Category: Application Security

Offensive AI Series: My Experiments with Neo by ProjectDiscovery – AppSec, Pentesting & Beyond [Part 1]

Hi, I am Ashutosh, a security researcher specializing in application security, VAPT, and Purple teaming. Over the past year, AI agents for cybersecurity have exploded in popularity. From open-source tools to premium enterprise solutions, AI-powered security assessment platforms are everywhere, each promising to revolutionize how we approach security work. But do they actually work? Let’s see. […]

From Social Media Complaints to $12,000: Story of Hacking Another Airline Company using OSINT

Hi, I am Ashutosh, a security researcher with specialization in application security, VAPT, and Purple teaming. I have worked for a Big 4 firm where I conducted security assessments for multiple Fortune 500 clients. In my free time, I hunt for vulnerabilities in some of the largest companies’ systems through bug bounty programs. I have […]

Protect Your MongoDB – Story of “The Same Database”

It’s normal now to hear stories about data breaches. Some of them involve publicly exposed Databases, S3 buckets etc. The vulnerability falls into ‘Security Misconfiguration’, A6 – OWASP Top 10 (2017). ” Attackers will often attempt to exploit unpatched flaws or access default accounts, unused pages, unprotected files and directories, etc to gain unauthorized access […]

Crypto-Mining Marketplace NiceHash Fixed a Vulnerability Which Leaked Miners’ Information

Privacy matters to most of us! That applies for crypto world too. Bitcoin transactions don’t directly link to a person, but in case of NiceHash, attackers could find a miner’s BTC wallet address using his Email address. This is a story about How I found a random guy’s recent payments from his cryptocurrency mining activity […]

Back To Top