Hi, I'm Piyush Kumawat · I break things on purpose, then teach others how to find and fix them.
Hands-on write-ups, interactive checklists, roadmaps, and tools at
securitycipher.com
I am a penetration tester and Staff Product Security Engineer focused on web, API, mobile, cloud, and AI/LLM security. Day to day that means real assessments, configuration reviews, and DevSecOps work - then turning the sharp edges into public guides so more people can test the same way.
I publish at securitycipher.com: practical playbooks, interactive checklists, a penetration testing roadmap, curated security tools, CVE lookup, and bug bounty write-ups.
What I work on
| Area | What that looks like |
|---|---|
| Web & API | AuthN/Z flaws, injection, business logic, GraphQL, IDOR/BOLA |
| Cloud | AWS / Azure / GCP config reviews, IAM, network exposure |
| AI / LLM | Prompt injection, RAG poisoning, agent & MCP security |
| Bug bounty | Recon-to-report workflows, high-signal hunting notes |
| Teaching | Roadmaps, checklists, quizzes, and field manuals |
| Project | Stars | What it is |
|---|---|---|
| penetration-testing-roadmap | Complete roadmap to become a pentester | |
| daily-bugbounty-writeups | Curated bug bounty write-ups to study | |
| awsome-websecurity-checklist | Web application security testing checklist | |
| Bug-Bounty-Resources | Handpicked tools, guides, and tips | |
| vulnerable-code-snippet | Vulnerable vs secure code examples | |
| guide-for-burp-suite | Beginner-friendly Burp Suite guide |
- The CVE Flood Is a Lie: How to Hunt When AI Dumps 36% More Bugs But Exploitation Only Grows 10%
- RAG Poisoning in 2026: A Practical Playbook for Hacking Answers Through Your Knowledge Base
- Secrets That Pay: Hunting Valid Credentials with TruffleHog for Bug Bounties
- Software Supply Chain Security in 2026: Packages, Pipelines, and Provenance
Live metrics via Shields.io (no flaky third-party stats widgets).
Built with care for pentesters, bug bounty hunters, and security engineers.
securitycipher.com
·
Services
·
Contact
