!Manan

4.4K posts

!Manan banner
!Manan

!Manan

@0xManan

Security Research & Compliance | CVE-2026-1462 | CVE-2025-6209 | CVE-2025-6210 | CVE-2026-1117 | Trying to live at my standards - i'm weird, i hack🕊️💸

Dreaming Katılım Haziran 2020
1.3K Takip Edilen2K Takipçiler
!Manan retweetledi
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
0 chrome submissions(?), 3 firefox renderer, 1 edge, 2 safari renderer, and exchange/sharepoint each. devcore still showing up with multiple submissions in the hard targets, including exchange, sharepoint, and edge, from known names. so why are we not seeing a huge amount of submissions? i think, either: 1. defense got stronger with llms, and software like chrome/firefox is fixing a ton of bugs before they ever reach pwn2own or 2. hacking of complex software is still bottlenecked by a small number of top-tier researchers. i would guess it’s the latter(?). there is no denying the fact that, llms are probably closing some defense gap, but i think that doesn’t mean the asymmetry moved to the defense side and making defense stronger, i still think it’s the usual attacker-favored game. and looking at pwn2own submissions, it seems pretty obvious to me that llms are still only as good as the operator using them. there are only a few people good enough to point them at hard targets properly and use them to actually accelerate research. cuz, if llms were actually giving everyone exploit superpowers to "anyone", you’d expect more people showing up with chrome/exchange/browser-class bugs. instead, what we’re seeing is still mostly people with skin in the game hitting the hard targets. zerodayinitiative.com/blog/2026/5/13…
s1r1us (mohan)@S1r1u5_

this year's pwn2own isn't just interesting because there will be lots of entries with AI+human. it is also interesting because a) anthropic burned a ton of tokens on firefox, basically running claude in a loop until it found something for a month, probably exhausting whatever claude can one shot. b) if someone submits full chain without much use of ai, it tells you one shotting plateaus and these models are bit like fuzzers than seasoned security reseachers. c) even if they used an llm to find the bug, this tells us scaffolding/harnesss design, prompting, and the operator matters a lot.

English
5
5
70
9.4K
!Manan retweetledi
Priyav K Kaneria
Priyav K Kaneria@_diginova·
@bolobhaidotin first prototype is ready. not sure if you can see but this is a huge moment and I'm super happy!! 🌸
English
7
7
35
1.2K
!Manan
!Manan@0xManan·
Even if it takes years to create your own wave, that’s still better than riding someone else’s.
English
0
0
4
100
!Manan
!Manan@0xManan·
Entrepreneurship is realising the person i have to become - the changes - the adaptations- i will have to incorporate is harder to build than the business itself.
English
2
0
5
85
!Manan
!Manan@0xManan·
If you are going through hell, keep going. WHY WOULD YOU STOP IN HELL??!
English
0
1
2
65
!Manan
!Manan@0xManan·
You can’t force people to choose you, but you should know that THE RIGHT PEOPLE WILL!!!
English
0
0
3
61
!Manan
!Manan@0xManan·
Is it worth the effort? Emm idk i guess find what you’d DIE for, and then LIVE for it.
English
0
0
2
80
!Manan
!Manan@0xManan·
I don’t think i’ll ever tell anyone the full story. You must have your own experiences to understand life.
English
0
0
2
66
!Manan
!Manan@0xManan·
It hurts today, but i don’t have luxury to quit.
English
1
0
6
110
!Manan
!Manan@0xManan·
The best way to predict the future is to create it!
English
1
0
7
72
N$🌟
N$🌟@nav1n0x·
huntr.com is not maintained anymore? Anyone got thier report validated recently?
English
2
0
14
2.7K
!Manan retweetledi
Teesha Ghevariya
Teesha Ghevariya@iamteeshaa·
Make sure to turn this off. @vercel is going to train their models based on your data, and this option is enabled by default in their newly updated terms and policies. It's not about Vercel - I'm a big fan of it. It's about all the software and services we use. Sometimes you don't even know where your data is being used until you dig deep into the policies. For a casual developer it's fine, but if you have any sensitive data, it's better to turn this off. No offense, just raising awareness for all the tools you use.
Teesha Ghevariya tweet media
English
0
1
7
153
!Manan retweetledi
Anonymous
Anonymous@YourAnonOne·
Google Maps just got its 'biggest update in over a decade.'
English
25
54
1.7K
308.8K
!Manan
!Manan@0xManan·
Scissor in Hindi sounds catchy!
English
1
0
3
191
!Manan retweetledi
Priyav K Kaneria
Priyav K Kaneria@_diginova·
i love my current wallpaper but the app has no more customisations SO I'M GOING TO REVERSE ENGINEERE THE BLUETOOTH PACKETS AND FORCE SEND A CUSTOM WALLPAPER let's see how long it takes
Priyav K Kaneria tweet media
English
4
1
26
519
!Manan
!Manan@0xManan·
This shit is crazyy🧎🏻 worldmonitor[.]app Ps: for some reason X is not allowing it to post normally!
English
0
0
3
159
!Manan
!Manan@0xManan·
Feb 2026 has been weirdly satisfying —> Got one more CVE. —> First 4 digit bounty. Feels nice! —>Had a crazy nightout with @_MrNiko —>Got so many duplicates that it feels like i am not being quick enough and was this all just a mere luck. —>Still learning and trying to improve.
English
0
1
6
233
Priyav K Kaneria
Priyav K Kaneria@_diginova·
inside. I am bangalore you
Priyav K Kaneria tweet mediaPriyav K Kaneria tweet mediaPriyav K Kaneria tweet media
English
26
21
1.2K
41.4K
!Manan retweetledi
vx-underground
vx-underground@vxunderground·
ZXX
147
1.6K
22.5K
925.9K