Sreeram KL (@kl_sree) 's Twitter Profile
Sreeram KL

@kl_sree

Infosec enthusiast! | @googlevrp fan boy ๐Ÿ˜ | CTF @thehackerscrew1 | CS student | Web Security

ID: 952234523965575168

linkhttps://blog.geekycat.in/ calendar_today13-01-2018 17:42:56

2,2K Tweet

2,2K Followers

863 Following

Derin Eryilmaz (@deryilz) 's Twitter Profile Photo

๐Ÿ”ฅBlog post is up! How extensions could exploit JS bindings to use webRequestBlocking prior to Chrome 118: 0x44.xyz/blog/web-requeโ€ฆ

BApp Store (@bapp_store) 's Twitter Profile Photo

New: Repeater Strike Written by Gareth Heyes \u2028, powered by Burp AI! Scale IDOR & fuzzing like never before: ๐Ÿค– Auto-build regex rules with AI ๐Ÿ“Š Scan proxy history for similar bugs ๐Ÿ› ๏ธ Save, edit, and re-run rules easily #BurpAI

New: Repeater Strike

Written by <a href="/garethheyes/">Gareth Heyes \u2028</a>, powered by Burp AI!

Scale IDOR &amp; fuzzing like never before:
๐Ÿค– Auto-build regex rules with AI
๐Ÿ“Š Scan proxy history for similar bugs
๐Ÿ› ๏ธ Save, edit, and re-run rules easily

#BurpAI
0x999 ๐Ÿ‡ฎ๐Ÿ‡ฑ (@_0x999) 's Twitter Profile Photo

New blog post is up: How I leaked the IP addresses of Brave's Tor window and Chrome VPN extension users--plus, a new Popunder technique and connect-src CSP directive bypass. Read more @ 0x999.net/blog/leaking-iโ€ฆ

Caido (@caidoio) 's Twitter Profile Photo

We are super excited to share that we acquired the Shift Plugin (shiftplugin.com) and we are making it free to Caido paid users ๐Ÿš€ Shift is a Caido plugin that is a smart AI companion for your hacking. It can craft payloads, Match&Replace rules, HTTPQL queries and much

We are super excited to share that we acquired the Shift Plugin (shiftplugin.com) and we are making it free to Caido paid users ๐Ÿš€ 

Shift is a Caido plugin that is a smart AI companion for your hacking. It can craft payloads, Match&amp;Replace rules, HTTPQL queries and much
Justin Gardner (@rhynorater) 's Twitter Profile Photo

Exciting announcement - our (cc Joseph Thacker) plugin Shift was acquired by Caido! Aaand they've made it free. ^_^ thanks Caido Now, natural language HTTP modification, AI-powered Replay tab renaming, and much more are available to all. Check the vid below for features.

Adversary Village (@adversaryvillag) 's Twitter Profile Photo

The Schedule is Live! Check out the lineup of talks, workshops, panel discussions, and hands-on activities happening at Adversary Village at DEF CON 33! Schedule: adversaryvillage.org/adversary-evenโ€ฆ Mark your calendars - we can't wait to see you all at DEF CON! #AdversaryVillage #DEFCON33

The Schedule is Live!
Check out the lineup of talks, workshops, panel discussions, and hands-on activities happening at Adversary Village at <a href="/defcon/">DEF CON</a> 33!
Schedule: adversaryvillage.org/adversary-evenโ€ฆ
Mark your calendars - we can't wait to see you all at DEF CON!
#AdversaryVillage #DEFCON33
Utkarsh Kanwat (@ukanwat) 's Twitter Profile Photo

After building multiple AI agents in production, I'm convinced 90% of current approaches are fundamentally broken, Most companies are building expensive chatbots and calling them "agents." Here's what actually works (and what doesn't): utkarshkanwat.com/writing/bettinโ€ฆ

Denis Laskov ๐Ÿ‡ฎ๐Ÿ‡ฑ (@it4sec) 's Twitter Profile Photo

Reverse engineering Ecovacs vacuum and lawn mowing robots and using Bluetooth RCE to turn them into moving webcams. ๐Ÿ‘ฉ๐Ÿฝโ€๐Ÿฆฏ๐Ÿ’ฅ๐Ÿ‘๏ธ๐Ÿฅท More details on: LinkedIn: linkedin.com/posts/dlaskov_โ€ฆ Substack: it4sec.substack.com/p/reverse-engiโ€ฆ

Reverse engineering Ecovacs vacuum and lawn mowing robots and using  Bluetooth RCE to turn them into moving webcams. ๐Ÿ‘ฉ๐Ÿฝโ€๐Ÿฆฏ๐Ÿ’ฅ๐Ÿ‘๏ธ๐Ÿฅท

More details on:
LinkedIn: linkedin.com/posts/dlaskov_โ€ฆ
Substack: it4sec.substack.com/p/reverse-engiโ€ฆ
HackProve (@hackprove_) 's Twitter Profile Photo

๐Ÿ’ฃ Google Drive Auth Bypass: How View-Only Folder Sharing Leaked Google Form Responses ($5000 Bug) more information: discord.com/invite/h6dKuEtโ€ฆ medium.com/bugbountywriteโ€ฆ

Zeyu (Zayne) | @zeyu2001@infosec.exchange (@zeyu2001) 's Twitter Profile Photo

Can you execute arbitrary Python code from only a comment? This was the premise of a recent CTF challenge, which I solved after diving into the CPython source code with the help of Hacktron AI (after a long night chasing a dead end, customising a few Hacktron agents helped me to

Can you execute arbitrary Python code from only a comment? This was the premise of a recent CTF challenge, which I solved after diving into the CPython source code with the help of <a href="/HacktronAI/">Hacktron AI</a> (after a long night chasing a dead end, customising a few Hacktron agents helped me to
NULLCON (@nullcon) 's Twitter Profile Photo

In this session at #NullconBerlin2025, intrigus will use formal verification (read: bug-finding with mathematical superpowers ๐Ÿง โœจ) to crack open V8โ€™s Turboshaft JIT engine. Know More: nullcon.net/berlin-2025/spโ€ฆ #V8Engine #FormalVerification #JSTalks #SecurityResearch

In this session at #NullconBerlin2025, <a href="/intrigus_/">intrigus</a> will use formal verification (read: bug-finding with mathematical superpowers ๐Ÿง โœจ) to crack open V8โ€™s Turboshaft JIT engine.

Know More: nullcon.net/berlin-2025/spโ€ฆ

#V8Engine #FormalVerification #JSTalks #SecurityResearch
Hacktron AI (@hacktronai) 's Twitter Profile Photo

Hacktron is the first company to be backed by Project Europe, and we're incredibly excited to be part of the it's cohort. From the day we met the Project Europe and 20VC Fund team, we knew that they were the kind of people we wanted on our side. We had an oversubscribed

Hacktron is the first company to be backed by <a href="/ProjectEurope_/">Project Europe</a>, and we're incredibly excited to be part of the it's cohort.

From the day we met the Project Europe and <a href="/20vcFund/">20VC Fund</a> team, we knew that they were the kind of people we wanted on our side. We had an oversubscribed
Chi-en (Ashley) Shen (@ashl3y_shen) 's Twitter Profile Photo

I admire so much how chompie is not only an incredibly intelligent researcher but also such a kind and warm friend Iโ€™m truly grateful for. Congrats on Phrack Zineโ€™s 40th anniversary!! #defcon33

I admire so much how <a href="/chompie1337/">chompie</a> is not only an incredibly intelligent researcher but also such a kind and warm friend Iโ€™m truly grateful for. Congrats on <a href="/phrack/">Phrack Zine</a>โ€™s 40th anniversary!! #defcon33
Orange Tsai  ๐ŸŠ (@orange_8361) 's Twitter Profile Photo

Thanks PortSwigger and Bug Bounty Village for this awesome event โ€” and also to my DEVCORE buddies for standing on stage to collect the trophy for me! A little follow-up article on this research is coming soon... stay tuned! ๐Ÿค˜

Thanks <a href="/PortSwigger/">PortSwigger</a> and <a href="/BugBountyDEFCON/">Bug Bounty Village</a> for this awesome event โ€” and also to my <a href="/d3vc0r3/">DEVCORE</a> buddies for standing on stage to collect the trophy for me!

A little follow-up article on this research is coming soon... stay tuned! ๐Ÿค˜
Ivan Fratric ๐Ÿ’™๐Ÿ’› (@ifsecure) 's Twitter Profile Photo

If you've been keeping track on the Big Sleep bug tracker at goo.gle/bigsleep you might have noticed it lists more bugs now compared to last week. Including a "High impact issue in V8" :)