Pinned
Founder at @SeatsAero. Travel/points, application security, security research, etc. bsky.app/profile/ian.sh
- There is a trend of bug bounty programs reducing rewards under the guise that they can find the issues themselves with AI. This is basically absurd, you don't pay bounties for issues you've already found. It just seems like an excuse due to limited budgets.
- A fun SQL injection in 2026 with a bit of help from Claude! It is pretty crazy that simple unauthenticated vulnerabilities can still exist in core production systems like this. Technical details: ian.sh/fgtSecurity researcher @iangcarroll found Claude could independently code an exploit to hack into Front Gate Tickets, the ticketing platform for almost every major US music festival from Lollapalooza to Bonnaroo. He could then issue any tickets at will. wired.com/story/claude-h…


