art: https://bsky.app/profile/alternet.site
Sijisu @sijisu.eu computers are an insecure mess
Computer Science student mff.cuni.cz, CTFs with wrecktheline.com & czechcyberteam.github.io
szymex73 @szy.bsky.social 🎶🎮 & CTFs | Capturing 🚩 with justCatTheFish
Jorian @jorianwoltjer.com Normalize being weird.
Foxtrot Charlie @foxtrot-charlie.bsky.social I just want to be a hacker.
stfn @stfn42.bsky.social Leading Red Teaming @ Google.
IntentToShip @intenttoship.dev I post when browser makers announce an intent to ship, change or remove features in their web engines!
I was made by @burrito.space.
https://github.com/autonome/intenttoship-bot
Michal Melewski @carste1n.bsky.social Security Engineer @ Cloudflare,
ex-Google ISE,
I use bad software and bad machines for the wrong things.
My writing: https://carstein.github.io
dragosr @dragostech.bsky.social Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense.
Host of CanSecWest, and PacSec.
Security audits, code, IR, LLM, red team consulting.
Specialize in Firmware, and RF.
VA7MOV
Freddy @freddyb.bsky.social manager/security things for Firefox. love my family, my bike and reading books.
You can also find me on Mastodon as @freddy@security.plumbing, which I consider my primary account.
Homepage: https://frederikbraun.de/
ZaufanaTrzeciaStrona.pl @zaufana3strona.bsky.social Spowiedź bezpieczeństwa AD 2026 - poznaj sekrety moich zabezpieczeń: https://z3s.pl/spowiedz
Michał Kowalczyk @mkow.bsky.social reverse-engineering / low-level security
Dragon Sector CTF vice-captain, Invisible Things Lab
Mastodon: @redford@infosec.exchange
Also known as Redford
Alex Rebert @ayper.bsky.social Memory Safety @ Google. Previously co-founder of Mayhem Security (formerly known as ForAllSecure). Opinions here are my own.
@nazywam.bsky.social @nazywam.bsky.social Security research @cert.pl
April King @april.social Staff Security Engineer at some random tech company, previously Mozilla, Dropbox, LinkedIn, and (pre-Elon) Twitter. Has read @kateconger.bsky.social’s autobiography.
web @ grayduck.mn // also github.com/april
@arturjanc.bsky.social @arturjanc.bsky.social
@ddworken.bsky.social @ddworken.bsky.social
Feross @feross.bsky.social 🧙♂️ Mad scientist • ✨ Founder + CEO @Socket.dev (http://socket.dev) •🌲 Stanford lecturer (http://cs253.stanford.edu) • ❤️ Open source at WebTorrent + StandardJS
s1r1us | Mohan Sri Rama Krishna Pedhapati @mohansrk.bsky.social Founder @ElectrovoltSec Browser and Web Security @cure53berlin, Blockchain Security @osec_io, Rambling on http://mohansrkp.substack.com
Bjarki Ágúst Guðmundsson @suprdewd.bsky.social Senior Software Engineer at Google working on secure-by-design web development
CaidoIO @caido.io We help security professionals and enthusiasts audit web applications with efficiency and ease
https://caido.io
@cybergremlin.bsky.social @cybergremlin.bsky.social
Troy Hunt @troyhunt.com Founder & CEO of @haveibeenpwned.com, the most trusted name in data breach intelligence. Speaker, blogger, Microsoft Regional Director. Gold Coast, Australia.
Gábor Molnár @molnarg.bsky.social Information Security Engineer at Google
Rory McCune @mccune.org.uk Security geek, Containers, Kubernetes, Golang/Ruby, hillwalking
Home Page :- https://www.mccune.org.uk
Blog:- https://raesene.github.io
Simon Bennetts @psiinon.bsky.social ZAP Project Lead
ZAP by Checkmarx @zaproxy.org The Worlds Most Popular Web App Scanner.
kingthorin_rm @kingthorin.bsky.social IT Sec guy, zaproxy co-lead, WSTG co-lead, VWAD co-lead, OWASP Ottawa volunteer, Hac≺3r, supporter of oxford commas, #INTJ. (Opinions == mine) 🍁
OWASP® Foundation @owasp.org We improve the security of apps with community-led open source projects, 260 local chapters, and tens of thousands of members worldwide. Famous for OWASP Top 10
OWASP Juice Shop @owasp-juice.shop Probably the most modern and sophisticated insecure web application. Only we offer a 100% @owasp.org Top Ten incompliance guarantee! Skeets by @bkimminich.bsky.social
OWASP London Chapter @owasplondon.bsky.social #OWASP London Chapter
Follow us on X/Facebook/Meetup/Eventbrite/LinkedIN/YouTube. Mastodon: https://infosec.exchange/@owasplondon
🌐 Webpage: https://owasp.org/london
👋 Meetup: https://meetup.com/OWASP-London
📺 YouTube: https://youtube.com/OWASPLondon
OWASP Ottawa @owaspottawa.bsky.social The OWASP Chapter for Canada's Capital region.
https://owasp.org/ottawa/
Join us for monthly meetups discussing a variety of security topics.
Robin @digi.ninja Hacker, coder, climber, runner, triathlete.
Always learning.
Co-flounder of SteelCon
Dafydd Stuttard @dafyddstuttard.bsky.social Founder and Chief Swig at PortSwigger. Creator of Burp Suite and the Web Security Academy. Author of The Web Application Hacker's Handbook.
David Paterson @djpaterson.dev Software Engineer at PortSwigger and Man City season ticket holder
Sam Stepanyan @securestep9.bsky.social OWASP London Chapter Leader. #OWASP Global Board Member. OWASP #Nettacker Project Leader. #AppSec Consultant, #CISSP. Follow me on Twitter/X and Mastodon https://twitter.com/securestep9 https://infosec.exchange/@securestep9
Tib3rius @tib3rius.bsky.social Web App (mostly) Hacker | Cybersecurity Educator | Content Creator | Ex-Brit | Links: http://linktr.ee/tib3rius (he/him) 🇺🇸 A mostly unserious person. @therealc3rul34n.bsky.social is bae 🥰
Josh Grossman (tghosth 👻) @joshcgrossman.com Friendly AppSec Ghost 👻
https://appsecg.host
Dominique Righetto @righettod.eu 👨💻 AppSec enthusiast | 🐶 Addicted to Shetland Sheepdogs | 🌏 Open Source/AppSec/OWASP junkie | 🐝 OWASP Secure Headers Project Leader.
🚩 Opinions mentioned are mine.
garthoid @garthoid.bsky.social Father,Husband,Software Security Architect, Ethical Hacker,Musician,& Karate Geek.OWASP Ottawa Chapter Leader. Trying to learn Kendo. Devious-Plan.com founder. He/Him
Mastodon is better @garthoid@infosec.exchange
📍🇨🇦
garethr @garethr.bsky.social VP Product @snyksec. @openpolicyagent Conftest maintainer. Developer, designer, product. Open source geek. Devops Weekly. @gdsteam alum. he/him.
Daniel Cuthbert @dcuthbert.bsky.social Ageing hacker, long time documentary photographer. Black Hat Review board. Now sitting on numerous government cyber security boards so I guess that means I’ve grown up right?
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social Secure Code Trainer - Best-selling author of Alice and Bob Learn Secure Coding & Alice and Bob Learn Application Security. #AppSec she/her
https://shehackspurple.ca 🌻
Mastering Burp Suite @mastering-burp.agarri.fr Tips and tricks for Burp Suite Pro 🛠️
Not affiliated with @portswigger.net ©️
Managed by @agarri.fr 🇫🇷
Additional free resources 🎁
http://hackademy.agarri.fr/freebies
Björn Kimminich @bkimminich.bsky.social IT Product Group Lead at Kuehne+Nagel; @owasp-juice.shop Project Leader; @owasp-de.bsky.social Chapter Co-Leader; @owasp.org Project Committee Chair; @magic.wizards.com Amateur Player @mull2five.bsky.social
Liran Tal @lirantal.com 🦄 Node.js Secure Coding: http://nodejs-security.com
🌟 @GitHub Star
🏅 @OpenJS Pathfinder award for Security
🥑 DevRel at @snyksec
Erlend Oftedal @webtonull.bsky.social Security researcher at Crosspoint Labs. AppSec. Tweets are my own and do not express the opinion of my employer. OWASP. retire.js
Jeremy Long @ctxt.bsky.social Builder, infosec, SCA and SAST enthusiast, blue team.
Founder of OWASP dependency-check.
https://github.com/sponsors/jeremylong
Dan @basic-123.bsky.social
Gerald Benischke @beny23.github.io Maker, breaker and fixer of software. Adventures in #appsec and #agile: beny23.github.io he/him
SeanWrightSec @seanwrightsec.com Principal Application Security Engineer focused on all things #AppSec. Occasionally dabble in my own research. Also keen gamer and aspiring photographer.
Eiji Kitamura / えーじ @agektmr.com Google Chrome DevRel Identity Tech Lead - Anything about browser identity features: passwords, OTPs, passkeys, identity federation, digital credentials, etc
Philippe De Ryck @philippederyck.bsky.social I help developers protect companies through better web security
Michal Špaček @spazef0rze.bsky.social In your web, securing your app. Hacker, webdev, speaker, engineer. Security shoptet.cz, ex-report-uri.com, ex-teenager. HTTPS = How To Transfer Private Sh💩. Also https://infosec.exchange/@spazef0rze
Ben Stock @benstock.bsky.social Tenured Faculty @c-i-s-p-a.bsky.social Helmholtz Center for Information Security
Michele Spagnuolo @miki.it 💼: Staff Information Security Engineer at Google. 🛠️: Rosetta Flash, BitIodine. 💛: web security, ⟠, ₿, finance. Data is the most dangerous form of opinion.
Joo N/A @joohoi.bsky.social Hacks for beer. FOSS, infosec and privacy. Chaotic good.
Maddie Stone @maddiestone.bsky.social Security Researcher at Google Project Zero. 0-days all day. Love all things reverse engineering. she/her
Yoav Weiss @yoav.ws On a mission to make the web faster, one perf feature at a time. Web platform @ Shopify. WebPerfWG and WICG co-chair. RICG4life. Opinions are my own, etc.