Shivam Pandey 🇮🇳 (@shivam31200) 's Twitter Profile
Shivam Pandey 🇮🇳

@shivam31200

Infosec | Synack |Write poems in meantime

ID: 1045683038380789760

linkhttps://shivam312000.medium.com calendar_today28-09-2018 14:33:59

4,4K Tweet

1,1K Followers

601 Following

shubs (@infosec_au) 's Twitter Profile Photo

The security research team at Assetnote found and reported a critical pre-auth RCE vulnerability to Metabase earlier this month CVE-2023-38646: blog.assetnote.io/2023/07/22/pre… This one was an incredibly fun discovery as there are many roads to RCE through JDBC. We've published details

The security research team at <a href="/assetnote/">Assetnote</a> found and reported a critical pre-auth RCE vulnerability to Metabase earlier this month CVE-2023-38646:

blog.assetnote.io/2023/07/22/pre…

This one was an incredibly fun discovery as there are many roads to RCE through JDBC. We've published details
Sam Curry (@samwcyo) 's Twitter Profile Photo

New writeup: Between March, 2023 and May, 2023 we found multiple critical vulnerabilities in points[.]com the global provider for major airline and hotel rewards programs. Full post is available here: samcurry.net/Points-com/ Work from: shubs Ian Carroll

Nuclei by ProjectDiscovery (@pdnuclei) 's Twitter Profile Photo

[NEW-RELEASE] Nuclei Template Editor - AI-powered hub to create, debug, scan, and store templates. Collaborate effortlessly with your team and community. Public signup is open; we're eager to hear your feedback on this early release. - Editor: templates.nuclei.sh - Docs:

ISRO (@isro) 's Twitter Profile Photo

Chandrayaan-3 Mission: 'India🇮🇳, I reached my destination and you too!' : Chandrayaan-3 Chandrayaan-3 has successfully soft-landed on the moon 🌖!. Congratulations, India🇮🇳! #Chandrayaan_3 #Ch3

shubs (@infosec_au) 's Twitter Profile Photo

Thanks everyone who attended my keynote presentation at Security BSides Ahmedabad. I've published my slides here: drive.google.com/file/d/1aeNq_5… I hope that the keynote was informative and inspiring :)

HTTPVoid (@httpvoid0x2f) 's Twitter Profile Photo

Check out our new blog post! We hacked into Apple Travel Portal (yes, again!) using a 0-day Remote Code Execution exploit. Part 1 is live now, stay tuned for the follow-up on another RCE worth a total bounty of $40k! blog.projectdiscovery.io/hello-lucee-le…

Andres Freund (Tech) (@andresfreundtec) 's Twitter Profile Photo

Binni Shah FWIW, I didn't actually start looking due to the 500ms - I started looking when I saw failing ssh logins (by the usual automated attempts trying random user/password combinations) using a substantial amount of CPU. Only after that I noticed the slower logins.

Nick Percoco (@c7five) 's Twitter Profile Photo

Kraken Security Update: On June 9 2024, we received a Bug Bounty program alert from a security researcher. No specifics were initially disclosed, but their email claimed to find an “extremely critical” bug that allowed them to artificially inflate their balance on our platform.

Rebane (@rebane2001) 's Twitter Profile Photo

new blogpost time!! this one's a fun writeup on a vulnerability chain i found across multiple google services that earned me a $4133.70 bounty lots of fun css as usual! i had to recreate a bunch of drive/docs/gmail/youtube UIs c: have fun! lyra.horse/blog/2024/09/u…

s1r1us (@s1r1u5_) 's Twitter Profile Photo

Imagine opening a Discord message and suddenly your computer is hacked. We discovered a bug that made this possible and earned a $5,000 bounty for it. Here's the story and a beginner-friendly deep dive into V8 exploit development. Watch: youtube.com/watch?v=R3SE4V…

Imagine opening a Discord message and suddenly your computer is hacked.

We discovered a bug that made this possible and earned a $5,000 bounty for it.

Here's the story and a beginner-friendly deep dive into V8 exploit development.

Watch: youtube.com/watch?v=R3SE4V…
Sachin Tendulkar (@sachin_rt) 's Twitter Profile Photo

A knock to remember by Nitish. He has impressed me right from the 1st Test and his composure and temperament have been on display right through. Today he took it a notch higher to play a crucial innings in this series. Wonderfully and ably supported by Washington Sundar as well. Well

A knock to remember by Nitish. He has impressed me right from the 1st Test and his composure and temperament have been on display right through. Today he took it a notch higher to play a crucial innings in this series. Wonderfully and ably supported by <a href="/Sundarwashi5/">Washington Sundar</a> as well.
Well
zhero; (@zhero___) 's Twitter Profile Photo

the research paper is out: Next.js and the corrupt middleware: the authorizing artifact result of a collaboration with inzo that led to CVE-2025-29927 (9.1-critical) zhero-web-sec.github.io/research-and-t… enjoy the read!

the research paper is out:

Next.js and the corrupt middleware: the authorizing artifact

result of a collaboration with <a href="/inzo____/">inzo</a> that led to CVE-2025-29927 (9.1-critical)

zhero-web-sec.github.io/research-and-t…

enjoy the read!