Ayush Shrestha
14 posts


Yall lookout, I just got an email to my hackerone account with a bugcrowd message saying a report was posted using my email and giving me a link to click to claim the bug... seems phishy repost for reach please. @Jhaddix @thedawgyg @BadAt_Computers

English
Ayush Shrestha retweetledi

Our team, THREATNIX, secured 28th place with 1416 points at the BlackHat MEA Quals CTF 2025!
Huge shoutout to my amazing teammates @AyushXth and @OrionJoshi great work, team!

English

Hey hackers! We're running a beta for Hai for Hackers, our AI security agent. If you're interested, please reply with your HackerOne username (we will probably limit to ~100 hackers for now). After it's been enabled, you can start using it by clicking the Hai button in the top right corner of the app. It’s free to use (with a limited daily budget for now). It is like any other AI you’ve interacted with, with the added benefit that it has access to a whole bunch of HackerOne data, like reports and programs. We’re shipping improvements to Hai almost every day. Here are some neat use cases:
- “take all the learnings from STÖK, jhaddix, and nahamsec's recon strategy and build one for me!”
- “write a python script for a typical recon process”
- “i need an XSS payload that doesn’t use single or double quotes”
- “my XXE payload doesn't call back to my server, what could go wrong?”
- “write a response for report #133337”
The beta also comes with Hai Plays for you, which allows you to build your own security agents in HackerOne. You can create them at hackerone.com/settings/hai_p…. Some of the cool use cases we’ve seen so far are:
- write reports with minimal input from you (efficiency++!)
- convert reports into blogposts with a single prompt
- AI mentor to give feedback about your communication and increase the likelihood of a reward
In the background we’ve been working on agentic behavior, which we expect will soon come to Hai for Hackers as well. These AI agents can act like your hacking buddy and hack alongside you. We’ll keep you in the loop on our progress.

English
Ayush Shrestha retweetledi

🚨Call for Bug Bounty Hunters in Nepal🚨
We are hosting the first-ever Live Hacking Meetup for Nepal's bug bounty hunters. Join us for exciting hacking and collaboration from May 10th to May 17th!!
DM me for the Discord server invitation.
h1.community/events/details…

English
Ayush Shrestha retweetledi

Server-Side Request Forgery (SSRF) is often underestimated, but it can lead to severe consequences—including Remote Code Execution (RCE).
Read here: @0xUN7H1NK4BLE/how-ssrf-leads-to-rce-in-a-net-application-ee1b13812245" target="_blank" rel="nofollow noopener">medium.com/@0xUN7H1NK4BLE…
#CyberSecurity #SSRF #RCE #EthicalHacking #hackingtips
English
Ayush Shrestha retweetledi
Ayush Shrestha retweetledi

We're giving away an OSCP voucher to our community.🎉
To participate :
1. Follow us on Twitter.
2. Retweet this post.
3. Like this tweet.
It's that simple! By completing these steps, you'll be eligible to win.
Also, register now at threatcon.io/pricing.
#offsec #giveaway

English
Ayush Shrestha retweetledi

Workshop Tickets Are Now Available!🤩
Learn More about our workshops:
threatcon.io/hacking-androi… threatcon.io/application-se…
📅Sept 11-12, 2023
⏰10 AM - 5 PM
Please note that both workshops are running in parallel.
#threatcon2023

English
Ayush Shrestha retweetledi

📣Our CFP is ending in 10 days!!
Don't miss the chance to present your awesome research to security enthusiasts all over the world. Send your papers soon.
threatcon.io/cfp
threatcon.io/cfw
threatcon.io/bounty_track
#THREATCON2023 #CFP #poweredbythreatnix

English
Ayush Shrestha retweetledi
Ayush Shrestha retweetledi
Ayush Shrestha retweetledi

@THREAT_CON team is at Ahmedabad for @bsidesahmedabad . If anyone is around let’s catch up.
Cc : @1lastBr3ath @SuyashNP @0x4D5341 @Ayush_Xth

English

Honored to be invited at BountyCon 2022.
See you guys at Singapore :-)
#BountyCon #Singapore

English





