hack_n_code's profile picture. Tester of pens, AI prompt connoisseur.  Terrible Speller. All thoughts are my own 💭

Vinay⚡

@hack_n_code

Tester of pens, AI prompt connoisseur. Terrible Speller. All thoughts are my own 💭

Vinay⚡ gönderiyi yeniden yayınladı
kmcnam1's tweet image.

Vinay⚡ gönderiyi yeniden yayınladı
kmcnam1's tweet image.

Vinay⚡ gönderiyi yeniden yayınladı

"they did not feel their research was ready to publicly demonstrate"

b1ack0wl's tweet image. "they did not feel their research was ready to publicly demonstrate"

Vinay⚡ gönderiyi yeniden yayınladı

Is this real or a joke CVE-2025-55315 ? ASP.NET Core is vulnerable to http request smuggling !!!! And why is no one talking about it? github.com/advisories/GHS…

h4x0r_dz's tweet image. Is this real or a joke CVE-2025-55315 ? ASP.NET Core is vulnerable to http request smuggling !!!! 

And why is no one talking about it? 

github.com/advisories/GHS…

Vinay⚡ gönderiyi yeniden yayınladı

AWS engineers right now: - Hey Claude, prod is down fix it!!! Claude:

jacobferus's tweet image. AWS engineers right now:

- Hey Claude, prod is down fix it!!!

Claude:

Vinay⚡ gönderiyi yeniden yayınladı

SSRF is just asking the person outside the gas station to buy you beer before you're 21


Vinay⚡ gönderiyi yeniden yayınladı

💥 Wiz Research has uncovered a critical Redis vulnerability that's been hiding for 13 years We found RediShell (CVE-2025-49844): an RCE bug in Redis that affects every version of Redis out there. It's rated CVSS 10 - the highest severity possible. The vulnerability lets…

wiz_io's tweet image. 💥 Wiz Research has uncovered a critical Redis vulnerability that's been hiding for 13 years

We found RediShell (CVE-2025-49844): an RCE bug in Redis that affects every version of Redis out there. It's rated CVSS 10 - the highest severity possible.

The vulnerability lets…

Vinay⚡ gönderiyi yeniden yayınladı
TMTLongShort's tweet image.

Vinay⚡ gönderiyi yeniden yayınladı

every ai app today


Vinay⚡ gönderiyi yeniden yayınladı

I'm improving my co-hacking AI system (built on Claude Code). One of the coolest new things I added to it was @browserbase's MCP server. It only took 20 seconds to add, and now it can take UI-based actions on any website. Here Claude used it to make a ChatGPT account: 😝

rez0__'s tweet image. I'm improving my co-hacking AI system (built on Claude Code). One of the coolest new things I added to it was @browserbase's MCP server. It only took 20 seconds to add, and now it can take UI-based actions on any website.

Here Claude used it to make a ChatGPT account:
😝

Vinay⚡ gönderiyi yeniden yayınladı

Lavamoat. It was literally built for supply chain attacks. It would've prevented the malicious code from monkey patching globals (`xmlhttprequest`, `fetch`, `window.ethereum`) at runtime. It's free. Tell your favorite dapp dev. npmjs.com/package/@lavam…


Vinay⚡ gönderiyi yeniden yayınladı

treat your code like bonsai, ai makes it grow faster, you have to prune it from time to time to keep its structure and establish the overall design


Vinay⚡ gönderiyi yeniden yayınladı

appsec engineers be like, "surely noone can bypass ssl pinning on iOS, no one can reverse-engineer iOS binaries, no need to ratelimit the mobile API!" lmeow

gf_256's tweet image. appsec engineers be like, "surely noone can bypass ssl pinning on iOS, no one can reverse-engineer iOS binaries, no need to ratelimit the mobile API!" lmeow

Vinay⚡ gönderiyi yeniden yayınladı

WhatsApp 0-day exploited in the wild

h4x0r_dz's tweet image. WhatsApp 0-day exploited in the wild

Vinay⚡ gönderiyi yeniden yayınladı

Prompt engineering feels like doing science experiments, have a variety of inputs their corresponding intended outputs, and come up with a scoring system to evaluate the accuracy, then we slowly work on our prompt to maximize the accuracy score while balancing time + cost.


Vinay⚡ gönderiyi yeniden yayınladı

Novel jailbreak discovered. Not only does OpenAi putting your name in the system prompt impact the way GPT responds, but it also opens the model up to a prompt INSERTION. Not injection. You can insert a trigger into the actual system prompt, which makes it nigh indefensible.

LLMSherpa's tweet image. Novel jailbreak discovered.

Not only does OpenAi putting your name in the system prompt impact the way GPT responds, but it also opens the model up to a prompt INSERTION.

Not injection.

You can insert a trigger into the actual system prompt, which makes it nigh indefensible.
LLMSherpa's tweet image. Novel jailbreak discovered.

Not only does OpenAi putting your name in the system prompt impact the way GPT responds, but it also opens the model up to a prompt INSERTION.

Not injection.

You can insert a trigger into the actual system prompt, which makes it nigh indefensible.

Vinay⚡ gönderiyi yeniden yayınladı

AI agents that can browse the Web and perform tasks on your behalf have incredible potential but also introduce new security risks. We recently found, and disclosed, a concerning flaw in Perplexity's Comet browser that put users' accounts and other sensitive info in danger.

brave's tweet image. AI agents that can browse the Web and perform tasks on your behalf have incredible potential but also introduce new security risks.

We recently found, and disclosed, a concerning flaw in Perplexity's Comet browser that put users' accounts and other sensitive info in danger.

Vinay⚡ gönderiyi yeniden yayınladı

When you make money, the first thing you have to do is "fix your health issues." All other things can wait.


Vinay⚡ gönderiyi yeniden yayınladı

I recently discovered a critical race condition vulnerability at a multi-million dollar investment firm! The vulnerability allowed attackers to execute a single-packet attack that bypassed financial controls, potentially enabling: ✅ Purchasing stocks worth twice the available…


Vinay⚡ gönderiyi yeniden yayınladı

Just published my first blog post "Cache Deception + CSPT: Turning Non Impactful Findings into Account Takeover" You can read the full write-up here: zere.es/posts/cache-de…


Loading...

Something went wrong.


Something went wrong.