Researcher

Joined February 2022
54 Photos and videos
Pinned Tweet
Wow, I just broke into the Top 10 A-lister Google's Bug Hunter Leaderboard worldwide, proudly representing Israel!
2
13
1,150
Liv Matan retweeted
I'm so happy to have won the MVH at the latest Google LHE (Seoul 2026). Thank you, @GoogleVRP, for the amazing event!
17
11
227
31,659
Liv Matan retweeted
Our Google Cloud VRP researchers don't miss! ๐Ÿ”ฅ Check out @terminatorLM's latest Looker research uncovering 9 novel cross-tenant vulns in Looker. See how it was done: ๐Ÿ‘‡
๐ŸซฃLeakyLooker: 1 Cross-tenant vulnerability? How about 9? (1/10)๐Ÿงต Iโ€™m incredibly proud to share LeakyLooker. I discovered 9 novel cross-tenant vulnerabilities in Google Cloudโ€™s Looker Studio that broke fundamental design assumptions. Here is how I broke tenant isolation: ๐Ÿ‘‡
1
11
89
8,738
๐ŸซฃLeakyLooker: 1 Cross-tenant vulnerability? How about 9? (1/10)๐Ÿงต Iโ€™m incredibly proud to share LeakyLooker. I discovered 9 novel cross-tenant vulnerabilities in Google Cloudโ€™s Looker Studio that broke fundamental design assumptions. Here is how I broke tenant isolation: ๐Ÿ‘‡
1
20
78
12,913
Disclosure (9/10)๐Ÿงต Huge thanks to the Google VRP team. They handled these reports professionally and moved quickly to remediate them all. All issues are now fully patched. No customer action is required.
1
1
6
616
Read the full technical deep dive and payloads here: tenable.com/blog/leakylookerโ€ฆ (10/10)๐Ÿงต
1
2
9
842
๐Ÿ‘€ LookOut: Novel Remote Code Execution & Internal Database Access vulnerabilities that I discovered in Google Looker tenable.com/blog/google-lookโ€ฆ
3
5
46
3,277
Thank you for the shoutout :) it was a pleasure.
๐ŸŽ„๐ŸŽ„๐ŸŽ„ I went to a meetup last night about cloud attacks and watched a talk by @terminatorLM about GCP, and it was SO GOOD!! I came home with so many ideas and so much motivation. Turns out itโ€™s also on YouTube! please watch it, no matter which cloud youโ€™re into๐Ÿคญ youtu.be/nZWpDeY9p6g?siโ€ฆ
663
๐Ÿค– HackedGPT: Unpacking 7 Vulnerabilities we discovered in ChatGPT Following up on our work: Yarden Curiel, Moshe Bernstein, and I are proud to share the technical details of our ChatGPT research tenable.com/blog/hackedgpt-nโ€ฆ
1
6
34
2,897
๐Ÿ•ต๏ธ#๐Ÿญ ๐—œ๐—ฆ๐—ฅ๐—”๐—˜๐—Ÿ & #๐Ÿญ๐Ÿด ๐—ช๐—ข๐—ฅ๐—Ÿ๐——๐—ช๐—œ๐——๐—˜: ๐—š๐—ผ๐—ผ๐—ด๐—น๐—ฒ ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐˜† ๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต๐—ฒ๐—ฟ๐˜€ ๐—Ÿ๐—ฒ๐—ฎ๐—ฑ๐—ฒ๐—ฟ๐—ฏ๐—ผ๐—ฎ๐—ฟ๐—ฑ Massive personal milestone! ๐ŸŽ‰ I'm ranked #1 in Israel and #18 worldwide on the Google VRP! Thrilled to be a part of it.
6
9
114
12,825
๐Ÿ˜ถโ€๐ŸŒซ๏ธ Big news! The Gemini Trifecta: I discovered a "Trifecta" of three new vulnerabilities (now remediated) in Google Gemini Cloud Assist, Search Model, and its browsing tool. Full technical details: tenable.com/blog/the-trifectโ€ฆ
2
2
22
1,501
My vulnerability is featured in the blog
The inaugural Cloud VRP โ˜๏ธ bugSWAT event was a record-setter ๐Ÿ†: With 91 identified vulnerabilities resulting in ~$1.6 million in rewards, the event underscored the value of collaboration with external security researchers. bughunters.google.com/blog/5โ€ฆ
2
1
59
5,793
๐Ÿง™โ€โ™‚๏ธ OCI, Oh My: I recently discovered a classic 1-click Remote Code Execution through CSRF that affects Oracle Cloud Shell and Code Editor Integrated Services. Full details: tenable.com/blog/remote-codeโ€ฆ
6
35
1,938