Jason Haddix

Jason Haddix

Creator
0 followers

Jason Haddix is an application security and bug bounty expert (former Bugcrowd exec) who shares knowledge on penetration testing and web app security.

CLI‑enabled Agents Risk Identity‑changing Prompt Injections
SocialJan 30, 2026

CLI‑enabled Agents Risk Identity‑changing Prompt Injections

With autonomous agents who have access to the command line, like Claude code and Open Claw, you don't only have to worry about prompt injection that executes commands and operations, but you also have to worry about prompt injection that...

By Jason Haddix
VPS as Reliable Fallback for Browser‑Only Tasks
SocialJan 29, 2026

VPS as Reliable Fallback for Browser‑Only Tasks

Why not a VPS for Molt? In my use cases, research and testing, sometimes fetch and browser tools are blocked by anti-bot tech, or there is some workflow that doesn't have an API.... it's purely browser driven. With cui and...

By Jason Haddix
Gain Real Visibility Over Fast‑Moving Agentic AI
SocialJan 23, 2026

Gain Real Visibility Over Fast‑Moving Agentic AI

Agentic AI is moving fast and most teams lack visibility into what’s actually happening. Meet our sponsor for this weeks newsletter: @harmonicsec ! Harmonic's Security’s MCP Gateway is a lightweight, developer-friendly gateway that gives security teams real visibility...

By Jason Haddix
Claude Extension Serves as Fallback when Browsers Blocked
SocialJan 22, 2026

Claude Extension Serves as Fallback when Browsers Blocked

When you don't have an Skill/MCP, a headless browser is blocked, curl and fetch are blocked... the Claude extension is a slow but serviceable backup.

By Jason Haddix
PAI Boosts Claude Code Efficiency by 50% – Free Workshop
SocialJan 20, 2026

PAI Boosts Claude Code Efficiency by 50% – Free Workshop

PAI is a super power. @DanielMiessler created features on top of Claude Code that increase its efficacy by 50%... and that's a lot based on how awesome Claude Code is. Incoming FREE workshop of PAI and other tools I'm using to...

By Jason Haddix
Read the Manual: Hidden Admin Paths Reveal Bypass
SocialJan 14, 2026

Read the Manual: Hidden Admin Paths Reveal Bypass

RTFM…. Literally I once was testing an older piece of software but didn’t have creds. Nothing available to me. Downloaded the manual and saw the url paths to the admin section. Plugged those in to my domain, one hit, boom 5k authorization...

By Jason Haddix