hehe

Joined June 2019
5 Photos and videos
ungraduate engineer retweeted
Replying to @S1r1u5_
Really hope more people get to try Hacktron. You guys are doing great so far and I love the open source initiative
1
2
6
3,015
ungraduate engineer retweeted
So @Doyensec recently published a report comparing @xbow and @AikidoSecurity, two AI pentest platforms. I figured, why not run @HacktronAI on the same test? So I ran a pentest on one of the target. Hacktron cost $350, while XBOW and Aikido cost $4,000 each. We did pretty well!
8
20
236
15,024
ungraduate engineer retweeted
oh interesting! i am not aware of this. we're leading the leaderboard for most critical and weaponizable vulnerabilities, ahead of Anthropic and XBOW haha.
Replying to @corban_villa
Who's finding what? @AnthropicAI owns critical count. @HacktronAI leads on severity exploitability. AISLE covers the most CWE types. There’s no clear overall winner.
2
2
111
10,488
ungraduate engineer retweeted
Who's finding what? @AnthropicAI owns critical count. @HacktronAI leads on severity exploitability. AISLE covers the most CWE types. There’s no clear overall winner.
1
4
23
12,880
ungraduate engineer retweeted
Hacktron Review plugs into your pull requests and catches exploitable vulnerabilities other scanners walk straight past. Find real security issues within 24 hours of onboarding. Try it free → hacktron.ai
3
10
1,050
ungraduate engineer retweeted
When Your VPN Opens Your Private Network to the Public! An auth bypass in Palo Alto PAN-OS CAS Auth (CVE-2026-0265) that lets an attacker connect to the company's GlobalProtect VPN. Blog - hacktron.ai/blog/cve-2026-02…
4
75
260
118,329
ungraduate engineer retweeted
Check out our security work on Next.js. We’re also offering free security scans for open source projects. Apply here: hacktron.ai/blog/hacktron-re…
Last week's Next.js stable release patches multiple vulnerabilities found by @HacktronAI CVE-2026-44578: SSRF via WebSocket upgrade. It is the most impactful of all, it lets an attacker read internal hosts such as cloud metadata endpoints on self-hosted next.js applications. curl -H "Connection: Upgrade" -H "Upgrade: websocket" \ -H "Sec-WebSocket-Version: 13" \ -H "Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ==" \ "http://target:3000" \ --request-target "http://169.254.169.254/latest/meta-data/"
3
13
2,446
ungraduate engineer retweeted
Last week's Next.js stable release patches multiple vulnerabilities found by @HacktronAI CVE-2026-44578: SSRF via WebSocket upgrade. It is the most impactful of all, it lets an attacker read internal hosts such as cloud metadata endpoints on self-hosted next.js applications. curl -H "Connection: Upgrade" -H "Upgrade: websocket" \ -H "Sec-WebSocket-Version: 13" \ -H "Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ==" \ "http://target:3000" \ --request-target "http://169.254.169.254/latest/meta-data/"
6
33
184
17,003
ungraduate engineer retweeted
This is a critical auth bypass (affecting GlobalProtect VPN), not sure why this was marked as high. I have already managed to get VPN access to major corps! Unlike the buffer overflow this isn't limited to PAN OS. Will be disclosing full details later next week on @HacktronAI blog. security.paloaltonetworks.co…
7
30
208
20,443
ungraduate engineer retweeted
Hacktron ā¤ļø Open Source TL;DR: If you maintain an open source project, we want to give you Hacktron Review for free. Because giving maintainers the same capabilities as attackers would otherwise use against them felt like the right thing to do. hacktron.ai/blog/hacktron-re…
10
27
3,150
ungraduate engineer retweeted
Next.js v16.2.5 fixes a bunch of vulnerabilities reported by @HacktronAI. Patch ASAP, especially if you’re running self-hosted Next.js that SSRF might affect you CVE-2026-44574: Middleware / Proxy bypass via dynamic route parameter injection CVE-2026-44578: SSRF in applications using WebSocket upgrades CVE-2026-44581: XSS in App Router applications using CSP nonces
17
141
12,531
ungraduate engineer retweeted
How tech bros be seeing their move to sf
1
1
11
1,438
ungraduate engineer retweeted
when react2shell hit last year, i think vercel handled it brilliantly. to protect their users, they paid $50,000 for every bypass researchers could find. we decided to participate, and ended up earning $170,000. read how we did it here: hacktron.ai/blog/react2shell…
5
69
383
19,760
ungraduate engineer retweeted
"Mohan Pedhapati (@S1r1u5_), CTO of Hacktron, described how he used Opus 4.6 to create a full exploit chain targeting the V8 JavaScript engine in Chrome 138, which is bundled into current versions of Discord." theregister.com/2026/04/17/c…
5
20
1,808
ungraduate engineer retweeted
Mythos showed that frontier models can find complex vulnerabilities with a skilled operator in the loop. But for applications that don't have the complexity of a JIT compiler, we found that smaller models run repeatedly can outperform larger frontier models on cost-to-recall. hacktron.ai/blog/why-mythos-…
3
12
54
7,232
ungraduate engineer retweeted
Introducing Hacktron Review: an AI security reviewer for your pull requests. It understands your whole codebase, builds a threat model, takes your feedback, and catches exploitable vulnerabilities before they reach production. Try for free: app.hacktron.ai
20
39
210
45,886
ungraduate engineer retweeted
We won 2nd place at Vercel's AI Accelerator Demo Day and I've been told on very short notice that today is Vercel Day on Product Hunt and to do a launch on it. So here it is. We would love to have your support: producthunt.com/products/hac…
4
8
61
9,342
ungraduate engineer retweeted
The exploit for CVE-2026-1731 is out. The APT of CVE-2026-1281 missed a major target šŸ˜…. Props to watchTowr for the blog on it. The moment I read it, my instinct said there had to be a variant in remote support, given how heavily it relies on bash scripts. @HacktronAI did the rest. Literally gave me PoC in hand. (Vibe hacking?) What surprised me was that I didn’t know this bash quirk earlier, even though I’d already run into a similar quirk in another language. Consider this a reminder: read the blogs. Always.
We just published our @rapid7 analysis of CVE-2026-1731, a critical command injection affecting BeyondTrust Privileged Remote Access (PRA) & Remote Support (RS). Unauthenticated RCE, with a root cause due to Bash arithmetic evaluation. Analysis/PoC here: attackerkb.com/topics/jNMBcc…
1
13
96
15,021