
Leandro Barragan
@lean0x2f
Followers
3K
Following
2K
Media
38
Statuses
609
Offensive Security Researcher https://t.co/zhzGBvhEUz | https://t.co/XyZBK7P9wo. Building the best autonomous pentester @ https://t.co/mF7RKaHmHw. Opinions are my own
Buenos Aires, Argentina
Joined November 2016
As a pentester, you sometimes spend hours reading obscure docs about a library you never heard of, chaining vulns, and praying your work turns into something useful. Xbow-dude did all that in 12 minutes. SSRF -> expression injection -> RCE.
xbow.com
A methodical analysis of TiTiler's API endpoints and its expression parser, leading to arbitrary Python code execution on the server.
3
17
120
Man you gotta love container escapes. The amount of times I’ve seen companies rely on containers to isolate tenants. you are an escape away from a complete compromise of your cloud solution.
We found a new container escape affecting all container runtimes using @NVIDIA GPUs. The crazy part?.The exploit is just three lines long 🤯. This is the story of #NVIDIAScape 🧵👇
0
4
29
RT @TheStoicEmperor: Many advancements come from people trying to teach themselves something and tripping over a better way to do it.
0
19
0
I can’t believe how many pentesters, red teamers, and bounty hunters missed this bug (myself included!) A prime example of why we need to scale up with AI.
Even mature products hide critical flaws – and @XBOW just found another one. CVE-2025-49493: XXE in Akamai CloudTest discovered during our climb to #1 on HackerOne. A complete technical breakdown from an error-based detection to a full exfiltration by @djurado9
0
1
6
Hacking with friends always pays off :) thank you HackerOne & Salesforce for such an amazing event! This time I teamed up with Kcho, @djurado9 and @niemand_sec to land a few crits that got us the eliminator award 😊.
Congrats to these award winners for their innovation, collaboration, and relentless pursuit of impact. 🔥 Most Valuable Hacker | Top Criticality, Community, & Consistency of the event.>>WINNER: shubs. 🕷️ Exterminator | Best/most Impactful bug of the event .>>WINNERS:
2
2
19
RT @moyix: Woohoo!! I'll be going to Las Vegas this August to talk at @BlackHatEvents USA about how we built an AI agent for finding vulns….
0
12
0
RT @nicowaisman: Bribing sub-contractors is not new (re: @coinbase), how you though about what that means for your open source supply chain?.
0
1
0
I always tell my social engineering pentest clients to test from the perspective of a malicious insider, especially low-level roles like support staff or contractors. Sure, you can go after them legally for breaking contracts, but only *after* the damage is done.
🚨 Breaking: Coinbase reveals insider threat incident where overseas support agents were bribed to exfiltrate customer data. Company refusing $20M extortion demand, instead offering same amount as bounty for threat actor identification.
0
0
6
RT @OpenAIDevs: You can now connect GitHub repos to deep research in ChatGPT. 🐙 . Ask a question and the deep research agent will read and….
0
973
0
RT @lbeurerkellner: 👿 MCP is all fun, until you add this one malicious MCP server and forget about it. We have discovered a critical flaw….
0
398
0