Static wordlists are a lie we tell ourselves: same wordlists == same bugs. This talk shows why content discovery and fuzzing in real-world bug bounty targets fail when every assessment starts from the same stale inputs. This talk walks through dynamic fuzzing techniques and introduces an open-source tool that builds, mutates and combine wordlists based on the live context of the assessment, tested across bug bounty programs and pentest engagements.
Presented at Ekoparty Miami 2026