Leandro Barragan Profile
Leandro Barragan

@lean0x2f

Followers
3K
Following
2K
Media
38
Statuses
609

Offensive Security Researcher https://t.co/zhzGBvhEUz | https://t.co/XyZBK7P9wo. Building the best autonomous pentester @ https://t.co/mF7RKaHmHw. Opinions are my own

Buenos Aires, Argentina
Joined November 2016
Don't wanna be here? Send us removal request.
@lean0x2f
Leandro Barragan
2 days
As a pentester, you sometimes spend hours reading obscure docs about a library you never heard of, chaining vulns, and praying your work turns into something useful. Xbow-dude did all that in 12 minutes. SSRF -> expression injection -> RCE.
Tweet card summary image
xbow.com
A methodical analysis of TiTiler's API endpoints and its expression parser, leading to arbitrary Python code execution on the server.
3
17
120
@lean0x2f
Leandro Barragan
6 days
Man you gotta love container escapes. The amount of times I’ve seen companies rely on containers to isolate tenants. you are an escape away from a complete compromise of your cloud solution.
@nirohfeld
Nir Ohfeld
9 days
We found a new container escape affecting all container runtimes using @NVIDIA GPUs. The crazy part?.The exploit is just three lines long 🤯. This is the story of #NVIDIAScape 🧵👇
Tweet media one
0
4
29
@lean0x2f
Leandro Barragan
8 days
RT @moyix: Albert's excellent blog post on "model alloys" – a clever technique for combining the strengths of different models without maki….
0
6
0
@lean0x2f
Leandro Barragan
11 days
RT @Xbow: When simple attack vectors fail, XBOW doesn't give up. ⚡️New discovery: Arbitrary file read in WordPress Ninja Tables plugin. H….
0
16
0
@lean0x2f
Leandro Barragan
18 days
RT @Xbow: Sometimes the most illogical approach wins. XBOW discovered XSS in Salesforce Aura by testing aura.format=JSON - which counterin….
0
58
0
@lean0x2f
Leandro Barragan
20 days
RT @TheStoicEmperor: Many advancements come from people trying to teach themselves something and tripping over a better way to do it.
0
19
0
@lean0x2f
Leandro Barragan
23 days
Way to start the quarter! (worldwide leaderboard)
Tweet media one
1
1
49
@lean0x2f
Leandro Barragan
24 days
I can’t believe how many pentesters, red teamers, and bounty hunters missed this bug (myself included!) A prime example of why we need to scale up with AI.
@Xbow
XBOW
26 days
Even mature products hide critical flaws – and @XBOW just found another one. CVE-2025-49493: XXE in Akamai CloudTest discovered during our climb to #1 on HackerOne. A complete technical breakdown from an error-based detection to a full exfiltration by @djurado9
Tweet media one
0
1
6
@lean0x2f
Leandro Barragan
25 days
RT @Xbow: The top hacker in the US is not a human, but a machine. @XBOW founder and CEO @oegerikus and @apoorv03 of @altcap joined @Bloombe….
0
15
0
@lean0x2f
Leandro Barragan
1 month
Hacking with friends always pays off :) thank you HackerOne & Salesforce for such an amazing event! This time I teamed up with Kcho, @djurado9 and @niemand_sec to land a few crits that got us the eliminator award 😊.
@Hacker0x01
HackerOne
1 month
Congrats to these award winners for their innovation, collaboration, and relentless pursuit of impact. 🔥 Most Valuable Hacker | Top Criticality, Community, & Consistency of the event.>>WINNER: shubs. 🕷️ Exterminator | Best/most Impactful bug of the event .>>WINNERS:
Tweet media one
2
2
19
@lean0x2f
Leandro Barragan
2 months
RT @YuG0rd: 🚀 We just released my research on BadSuccessor - a new unpatched Active Directory privilege escalation vulnerability.It allows….
0
373
0
@lean0x2f
Leandro Barragan
2 months
RT @moyix: Woohoo!! I'll be going to Las Vegas this August to talk at @BlackHatEvents USA about how we built an AI agent for finding vulns….
0
12
0
@lean0x2f
Leandro Barragan
2 months
RT @nicowaisman: Bribing sub-contractors is not new (re: @coinbase), how you though about what that means for your open source supply chain?.
0
1
0
@lean0x2f
Leandro Barragan
2 months
RT @moyix: Another nice 0day found autonomously by XBOW :D
Tweet media one
Tweet media two
0
6
0
@lean0x2f
Leandro Barragan
2 months
I always tell my social engineering pentest clients to test from the perspective of a malicious insider, especially low-level roles like support staff or contractors. Sure, you can go after them legally for breaking contracts, but only *after* the damage is done.
@mattjay
Matt Johansen
2 months
🚨 Breaking: Coinbase reveals insider threat incident where overseas support agents were bribed to exfiltrate customer data. Company refusing $20M extortion demand, instead offering same amount as bounty for threat actor identification.
Tweet media one
0
0
6
@lean0x2f
Leandro Barragan
2 months
RT @OpenAIDevs: You can now connect GitHub repos to deep research in ChatGPT. 🐙 . Ask a question and the deep research agent will read and….
0
973
0
@lean0x2f
Leandro Barragan
3 months
Sorry not sorry 😜.
@mbrg0
mbg
3 months
an ai system is the top hacker at h1 us leaderboard
Tweet media one
1
1
19
@lean0x2f
Leandro Barragan
3 months
RT @djurado9: XBOW is hiring!! If you want to join our team and work with some of the most talented people I have ever met, don't miss your….
0
7
0
@lean0x2f
Leandro Barragan
4 months
I’m thrilled to announce that I’ll be joining the brilliant minds at the XBOW team next week!.After 10 years of breaking things for a living, it’s time to get back to building… this time, building an AI product that breaks things in a scalable, safe, and automated way 🦾
Tweet media one
7
5
136
@lean0x2f
Leandro Barragan
4 months
RT @lbeurerkellner: 👿 MCP is all fun, until you add this one malicious MCP server and forget about it. We have discovered a critical flaw….
0
398
0