Jason Haddix

Jason Haddix

Creator
0 followers

Jason Haddix is an application security and bug bounty expert (former Bugcrowd exec) who shares knowledge on penetration testing and web app security.

Parallel AI Agents and Result Aggregation Boost Offensive Success
SocialApr 24, 2026

Parallel AI Agents and Result Aggregation Boost Offensive Success

Sometimes success of using AI agents for offense is using them in multiple or parallel rounds. With different models. And aggregating the results.

By Jason Haddix
Synthetic Data Promises Massive Leap over Fuzzing DBs
SocialApr 23, 2026

Synthetic Data Promises Massive Leap over Fuzzing DBs

We've dabbled with agents and models using large fuzzing DBs as context. It was good. We are moving to tuning and training with synthetic data soon. Based on some experiments its gonna be epic. Synthetic data generated on private methodology...

By Jason Haddix
Continuous Identity Exposure Monitoring Stops Credential‑Based Breaches
SocialApr 22, 2026

Continuous Identity Exposure Monitoring Stops Credential‑Based Breaches

Most security programs are sleeping on Identity Exposure Management, and hackers are cashing in. The fastest path into an environment is almost always a leaked credential or a stolen session cookie sitting in an infostealer log. MFA doesn't help when...

By Jason Haddix
AI Hits Inflection Point: Models Ready for Deep Research
SocialApr 20, 2026

AI Hits Inflection Point: Models Ready for Deep Research

The model inflection point is around the corner. Minimax, GLM, and Kimi are performing at Opus 4.5 golden-days levels. Tbh that's the point where i felt AI could really offload and help with in depth research and dev. Excited.

By Jason Haddix
AI Code Tools Still Need Rigorous Human Verification
SocialApr 11, 2026

AI Code Tools Still Need Rigorous Human Verification

Anyone using Claude Code this week and counting on it for analysis, double-check all output and recheck that it's doing things. Even with markdown-based checklists and hard gates to verify it has run on certain things, Opus has flat-out lied...

By Jason Haddix
Mythos Brings Scalable Security, Not Full VM Replacement
SocialApr 9, 2026

Mythos Brings Scalable Security, Not Full VM Replacement

I’m excited about Mythos. We have been asking for scale in security for years and we are getting glimpses of it. I sincerely doubt it will replace all of vulnerability management or vulnerability research but it probably will do a...

By Jason Haddix
RSA 2026: AI, Agents, and Security Reality Check
SocialApr 2, 2026

RSA 2026: AI, Agents, and Security Reality Check

New Executive Offense: "RSA 2026: Hot Takes on AI, Agents, and Offensive Security Reality Checks" (This one is more a an opinion piece but hope you enjoy it 🫶 ) https://t.co/pMeHfOXfex

By Jason Haddix
Frontier AI API Costs $100‑200 Daily for Power Users
SocialApr 1, 2026

Frontier AI API Costs $100‑200 Daily for Power Users

*things* I'm musing on today: I talked to a *bunch* of friends at frontier AI labs over dinners this last week at RSA. One undertone that kept coming up was that the *max* plans for all frontier labs are not meant...

By Jason Haddix
Prompt Engineering Is the Real Power Behind Agents
SocialMar 31, 2026

Prompt Engineering Is the Real Power Behind Agents

One thing the big leak today proves is how fucking important prompting is to an agent framework. Stop telling people it’s not. Some of the biggest current and yet to be released features are not code but prompts. Meticulously...

By Jason Haddix
Anthropic AI Lacks Open Researcher Verification, Causing Refusals
SocialMar 27, 2026

Anthropic AI Lacks Open Researcher Verification, Causing Refusals

. @AnthropicAI has stated previously that they want to work with the security research community. Other than the fellow program (a paid, exclusive program), where is the sign-up to prove you are a legitimate researcher, verify your identity, and report...

By Jason Haddix
Litellm Breach Pales Beside Worse AI Supply Chain Threats
SocialMar 24, 2026

Litellm Breach Pales Beside Worse AI Supply Chain Threats

the litellm compromise is bad… But you’d 🤮 if you’ve seen some of the stuff in the AI supply chain I’ve seen 🫠

By Jason Haddix
Demand Thorough Evaluations Before Buying AI Security Tools
SocialMar 10, 2026

Demand Thorough Evaluations Before Buying AI Security Tools

RE: Agentic security testing claims Buyer beware. Make vendors provide you evals for their claims. Describe architecture. Prove workflows. Define models and tuning. Cite data sources. Provide references and case studies. Then buy 🤗

By Jason Haddix
Speed Up Pen‑Test Remediation with PlexTrac’s Automated Workflow
SocialFeb 26, 2026

Speed Up Pen‑Test Remediation with PlexTrac’s Automated Workflow

(Sponsor) If pentest reporting takes weeks, remediation stalls.  ⏱️ PlexTrac replaces spreadsheet tracking with a findings-to-fix workflow and exec-ready reporting. See Demo: https://t.co/NuE4kH3FXK https://t.co/DbP8Xmotdx

By Jason Haddix
GraySwanAI Launches Real-World AI Safeguards Challenge
SocialFeb 20, 2026

GraySwanAI Launches Real-World AI Safeguards Challenge

AI safeguards shouldn’t just sound good, they should hold up under pressure. @GraySwanAI is putting them to the test with the Safeguards Challenge: real prompts, real attacks, real failures. Think you can break them (or prove they work)? We will be playing...

By Jason Haddix