Mahendra Purbia

2.8K posts

Mahendra Purbia banner
Mahendra Purbia

Mahendra Purbia

@Mah3Sec

🕉️ 🚩| Security Engineer🇮🇳 | 3 CVE | CRTP | CEH |Secured 200+ Companies

Rajsamand, Rajasthan Katılım Eylül 2019
431 Takip Edilen2.8K Takipçiler
Sabitlenmiş Tweet
Mahendra Purbia
Mahendra Purbia@Mah3Sec·
Corruption. Broken education. Poor infrastructure. A dying environment. Every taxpayer can see what's happening. My patriotism is for my country, not any political party. As citizens, we have every right to question the government. Accountability is their duty. #neetleak
English
0
1
1
124
Het Mehta
Het Mehta@hetmehtaa·
Got a new M5 Pro What should I install first?
Het Mehta tweet media
English
159
3
388
32.2K
Shruti Codes
Shruti Codes@Shruti_0810·
GOODBYE TO CYBERSECURITY! Someone just open-sourced an arsenal of AI hacking tools. Not one. Not ten. Hundreds. Inside the repository: • Jailbreak frameworks for LLMs • Prompt injection testing tools • AI red team agents • Model extraction utilities • Supply chain attack demos • Automated AI pentesting frameworks These are the same categories of tools security researchers use to find vulnerabilities before attackers do. Now anyone can study them. That's both exciting... and terrifying. The biggest threat to AI isn't smarter models. It's insecure ones. If you're building with LLMs and you're not actively testing your prompts, agents, and infrastructure— You're probably shipping vulnerabilities you don't even know exist. Open source is accelerating AI. It's also accelerating AI attacks. Repository link in the comments ↓
English
69
232
1.5K
116.7K
Google
Google@Google·
Learn more about its security features and how selfie video works ↓ goo.gle/4bAoiv6
English
23
25
254
203.1K
Google
Google@Google·
Forgot your password? Lost your phone? Can’t get into your account? You can now use a selfie video to log into your Google Account. The new feature is easy to use and lets you sign in — even if you forget your password or don’t have your usual phone or laptop — with a quick selfie.
GIF
English
1.8K
950
7K
5M
Dharmendra Pradhan
Dharmendra Pradhan@dpradhanbjp·
LoP Shri @RahulGandhi and @INCIndia continue to shamelessly exploit students as political tools to manufacture disruption during the Monsoon Session of Parliament. Shri @RahulGandhi and @INCIndia chose to stage a dharna outside the Hon'ble Prime Minister's residence , causing inconvenience to the public and disregarding established security protocols. Even after Government conveyed its readiness for a comprehensive discussion, the Congress chose political spectacle over democratic debate. Their objective was never solutions for students, it was disruption for political headlines For Rahul Gandhi, this is not about students. This is about manufacturing confrontation after every genuine avenue for discussion has been opened. Our Government remains 100% committed to discussing NEET and addressing every genuine concern of our youth on the floor of the House. The students of India deserve far better than being treated as props in a political campaign. They deserve certainty over chaos, solutions over slogans and responsibility over disruption. We owe our students more than outrage. We owe them answers, reforms and accountability. That is exactly what our government remains committed to delivering.
English
46.4K
5.8K
35.8K
17.3M
Mahendra Purbia
Mahendra Purbia@Mah3Sec·
😆😆Storytime (Characters: Peter & Miles) Miles used AI to perform a white-box penetration test on a web application running in a non-WAF environment. In just 2 days, the AI-generated report contained 65 findings, including a mix of critical, high, medium, and chained vulnerabilities. Their manager asked Peter to review and validate the AI-generated penetration test report. Peter spent an entire week just understanding what the AI had actually done and how it reached its conclusions. Revalidating every finding ended up taking longer than the original penetration test itself. After the review, Peter concluded that around 88% of the reported findings were either false positives or not vulnerabilities at all. Most of the remaining valid issues were relatively basic findings such as TLS misconfigurations, missing Secure cookie flags, clickjacking, and missing security headers. Moral of the story: AI can speed up finding potential issues, but if its output isn't validated, the time saved during testing can be lost during review. In this case, validating the AI's results took longer than performing the penetration test from scratch. So, who's responsible: the person who blindly trusted the AI, or the AI for generating incorrect assumptions and hallucinated findings? I think Both
English
1
0
1
74
Jerry
Jerry@Mdhsan19·
First in mine bloodline who spend 20 hrs to automate something that took 20 mins max to do manually 😎🥹
English
5
0
26
1K
Mahendra Purbia
Mahendra Purbia@Mah3Sec·
@Hacker0x01 triage experience has been frustrating lately. Some analysts seem to rely almost entirely on AI-generated reviews instead of actually reading the report or following the reproduction steps. If a report can be marked as N/A without even validating the provided PoC, that's a serious problem. Security analysis requires human verification. At that point, they're acting more like AI operators than security analysts. #bugbounty #hackerone #AIslop
English
0
0
3
182
Mahendra Purbia
Mahendra Purbia@Mah3Sec·
Peak PR wording: "A Mythos-class model that we've made safe for general use." 👀 #Ai #claude
English
0
0
1
75
Gaurav
Gaurav@MrKryp70n·
4 and a half hr ------> Secret.txt Finally after a long time I have something to post 😅. At 22, I have achieved #OSEP certification by @offsectraining. For the last 2 months i have been preparing for this examination. And finally now I have it 😤 #offsec #osep #oscp #redteam
Gaurav tweet media
English
11
7
130
3.1K
the_IDORminator
the_IDORminator@the_IDORminator·
Apparently AI didnt kill bug bounty itself, it just killed triage times which caused hackers to starve to death while waiting on payouts. Didnt see that coming!
English
16
16
307
37K