
I'm Sharan, an independent Security Researcher.
My work centers on web and API security, vulnerability research, and the emerging space of AI and agentic-system security. Over the past year I've tested production AI systems like HubSpot's Breeze AI across 17 attack vectors, uncovering a trust asymmetry between its email and CRM pipelines that let an external sender steer agentic actions — reported through HackerOne and later published as a full technical write-up. I've also responsibly disclosed vulnerabilities across platforms including VIT Paper Vault, Elala, and Bumba Global, and reported a High-severity unauthenticated LLM/ML API exposure to the affected organization.
Outside of formal engagements, I build for the fun of it — writing scripts that simulate attack chains end-to-end, prototyping proof-of-concept exploits just to understand how a vulnerability class actually behaves, and automating the small repetitive parts of my workflow so I can spend more time on the interesting problems. Some of these scripts never leave my own lab; others turn into tools like WNSA, WAVE, and Echo Defend.
I'm pursuing my B.Tech in Computer Science & Engineering with a specialization in Cybersecurity at Vellore Institute of Technology, and I'm currently working toward my CEH certification.
Beyond the technical work, I care about making security knowledge accessible — through writing on Medium — and I'm working toward speaking at top-tier security conferences like Nullcon, BSides Mumbai, and DEF CON AI Village. Outside of security, I'm also a photographer, always looking at the world through one more lens than usual.
RésuméWhat I reach for, grouped by where it fits.
Web/API penetration testing, mobile VAPT, OWASP Top 10, authentication & authorization testing, race conditions, LLM/prompt-injection testing, CVSS scoring, threat modeling, MITRE ATT&CK.
Secure code review, SAST, DAST, CI/CD security.
Burp Suite, Nmap, Metasploit, Postman, Wireshark, Linux, SIEM, HackerOne.
Python, Bash, JavaScript, C++, Java, C, SQL, HTML/CSS.
Carrom nights, staying in shape, living in the terminal — and working toward the stage.




Competitions, meetups, and the people I break things with.



Frames from my camera roll — the other way I look at the world.























