Actively hiring
Follow
Overview
News
Technologies
Salaries
Products
People
Growth
Financials
Overview
Evaluations and research on security, software, and AI by Vikrant Singh Chauhan.
News
Leaking internal headers in Flask Ninja with deserialization
There's an unfixed gadget living in Flask Ninja. Its HttpBearer authenticator reads the credential from a header named by a plain, writable attribute, so a deserialization sink that calls its result, or config that hydrates the auth object from untrusted
Read more
Report
Simple Prompts to get the System Prompts
Exploring prompt injection techniques to extract hidden system prompts from popular AI wrappers and chatbots.
Read more
Report
CVE-2024-5569: Denial of Service in Zipp (and Zipfile module of Python's standard library)
Reported a Denial of Service (infinite loop) vulnerability in the zipp module, which also affects Python's built-in zipfile module (part of the standard library).
Read more
Report
Stealing OAuth tokens of connected Microsoft accounts via open redirect in Harvest App
Reported an OAuth token leak via open redirect in Harvest.
Read more
Report
Breaking The Mutant Language's "Encryption (Writeup)"
AppSec Village DEF CON 31 CTF2 (developer) winning entry. Bypassed the encryption and mutation techniques of the Mutant Language.
Read more
Report
Pro access
Upgrade to see all 15 mentions
Upgrade to a paid plan to read every media mention of this company - funding news, awards, product launches and press releases from all the outlets writing about it.
Every media mention and press release
Funding news, awards and product launches
Fresh coverage from every outlet writing about the company
Upgrade now
Cancel anytime. Secure checkout. Instant activation.
