From a marble factory → London.
Feels unreal.
Life is about persistence, patience, and believing that where you start doesn’t define where you’ll end up.
وفي الآخر، الفضل كله لله.
Announcing #Pwn2Own Ireland for 2025! We return to the Emerald Isle with our new partner @Meta and a $1,000,000 WhatsApp bounty. Yes - one million dollars. Plus new USB attack vectors on phones and more. Check out the details at https://t.co/dgHvL8QC2R
Imagine opening a Discord message and suddenly your computer is hacked.
We discovered a bug that made this possible and earned a $5,000 bounty for it.
Here's the story and a beginner-friendly deep dive into V8 exploit development.
Watch: https://t.co/QtAro4fj4t
Check out our latest blog post! We dive into GitHub Enterprise’s SAML implementation and explore an authentication bypass in encrypted assertion mode.
CVE-2024-4985 / CVE-2024-9487: GitHub Enterprise SAML Authentication Bypass.
https://t.co/mFOE6GGkhO
MXSS Explained Part 1: Why Server-Side HTML Sanitizers Are Doomed to Fail with this XSS!
In this video, I dive into how sanitizers work, discuss the first known MXSS in IE, and showcase an MXSS vulnerability in the popular Node.js module, sanitize-html.
https://t.co/4kghaCIYBc
New blog! This time a high severity session takeover in Zoom worth $15,000. Read the story of how @sudhanshur705 , @BrunoModificato and I chained 2 completely useless XSS vulns to steal OAuth tokens, hijack browser permissions, and more:
https://t.co/qVUgk5shqh
I was getting a lot of DMs asking me how I got started, how I progressed so fast and if I can suggest a Roadmap for the beginners who also wanna get started and progress. Sharing the answer publicly.
Link: https://t.co/AUYJ3HY2J5
#BugBounty#bugbountytips
We uploaded a backdoored AI model to @HuggingFace which we could use to potentially access other customers’ data✨
Here is how we did it - and collaborated with Hugging Face to fix it 🧵⬇️
I wrote a hacker roadmap with my personal experience.
Becoming a Hacker: A Personal Narrative and a Roadmap
https://t.co/g7Hp1rhyEI
Please let me know if you have suggestions to improve. I will be sharing with people around me.
Here is the blog post for
CVE-2023-22515: Broken Access Control Vulnerability in Confluence Data Center and Server
I've left two challenges in it, try to solve them. If you solve second one, that would be a 0-day 😅
https://t.co/HZDFKRykR8
🚨 BREAKING: Wiz Research discovers a massive 38TB data leak by Microsoft AI researchers, including 30,000+ internal Teams messages.
Here's what you need to know 🧵
How we @zomato, made and scaled Vinifera to track team activity on Github and expanded it to other platforms.
Introducing Vinifera - https://t.co/MOvWKdkcyc
It was a blast brainstorming about this in the pink room with @prateek_0490 and @ehsahil.
We aimed to create a straightforward tool for tracking our team's GitHub activities, safeguarding sensitive info.
Check out Vinifera's journey so far: https://t.co/unG2BjVNUw
Fun fact: We named it "Vinifera" as our security team munched on grapes while brainstorming! 🍇 #Vinifera #infosec #infosecurity
Today, we are proud to announce the private beta of Nuclei Cloud – expanding the power of nuclei with enterprise-grade SaaS capabilities on our mission to democratize security.
Sign up today https://t.co/5T2sp9ltEj