Jenish Sojitra
2.1K posts

Jenish Sojitra
@_jensec
$2M in bug bounty. Offensive Security researcher. Product developer who likes Building in Public. Creator of https://t.co/0N9TViCzQ4


While AI is helping us tackle big challenges, it also poses new potential security risks. That’s why we’re focused on building tools that keep the broader ecosystem safe — like CodeMender, a code security agent that automatically finds and fixes critical software vulnerabilities. Today, we’re inviting a select group of experts to test a new CodeMender API, and we’ll be launching it more broadly soon. #GoogleIO




My first bug bounty payment, and it was accelerated. Thank you Apple. #bugbounty #AppleBugBounty

okay im calling it officially. codex is cracked. if you're a bb hunter and you dont have a hackbot set up yet, i recommend codex with gpt5.5 over claude code.

Confirmed! Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) chained 4 logic bugs to achieve a sandbox escape on Microsoft Edge, earning $175,000 and 17.5 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin









We were made aware of concerns regarding the visibility of chat messages and code on Lovable projects with public visibility settings. To be clear: We did not suffer a data breach. Our documentation of what “public” implies was unclear, and that’s a failure on us. Specifically for public projects, chat messages used to be visible — this is now no longer possible. When it comes to code of public projects: That is intentional behavior. We have experimented with different UX for how the build history is surfaced on public projects, but the core behavior has been consistent and by design. Importantly, for enterprise customers, being able to set visibility to public for new projects has been disabled since May 25, 2025.












