Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sandeep_kamble
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
sandeep_kamble
23d ago
Hmm expected Harness as a service offering.
2.
▲
PROMPTPurify: 14 MB CPU-only prompt-injection guard (benchmarked vs. OSS guard)
(github.com)
1 points
by
sandeep_kamble
4mo ago
|
0 comments
3.
▲
Sandyaa: Recursive-LLM source code auditor that writes exploitable PoCs
(github.com)
2 points
by
sandeep_kamble
6mo ago
|
1 comments
4.
▲
by
sandeep_kamble
6mo ago
Sandyaa is an open-source autonomous source code auditor. Point it at a directory or a git URL and it runs end-to-end: builds context, detects vulnerabilities, writes runnable proof-of-concepts, and emits a findings/ folder whe
5.
▲
GeminiJack: A prompt-injection challenge demonstrating real-world LLM abuse
(geminijack.securelayer7.net)
1 points
by
sandeep_kamble
10mo ago
|
1 comments
6.
▲
by
sandeep_kamble
10mo ago
A few days ago, a research team disclosed GeminiJack, a prompt-injection vulnerability affecting LLM-powered applications. I recreated the same class of vulnerability as an interactive challenge to demonstrate how subtle prompt injection fl
7.
▲
Show HN: AI Agent for Microsoft Grap Red Team Framework
(github.com)
3 points
by
sandeep_kamble
1y ago
|
0 comments
8.
▲
CVE-2025-4318 RCE AWS Amplify Studio via Unsafe Property Expression Evaluation
(blog.securelayer7.net)
1 points
by
sandeep_kamble
1y ago
|
0 comments
9.
▲
Episode 1: Decoding Pentest Findings: Accept or Reject? [video]
(youtube.com)
3 points
by
sandeep_kamble
1y ago
|
0 comments
10.
▲
by
sandeep_kamble
1y ago
CVE-2025-2783 is a high-impact vulnerability in the Google Chrome web browser, specifically affecting the Mojo inter-process communication (IPC) component on Windows systems. The flaw is rooted in improper handle validation and management i
11.
▲
Nat, firewalls MFA all in place Yet I got in and walked away with sensitive data
(linkedin.com)
5 points
by
sandeep_kamble
2y ago
|
2 comments
12.
▲
by
sandeep_kamble
2y ago
Congratulations Paras, you made it! Looking forward to your next gig!
13.
▲
Exploitable in Wild: Critical Remediations for CVE-2024-20767 and CVE-2024-21216
(blog.securelayer7.net)
2 points
by
sandeep_kamble
2y ago
|
1 comments
14.
▲
by
sandeep_kamble
2y ago
Two critical vulnerabilities, CVE-2024-20767 and CVE-2024-21216, have been identified as actively exploitable in the wild, posing serious risks to affected systems. This post dives into their impact, the attack vectors, and detailed remedia
15.
▲
Easy to Use Self-Hosted API Security Scanner Launched
(securelayer7.net)
1 points
by
sandeep_kamble
2y ago
|
0 comments
16.
▲
AI Powered Fraud Prevention for Woocommerce Store
(sensfrx.ai)
2 points
by
sandeep_kamble
2y ago
|
0 comments
17.
▲
Analysis of CVE-2024-37084: Spring Cloud Remote Code Execution
(blog.securelayer7.net)
3 points
by
sandeep_kamble
2y ago
|
0 comments
18.
▲
by
sandeep_kamble
2y ago
The blog post discusses CVE-2024-22263, a critical vulnerability in Spring Cloud Data Flow. It explains how the Skipper server's insufficient file path sanitization allows attackers with API access to write arbitrary files to the serve
19.
▲
High-Risk Vulnerability of Spring Cloud Data Flow Lead to Compromise
(blog.securelayer7.net)
1 points
by
sandeep_kamble
2y ago
|
1 comments
20.
▲
High Rated CVSS Apache Airflow Remote Code Execution
(blog.securelayer7.net)
3 points
by
sandeep_kamble
2y ago
|
1 comments
21.
▲
by
sandeep_kamble
2y ago
The blog post discusses a vulnerability (CVE-2024-39877) in Apache Airflow, allowing authenticated users to execute arbitrary code via the doc_md parameter. The issue involves improper handling of Jinja2 templates, leading to potential secu
22.
▲
by
sandeep_kamble
3y ago
Our WHMCS is protected with some product. I wanted to ensure we are foolproof against at least low-hanging frauds, and I wanted to understand from you if you're using WHMCS or Blesta. What settings or extensions are you using to stop f