Himanshu Anand

Himanshu Anand

Security Researcher & Engineer

$ cat ~/.now → Cloudflare · 3× DEF CON Finalist · Water Paddlers CTF

Blog GitHub X / Twitter Contact
10+
Years
30+
Articles
2
Patents
DEF CON Finalist
5+
Conf Talks
$ cat ~/about.md

About

Security researcher with 10+ years in the field spanning both red and blue teams. I specialize in malware analysis, reverse engineering, client-side threat detection, and WAF engineering.

I've worked in SOCs (Tier 1–3), built IPS/IDS signatures, and currently focus on web application firewall engineering and cloud-scale threat intelligence at Cloudflare. I compete with Water Paddlers in CTFs, finishing 2nd at DEF CON three consecutive years (2023–2025).

Malware AnalysisReverse EngineeringWAF EngineeringClient-Side SecurityThreat IntelligenceExploit AnalysisIPS/IDSFuzzingCloud SecurityLLM / AI SecurityCTF
$ cat ~/experience.log

Experience

Firewall Security Analyst
Cloudflare
Current
WAF rule engineering, zero-day response, client-side threat research, and AI-powered detection.
Security Researcher
Symantec (now Broadcom)
Previous
Malware analysis, SOC operations, IPS/IDS rule development, exploit analysis, and threat intelligence.
$ ls ~/research/latest/

Latest Research

a fake resume invoked China's defence-tech elite, then installed VShell

Disclosure: this research was conducted using an ANY.RUN account provided as part of a collaboration. All analysis and c...

malwarethreat-intel2026
I had some free time, so I tried to pwn V8

TLDR I am not working full time right now, which means I have free time which is dangerous. You start by reading one V8 ...

v8chrome2026
someone is filing your GST return, and it is not your CA

Disclosure: this research was conducted using an ANY.RUN account provided as part of a collaboration. All analysis and c...

malwarethreat-intel2026
The Anti-India Influence Machine: Troll Farms, Fake News, Newsrooms, Algorithms and AI

The Anti-India Influence Machine: Troll Farms, Fake News, Newsrooms, Algorithms and AI Scope and disclaimer: This is a c...

cybersecuritydisinformation2026
I found a KVM guest-to-host heap corruption bug and someone else got there first

TLDR I independently found a heap out-of-bounds read/write in KVM’s SEV-SNP Page State Change handler. A malicious...

kvmsandbox2026
View all posts →
$ ls ~/published/

Published at Cloudflare, c/side & Symantec

AI WAF Detected Ivanti Zero-Day

ML-driven detections in practice.

CloudflareWAFZero-Day
Navigating the Maze of Magecart

Mitigations and lessons from the field.

CloudflareMagecart
CoinMarketCap Client-Side Attack: A Comprehensive Analysis

Deep dive into the compromise chain and mitigations.

c/sideClient-Side
Confluence Zero-Day (CVE-2022-26134)

Attack surface and mitigations.

CloudflareCVE
How Traffic Hijacking and Affiliate Fraud Harm Websites

How malicious actors hijack traffic and commit affiliate fraud — and defenses that work.

c/sideFraud
WAF Mitigations for Spring4Shell

Rule design and tuning.

Cloudflare
Protected from Atlassian CVE-2023-22515

Rapid response at scale.

Cloudflare
Top Exploited Vulns of 2022

Trends from global traffic.

Cloudflare
Is Relying on IoCs Secure Enough?

Limits of IoCs and how to augment them.

c/side
Weaponized Google OAuth Triggers Malicious WebSocket

OAuth abuse patterns on the client side.

c/side
Ruthless Client-Side Attacks with ClickFix

Multi-platform targeting via UI manipulation.

c/side
PWA Injection Scam Targets Mobile Users

Abusing web app install flows for fraud.

c/side
150k+ Sites Hit by Full-Page Hijack

Mass injections and redirect monetization.

c/side
35k+ Sites in Gambling Scam Hijack

Campaign evolution and blockers.

c/side
ScriptAPI[.]dev Attack on Gov/Uni Sites

Third-party supply chain risk realized.

c/side
The Cost of False Positives

Operational impact and how we adapted.

c/side
5,000+ WordPress Sites in WP3[.]XYZ Attack

Indicators and containment.

c/side
New Client-Side Attack Only a Proxy Could Stop

Where inline protections fall short.

c/side
10,000 WordPress Sites Delivering Malware

Cross-platform payload delivery.

c/side
Kuwait E-commerce Site Used for Skimming

Infrastructure re-use and takedown paths.

c/side
New Magecart Attack Code Revealed

Obfuscation tricks and exfil flows.

c/side
3rd-Party Script Attack: artifyau[.]com & quantifymy[.]com

Third-party trust boundaries tested.

c/side
Cisco Client-Side Magecart Attack

Merchant-side script compromise analysis.

c/side
Ticketmaster Data Breach: Déjà Vu

Repeat patterns, repeat impact.

c/side
Vulnerable Joomla! Installation Under Attack

Field report on active exploitation.

Symantec
One-Click Fraudsters Learn Chinese

Localization tactics in fraud ops.

Symantec
Facebook Scam → Nuclear Exploit Kit

Social lures meet exploit delivery.

Symantec
$ ls ~/talks/

Conference Talks

Area41 2024 — Public Cloud Public Attacks

A summary of attacks seen by Cloud Intel. [PDF]

Black Hat Asia 2024 — CalMal: Malware Clustering via Unsupervised ML

Arsenal demo of unsupervised malware family classification. [PDF] · [GitHub]

VB2017 — The Router of All Evil

Router exploitation and botnet infrastructure analysis.

VB2016 — One-Click Fileless Infection

Fileless malware techniques and detection challenges.

$ grep -r "himanshu" ~/media/

In The Media

TechCrunch

WordPress Sites Hijacked to Push Malware

Computerworld

Short-lived Certificates — What IT Should Know

The CTO Club

Crush Your New Gig in Cybersecurity From Day One

Cloudflare TV

Security Week — Magecart Attacks

$ ls ~/patents/ ~/papers/

Patents & Papers

$ ls ~/projects/

Projects

Prompt Injection Detection

AI firewall for detecting & preventing prompt injection attacks.

AIWorkers
CalMal

Unsupervised clustering of malware families via ML.

MLMalware
Cloud Intel

High-fidelity public cloud threat intel and atomic IOCs.

Threat IntelAPI
Personal LLM

LLaMA-based personal model on Cloudflare Workers.

LLMWorkers
Legally Blocked

Tracking blocked websites and apps worldwide.

Censorship
UK Strike Calendar

Calendar built with ChatGPT & Cloudflare Workers.

Workers
$ cat ~/.social

Find Me Online

$ cat ~/contact.md

Get In Touch

$ For speaking engagements, research collaboration, or security consulting.