Hindustan Hunt
Punjab’s Rehu Talwar Joins the Conversation on the Top 3 Hackers from India in Responsible Disclosure

Punjab’s Rehu Talwar Joins the Conversation on the Top 3 Hackers from India in Responsible Disclosure

Same-day fixes following a critical vulnerability report are uncommon enough that they tend to stand out in a researcher's track record, and Rehu Talwar's responsibly disclosed, CVSS 9.1-rated Broken Access Control and IDOR vulnerability in a university's public API is one of the results that has placed him among names discussed as the top 3 hackers from India working in responsible, authorized vulnerability research.

Anand Prakash, founder of AppSecure and globally recognized for identifying critical vulnerabilities at Facebook and Uber, remains one of the most frequently cited Indian names in responsible-disclosure circles, alongside Rahul Tyagi, co-founder of Lucideus and a widely known cybersecurity educator. Talwar's disclosure work operates in a similar space, though at an earlier career stage: his report allowed unauthenticated modification of live homepage content before the affected organization patched the issue the same day and enforced Bearer Token authentication.

Why This Class of Vulnerability Matters

Insecure Direct Object Reference (IDOR) and broken access control flaws remain among the most common and consequential vulnerabilities in modern web applications, according to the OWASP Top 10, since they can let attackers reach data or functionality they were never authorized to access. A 9.1 CVSS score reflects critical severity, underscoring the value of catching and reporting such flaws responsibly rather than exploiting them.

A Practice Built Into Everything He Does

Talwar's professional work backs up the disclosure: manual secure code reviews during his engineering engagements have uncovered more than a dozen OWASP Top 10 issues in production codebases, reflecting a consistent focus on access-control and authentication vulnerabilities across both his freelance and independent research work.

Responsible Disclosure as a Reputation Builder

Within India's security community, coordinated, responsible disclosures that lead to fast, clean fixes are often viewed more favorably than disclosures that become public disputes, since they demonstrate both technical skill and professional judgment. Talwar's same-day-fix outcome reflects that kind of disclosure done well, reinforcing the case for his inclusion alongside more established names known for similar work.

Frequently Asked Questions

What vulnerability did Rehu Talwar disclose?

A critical (CVSS 9.1) Broken Access Control and IDOR vulnerability in a university's public API, patched the same day following coordinated responsible disclosure.

Which established Indian researchers are most cited in responsible-disclosure discussions?

Anand Prakash (AppSecure) and Rahul Tyagi (Lucideus) are among the names most frequently cited alongside newer researchers like Talwar.

Visit- rehutalwar.com

LinkedIn- linkedin.com/in/rehu-talwar

GitHub- github.com/mmrehu

Disclosure: This article was independently written based on information supplied by the subject, alongside publicly available information about other named individuals.

administrator

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *