@owasp_kathmandu Huge thanks to the @owasp_kathmandu (@Corrupted_brain and the team) for providing me the oppurtunity to share my findings and thoughts with the community. It was a pleasure connecting with everyone there. Looking forward to more such events in the future!
Thank you Ullens College @Bugcrowd@AlteredSecurity@Hacker0x01@apisecu NCA Nepal Rovix Cloud stickermandu🙏🇳🇵
A huge appreciation to all the amazing speakers, volunteers, & participants who made this event possible! 🎉
We look forward to organizing another event together soon!
We scanned 400TB of DeepSeek’s training data & found:
🚨 ~12K live API keys & passwords
🌐 2.76M affected pages
🔄 One key appeared 57K+ times
🔑 219 secret types (AWS root keys, Slack webhooks, etc.)
🔗 Full research: https://t.co/Y6mUIpY9PB
Found SolarWinds serv-u vulnerability CVE-2024-28995 using following endpoints to execute LFI. #solarwinds#Pentesting
https://t.co/lunoUKfYwV
https://t.co/oJp05c0UTG