
Himanshu Anand
@anand_himanshu
Followers
539
Following
2K
Media
204
Statuses
2K
Mostly security CTF with @Water_Paddler
Ring 0
Joined November 2009
NPM is forked, Time to declare JS as rogue. Not fit for the internet. https://t.co/Jm66vwZW7J
aikido.dev
The popular packages debug and chalk on npm have been compromised with malicious code
0
0
0
#BSidesLDN2025 tickets are now available! https://t.co/lRbIvBCtK7
#Security #BSides #London #Tickets
15
24
61
Meanwhile, the website took ~30,000 milliseconds just to load that resource. When AI is faster than the network… what are we even doing? 😅
0
0
0
People are raving about https://t.co/1OJkblMKdp , so I tried it for the first time. On the home page this image was generated in 0.8 seconds. 🚀
1
0
0
In arguments between two people, the one with more followers is the winner by default.
0
0
0
While day job i.e: analyzing JavaScript files for bad code I came across something unusual. Not malicious, but clearly AI generated (TBH very common now) the variable names, comments and structure gave it away
1
1
0
Curious to hear your thoughts have you spotted AI coded snippets in the wild?
0
0
0
We are heading into an era where LLMs are coding with vibes not security in mind. The result? A growing surface of silent vulnerabilities.
1
0
0
TL;DR AI generated code can introduce major security flaws Developers may treat it as "safe by default." Security teams will face a new wave of risky patterns at scale
1
0
0
That discovery sent me digging deeper… what I found is turned into a blog post. `Why Relying on LLMs for Code Can Be a Security Nightmare` https://t.co/gcUKOY1qdZ
blog.himanshuanand.com
LLM generated code can ships demo logic with security issues not defenses. Here is a real world example and how it could be abused.
1
0
0
While day job i.e: analyzing JavaScript files for bad code I came across something unusual. Not malicious, but clearly AI generated (TBH very common now) the variable names, comments and structure gave it away
1
1
0
A few things! The first #BSidesLDN2025 ticket release is now less then a week away! Our logo competition is still open! See https://t.co/cw5L5KjdcA for more information on both Oh, CFP is open too! https://t.co/HiM2e9TSXg It's all going on! #Security #BSides #London
0
10
28
Give a shitty service, when someone complains about it give them 25% off during the next billing. #LifeHack
0
0
0
We recently analyzed GodRAT, a new malware strain derived from Gh0stRAT, actively targeting financial organizations. More details here -
securelist.com
Kaspersky experts analyze GodRAT, a new Gh0st RAT-based tool attacking financial firms. It is likely a successor of the AwesomePuppet RAT connected to the Winnti group.
1
5
12
Defending against GuLoader delivering AgentTesla? It's in @anyrun_app top 10 malware TAR → EXE → URL → PS1 🛡️ 2 high-fidelity Sigma rules -> ready to drop: Process Tree: Yara Rules: Pe-sieve dump + YARA-forge scan quickly confirmed AgentTesla
1
14
40
@unusual_whales Imagine being such a incompetent threat actor you compromise a large news account and only steal $100
57
55
986
Here is the PoC of the exploit for cve-2025-30712 as well as some of the code for the fuzzer i created to find the bug! https://t.co/g82641DT2I
github.com
… DevVGA device (#228)
1
52
209