Himanshu Anand Profile
Himanshu Anand

@anand_himanshu

Followers
539
Following
2K
Media
204
Statuses
2K

Mostly security CTF with @Water_Paddler

Ring 0
Joined November 2009
Don't wanna be here? Send us removal request.
@anand_himanshu
Himanshu Anand
2 days
NPM is forked, Time to declare JS as rogue. Not fit for the internet. https://t.co/Jm66vwZW7J
Tweet card summary image
aikido.dev
The popular packages debug and chalk on npm have been compromised with malicious code
0
0
0
@NoContextBrits
No Context Brits
5 days
Tweet media one
46
133
2K
@BSidesLondon
BSides London
9 days
Tweet media one
15
24
61
@anand_himanshu
Himanshu Anand
12 days
Meanwhile, the website took ~30,000 milliseconds just to load that resource. When AI is faster than the network… what are we even doing? 😅
Tweet media one
0
0
0
@anand_himanshu
Himanshu Anand
12 days
People are raving about https://t.co/1OJkblMKdp , so I tried it for the first time. On the home page this image was generated in 0.8 seconds. 🚀
Tweet media one
1
0
0
@anand_himanshu
Himanshu Anand
13 days
In arguments between two people, the one with more followers is the winner by default.
0
0
0
@anand_himanshu
Himanshu Anand
14 days
While day job i.e: analyzing JavaScript files for bad code I came across something unusual. Not malicious, but clearly AI generated (TBH very common now) the variable names, comments and structure gave it away
1
1
0
@anand_himanshu
Himanshu Anand
14 days
Curious to hear your thoughts have you spotted AI coded snippets in the wild?
0
0
0
@anand_himanshu
Himanshu Anand
14 days
We are heading into an era where LLMs are coding with vibes not security in mind. The result? A growing surface of silent vulnerabilities.
1
0
0
@anand_himanshu
Himanshu Anand
14 days
TL;DR AI generated code can introduce major security flaws Developers may treat it as "safe by default." Security teams will face a new wave of risky patterns at scale
1
0
0
@anand_himanshu
Himanshu Anand
14 days
That discovery sent me digging deeper… what I found is turned into a blog post. `Why Relying on LLMs for Code Can Be a Security Nightmare` https://t.co/gcUKOY1qdZ
blog.himanshuanand.com
LLM generated code can ships demo logic with security issues not defenses. Here is a real world example and how it could be abused.
1
0
0
@anand_himanshu
Himanshu Anand
14 days
While day job i.e: analyzing JavaScript files for bad code I came across something unusual. Not malicious, but clearly AI generated (TBH very common now) the variable names, comments and structure gave it away
1
1
0
@BSidesLondon
BSides London
15 days
A few things! The first #BSidesLDN2025 ticket release is now less then a week away! Our logo competition is still open! See https://t.co/cw5L5KjdcA for more information on both Oh, CFP is open too! https://t.co/HiM2e9TSXg It's all going on! #Security #BSides #London
0
10
28
@anand_himanshu
Himanshu Anand
21 days
Give a shitty service, when someone complains about it give them 25% off during the next billing. #LifeHack
0
0
0
@orange_8361
Orange Tsai 🍊
21 days
Turns out my #PHRACK article is live! 🔥 > The Art of PHP — My CTF Journey and Untold Stories! Kinda a love letter to those CTF players & PHP nerds! Hope all the credit goes to the right ppl. Also huge thanks to @0xdea for not forgetting me, @guitmz for the edits, and the
Tweet media one
20
217
877
@SaurabhSha15
Saurabh Sharma
22 days
We recently analyzed GodRAT, a new malware strain derived from Gh0stRAT, actively targeting financial organizations. More details here -
Tweet card summary image
securelist.com
Kaspersky experts analyze GodRAT, a new Gh0st RAT-based tool attacking financial firms. It is likely a successor of the AwesomePuppet RAT connected to the Winnti group.
1
5
12
@Securityinbits
Ayush Anand
26 days
Defending against GuLoader delivering AgentTesla? It's in @anyrun_app top 10 malware TAR → EXE → URL → PS1 🛡️ 2 high-fidelity Sigma rules -> ready to drop: Process Tree: Yara Rules: Pe-sieve dump + YARA-forge scan quickly confirmed AgentTesla
Tweet media one
Tweet media two
Tweet media three
1
14
40
@zachxbt
ZachXBT
24 days
@unusual_whales Imagine being such a incompetent threat actor you compromise a large news account and only steal $100
Tweet media one
Tweet media two
Tweet media three
57
55
986
@shodanhq
Shodan
25 days
$5 Membership sale is live for the next 24 hours:
129
657
2K
@thatjiaozi
那个火饺🦆(JJ)
25 days
Here is the PoC of the exploit for cve-2025-30712 as well as some of the code for the fuzzer i created to find the bug! https://t.co/g82641DT2I
Tweet card summary image
github.com
… DevVGA device (#228)
1
52
209