Himanshu J @jhimansh
Strategy | Security. Recognized and awarded under responsible disclosure program by Microsoft, Google, Red Hat, Zoom and many more in the past. Pune, India Joined May 2015-
Tweets305
-
Followers116
-
Following355
-
Likes3K
Need to extract API endpoints and the request body schema of each endpoint after supplying a web URL as input. Exploring Puppeteer and Cheerio library, but facing accuracy issues affecting data quality. Which library should I use? Suggestions? #appsec #opensource #NodeJS #API
What happens to AppSec when moving to an API environment? One of the things that I observed when trying to understand the difference between doing application security and API security, is that we're often pushing business logic out to the client. This…lnkd.in/d3-FFK7F
Agentless vs. agent AppSec for SaaS startups Let me start by saying - I know. I know the sound of the word agent probably gives you the shivers. Hear me out. Agents have gotten a really bad reputation in the past years, and in most cases rightfully so…lnkd.in/dQbG6Bt6
Thrilled to get an invite to celebrate with Microsoft MSRC's most valuable security researchers and Microsoft employees in Las Vegas next month. #SecurityResearch #infosec #responsibledisclosure #bugbounty #MSRC
If your repeater tab is not like this then you are doing something wrong x) #Burpsuite #Bugbounty
just because an exploit payload looks simple doesn’t mean it didn’t take a bajillion hours of source code auditing to find
A thread all about CSRF Tips Pro tip : Bookmark and Retweet this Tweet!
Another security report triaged, accepted and resolved. Program: Private. Severity: Medium. #cybersecurity #responsibledisclosure #hacktosecure #informationsecurity
Thank you @GoogleVRP for the book! Looking forward to reading this one soon. #InformationSecurity #Bugbounty #hacktosecure
Happy birthday @stokfredrik!🎉 Thank you for the amazing work that you do! Wishing you a wonderful year of good health, happiness and success! Hoping to see many more Bounty Thursdays in the future. Cheers!
Be humble. Be teachable. The universe is bigger than your view of the universe. There's always room for a new idea. Humility is necessary for growth. 🧠
One of the very first few reports that I submitted to Rockset on Hackerone just got disclosed. A non-admin user could access a page meant to be accessed only by the user with admin privileges. Severity: Medium(4.3) hackerone.com/reports/946384 #informationsecurity #infosec
Rockset disclosed a bug submitted by @jhimansh: hackerone.com/reports/946384 #hackerone #bugbounty
A submission got accepted as a valid issue by Asana on Bugcrowd. Vulnerability falls under broken access control to information disclosure. Severity: P4 #hacktosecure #responsibledisclosure #bugbounty #infosec #CyberSec #informationsecurity
“Hacking cannot be taught. Hacking can only be learned.” (based on a quote from Mikhail Botvinnik about Chess)
I’ve been doing a lot of offensive security source code auditing of enterprise apps over the last six months and every time I show my friends critical pre-auth PoCs they usually respond with “wow i can’t believe no else found that” - the magic is uncovering this attack surface
There are little to no good courses or books that go beyond beginner level. And training is very expensive. How do you keep up as an intermediate/advanced then? One answer: by reading boring documentation and figuring out new techniques yourself.
🚨ONGOING: we are investigating systems infected with a malicious version of the npm package UAParser.js (7 million weekly downloads). The hijacked package delivers a malware loader and a cryptominer. IOCs below:

QI Jin @g0cns2023
5 Followers 397 Following
g0cns13337 @NYang50663
25 Followers 846 Following
distrozeroday @distro_0day
314 Followers 1K Following #Cyber security , #fitness , #martial arts .#OSINT .originally I was a jeweler . went to school for jewelry design. #SIGINT.#psychology
Viktor Hedberg 🛡�... @headburgh
1K Followers 616 Following I do security stuff @Truesec • MVP • Father • My tweets are my own • He/him
Anil Kumar Gadari @gadarianil
137 Followers 2K Following Cyber Security Researcher, Bug hunter,Youtuber & Ethical Hacker
Md Ismail Šojal �... @0x0SojalSec
31K Followers 5K Following Cyber_Security_Re-searcher || 0SINT || Malware Analysis II Pwn || Ai Re-searcher || Project @AIStrikeSec || 0ld Accounts Suspended @0xSojalSec ||
AkashTH @AkashTH5
250 Followers 5K Following Top 300 security researcher at bugcrowd | HOF in over 50+ companies | Sometimes try to dance ;)
kirti soni @Kirti070Soni
64 Followers 969 Following
BubuBangles @Bububangles
412 Followers 748 Following Be kind 😊 I am a Veteran. I work in IT Security and I stream on Twitch! Come Hang out with me! Call me Dad. #WomenInTech #infosec #twitchaffiliate #veteran
mr bright @mohammadd113
82 Followers 2K Following
403 @sudoroot001
49 Followers 738 Following Web application testing beginner💚 curious to learn new things💚 Experiment, Fail, Learn and Repeat. 💚
techObserver @tech0x
0 Followers 60 Following I observe and learn from people working and solving the tech
Truesec @Truesec
8K Followers 380 Following This account is monitored but not active. For updates, follow us on https://t.co/q2eXHkQgrm or Linkedin.
pho3nixx @pho3nixx2
98 Followers 3K Following
Jubayer Ahmed Rhyme @Jub4y3r_3x009
240 Followers 3K Following مهاجم آسيوي عشاق الأمن السيبراني | _-_ | المتعلم | باغ باونتي هنتر Web Application Security Researchers At Hackerone & Bugcrowd
notsoparry @ShubhamPargaon1
2 Followers 41 Following
pritam priyadarshani ... @pritamp1995
1 Followers 108 Following
BASITH ILLYAS @BasithIllyas
2K Followers 5K Following
Chirag 0x22 🇮🇳 @ChiragSoni404
710 Followers 5K Following The tweets may pretend that I have knowledge but I don't know anything. We Are All NOOB's. 🇮🇳
0xhari Bhai @i_TheLastPerson
15 Followers 216 Following Cyber security enthusiast | avid learner | learning new things daily | Bug Bounties ♥️
coke @sokolicav
795 Followers 1K Following Ethically Hacked @Google @Verizon @AmericanExpress @Microsoft @BMW @RedHat @Dominos @Kaspersky @Avast
Ambrewal Wulla @ambrewal
170 Followers 2K Following CS Student, Security Researcher, Full time Bug Hunter, Ethical Hacker, Python Programmer
Hari Kishore @Hari_Kishore_hk
132 Followers 1K Following Bug Bounty Hunter | Cyber security enthusiast | CSE Student
Ajinkya Kunjir @ajinkyakunjir19
58 Followers 180 Following
Meow's Joy @meowsjoy
5K Followers 3K Following Cat lover extraordinaire! Living for purrs, paws, and whisker kisses. Sharing feline adventures and wisdom, one meow at a time. #meowsjoy
Hac @Hac10101
5K Followers 832 Following 🇮🇳 Hacker| CTF With Team:- @5h4d0wbr0k3r5 | Views are my own and do not represent those of my employers.
Alexandre @itsmegroxo
33 Followers 730 Following
h4ck3r @numoniam
46 Followers 1K Following
Prakash c @prakash_C_k
207 Followers 3K Following வறுமை ஒரு வரப்பிரசாதம். Developer || Learner || Smile
Ramy @ramyger57465945
187 Followers 5K Following
instant123 @gurrrriiiiii
141 Followers 438 Following
zseano @zseano
79K Followers 703 Following #1 Amazon Security Researcher. full time hacking team with @jonathanbouman @fransrosen @avlidienbrunn
RyotaK @ryotkak
7K Followers 662 Following Security researcher? | Icon: @MelvilleTw | Private: @RyotaK_Private | Misskey: https://t.co/63E5Rpv2pk | Blog: https://t.co/c7NFQXhV90
suhas palshikar @PalshikarSuhas
23K Followers 99 Following based at Pune, India; taught political science; retweets not endorsements, only for generating discussion. Raw language and abuse will be strictly blocked.
James Kettle @albinowax
79K Followers 92 Following Director of Research at PortSwigger aka Burp Suite. Find my research, tools & contact details at https://t.co/vP6UbGmvl3Hillel Solow @hsolow
262 Followers 745 Following Addicted to Startups: * Chairman @ ProtectOnce * Chairman @ Perimeters * Advisor @ Polar Security * Advisor @ Jed Security * Advisor @ CentralEyes
Anil Kumar Gadari @gadarianil
137 Followers 2K Following Cyber Security Researcher, Bug hunter,Youtuber & Ethical Hacker
Ajay Kumar @akumar_net
71 Followers 399 Following #CyberSecurity, #digital, #security #CloudSecurity, #ArtificialIntelligence, #IoT, #Dataprotection, #Influencer, #AI, #Bitcoin
ᅟ @aqibshah
535 Followers 1K Following Self employed and A security researcher publicly acknowledged by google, Microsoft, Apple, Nasa etc. @HackenProof Security Researcher
Save to Notion @SaveToNotion
217K Followers 2 Following I save your favorite Tweets and Threads to your Notion Workspace! Just follow @SaveToNotion & check the pinned tweet to start, Developed by: @Abdulhade_Ahmad
मराठी ह�... @HackersMarathi
1K Followers 9 Following हा मराठी हॅकर्सचा अधिकृत गट आहे. पण नियम व कायदे अनौपचारिक आहेत...! आम्ही भारताचे अभिमानी नागरिक आहोत. जय महाराष्ट्र 🇮🇳 जय हिंद 🇮🇳
Caitlin McEvoy @crmcevoy
5K Followers 408 Following Graphic designer. Founder @District23UK. Fuelled by sarcasm, deafeningly loud music and copious bowls of cereal.
Jon Geater @jongeater
309 Followers 22 Following Cyber security expert, aged athlete. CTO at RKVST. All opinions are my own.
nikhil(niks) @niksthehacker
10K Followers 1K Following @SynackRedTeam Legend | Lead Pentester @Cobalt_io | Founder @BSidesAhmedabad | Speaker @Blackhatmea @defcon | Board of Advisor @riskprofilerio
Jon Bottarini @jon_bottarini
13K Followers 749 Following Product Manager @ Google. I post about bug bounties, infosec, and everything in between. This is a personal account. Formerly: @Hacker0x01
Kuldeep Pandya @kuldeepdotexe
5K Followers 348 Following OSINT | Web | Binary | [email protected] | @SynackRedTeam Envoy && Hero
shubs @infosec_au
56K Followers 2K Following Co-founder, security researcher. Building an attack surface management platform, @assetnote
Daily Stoic @dailystoic
631K Followers 10 Following Stoic wisdom for everyday life. Sign up for our free daily email and our New Year, New You Challenge:
Ketan Sirigiri @tweetketan
2K Followers 661 Following InfoSec Researcher; Listed - PayPal/Microsoft/Netflix/Soundcloud/Adobe/Zynga/MailChimp/GetBase/GetPocket/PagerDuty/CloudApp
HackSys Team @HackSysTeam
10K Followers 628 Following Vulnerability Research, Kernel Exploitation, Reverse Engineering, Exploit Development, Program Analysis, Malware Research, Web, Machine Learning
Murtuja Bharmal @murtuja_bharmal
731 Followers 71 Following IT/Network Security Professional, Linux/Unix Enthusiast, Interested in anything related to security.
arthur aires @arthurair_es
3K Followers 373 Following Bug Hunter at HackerOne ex-Medical Student at the Federal University of Amapá [email protected]
Maciej Pulikowski �... @pulik_io
3K Followers 344 Following 🧙 Software Engineer | 👾 Security Researcher | 🏆 8 x Google Hall of Fame | Working on: ♟️ https://t.co/5VBC921Hon 🦜 https://t.co/SLmRlO5OyX
Udhaya Prakash @sherlocksecure
4K Followers 190 Following Product Security Engineer | I'm that SherlockSecure ;(
Aditi Singh @aditi_singghh
13K Followers 731 Following Bug Bounty Hunter | Cyber security Researcher
kirti soni @Kirti070Soni
64 Followers 969 Following
Hussein Ayoub @HusseinAy0ub
997 Followers 2K Following DevOps 🏗️| Security ⚡️ | AWS Community Builder ☁️ | 9x AWS Certified | CAPM
Sayaan Alam @ehsayaan
9K Followers 969 Following Offensive Security Researcher, Pentester, Red Teamer and Bug Bounty Hunter | SRT Hero at @Synack Red Team | Hackerone - sayaanalam
Akita ZeN 🇦🇷 @akita_zen
26K Followers 1K Following Alchemist ✨🧙♂️ Energy Master ✨ Spiritual hacker 🌟 bugbounty hunter ✨ ptsd survivor ✨ Man of Faith 🌟
Google VRP (Google Bu... @GoogleVRP
39K Followers 0 Following We ❤️ 🐜🐞🦗🦟🦋. {echo,{{{Google,Chrome,Android,Abuse,Mobile,OSS,Cloud}Vulnerability,Patch}Reward,VulnerabilityResearchGrants}Program}
BubuBangles @Bububangles
412 Followers 748 Following Be kind 😊 I am a Veteran. I work in IT Security and I stream on Twitch! Come Hang out with me! Call me Dad. #WomenInTech #infosec #twitchaffiliate #veteran
Busra @turakbusra
2K Followers 481 Following Cyber Security | Bug Hunter | Researcher @SynackRedTeam 👩🏼💻
Ellen Burbidge @EllenBurbidge
7K Followers 153 Following 🎬 Actor, singer, dancer, funny guy 🦘 Living & working on Palawa land 🐚 https://t.co/rhT5pnNpv9
Ryan Dewhurst @ethicalhack3r
21K Followers 747 Following Head of Threat Intelligence at watchTowr | Founder of @_WPScan_ (acquired by Automattic) | Founder of DVWA | Ethical Hacking Graduate
John Hammond @_JohnHammond
298K Followers 3K Following Cybersecurity Researcher @HuntressLabs || Just Hacking Training @JustHackingHQ w/ @ethicalhacker || https://t.co/UtsNJiyQtS || https://t.co/narO3sz7y6
Aanchal Gupta @nchlgpt
2K Followers 181 Following CVP & Deputy CISO (Microsoft) Happy to discuss anything related to security, privacy, compliance, gardening, & hiking (nchlgpt =full name without vowels)
NotPinkCon @NotPinkCon
3K Followers 134 Following First security conference with #infosec talks given by women to everybody. Since 2018.
Mastering Burp Suite ... @MasteringBurp
16K Followers 0 Following Tips and tricks for Burp Suite Pro Managed by @Agarri_FR | Not affiliated with @Portswigger More free resources at https://t.co/MWqXmV66lr
Dafydd Stuttard @DafyddStuttard
7K Followers 78 Following Founder and Chief Swig at @PortSwigger. Creator of @Burp_Suite and @WebSecAcademy. Author of The Web Application Hacker's Handbook.
Viktor Hedberg 🛡�... @headburgh
1K Followers 616 Following I do security stuff @Truesec • MVP • Father • My tweets are my own • He/him
Ænna Westelius @bubblewire
12K Followers 1K Following Director of Security @ Netflix | Chaotic Good | tweets are my own | https://t.co/mEdXg4AhiX
Fabio Viggiani @fabio_viggiani
4K Followers 992 Following CTO / Red Team / Blue Team / Incident Response / Threat Intel / Speaker / at @Truesec