
Sayaan Alam
2.5K posts

Sayaan Alam
@ehsayaan
Security Researcher @nuasecurity | Red Teamer and Bug Bounty Hunter | SRT Hero at @Synack Red Team | Hackerone - sayaanalam
Katılım Nisan 2017
998 Takip Edilen9.4K Takipçiler
Sabitlenmiş Tweet

Finally, the Most awaited write-up is here , SSRF (Server Side Request Forgery) worth $4,913 | My Highest Bounty Ever!
Kudos to @TechFenixSec Red team for helping me throughout the research
Retweet if you like it.🙂
#bugbounty
medium.com/techfenix/ssrf…
English

Absolutely thrilled that one of the most amazing cybersecurity conferences is happening in breathtaking Mussoorie!
@BsidesMussoorie is more than a conference, it’s an experience: insightful talks, brilliant minds, networking, and fresh mountain air.
English

@rauchg @tech_savvy_guy_ @vercel You should change that setting to allow everyone @rauchg since you are always expecting some DMs, hahaha!
English

@rauchg Obsession can make me sit on a screen for straight 16 hours or more. A job could never match that productivity!! Obsession + Goal is key to super productivity.
English

@ArmanSameer95 Sorry to hear bro, you can always call whenever you don’t feel good or need someone.
English

@dhruvagoyal Less AI interactions when using MCP, you just give input and final output/results. No follow up on each step
English

Builders ✨showed up ✨
Check out the leaderboard today - it’s exciting to see so many YC applications!


Product Hunt 😸@ProductHunt
We're teaming up with @ycombinator to get builders to launch. Schedule your launch for tomorrow, tag "YC application." and @aaron_epstein will review launches. Top ones could get a YC interview + potential funding. 👇
English

@arshadkazmi42 Takeover check failed: incompatible encoding regexp match (UTF-8 regexp with ASCII-8BIT string)
English

I recently added subdomain takeover monitoring to issl.today, along with an API.
You can now generate an API key and programmatically check whether a domain is vulnerable or potentially vulnerable to subdomain takeover.
It also supports importing your HackerOne scope via API key. The system will:
Import all in-scope domains
Perform subdomain enumeration (including wildcards)
Continuously monitor them for services that could lead to takeover
Useful if you’re tracking takeover opportunities across many programs.
Jenish Sojitra@_jensec
Is there an updated version or library or API for github.com/EdOverflow/can… ?
English

@rauchg @YShahinzadeh Haha i didn’t expect a lightning fast response like that. I must applaud for your responsiveness on such issues. I wish all other C Suite executives were like that🙌🏻
English
Sayaan Alam retweetledi

Track trending vulnerabilities and active exploitation signals. Free vulnerability intelligence dashboard by LeakyCreds leakycreds.com/vulnerability-…
English
Sayaan Alam retweetledi

Live Vulnerability Intelligence & Trending CVEs | LeakyCreds leakycreds.com/vulnerability-…
English

@ehsayaan Hi @ehsayaan, this is definitely not the experience we want you to have. Kindly share your registered contact number and vehicle details with us via DM, so we can connect and address the issue more effectively. Regards, MahindraForYou twitter.com/messages/compo…
English

@rauchg Hahaha it’s good to see you involved in bug bounties lately. Especially during Vercel WAF challenge. Can’t donate funds to some early age cybersecurity startup to kickstart their journey?
English

We've identified, responsibly disclosed, and confirmed 2 critical, 2 high, 2 medium, 1 low security vulnerabilities in Cloudflare's vibe-coded framework Vinext.
We believe the security of the internet is the highest priority, especially in the age of AI. Vibe coding is a useful tool, especially when used responsibly.
Our security research and framework teams are extending their help and expertise to Cloudflare in the interest of the public internet's security.
English

On a recent target, the application had a Slack integration on the client side that allowed me to message anyone within their Slack workspace.
#bugbounty

English


What’s next from them?
Claude@claudeai
Introducing Claude Code Security, now in limited research preview. It scans codebases for vulnerabilities and suggests targeted software patches for human review, allowing teams to find and fix issues that traditional tools often miss. Learn more: anthropic.com/news/claude-co…
English





