Log inSign up
Himanshu Anand
2,782 posts
@anand_himanshu

Himanshu Anand

@anand_himanshu
Burning tokens pretending to be good at cybersecurity. Past company's : @Cloudflare , @csideai , @symantec Ex-CTF @Water_Paddler
Ring 0
himanshuanand.com
Joined November 2009
1,769
Following
710
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @anand_himanshu
    Himanshu Anand
    @anand_himanshu
    Aug 11
    I found a guest -> host memory corruption bug in KVM. Then I emailed the kernel security team. Their response, basically: Someone found it before you and the problem is bigger than what you found. That second part hurt more. 🧵 CVE-2026-53360 blog.himanshuanand.com/2026/08/i-foun…
    2
  • @anand_himanshu
    Himanshu Anand
    @anand_himanshu
    16h
    @ProductHunt I wonder if this is intended or some sort of attack against LLMs reading your emails and processing it?
  • @anand_himanshu
    Himanshu Anand
    @anand_himanshu
    Aug 28
    One RT: and I will work on Kernel CTF blog. 😜
  • @anand_himanshu
    Himanshu Anand
    @anand_himanshu
    Aug 27
    I pulled apart a Chinese language “resume” that was actually a Windows executable. The victim gets a real Word document. In memory, the machine gets: Go loader → SNOWLIGHT → VShell RAT I spent some time reconstructing the whole chain. 🧵
    1
  • @anand_himanshu
    Himanshu Anand
    @anand_himanshu
    Aug 26
    I chained 3 public V8 bugs against Google's v8CTF Chrome build and got a real flag. OOB read → GC stale slot → fake array → caged R/W → native leak → JSPI/JDT stack pivot → ROP. V8 sandbox escape: yes. $10k ??
    4