NahamSec
Educational hacking channel by a top bug bounty hunter, featuring tutorials, live hacking sessions, and bug bounty videos for the security community ([www.linkedin.com](https://www.linkedin.com/posts/danielmakelley_introducing-44-cybersecurity-youtube-channels-activity-7309901512430813184-Beok#:~:text=Cybersecurity%20tools%2C%20tactics%2C%20and%20techniques,40)).

One ChatGPT Connector. One Email. Full AI Agent Hijack. #BugBounty #PromptInjection #ai #hacking
The video warns that a single ChatGPT connector linked to a user's inbox can turn an AI assistant into a weapon, allowing an attacker to hijack the email account and act on the user's behalf. By granting the AI full mailbox permissions, the attacker can read confidential conversations, harvest password‑reset messages, exfiltrate proprietary data, and even send malicious messages to executives. The presenter emphasizes that email now serves as the primary authentication hub for most services, making it a treasure trove for threat actors. A striking quote from the speaker underscores the risk: “Your email is the main key to every account… there’s all kinds of gold in there.” The demo shows how prompt‑injection techniques can instruct the AI to compose and dispatch a hostile email to the CEO, illustrating the ease of abuse. The implications are clear: organizations must scrutinize third‑party AI connectors, enforce least‑privilege access, and implement robust validation of AI prompts. Failure to do so could lead to data breaches, account takeovers, and reputational damage.

This Hacker Made $40,000 Using Claude #ai #hacking #bugbounty
At a recent live hacking event, a security researcher leveraged Claude’s Cloud Code to generate $40,000‑$50,000 in bug‑bounty rewards. By relying exclusively on the AI‑driven platform, he eliminated manual scripting and accelerated vulnerability discovery. The AI tool automated complex tasks such...