Electronic Frontier Foundation @eff.org We're the Electronic Frontier Foundation. We're a nonprofit that fights for your privacy and free speech online. Find all of EFF's social media accounts at eff.org/social.
cactuscon @cactuscon.com Arizona's hacker con. CactusCon 14: Feb 6-7, 2026 in beautiful Mesa, AZ. https://cactuscon.com + LinkedIn, X, Mastodon
Willy Brauner @willybrauner.com Front-end developer, driven by design.
Former lead front-end @ cher-ami.tv.
Musician, drummer.
Based in Lyon, France.
Freelancer
↳ https://willybrauner.com
↳ https://github.com/willybrauner
Dafydd Stuttard @dafyddstuttard.bsky.social Founder and Chief Swig at PortSwigger. Creator of Burp Suite and the Web Security Academy. Author of The Web Application Hacker's Handbook.
James Kettle @jameskettle.com Director of Research at @portswigger.net
Also known as albinowax
Portfolio: https://jameskettle.com/
Daphne Oakes @thebetterdaphne.bsky.social Conference speaker, sketch writer, standup comedian | Software engineer at Grow Therapy
Gareth Heyes @garethheyes.co.uk Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor.
https://garethheyes.co.uk/#latestBook
Nicolas Grégoire @agarri.fr Web hacker 😈
Burp Suite Pro trainer 👨🏫
Maintainer of @mastering-burp.agarri.fr 🛠️
jub0bs @jub0bs.com infosec enthusiast • Go dev & trainer • contributor to the Go project • minimalist • chaotic good • trying to make sense of the Web • he/him
Blog: https://jub0bs.com
Free Go course: https://github.com/jub0bs/go-course-beginner
Free 🇵🇸! Leave 🇱🇧 alone!
Burp Suite @burpsuite.bsky.social Burp Suite is the leading software for web security testing.
PortSwigger @portswigger.net We are a leading provider of software and learning on web security. We make Burp Suite and the Web Security Academy.
TomNomNom @tomnomnom.com Computer booper and food enthusiast. He/him.
rs @rslovesbugs.bsky.social interested in anything related to computer security - https://github.com/rs-loves-bugs/xsshunter
Mastering Burp Suite @mastering-burp.agarri.fr Tips and tricks for Burp Suite Pro 🛠️
Not affiliated with @portswigger.net ©️
Managed by @agarri.fr 🇫🇷
Additional free resources 🎁
http://hackademy.agarri.fr/freebies
Aethlios @aethlios.bsky.social Lead developer | Bug hunter (approximately every 3 months)
> https://aeth.cc
jstnkndy @jstnkndy.bsky.social Infosec professional, beverage snob, and fantasy book consumer. Vice President @ Atredis Partners. Forever terrified of Kithicor.
jcran @cybe.rs knowledge seeker
Rob Ragan @theoradical.bsky.social https://theoradical.ai
foxinSOCKS5 @foxinsocks5.bsky.social Recovering software engineer. Offensive security focused TPM.
Joel Margolis (teknogeek) @teknogeek.io hacker
noperator @noperator.bsky.social tech tasks are cool and hacking is great
Liam @leesoh.bsky.social
terjanq @terjanq.me security enthusiast that loves hunting for bugs in the wild. co-founder and player of @justCatTheFish.
infosec at @google. opinions are mine.
From: https://twitter.com/terjanq
harisec @harisec.bsky.social Interested in web security, bug bounties, machine learning and investing. SolidGoldMagikarp
pwneip @pwneip.bsky.social Principal RTO @F500, SANS Instructor & #SEC565 Red Team Ops Author, Red Team Village lead, former Bishop Fox, US Air Force. Tweets are my own, memes are stolen
STÖK @stokfredrik.bsky.social Hacker / Creative
Mischief & GOOD VIBES ONLY
Alex Chapman @ajxchapman.bsky.social Full Time #BugBounty Vulnerability Researcher
https://blog.ajxchapman.com
vortex @vortex.au I do offensive security things on the internet
ᴅᴀɴɪᴇʟ ᴍɪᴇꜱꜱʟᴇʀ @danielmiessler.bsky.social AI / Security Researcher and Entrepreneur.
Founder/CEO of Unsupervised Learning.
Building AI that upgrades humans.
zseano @zseano.bsky.social @zseano
renniepak @renniepak.nl Self-XSS connoisseur. Elite Hacker. MVH H11337UPBash. One-Percent Man. Creator of CSPBypass.com. (he/him)
Glenn Pegden @glenn.pegden.com Good Guy Hacker, Dad, App Sec / Vuln Man / Pentest specialist and leader, conference organiser, volunteer, speaker and attendee, retro gamer, Blackburn Rovers and Leeds Knight fan ….. hacker
http://Glenn.pegden.com/findmeon
HollyGraceful @hollygraceful.bsky.social I climb stuff and I hack things.
Malware Unicorn @malwareunicorn.bsky.social @Straiker. Ex-Microsoft. Ex-Meta RedTeam, Ex-Endgame, Ex Fireeye. malwareunicorn.org
Jason Haddix @jhaddix.bsky.social CEO, CISO, Trainer, Hacker, and Speaker.
AI + hacking + sec leadership.
ex:BuddoBot-Ubisoft-Bugcrowd-Fortify-HP-Redspin-Citrix.
hakluke @hakluke.com Dad, hacker, solo founder of haksec.com and hackercontent.com.
sshell @sshell.co propane and propane accessories
ai + security research
ccdc red team
Gynvael Coldwind @gynvael.bsky.social Security researcher/programmer ⁂ Managing director @ HexArcana ⁂ @DragonSectorCTF founder ⁂ he/him
Rob Fuller @mubix.com (he/him) Dad / Husband / Marine / Student / Teacher / @Hak5 / @NoVAHackers / @SiliconHBO / @NationalCCDC / @MARFORCYBER Auxiliary
Justin Elze @handle.invalid CTO @TrustedSec.com | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
LiveOverflow 🔴 @liveoverflow.bsky.social wannabe hacker... he/him
🌱 grow your hacking skills https://hextree.io
Daniel Cuthbert @dcuthbert.bsky.social Ageing hacker, long time documentary photographer. Black Hat Review board. Now sitting on numerous government cyber security boards so I guess that means I’ve grown up right?
Michael Skelton @codingo.com VP of Security Operations at Bugcrowd, Security Content @ http://youtube.com/codingo, tools @ http://github.com/codingo. SecTalks and BSides Gold Coast co-organizer - He/Him
d0nut @d0nut.dev 🦀 Rust + Security 🔑
garethr @garethr.bsky.social VP Product @snyksec. @openpolicyagent Conftest maintainer. Developer, designer, product. Open source geek. Devops Weekly. @gdsteam alum. he/him.
Phillip Wylie @phillipwylie.bsky.social Offensive Security Professional | Phillip Wylie Show Podcast Host | The Pentester Blueprint coauthor | TribeOfHackers Red Team | https://linktr.ee/phillipwylie
Lesley Carhart @hacks4pancakes.com I am eminently qualified to speak from experience about a variety of dumpster fires.
ICS DFIR at Dragos, martial artist, marksman, humanist, level 14 Neutral Good rogue, USAF retired. I post *very serious* things about infosec. Thoughts my own. Enby. 🏳️🌈
lcamtuf @lcamtuf.coredump.cx Blog: https://blog.coredump.cx/archive
Homepage: https://lcamtuf.coredump.cx
PortSwigger Research @portswiggerres.bsky.social Web security research from the team at PortSwigger.
Simon Bennetts @psiinon.bsky.social ZAP Project Lead
@arturjanc.bsky.social @arturjanc.bsky.social
Sandy Carielli @sandycarielli.bsky.social VP & Principal Analyst at Forrester, covering #appsec. Post about security, the Muppets, #NHLBruins, my beagle. All opinions are my own. she/her
Louis Columbus @louiscolumbus.bsky.social VentureBeat contributor on cybersecurity; husband & dad; writer and speaker on AI, cybersecurity, ERP, and zero trust.
LinkedIn: https://www.linkedin.com/in/louiscolumbus/
VentureBeat: https://venturebeat.com/author/louis-columbus/
Ben Stock @benstock.bsky.social Tenured Faculty @c-i-s-p-a.bsky.social Helmholtz Center for Information Security
Michele Spagnuolo @miki.it 💼: Staff Information Security Engineer at Google. 🛠️: Rosetta Flash, BitIodine. 💛: web security, ⟠, ₿, finance. Data is the most dangerous form of opinion.
Marco Squarcina @minimalblue.bsky.social Senior Scientist @TU Wien / Web & Mobile Security / #drumandbass DJ
🚩 with @mhackeroni.bsky.social We_0wn_Y0u kukhofhackerei Team Austria
🔗 https://minimalblue.com/
Michal Špaček @spazef0rze.bsky.social In your web, securing your app. Hacker, webdev, speaker, engineer. Security shoptet.cz, ex-report-uri.com, ex-teenager. HTTPS = How To Transfer Private Sh💩. Also https://infosec.exchange/@spazef0rze
Koto @kkotowicz.bsky.social Security ninja wannabe / board game geek / photon catcher
Web Security Academy @websecacademy.bsky.social Free web security training from PortSwigger.
Philippe De Ryck @philippederyck.bsky.social I help developers protect companies through better web security
Eiji Kitamura / えーじ @agektmr.com Google Chrome DevRel Identity Tech Lead - Anything about browser identity features: passwords, OTPs, passkeys, identity federation, digital credentials, etc
Emily Stark @estark.bsky.social Encryption, HTTPS, certificates, web security, security UX, software engineering and management, TMI about parenting. Opinions are my own.
Lukas Weichselbaum @webappsec.dev Leading Google's web security team.
Passionate about web security and making secure-by-default web development the norm. Contributed to web platfom security features like CSP, Fetch Metadata, COOP and Trusted Types.
Soroush Dalili 🍏🍐 @irsdl.bsky.social Hacker (ethical), web appsec specialist, trainer, tools builder & apps breaker, X: @irsdl
https://secproject.com/
https://soroush.me/
https://burpsuite.ninja/
SeanWrightSec @seanwrightsec.com Principal Application Security Engineer focused on all things #AppSec. Occasionally dabble in my own research. Also keen gamer and aspiring photographer.
Dan @basic-123.bsky.social
Jeremy Long @ctxt.bsky.social Builder, infosec, SCA and SAST enthusiast, blue team.
Founder of OWASP dependency-check.
https://github.com/sponsors/jeremylong
Erlend Oftedal @webtonull.bsky.social Security researcher at Crosspoint Labs. AppSec. Tweets are my own and do not express the opinion of my employer. OWASP. retire.js
Liran Tal @lirantal.com 🦄 Node.js Secure Coding: http://nodejs-security.com
🌟 @GitHub Star
🏅 @OpenJS Pathfinder award for Security
🥑 DevRel at @snyksec
Björn Kimminich @bkimminich.bsky.social IT Product Group Lead at Kuehne+Nagel; @owasp-juice.shop Project Leader; @owasp-de.bsky.social Chapter Co-Leader; @owasp.org Project Committee Chair; @magic.wizards.com Amateur Player @mull2five.bsky.social
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social Secure Code Trainer - Best-selling author of Alice and Bob Learn Secure Coding & Alice and Bob Learn Application Security. #AppSec she/her
https://shehackspurple.ca 🌻
Dominique Righetto @righettod.eu 👨💻 AppSec enthusiast | 🐶 Addicted to Shetland Sheepdogs | 🌏 Open Source/AppSec/OWASP junkie | 🐝 OWASP Secure Headers Project Leader.
🚩 Opinions mentioned are mine.
Josh Grossman (tghosth 👻) @joshcgrossman.com Friendly AppSec Ghost 👻
https://appsecg.host
Tib3rius @tib3rius.bsky.social Web App (mostly) Hacker | Cybersecurity Educator | Content Creator | Ex-Brit | Links: http://linktr.ee/tib3rius (he/him) 🇺🇸 A mostly unserious person. @therealc3rul34n.bsky.social is bae 🥰
Sam Stepanyan @securestep9.bsky.social OWASP London Chapter Leader. #OWASP Global Board Member. OWASP #Nettacker Project Leader. #AppSec Consultant, #CISSP. Follow me on Twitter/X and Mastodon https://twitter.com/securestep9 https://infosec.exchange/@securestep9
David Paterson @djpaterson.dev Software Engineer at PortSwigger and Man City season ticket holder
Robin @digi.ninja Hacker, coder, climber, runner, triathlete.
Always learning.
Co-flounder of SteelCon
OWASP Ottawa @owaspottawa.bsky.social The OWASP Chapter for Canada's Capital region.
https://owasp.org/ottawa/
Join us for monthly meetups discussing a variety of security topics.
OWASP Juice Shop @owasp-juice.shop Probably the most modern and sophisticated insecure web application. Only we offer a 100% @owasp.org Top Ten incompliance guarantee! Skeets by @bkimminich.bsky.social
kingthorin_rm @kingthorin.bsky.social IT Sec guy, zaproxy co-lead, WSTG co-lead, VWAD co-lead, OWASP Ottawa volunteer, Hac≺3r, supporter of oxford commas, #INTJ. (Opinions == mine) 🍁
OWASP® Foundation @owasp.org We improve the security of apps with community-led open source projects, 260 local chapters, and tens of thousands of members worldwide. Famous for OWASP Top 10
ZAP by Checkmarx @zaproxy.org The Worlds Most Popular Web App Scanner.
Rory McCune @mccune.org.uk Security geek, Containers, Kubernetes, Golang/Ruby, hillwalking
Home Page :- https://www.mccune.org.uk
Blog:- https://raesene.github.io
Johan Carlsson @joaxcar.bsky.social Full time bug bounty hunter. Look for ”joaxcar” on other platforms
Eduardo Vela @sirdarckcat.bsky.social
₦฿₭ @nbk.bsky.social Paw / Pwn / Purr
@nbk_2000
Kévin Gervot (Mizu) @mizu.re About me?
| Website: https://mizu.re
| Tool: https://github.com/kevin-mizu/domloggerpp
| Teams: @rhackgondins, @FlatNetworkOrg, @ECSC_TeamFrance
| From: https://twitter.com/kevin_mizu
0xacb @0xacb.com Hacker grinding for L1gh7 and Fr33dφm, straight outta the cosmic realm.
Co-founder @ethiack.com
https://0xacb.com
/ XNL -н4cĸ3r @xnl-h4ck3r.bsky.social Aspiring Bug Bounty Hunter & dev of tools: GAP, xnLinkFinder & waymore, featured in "Bug Hunter’s Methodology: Application Analysis v1" by JHaddix 🤘
RTFM🧐
Mathias Karlsson @avlidienbrunn.se Web security fiddler. Bug bounty bastard. Sometimes I cut shapes.
Michael Blake @michael1026.bsky.social Application security engineer / bug bounty
Tom Anthony @tomanthony.bsky.social Web dev since 1998. Bug bounty & security enthusiast. PhD in AI. CTO at SearchPilot - data driven SEO.
https://www.tomanthony.co.uk
s1r1us | Mohan Sri Rama Krishna Pedhapati @mohansrk.bsky.social Founder @ElectrovoltSec Browser and Web Security @cure53berlin, Blockchain Security @osec_io, Rambling on http://mohansrkp.substack.com
Plenum @plenumlab.bsky.social Mostly crushing it, basically everyday
smaury @smaury.bsky.social Co-Founder @shielder.com
CTF Player jbz.team
Cliff Jumping Lover (23mt max so far)