Ivan at Wallarm / API security solution
@d0znpp
Followers
7K
Following
2K
Media
522
Statuses
10K
SSRF bible author; Bug Hunter (Google/Facebook/Twitter/Yandex/Tesla); Masters in Physics, MSU / quantum magnetism; CEO at @Wallarm
Austin, TX
Joined April 2010
Tired of scrolling the whole ATT&CK matrix mid-engagement? We use the BEAR Security Model instead: B – Break in E – Expand foothold A – Ascend privileges R – Rule the environment Same kill chain logic, zero clutter. Perfect for live pentests, reports, and exec briefs.
0
0
2
Like if you also see an eyeball in this lamp
1
0
1
Sandbox bypass → arbitrary code exec → OS cmd exec in GenAI dev platform. Found https://t.co/WUtRvwazeR, used SourceMapper to extract JS, analysed logic, used prototype pollution + object traversal to bypass. Got creds incl private keys, cloud, GitHub, DB, mail, other secrets.
4
20
232
Looking for security researcher with great public profile. Remote. API / AI exploits focus on novel techniques. No XSSers please ;) reply here or DM. Please repost
3
8
20
Check out the latest article in my newsletter: OWASP Top 10 - Release Candidate https://t.co/a6RutzkZ1k Link to the playlist - Link to the playlisy - https://t.co/PQM5SyVk8I
#infosec #CyberSec @owasp
0
4
7
Beernet Radio: Britt West of Gallo joins us, the architect of High Noon, VMC, Lucky One, etc.
0
2
16
Security isn’t just a technical problem. It’s a leadership one. Lefteris Tzelepis on what it takes to be a modern CISO, from incident response discipline to API visibility and secure coding. Read the full CISO Spotlight: https://t.co/oQptkVutvZ
#CyberSecurity #CISO
0
1
2
Looking for security researcher with great public profile. Remote. API / AI exploits focus on novel techniques. No XSSers please ;) reply here or DM. Please repost
3
8
20
Season’s greetings from Panasonic Avionics to our customers and colleagues across the aviation community. Wishing everyone a restful and happy holiday season. 🎉 #HappyHolidays #Aviation #IFEC
0
1
1
Everyone is predicting the future of AI security. These experts focus on what will actually break first in 2026. If you want to uncover the blind spots organizations are still underestimating, read the full article below. https://t.co/SCKQDouIAz
#CyberSecurity #APIsecurity
lab.wallarm.com
Experts reveal the AI security challenges organizations will overlook in 2026 and how to prepare for agentic threats, cascading failures, and rising AI misuse.
0
1
1
What a year. ⭐ Our 2025 recap is live, covering smarter sessions, real-time blocking, revenue protection, and more. Read it here: https://t.co/KIeUNxyGDN
#APIsecurity #Wallarm #Cybersecurity
0
1
1
Somos Novios - It's Impossible ..Not to love you.....await...patiently......my love......
0
0
13
WAF Bypass Discovered - Akamai & Cloudflare A fresh technique has been spotted that successfully bypasses WAFs like Akamai and Cloudflare. #infosec #Cybersecurity #bugbountytip
4
95
454
GenZ idiom: There are only killers and kidders in this world. Kidders are usually older.
0
0
0
GenZ vocab: married point of failure (previous generation-aged single point of failure)
0
0
0
EXW vs. FOB vs. DDP shouldn’t slow a shipment down. Download the Incoterms 2020 cheat sheet and get clarity in 2 minutes. → Click for free download
8
32
117
APIs are the #1 attack targets. Email topped reports in the past. But attackers follow the data flow, and that’s APIs now. Shadow endpoints, fast releases, noisy integrations… it’s where they strike. Agree or not? 👇 #APIsecurity #CyberSecurity #Wallarm
0
1
1
Proud to share that Wallarm has been named an Edge Tech Champion for Performance by The Fast Mode! Recognition like this reflects the work our team puts in and the trust our customers place in us. Grateful for both as we head into a new year. #Wallarm #APIsecurity
0
1
2
Vote! How fast local AI capabilities will be available via JS API? Client-side is waiting!
0
0
0
The Fragile Lock: Novel Bypasses for SAML Authentication will premiere this Wednesday at 10:20 at Black Hat Europe! I'll show you how to chain XML parser quirks to achieve complete authentication bypasses on multiple popular libraries #BHEU @BlackHatEvents
1
28
153
Alaska embodies the edge: vast, remote, and unforgiving. It demands technology that works where others can't. @AlaskaDOTPF's drone program reduced their critical decision-making window from 28+ hours to real time. Watch how they're reimagining what's possible with Armada at the
2
28
68
This talk is going to be absolutely insane
The Fragile Lock: Novel Bypasses for SAML Authentication will premiere this Wednesday at 10:20 at Black Hat Europe! I'll show you how to chain XML parser quirks to achieve complete authentication bypasses on multiple popular libraries #BHEU @BlackHatEvents
2
15
151
CVE-2025-66489 - https://t.co/nBfOsZLCJp Authentication Bypass via TOTP Code Presence Another #Pruva reproduction for today https://t.co/x28Stcilan curl -X POST http://localhost:3001/api/auth/callback/credentials \ -H "Content-Type: application/x-www-form-urlencoded" \ -b
🚨🚨CVE-2025-66489 (CVSS 9.9): https://t.co/Bc24fzUHWX Authentication Bypass If an attacker supplies any TOTP code during login, the password check is completely skipped thanks to broken conditional logic. Search by vul.cve Filter👉vul.cve="CVE-2025-66489" ZoomEye
0
15
110
APIs are multiplying rapidly in manufacturing, and even a single missed issue can disrupt production or supply chain workflows. A global manufacturer learned this the hard way when an API breach exposed gaps across internal systems. See how they fixed it and tightened their API
wallarm.com
Faced with increasing API security challenges, including an API security incident and insufficient static code analysis, this manufacturer sought a robust solution to protect its APIs. #CISO #appsec...
0
1
3