RSSAmplifier

Blog

hakluke

Hacking, bug bounty, and building businesses — by Luke Stephens (hakluke).

hakluke.comRSS feed ↗15 posts

Latest posts

How to start (or come back to) bug bounties in 2026

Getting back into bug bounties in 2026? What's changed, how the top hunters actually use AI, which vulns to chase, and where the good writeups live now.

Are bug bounties cooked?

Five years ago, a critical bug was rare and expensive to find. AI changed that overnight. What the quartz crisis in watchmaking reveals about hacking's future.

Honesty, intensity, and the cost of conforming to expectations

A reflection on loss, authenticity, and living without filters. How the death of a close friend reshaped my perspective on honesty, intensity, and the cost of conforming to social expectations. A reminder to speak freely, live fully, and resist becoming average.

Cybersecurity marketing is a mess, and it's hurting everyone

A dive into everything that's wrong with cybersecurity marketing, and how we can fix it.

People who say “PHP is insecure” are uninformed

I hear a lot of folks parrot the opinion that PHP is somehow less secure than other languages. This simply isn't true. Here's why.

Cybersecurity is lost: The story of the man in the van

Exploring the human side of cybersecurity, this post delves into personal stories, industry challenges, and the urgent need for innovation and collaboration.

10 tips for crushing bug bounties

I want to share with you my top 10 bite-sized tips to help you crush bug bounties in your first 12 months. Let’s dive in!

Remote Code Execution vs. Remote Command Execution vs. Code Injection vs. Command Injection vs. RCE

Remote Code Execution vs. Remote Command Execution vs. Code Injection vs. Command Injection vs. RCE. What's the difference?

How to achieve enterprise-grade attack-surface monitoring with open source software

Set up your very own in-depth EASM platform complete with screenshots, continuous monitoring and an API leveraging open-source software.

Hacking, ethics, inner conflict: Are we on the brink of a Hacktivism revival?

Was the cyber attack on JBS Meatworks inevitable, because their primary business is something that many feel is unethical?

List of Cybersecurity Subreddits

This one is for you cybersecurity redditors - a list of cybersecurity subreddits that you might not already know about!

How to hack your ex-girlfriend’s Facebook account

Ever wondered how to hack your ex-girlfriend's Facebook account? Here's everything you need to know.

Why I Quit My Job at Bugcrowd

I quit my awesome, well-paid job at Bugcrowd to start my own business.

Introducing Haktrails: A Small CLI Tool Harnessing the Power of SecurityTrails

Introducing Haktrails, a tool for querying SecurityTrails data conveniently from your terminal.

How to use Surge.sh: The perfect host for XSS payloads

You've found the perfect XSS, you just need to quickly host your payload somewhere... but where? Surge.sh comes to the rescue. Here's how to use it.