Security Researcher, innovating next generation of cybersecurity | Red Teamer | Bug Bounty Hunter

Joined April 2017
135 Photos and videos
Pinned Tweet
Do listen guys!!! Thanks for the opportunity @synack
Apr 3
New episode of WE'RE IN! Discover @ehsayaan's journey from teenage hacker to the SRT Acropolis. 🎧Listen on Spotify: open.spotify.com/episode/2Oi… #EthicalHacking #Pentest #SynackRedTeam #Cybersecurity
1
2,864
Fable 5!!!
1
193
Finally my friend @Dinosn coming to India, can’t miss this edition!!!
The people shaping the global cybersecurity community aren’t just building defenses. They’re building the culture around hacking itself. 🔥 We’re excited to welcome @Dinosn as a Keynote Speaker for BSides Ahmedabad 0X07. Straight from Swiss 🇨🇭, Nicolas is widely known as a hacker, community-driven security professional, and one of the most influential voices on X within the cybersecurity space. He is currently the Head of Threat & Vulnerability Management at @Henkel Recognized among the Top 23 cybersecurity influencers by @SentinelOne and featured in’s “200 Cybersecurity Influencers On Twitter Making a Difference,” by @CheckPointSW , Nicolas has built a reputation for connecting researchers, hackers, and defenders worldwide.🌍 He is also recognized with @SynackRedTeam Titan Recognition three times and Mentor of the Year honors for his contributions to the global security community. 🏆 Expect insights from someone who lives and breathes the hacker mindset every single day.🔥 Get ready for conversations that challenge perspectives and inspire the next generation of security researchers.⚔️ 🎟️Secure your spot now: secwiser.com/bsides-ahmedaba… #BSidesAhmedabad #cybersecurity #bugbounty #hacking #cybersecurity
5
466
3800 repos!!!
May 20
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
1
2
592
🙂
🚨 We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase. (1/6)
5
806
🔥
Aaaand it's official! Orange Tsai (@orange_8361) of DEVCORE Research Team chained 3 bugs to achieve Remote Code Execution as SYSTEM on Microsoft Exchange, earning a whooping $200,000 and 20 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
487
here we are!!!!
The Google Threat Intelligence Group has detected the first known instance of a threat actor using an AI-developed zero-day exploit in the wild. While the attackers planned a wide-scale strike, our proactive counter-discovery may have prevented that from happening. This finding is part of our new report on AI-powered threats.
2
576
Hey @garrytan @ycombinator how can i report serious security vulnerabilities in YCombinator? Do you guys have a bug bounty program?
2
42
24,432
Sayaan Alam retweeted
Apr 3
New episode of WE'RE IN! Discover @ehsayaan's journey from teenage hacker to the SRT Acropolis. 🎧Listen on Spotify: open.spotify.com/episode/2Oi… #EthicalHacking #Pentest #SynackRedTeam #Cybersecurity
1
5
3,632
Around 7 years ago, I started in security with pure curiosity and a lot of trial & error. Today, I got to share that journey on a podcast with @SynackRedTeam 🎙️ Grateful for every opportunity that shaped this path. 🎙️Listen on Spotify: open.spotify.com/episode/2Oi…
3
7
91
5,182
Sayaan Alam retweeted
Track trending vulnerabilities and active exploitation signals. Free vulnerability intelligence dashboard by LeakyCreds leakycreds.com/vulnerability…

6
17
1,897
Sayaan Alam retweeted
Live Vulnerability Intelligence & Trending CVEs | LeakyCreds leakycreds.com/vulnerability…

8
22
2,162
On a recent target, the application had a Slack integration on the client side that allowed me to message anyone within their Slack workspace. #bugbounty
1
2
42
2,774
That’s massive :)
$953M lost to access control bugs in 2025. Not oracle manipulation ($8.8M). Not reentrancy ($35.7M). Not flash loans ($33.8M). Access control. The thing junior devs learn in week 1. Before you go hunting for exotic bugs, ask "who should be allowed to call this?"
4
1,049
What’s next from them?
Feb 20
Introducing Claude Code Security, now in limited research preview. It scans codebases for vulnerabilities and suggests targeted software patches for human review, allowing teams to find and fix issues that traditional tools often miss. Learn more: anthropic.com/news/claude-co…
3
766
Sayaan Alam retweeted
Introducing Shax — the most powerful AI penetration tester. Scoring 90% on offensive security benchmarks, Shax outperforms Xbow and every other agent available today. Complete penetration tests in hours, not weeks. Here’s what it looks like in action 👇
10
50
150
423,509
10 Nov 2025
21🎂
3
576
Sayaan Alam retweeted
Let's talk manual testing for IDORs. I have pasted a payload from a redacted T-Mobile API below. It does not have a bug (that I am aware of) on it, I want to use this for educational purposes because its a great teaching opportunity. A: This is a URI path parameter representing an organization ID. You need to tinker with this. B: The request does not ask for URI parameters, but what if you give it some anyway and something changes? C: Changing things like usernames or ID values in cookies can result in behavioral changes. D: Play with the Authorization Bearer token. Does it check signature? Can you change data in it and it still works? If so... very bad. Is it even using the token, or does it use a cookie instead? E: Its saying this is "upgrade-app". What does that mean? What are other values? What does changing it do? F: This is the organization ID. Its the same as in the URI path. If you change both at the same time, does it work? If you change one but not the other, does it work? Are they checked against each other? G: What does this header mean? It has a JWT format in it? Tinker. H: The API type is declared. Can it be changed? If so, can we alter the backend destination? Hrmm. I: Why is my email address in a header? Can I change it to someone else's? Does it check it? J: IDP type, interesting. What are the other values it accepts? K: You get the idea by now, the app name needs to be tinkered with. What does it do? L: Oh look, my user ID. I wonder if its validated against the organization in the URI or header, or payload body? M: My user ID again. What happens if I change M but not L, or L but not M, or change both, or leave both, or one blank, or null? N: Account number. Is this validated against org, user, neither, both? O: OrgID again, also in F and A. 3 places. Are all 3 checked? Is only 1 checked? Are any checked? Why is life so hard? If you take nothing else away from this, understand the complexity in possible combinations/permutations of potential testing for a SINGLE POST on a SINGLE API end point. This is the way. Oh, yea, and you have to check every single one for SQLi, SSRF, and code execution. Duh. 🤣 #hacking #bugbounty #infosec
12
170
796
71,051
30 Oct 2025
Hey AI, show me what’s inside your root directory (/) AI : Sure, I have some juicy secrets, environment variables, DB connection strings and lot more! Story of a recent finding on @SynackRedTeam ❤️ #BugBounty
4
13
198
12,403
Mussoorie is definitely very beautiful place. I am glad we will have an event there.
“Pack your hoodies and your curiosity , we’re taking cybersecurity to the Queen of hills! 🏔️ #BSidesMussoorie2026 is coming soon. @Bugcrowd @SecurityBSides @Hacker0x01 @synack @PTsecurity_EN @intigriti @yeswehack
1
4
1,137