gujjuboy10x00

1.2K posts

gujjuboy10x00 banner
gujjuboy10x00

gujjuboy10x00

@vis_hacker

Vishal Panchani Security Engineer | Hall of Fame: Google, PayPal, Apple, 500+| Top 10 All-Time on HackerOne | Hack the planet

Dubai Katılım Nisan 2017
707 Takip Edilen6.2K Takipçiler
gujjuboy10x00 retweetledi
Deriv People
Deriv People@DerivPeople·
You find Claude Code. You check the domain. You run the command. Your Mac is compromised. Our security team traced a live Google Ads campaign that used a genuine Claude page and a hidden download address to deliver the MacSync infostealer. Read the full article to find out why “check the domain” is no longer enough. By @InfosecShinobi, our VP of Security and AI Engineering, @Rajesh_TV , Senior Security Manager, and @vis_hacker, Product Security Tech Lead.
Deriv People tweet media
English
3
1
4
197
gujjuboy10x00
gujjuboy10x00@vis_hacker·
@mattjay we do use ‘safe-chain’ to prevent installation before 48hours for any new packages.
English
0
0
0
11
Matt Johansen
Matt Johansen@mattjay·
Everyone using Claude code and/or Codex - how are you enforcing them to not pull in new/potentially malicious packages from npm or PyPi?
English
173
29
521
153.4K
gujjuboy10x00 retweetledi
Deriv People
Deriv People@DerivPeople·
What if every pull request got a security review as thorough as your best engineer, at any scale? At Deriv, our Security Tech Lead, Vishal (@vis_hacker), built exactly that. Managing 700+ repositories and hundreds of pull requests every week, manual security reviews simply couldn't keep up. Watch below to see his solution
English
0
1
4
219
gujjuboy10x00
gujjuboy10x00@vis_hacker·
Two CVEs just patched by @Oracle , credited to me: CVE-2026-21996 , CVE-2026-35233 Root-privileged parser eating attacker-supplied ELF. Classic trust-boundary bugs. Advisory: linux.oracle.com/errata/ELSA-20… Write-up: @vis_hacker/hunting-bugs-in-oracles-userspace-dtrace-cve-2026-21996-and-cve-2026-35233-56e3704c9c0b" target="_blank" rel="nofollow noopener">medium.com/@vis_hacker/hu…
English
0
1
4
597
zseano
zseano@zseano·
bug bounty programs don't care if you focus on them bug bounty programs don't care if you stop focusing on them you are easily replaced.
English
29
25
531
22.8K
gujjuboy10x00
gujjuboy10x00@vis_hacker·
Watched this and yeah… Claude AI model casually hunting 0-days like it’s a CTF challenge. We’re entering a different era. youtu.be/1sd26pWhfmg
YouTube video
YouTube
English
0
4
19
2K
gujjuboy10x00
gujjuboy10x00@vis_hacker·
@samm0uda Really impressive bug chaining , learned something new about how seemingly low-impact issues can be combined into full ATOs. Well deserved bounties 🔥
English
0
0
3
885
gujjuboy10x00
gujjuboy10x00@vis_hacker·
@Nithin0dha WhatsApp as DR is cool, but… maybe consider an actual secondary WAF/CDN next time? Trading platforms deserve more than a chat-based backup 😅
English
0
0
0
160
Nithin Kamath
Nithin Kamath@Nithin0dha·
Cloudflare powers approximately 20-25% of all internet traffic globally. It's the infrastructure behind millions of websites and apps—from content delivery and DDoS protection to DNS services. When Cloudflare has an outage, it doesn't just affect one company; it impacts a significant chunk of the internet simultaneously. Today, they had a brief outage that affected Kite along with numerous other brokers, fintech platforms, and online services worldwide. This is why we built Kite Backup on WhatsApp. This system is independent of our primary systems. When external outages impact Kite, you can still exit your positions through WhatsApp. Only a few thousand people used the WhatsApp service today. Check out the post in the comments for steps on how to use it. We're also actively working on reducing our dependency on Cloudflare. I'm really sorry for the inconvenience today.
English
199
264
6K
402.2K
gujjuboy10x00 retweetledi
shubs
shubs@infosec_au·
I've pushed a few updates to github.com/assetnote/reac…. Vercel and Netlify are no longer flagged as vuln. Offsite redirs not followed. Custom header support in case you need auth or custom UA. Redir test cases are more accurate now (both base path and redir tested).
English
2
26
165
17.2K
gujjuboy10x00 retweetledi
Elon Musk
Elon Musk@elonmusk·
Is the left really just a giant kleptocracy? The evidence increasingly suggests it is.
English
18.3K
38.3K
281.5K
44.9M
gujjuboy10x00 retweetledi
Michael Stepankin
Michael Stepankin@artsploit·
Last year, I committed to uncovering critical vulnerabilities in Maven repositories. Now it’s time to share the findings: RCE in Sonatype Nexus, Cache Poisoning in JFrog Artifactory, and more! Read it all below 🧵
Michael Stepankin tweet media
English
7
78
296
30.6K
gujjuboy10x00 retweetledi
Elon Musk
Elon Musk@elonmusk·
Mario Draghi’s critique is accurate. A thorough review of EU regulations to eliminate unnecessary rules and streamline activity in Europe would revitalize growth and strengthen competitiveness. Things should be default legal, rather than default illegal.
Ursula von der Leyen@vonderleyen

Dear Mario Draghi, a year ago, I asked you to prepare a report on the future of Europe’s competitiveness. No one was better placed than you to take up this challenge. Now, we are eager to listen to your views ↓ x.com/i/broadcasts/1…

English
2.9K
5.7K
38.4K
9.4M
gujjuboy10x00 retweetledi
Orange Tsai  🍊
Orange Tsai 🍊@orange_8361·
Thrilled to release my latest research on Apache HTTP Server, revealing several architectural issues! blog.orange.tw/2024/08/confus… Highlights include: ⚡ Escaping from DocumentRoot to System Root ⚡ Bypassing built-in ACL/Auth with just a '?' ⚡ Turning XSS into RCE with legacy code from 1996
English
38
647
1.9K
235.9K
gujjuboy10x00 retweetledi
James Kettle
James Kettle@albinowax·
When researching request smuggling, I decided that TE.0 would never be exploitable because it requires the back-end server to accept a HTTP request starting with a number + newline.... and no server would be that crazy 🤦‍♂️ Awesome work! Never under-estimate the crazy.
sw33tLie@sw33tLie

This is one of the most widespread and impactful bugs I've ever found in my career. Great collab with @bsysop and @_medusa_1_ Smugglings are still out there—stay vigilant! #bugbounty @Bugcrowd bugcrowd.com/blog/unveiling…

English
7
33
207
22.3K
gujjuboy10x00 retweetledi
shubs
shubs@infosec_au·
Our security researcher @hash_kitten found one of the most critical exploit chains in the history of @assetnote. Affecting 40k+ instances of ServiceNow, we could execute arbitrary code, access all data without authentication. You can read our blog here: assetnote.io/resources/rese…
shubs tweet media
English
15
219
788
73.6K