Jenish Sojitra

2.1K posts

Jenish Sojitra banner
Jenish Sojitra

Jenish Sojitra

@_jensec

$2M in bug bounty. Offensive Security researcher. Product developer who likes Building in Public. Creator of https://t.co/0N9TViCzQ4

Katılım Temmuz 2017
584 Takip Edilen24.5K Takipçiler
Sabitlenmiş Tweet
Jenish Sojitra
Jenish Sojitra@_jensec·
Last month was my highest in bug bounty so far with almost $131k in bounty. Total paid reports: 18 Average reward: $7.3k Category: most were logical findings via reversing mobile applications and discovering internal endpoints leading to code execution and missing auth etc
Jenish Sojitra tweet media
English
101
125
2.8K
239.1K
Jenish Sojitra retweetledi
drop
drop@dropn0w·
oh god... Triagers I feel your pain.
drop tweet media
English
8
4
203
27.7K
Jenish Sojitra retweetledi
Aastha
Aastha@Paaastha·
Hey @Hacker0x01 , Huge shoutout to triager "h1_analyst_malenia" 🌟 I’m seriously impressed by the level of professionalism, technical expertise and empathy they’ve shown over the past few months. Thank you!
English
0
1
33
1.6K
Google
Google@Google·
Gemini 3.5 Flash is built to help you execute complex, agentic workflows. 3.5 Flash rivals flagship models to deliver frontier performance for agents and coding, at the lightning speeds you expect from the Flash series.
Google tweet media
English
78
182
2.3K
964.6K
Google
Google@Google·
Meet Gemini 3.5 Flash — our strongest agentic and coding model yet. It delivers frontier-level performance at 4x the speed of comparable frontier models — often at less than half the cost. Generally available, starting today. 🧵 #GoogleIO
Google tweet media
English
394
944
9.5K
868K
Jenish Sojitra
Jenish Sojitra@_jensec·
@rez0__ @TakSec I am facing issues with context rotations any idea? Context window is so small and every time it hits context it restarts
English
2
0
3
2.6K
GitHub Security
GitHub Security@GitHubSecurity·
Here are our April bug bounty stats! ✅325 bounty reports submitted 👥226 hackers participated in our program 💰Awarded $2,367 in bounties Found a vulnerability? Submit it here: bounty.github.com.
English
24
8
169
84.2K
Jenish Sojitra
Jenish Sojitra@_jensec·
Seeing Claude Usage Policy banner despite being a part of Claude Cyber Verification Program, anyone else seeing this?
Jenish Sojitra tweet media
English
10
0
84
10K
Franc Vian
Franc Vian@fr4vian·
Opus 4.7 is THE worst model I used so far, so waste of money and time...
English
3
0
24
2.7K
Joseph Thacker
Joseph Thacker@rez0__·
For one of the most important companies on the internet, @Cloudflare's bug bounty program doesn't pay that well
Joseph Thacker tweet media
English
16
2
186
13.4K
Backpacking Daku
Backpacking Daku@outofofficedaku·
Coming out of VFS after submitting the docs and dodging all attempts for them to make traveller pay for Premium Lounge or any unnecessary add-ons
English
7
6
122
20.2K
Jenish Sojitra
Jenish Sojitra@_jensec·
One way to deal with AI spam reports would be to make program private with limited researchers and keep VDP only public. I know a couple of program managers are already considering this
English
8
1
100
6.1K
Fabian Hedin
Fabian Hedin@FabianHedin·
Thanks for bringing the issue to our attention. - On the first point, we switched so that free users have private projects by default. This was rolled start of November 2025, and released in December 2025. - Unfortunately our HackerOne partners thought public access of public projects’ chats was the intended behaviour. We are reviewing the triage process as a result of this, to ensure we avoid false-negatives in the future.
English
2
0
3
413
Lovable
Lovable@Lovable·
We’re sorry our initial statement didn't properly address our mistake. Here's what a public project on Lovable means, and how we got to where we are today: In the early days, people didn't know what Lovable was capable of. So we wanted to make it easy to explore what others were building, as a way to spark ideas and lower the barrier to getting started. Like scrolling GitHub or Dribbble: you browse projects to see what's possible, then go build your own. When you create a project on GitHub, you can make it private or public. Lovable worked the same. Users had a "Public" or "Private" option right in the chatbox. A public project meant the entire project was public, both chat and code. “Just like a public project on GitHub," we thought. Over time, we realized this was confusing. Many users thought "public" just meant others could see their published app, not the chat of an unpublished project. That's reasonable. On the free tier, users originally couldn't create private projects. They had to upgrade to a paid plan to do so. In May 2025, we changed this: users on the free tier could choose to make their projects private. For enterprise customers, the public visibility setting was disabled altogether. And in December 2025, we switched to private by default across all tiers. We also retroactively patched our API so public project chats couldn't be accessed, no matter what. Unfortunately, in February, while unifying permissions in our backend, we accidentally re-enabled access to chats on public projects. This was reported through our vulnerability disclosure program (via HackerOne). Unfortunately, the reports were closed without escalation because our HackerOne partners thought that seeing public projects’ chats was the intended behaviour. Upon learning this, we immediately reverted the change to make all public projects’ chats private again. We appreciate the researchers who uncovered this. We understand that pointing to documentation issues alone was not enough here. We’ll do better.
Lovable@Lovable

We were made aware of concerns regarding the visibility of chat messages and code on Lovable projects with public visibility settings. To be clear: We did not suffer a data breach. Our documentation of what “public” implies was unclear, and that’s a failure on us. Specifically for public projects, chat messages used to be visible — this is now no longer possible. When it comes to code of public projects: That is intentional behavior. We have experimented with different UX for how the build history is surfaced on public projects, but the core behavior has been consistent and by design. Importantly, for enterprise customers, being able to set visibility to public for new projects has been disabled since May 25, 2025.

English
150
87
987
384K
Jenish Sojitra
Jenish Sojitra@_jensec·
Need to say this now: Submitting vulnerabilities to companies without established bug bounty programs should be normalized and should not be prosecuted
English
11
6
144
11.8K
Riken Shah
Riken Shah@_RikenShah·
If you attended YC Startup School and are not using your credits, I will buy them for ₹100,000💰
Riken Shah tweet media
English
21
1
221
26K