Jeya Seelan @rootxjs
24y/o | Ethical Hacker 🇮🇳 | Security Engineer rootxjs.github.io Bangalore Joined August 2014-
Tweets713
-
Followers264
-
Following2K
-
Likes2K
Not everyone who reports to Google Cloud VRP does a writeup, but critical bugs still show up in CVEs and release notes Made a tool that aggregates both so you can see the types of bugs getting found in GCP gcp-cves.brutecat.com
StubZero: $148,337 RCE in Google Cloud Production brutecat.com/articles/googl…
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
Security things from the last few days: - CopyFail (linux pwn'd) - CopyFail 2/Dirty Frag - 13 advisories in Next.js - Over 70 CVEs addressed in MacOS 26.5 - ~50 CVEs addressed in iOS 26.5 - YellowKey (Windows Bitlocker pwn'd entirely) - GreenPlasma (Windows privilege escalation) - CVE-2026-21510 and CVE-2026-21513 confirmed to be used by Russia for Windows RCE - CVE-2026-32202 separately confirmed to be used by Russia for sensitive document access - Mini-Shai Hulud (over 300 JS and Python packages compromised via GitHub Action cache poisoning) - Google confirms they have identified AI-powered exploitation of zero days in an unidentified "open-source, web-based system administration too" - Canvas (popular LMS used in most schools) pwn'd entirely - PAN-OS (palo alto networks) pwn'd with a 9.3 severity CVE-2026-0300 Are you scared yet?
‼️🚨 UPDATE: The TanStack npm attack is now a full campaign. 'Mini' Shai-Hulud has hit: - OpenSearch - Mistral AI - Guardrails AI -UiPath - Squawk packages across npm and PyPI The malware specifically targets AI developer tooling. It hooks into Claude Code (.claude/settings.json) and VS Code (.vscode/tasks.json) to re-execute on every tool event, long after the infected package is gone. npm uninstall does not fix this.
‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you. The compromise happened today, across 42 official tanstack npm packages,
🚨SECURITY ALERT: Ongoing supply chain attack - “Shai-Hulud: Here We Go Again” We are continuing to track the latest attack in the “Shai-Hulud: Here We Go Again” campaign - Up until now 406 package versions were detected as compromised, including npm scopes @tanstack, @squawk, @uipath, and spreading to PyPI packages mistralai and guardrails-ai. JFrog Curation customers using an Immaturity policy were fully protected from this attack, as all of the hijacked packages were flagged in less than 24 hours. See our blog for a full analysis of this attack, including an ongoing list of compromised packages (link shared soon in this thread).
A few months ago, I found a Prompt Injection vulnerability on Google Tasks. It was simple, yet tricky. Google rewarded me with a $15,000 bounty for it. Here's the full story:
Open-source local AWS emulator with real databases github.com/ministackorg/m…
I achieved a cross-tenant #RCE in #GoogleCloud simply by abusing predictable bucket names. 🪣 In my latest research for @FocalSecurity, I look into "Bucket Squatting" - a cross-tenant attack that landed me 3 critical vulnerabilities in GCP. Here is how it works:
🚨 BREAKING: Wiz Research discovered Remote Code Execution on GitHub.com with a single git push The flaw in @github allowed unauthorized access to millions of repositories belonging to other users and organizations 🤯
Why is no one talking about this? @nvidia is offering around 80 AI models via hosted APIs absolutely for free. You get access to MiniMax M2.7, GLM 5.1, Kimi 2.5, DeepSeek 3.2, GPT-OSS-120B, Sarvam-M etc. This plugs straight into OpenClaude, OpenCode, Zed IDE, Hermes agent and even with Cursor IDE. Setup: – Grab API key: build.nvidia.com/models – base_url = "integrate.api.nvidia.com/v1" – api_key = "$NVIDIA_API_KEY" – select model (e.g. minimaxai/minimax-m2.7) If you’re building or experimenting, this is basically free inference. Lock in and start building today anon. Thank me later.
@DrVaishnavi14 @ICCCBengaluru @blrcitytraffic @TOIBengaluru @peakbengaluru @MALimbavali I’m sorry about that! I'll make sure use official channels.
#marathahalli #spacetechnology #Bengaluru Latest visuals from munnekolala, marathahalli Another vehicle stuck due to the poor roads. Around 2 months the roads are like this and no action is taken till now. @ICCCBengaluru @EASTCITYCORP @blrcitytraffic @TOIBengaluru @peakbengaluru
A traffic deadlock at munnekolala near asha tiffins, because of some incompetent officials from @chairmanbwssb , fust they dugged whole area 1 month ago, and then they dumped pipes on the road for last 2 weeks with no work going on. @blrcitytraffic wake up! Wake up!
@ICCCBengaluru @blrcitytraffic @TOIBengaluru @peakbengaluru @MALimbavali (Manjula Aravind Limbavali), MLA the condition in Munnekolala Mahadevapura is unacceptable. Basic issues have been ignored for months. Please take immediate action.
@BECCUPDATES @bwssbchairman @bbmpcommr @BBMPSWMSplComm @BbmpEast @GBA_office @MALimbavali (Manjula Aravind Limbavali), MLA the condition in Munnekolala Mahadevapura is unacceptable. Basic issues have been ignored for months. Please take immediate action.
@BECCUPDATES Only areas that have good roads are being re layed. Very Near to this our Munekolala Sai Baba Temple 2 kms stretch road is torn apart by @bwssbchairman 4 Months ago. Still no fixes. @BECCUPDATES @bbmpcommr @BBMPSWMSplComm @BbmpEast @GBA_office
@BECCUPDATES @bwssbchairman @bbmpcommr @BBMPSWMSplComm @BbmpEast @GBA_office @ChristinMP_ @osd_cmkarnataka @DeccanHerald @BangaloreMirror @BPACofficial @BECCUPDATES @BangaloreTimes1 @peakbengaluru @blrcitytraffic Kindly bring this to attention of higher officer in Bangalore East City Corporation - Location Munnekolala , Marathahalli
Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly. A Vercel employee got compromised via the breach of an AI platform customer called Context.ai that he was using. The details are being fully investigated. Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments. Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration. We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel. At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community. The recommendation for all Vercel customers is to follow the Security Bulletin closely (vercel.com/kb/bulletin/ve…). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature. In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback. We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance. It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.
Intigriti @intigriti
209K Followers 666 Following Bug bounty & VDP platform trusted by the world’s largest organisations! 🌍
Gokul A.P @gokulapap
2K Followers 258 Following DevSecOps Engineer | Web & Cloud Security Automating security with Python Breaking misconfigs before attackers can
0xGodson @0xGodson_
2K Followers 955 Following Christ is King 👑 | I like web security, and I love JavaScript | OSWE.
Aasif Ibrahim @thisis_asf
581 Followers 196 Following திரைக்காதல் | Writer-Director | Direction Team - #STR51 | Author | Social Media Strategist | Enquiries: [email protected]
Vvek ~ @VivekGhinaiya
107 Followers 782 Following Life is short , H4ck it :) https://t.co/NKjZrCQz0r
Tharani Dharan @tharanijpt
8 Followers 250 Following Inside the cocoon, learning to become an engineer
winson @winson22652
1 Followers 74 Following
Mohan Raj @Mohan_Mohe
22 Followers 300 Following
Abishua Blessmic @abishuablessmic
983 Followers 2K Following Product Manager 🏄🏽♂️ | Shipping Sh*t hot products while brewing coffee ☕️ | Building 🛝 https://t.co/bUrTIj5RK1 $257/m 🍱 https://t.co/5egqupH0f7 $0K/m
Ak Ak @AkAk145346
26 Followers 735 Following
Itachi Uchiha @SunilPrashanth4
35 Followers 226 Following Automation Tester | Ethical Hacker | Bug Bounty Hunter | CTF Player Eat | Sleep | Hack | Repeat Kono Te Boku Wa💚✨
🄲🅈🄱🄴🅁 ... @Cyber_Asia_
4K Followers 500 Following Follow us for the latest #cybersecurity news in Asia.
Qanon @qanonfree
0 Followers 5K Following
Dharmaraj @Dharmaraj149431
0 Followers 54 Following
Foxy_Proxy @harry_creation
146 Followers 436 Following Aspiring Cyber Security Researcher👤 | Security Engineer @RenaultGroup
Deepak @Deepa_k01
6 Followers 51 Following
Madhubala Anantharaj @MadhuAnantharaj
1K Followers 5K Following Product Manager @Zoho, Team - @ZohoSocial Building meaningful products Be happy and make others happy 🌼
Jason Harris @harrisja
3K Followers 3K Following Social and advocacy focused marketer. Writer and community manager into making new connections and learning new tech.
dvsj @dvsj_in
109 Followers 313 Following Flipping interesting bits into the void (and building stuff for @Zoho!)
ABHIJITH PK @ag3n7apk
443 Followers 569 Following Security Enthusiast | CTF Player | Bug Bounty Hunter | Member @in1tcr3w
Athesh Pargau R @athesh_pargau7
66 Followers 991 Following Human | CyberSec & Blockchain Nerd | Web3 & Crypto🚀 | Subscribe to my newsletter here! 👇
Sriram @sriramnk2000
22 Followers 211 Following
Naveen Prakaasham @NPrakaasham
242 Followers 503 Following
Archutha Santhiya @archutha83636
10 Followers 419 Following
Palani @impalanichamy
78 Followers 513 Following
MonsterChiru @MonsterChiru
3 Followers 107 Following
ASD @XplorerTech00
5 Followers 238 Following Designing interpretable AI-augmented cybersecurity architectures that assist humans, improve defensive operations, and maintain transparency, trust, and control
Roshith Karthik @roshith42
3 Followers 61 Following
Dinesh Kumar B @DineshK01496870
30 Followers 1K Following
Vulnlab @vulnlab_eu
6K Followers 1K Following Labs & Training by @xct_de | You are welcome to join the community @ https://t.co/p5R9zGJYHw Vulnlab is now part of Hack The Box.
D!nesh @Dineshkumar__S
14 Followers 385 Following
PentesterLab @PentesterLab
204K Followers 0 Following We make learning web hacking and security easier. Online systems, code review, videos & courses that can be used to understand, test and exploit bugs!
Intigriti @intigriti
209K Followers 666 Following Bug bounty & VDP platform trusted by the world’s largest organisations! 🌍
Ben Sadeghipour @NahamSec
247K Followers 1K Following Cofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
bugcrowd @Bugcrowd
199K Followers 6K Following The leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™
The XSS Rat - Proud X... @theXSSrat
165K Followers 1K Following Bug bounty profiles: https://t.co/3Uz5K130ah https://t.co/rzbqV5AmZ2 https://t.co/CDlzXdNvPB
John Hammond @_JohnHammond
320K Followers 3K Following Cybersecurity Researcher @HuntressLabs Just Hacking Training @JustHackingHQ w/ @ethicalhacker https://t.co/UtsNJiyiEk && https://t.co/narO3syzIy
Hack The Box @hackthebox_eu
246K Followers 228 Following Cyber Mastery: Community Inspired. Enterprise Trusted.
TryHackMe @tryhackme
305K Followers 83 Following An online platform that makes it easy to break into and upskill in cyber security, all through your browser.
InfoSec Community @InfoSecComm
55K Followers 635 Following Largest InfoSec publication with 80,000+ followers and 3M+ monthly views.
meg west @cybersecmeg
155K Followers 927 Following Tweets about #dogs & travel & fitness & cybersecurity, oh my! Opinions are my own. 📧: [email protected]
Dr. Maik Ro ➡️�... @maikroservice
18K Followers 703 Following ☠️ inactive account ☠️ - Training the next generation of Hackers over at bsky / linkedin / youtube 🏴☠️💜
Gokul A.P @gokulapap
2K Followers 258 Following DevSecOps Engineer | Web & Cloud Security Automating security with Python Breaking misconfigs before attackers can
Hacking Articles @hackinarticles
297K Followers 478 Following House of Pentesters Join us: https://t.co/Y6XOlSOA92
Youssef Sammouda (sam... @samm0uda
41K Followers 590 Following Security Researcher/Hacker 1st in Meta bug bounty program for 6 years Opinions are my own and not my employer's.
🇷🇴 cristi @CristiVlad25
55K Followers 593 Following
zseano @zseano
81K Followers 712 Following Amazon Hacker. back to development - working on relaunching https://t.co/O9jS78CnSn - SOON! :)
publiclyDisclosed @disclosedh1
68K Followers 2 Following This is an unofficial HackerOne public disclosure watcher who keeps you up to date about the recently disclosed bugs. By @NOBBD
LiveOverflow 🔴 @LiveOverflow
160K Followers 1K Following wannabe hacker... he/him 🌱 grow your hacking skills @hextreeio
STÖK ✌️ @stokfredrik
138K Followers 1K Following Hi.. im that hacker / creative that your friends told you about.,
skull @brutecat
7K Followers 372 Following hacker, security researcher. 21. i run a blog @ https://t.co/cBW6gzTpV2
Behi @Behi_Sec
6K Followers 78 Following Bug Hunter & Tool Builder. Racing to $1M in 2026 - tracking every dollar. 🐞 Bug Bounty: $53,760 💻 https://t.co/0Kfb8glzBs: $306
Akshat Kejriwal @AkshatKejriwal
697 Followers 126 Following Founder, CodeFiber Building https://t.co/fzNRrHuWmz - fastest way to compare grocery prices, food delivery and cab fares in one app
OmerAF @omer_asfu
667 Followers 27 Following Cloud Security Researcher | Founder @FocalSecurity | Hunting Cross-Tenant Vulnerabilities in Google Cloud
Gems of Bangalore @Gems_of_blr
330 Followers 12 Following Exposing trues gems in and around Bangalore, a city being ruined due to apathy of administration, City of garden turned into city of garbage.
azu @azu_re
23K Followers 757 Following JavaScriptな人です。セキュリティネタも好きです。 https://t.co/NsD2KXWFYr というサイトもやっています。 textlint作ってます。 https://t.co/TqRqRbYOnd https://t.co/FhFZSdyneG https://t.co/uMItLK7Gg7
Manjula Aravind Limba... @MALimbavali
6K Followers 8 Following MLA, Mahadevapura Assembly Constituency.
Dr. Vaishnavi @DrVaishnavi14
9K Followers 5 Following Doc|Bharatnatyam,Mohiniattam,Kathak, Odissi,Kuchipudi|Music|Sketch|Kalaripayattu|Civil Servant,Officer on Special Duty to CM K'taka @osd_cmkarnataka|Personal|
CM of Karnataka @CMofKarnataka
1.6M Followers 175 Following Official Page of the Chief Minister's Office, Karnataka
Common Man (ಸಾಮ... @commonman_KA
68 Followers 141 Following ನಿವೃತ್ತ ಜೀವನ. ಹಿರಿಯ ನಾಗರಿಕ. ಕರ್ನಾಟಕದಲ್ಲಿ ಕನ್ನಡವೇ ಸಾರ್ವಭೌಮ. ಸಮಾಜದ ಉನ್ನತಿಗಾಗಿ ,ಕೆರೆ ಮತ್ತು ರಾಜಕಾಲುವೆ ಒತ್ತುವರೆಗಳ ಬಗ್ಗೆ ಹೋರಾಟ..ಪರಿಸರ ಪ್ರೇಮಿ. .#SaveLakes
ಸಮಾಜ ಕಲ�... @SWDGoK
27K Followers 397 Following ಸಮಾಜ ಕಲ್ಯಾಣ ಇಲಾಖೆ, ಕರ್ನಾಟಕ ಸರ್ಕಾರ. Official handle of the Social Welfare Department, GoK | Call us at: 9482300400.
DC, Vijayanagara @dcvijayanagara
2K Followers 28 Following Official Twitter Account of District Administration,Vijayanagara District,Karnataka,India
Office of the OSD to ... @osd_cmkarnataka
14K Followers 2 Following Dr Vaishnavi K | Civil Servant,Officer on Special Duty to Hon’ble CM K'taka | Public Grievances | 241, Vidhan Soudha | [email protected] |
Bangalore Mirror @BangaloreMirror
230K Followers 134 Following When too much makes too little sense, we get to the heart of the matter
Deccan Herald @DeccanHerald
123K Followers 112 Following Bengaluru & Karnataka's leading news daily for over 75 years. Authentic, definitive, and fresh: like your morning filter coffee. Got a story? Tweet or DM us.
ChristinMathewPhilip @ChristinMP_
25K Followers 2K Following Journalist at https://t.co/hOxGGL5eSK . Ramnath Goenka awardee. Ex: TOI, TNIE. Views my own.
Socket @SocketSecurity
21K Followers 5K Following Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. 👀 @npm_malware
B.PAC - Bangalore Pol... @BPACofficial
18K Followers 186 Following A citizen’s collective that aims to build a #BetterBengaluru. Civic Leadership|Participatory Democracy|Women Empowerment/Safety|Sustainability|Advocacy|Mobility
Arsh Goyal @arsh_goyal
41K Followers 2K Following software , tech , ai education | ai @samsung | Startups | Ex-ISRO | Educator | 700K+ YT & IG | Reachout on mail : [email protected]
MV Karan @mvkaran
3K Followers 360 Following Director, International DevRel @github. Developer. Speaker. Avid book reader. Tweets about tech, life, books & dev jokes. Opinions are personal.
CardMaven @CardMavenIn
32K Followers 110 Following Helping you pick the right Credit Card in India 🇮🇳 | Maximizing Rewards, Miles & Cashback ✈️💰 | Honest Reviews & Best Deals. 👇 | DM for Collabs 🤝
Designinfo.in @designinfo_in
84 Followers 785 Following Source of Colors, Trends, Fashion Forecast, Digital Prints, Designs, Styling, Pantone & RAL Shades, Books & DVD, Graphics, Logos, Textures, for Men, Women, Kids
SecÑinja⚔️ @appexploit
120 Followers 588 Following Security Engineer - (breaking and building app security) 👨💻 | Thoughts are my own.
ಬೆಂಗಳೂರ... @blrcitytraffic
673K Followers 100 Following Promoting Traffic Awareness & Road Safety 🚦🛣 | Your Partners in Traffic Management 🚓💼 | #BengaluruTrafficPolice 🌆🚗
Peak Bengaluru @peakbengaluru
125K Followers 64 Following Startup, tech & hipster bangers from the hottest & fastest growing startup city in the world
Bengaluru East City C... @BECCUPDATES
2K Followers 23 Following Official account of the Bengaluru East City Corporation & maintained by the Public Relations Department.
AmirMohammad Safari @AmirMSafari
8K Followers 409 Following Part-time bug hunter, full-time thinker of thoughts nobody asked for
winfunc @winfunction
2K Followers 1 Following autonomous AI security agents that audit your codebase, prove exploitable vulnerabilities, and deliver fixes your team can ship.
redBus @redBus_in
21K Followers 288 Following redBus is the world’s largest online bus ticketing platform. It has sold 180 mn tickets till date and has a global customer base of 20 million. Bus yani redBus!
Abishua Blessmic @abishuablessmic
983 Followers 2K Following Product Manager 🏄🏽♂️ | Shipping Sh*t hot products while brewing coffee ☕️ | Building 🛝 https://t.co/bUrTIj5RK1 $257/m 🍱 https://t.co/5egqupH0f7 $0K/m
Greater Bengaluru Aut... @GBA_office
94K Followers 37 Following Page maintained by GBA Public Relations Dept Dial 1533 to report civic issues and tag issues @ICCCBengaluru
Parimal Ade @AdeParimal
290K Followers 18 Following Founder - https://t.co/4bmnyU28uQ | Financial Literacy
Sandro Gauci @sandrogauci
4K Followers 2K Following Offensive VoIP/WebRTC security; mostly harmless Writes at https://t.co/15yJ08eLrd Chief Mischief Officer @enablesecurity
Alex Birsan @alxbrsn
12K Followers 566 Following Views and opinions expressed here solely belong to my employer and are absolutely not my own.
Matthew Prince 🌥 @eastdakota
213K Followers 300 Following A little bit geek, wonk, and nerd. Repeat entrepreneur, recovering lawyer, and former ski instructor. Co-founder & CEO of Cloudflare (NYSE: NET).
Critical Thinking - B... @ctbbpodcast
26K Followers 86 Following A 'by Hackers for Hackers' podcast focused on technical bug bounty content. Exploits, techniques, stories, bounties. Hosts: @rhynorater, @rez0__, @gr3pme
gr3pme @gr3pme
3K Followers 652 Following Cohost @ctbbpodcast || Bug Bounty Hunter || hacker - OSWE, OSCP








































