Ashton Vaughan
Cybersecurity student & bug bounty hunter
I'm an 18-year-old cybersecurity student at QUT in Brisbane, Australia. I hunt vulnerabilities on HackerOne and Bugcrowd as @ashtonvaughan, reporting through coordinated disclosure. My focus is authentication, access control, and business-logic flaws in web applications and APIs. Alongside the hunting, I publish technical writeups and build independent projects.
- Status
- Hunting
- Focus
- Auth · Access control
- Research
- 300+ findings · 95+ programs
- Handle
- @ashtonvaughan
What I look for
How I move through a target, recon to logic.
Map the real attack surface: subdomains, JS bundles, exposed config, and the endpoints the UI never shows.
Recent research
- INFO Exposing the whole Montoya API: driving Burp Suite from an AI agent
- INFO Hypotheses over signatures: what I learned building an autonomous pentest agent
- INFO Goals, not selectors: building a browser runtime for AI agents
- INFO Ideas for running big MoE models on small hardware
- INFO One prompt is not a finding: proving an LLM jailbreak is universal
Coordinated disclosure
The lifecycle of the reports I file, redacted where a program's terms require it.
- ████████.com NDA
- reported
- triaged
- resolved
- disclosed
- [PRIVATE PROGRAM] NDA
- reported
- triaged
- resolved
- disclosed
- ██████████.io NDA
- reported
- triaged
- resolved
- disclosed
- [PRIVATE PROGRAM] NDA
- reported
- triaged
- resolved
- disclosed
- ████████.com NDA
- reported
- triaged
- resolved
- disclosed
Tools and experiments
burp-mcp-ultimate
A Burp Suite extension that exposes the entire Montoya API as an MCP server, so an AI agent can actually drive a hunt instead of just summarising proxy history.
AgentBrowser
A browser runtime built for AI agents instead of retrofitted from one: an API that speaks goals, a real visible cursor, per-site memory, and a replayable audit trail.
ProjectTriage
An autonomous, hypothesis-driven pentesting agent that hunts like a researcher rather than a scanner: reasoning modules and scaffolding over a large tool surface.
Get in touch
Questions about a finding, a writeup, or a program I have reported to: email is the fastest way to reach me.
# security.txt for ashtonvaughan.com (RFC 9116) # PLACEHOLDER: edit the PGP fingerprint below to match the real key. # PGP fingerprint: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 Contact: mailto:security@ashtonvaughan.com Encryption: https://ashtonvaughan.com/pgp.asc Preferred-Languages: en Canonical: https://ashtonvaughan.com/.well-known/security.txt Expires: 2027-06-12T00:00:00.000Z