whoami

Bhargav Hede_

AI Security Specialist | CVE Hunter | Bug Bounty Hunter

I simulate sophisticated adversaries to expose critical weaknesses before attackers do.

Specializing in Red Team Operations, AI/LLM Security, and Attack Chain Development.

From AI-powered chatbot vulnerabilities to multi-stage adversarial simulations, I help organizations understand their true security posture by thinking and acting like the threats they fear most. With 5+ years of offensive security experience and 9 CVEs discovered, I bring real-world attack expertise to every engagement.

5+ Years
9 CVEs
AI
Bounty
LPT Master

Professional Experience

5+ years in offensive security and red team operations

Senior Security Analyst

Sumasoft Pvt. Ltd., Pune

January 2025 – Present

Key Responsibilities

  • Leading red team engagements simulating sophisticated adversarial tactics across people, processes, and technology
  • Conducting AI/LLM security assessments, AI chatbot penetration testing, and RAG system security evaluations
  • Developing custom attack chains and C2 infrastructure for realistic adversarial simulations
  • Creating AI-powered workflows to automate and enhance penetration testing efficiency
  • Delivering executive-level threat intelligence briefings and remediation roadmaps
  • Performing MCP (Model Context Protocol) security testing for AI integrations

Technical Expertise

Web Application Penetration TestingAndroid & iOS Mobile Security TestingThick Client Testing & Sandbox BypassingRed Team EngagementsAI Chatbot & LLM Red TeamingRAG System Security TestingMCP TestingIoT Security (Dynamic & Static Firmware Analysis)API Security Testing (REST, GraphQL, SOAP)Network & Infrastructure TestingKiosk Application SecurityOSINT (Active & Passive)End-to-End Client Handling

Security Analyst | Penetration Tester

Sumasoft Pvt. Ltd., Pune

June 2021 – December 2024

Key Responsibilities

  • Executed comprehensive penetration tests across web, mobile, API, and network infrastructure
  • Performed vulnerability assessments using Nessus, Burp Suite, Metasploit, and custom tooling
  • Conducted thick client application testing with advanced bypass techniques
  • Performed IoT device security testing including firmware analysis
  • Identified and remediated critical security gaps for enterprise clients

Red Team & AI Security Services

Adversarial simulation | AI/LLM security | MCP testing | OSINT | Attack chain development

Red Team Engagements

Full-scope adversarial simulations testing people, processes, and technology to validate detection and response capabilities

  • Multi-stage attack simulation
  • C2 infrastructure setup & management
  • Lateral movement demonstration
  • Domain escalation scenarios
  • Physical security bypass

AI/LLM Red Teaming

Adversarial testing of AI/ML systems for prompt injection, jailbreaks, data leakage, and model manipulation

  • Direct & indirect prompt injection
  • LLM jailbreak techniques
  • Training data extraction attempts
  • Model poisoning detection
  • AI output manipulation testing

AI Chatbot & RAG Security

Comprehensive security testing of conversational AI, chatbots, and Retrieval-Augmented Generation systems

  • Business logic abuse scenarios
  • PII leakage through conversations
  • Context manipulation attacks
  • RAG document retrieval exploits
  • Vector database poisoning
  • MCP (Model Context Protocol) testing

MCP Testing

Security assessment of MCP implementations connecting AI models to external tools and data sources

  • Tool injection via MCP
  • Context window manipulation
  • Resource access bypass
  • Prompt leakage through MCP
  • Cross-session data contamination

Attack Chain Development

Building sophisticated kill chains from initial access to impact, demonstrating real-world adversary capabilities

  • Zero-day research & exploitation
  • Custom exploit development
  • Privilege escalation paths
  • Persistence mechanism testing
  • Data exfiltration simulation

OSINT

Open-source intelligence gathering to identify exposed assets, credentials, and attack surface

  • Passive reconnaissance (no contact)
  • Active enumeration techniques
  • Credential leak discovery
  • Subdomain & asset discovery
  • Employee social media analysis
  • Dark web monitoring setup

Security Research

9 CVEs discovered | Responsible disclosure | GitHub Security Advisories

CVE-2026-28798
CRITICAL

ZimaOS SSRF via Proxy Endpoint

Server-Side Request Forgery in ZimaOS proxy endpoint (/v1/sys/proxy) allowing unauthenticated access to internal services when Cloudflare Tunnel is enabled

IceWhaleTech/ZimaOS
CVSS: 9
CVE-2024-28232
MEDIUM

CasaOS Username Enumeration Bypass

Bypass of CVE-2024-24766 fix - username enumeration through error codes in login page

IceWhaleTech/CasaOS-UserService
CVSS: 6.2
CVE-2024-24766
HIGH

CasaOS Observable Response Discrepancy

Username enumeration through different error messages: "User does not exist" vs "Invalid password"

IceWhaleTech/CasaOS-UserService
CVSS: 7.5
CVE-2024-24767
CRITICAL

CasaOS Missing Rate Limiting

No restriction on excessive authentication attempts - 271 login attempts possible in 56 seconds enabling brute force attacks

IceWhaleTech/CasaOS-UserService
CVSS: 9.8
CVE-2024-48931
HIGH

ZimaOS Path Traversal

Path traversal in /v3/file API endpoint allowing authenticated users to read sensitive system files including /etc/shadow

IceWhaleTech/ZimaOS
CVSS: 7.5
CVE-2024-48932
HIGH

ZimaOS File Upload Vulnerability

Arbitrary file upload vulnerability in ZimaOS allowing potential remote code execution

IceWhaleTech/ZimaOS
CVSS: 7.8
CVE-2024-49357
HIGH

ZimaOS Authentication Bypass

Authentication bypass vulnerability in ZimaOS API endpoints

IceWhaleTech/ZimaOS
CVSS: 8.2
CVE-2024-49358
MEDIUM

ZimaOS Privilege Escalation

Privilege escalation vulnerability allowing unauthorized access to admin functions

IceWhaleTech/ZimaOS
CVSS: 6.5
CVE-2024-49359
MEDIUM

ZimaOS Information Disclosure

Information disclosure vulnerability exposing sensitive configuration data

IceWhaleTech/ZimaOS
CVSS: 6

Technical Capabilities

Offensive security expertise across multiple domains

Red Teaming

Full-scope adversarial simulations, APT emulation, C2 infrastructure

AI/LLM Security

Prompt injection, jailbreaks, model poisoning, training data extraction

AI Chatbot Testing

Business logic abuse, PII leakage, context manipulation, RAG security

MCP Testing

Model Context Protocol security, tool injection, context manipulation

Penetration Testing

Web, Mobile (Android/iOS), API, Network, Thick Client, IoT

Web Application Security

OWASP Top 10, SSRF, XXE, RCE, Auth bypass, Business logic flaws

Attack Chain Development

Multi-stage kill chains, zero-day research, custom exploit development

Mobile Security

Android/iOS app testing, reverse engineering, Frida, Objection

Vulnerability Management

Nessus, Burp Suite, Metasploit, Nuclei, Custom automation

OSINT

Reconnaissance, credential discovery, asset enumeration, dark web monitoring

Wireless & IoT

WiFi, Bluetooth, RFID, Hardware security, SDR, Firmware analysis

Thick Client

Desktop application testing, memory corruption, DLL injection, sandbox bypass

Certifications

Industry-recognized security credentials

Licensed Penetration Tester (Master)

EC-Council

February 2023

Verify Credential

Certified Penetration Tester (CPENT)

EC-Council

February 2023

Verify Credential

DIAT Certified Information Assurance Professional

DRDO

May 2021

CNSS Certified Network Security Specialist

ICSI, UK

May 2020

Bug Bounty Profiles

Active vulnerability disclosure on leading bug bounty platforms

Personal Achievements

Bug Bounty Hall of Fame

NestForms

Recognized for responsible disclosure of security vulnerabilities

Bounty Reward & Appreciation

IndiaMART

Monetary bounty for critical vulnerability disclosure

Hardware CTF - 2nd Place

IoTSecurity101 @ Security BSides Ahmedabad 2023

Hardware security competition involving embedded device penetration testing, desoldering, and chip-level analysis

View Recognition

EC-Council Featured Story

EC-Council

Featured for CPENT certification journey and offensive security career path

View Recognition

9 CVEs Discovered

Security Research

Independent vulnerability research resulting in 9 CVE assignments including critical SSRF (CVSS 9.0) and authentication bypass (CVSS 9.8)

View Recognition

Note: CVE discoveries and bug bounties are independent security research. Professional penetration testing and red team engagements are conducted through Sumasoft Pvt. Ltd.

Education

MSc in IT Technology

Savitribai Phule Pune University

202293%

BSc in Computer Science

Savitribai Phule Pune University

202074%

Available For Engagements

Accepting select red team engagements, AI security assessments, and security consulting opportunities. Reach out to discuss how I can help identify critical vulnerabilities in your environment.

Need a security assessment that goes beyond automated scans?

Let's discuss how I can help uncover the vulnerabilities that matter.